Categories
Securities Regulation

Commissioner Kara Stein Offers a Vision for Data at the SEC

Thank you, Michael [Barr], for that kind introduction.  Thank you also to the University of Michigan and the Office of Financial Research for organizing this important conference.  I am pleased to be here with you today.  This conference is a vital opportunity to discuss some of the forces shaping financial markets and regulation.

“What hath God wrought.”  That message, sent from Washington to Baltimore in 1844, signaled the arrival of the telegraph.  Originally an exclamation, but sometimes written as a question, it captures both the wonder and uncertainty that new technologies can inspire.[1]  The telegraph proved to be a transformative technology.  Information was no longer limited by the speed of a horse, but could spread almost instantaneously.  Farmers in one part of the country could learn about prices in distant markets, and an expanding country would soon communicate from one coast to another.[2]

The transformation of knowledge that began with the telegraph has continued for more than a century.  Over the last several decades, in particular, the amount of data, and our capacity to store and process it, has grown at an astounding rate. These technologies have touched nearly every endeavor, including science, healthcare, and, of course, finance.  Even the Bard has felt the effect – thanks to text analysis, Shakespeare will now have to share credit for several plays with Christopher Marlowe.[3]

Railroads and telegraphs, then automobiles and telephones, fundamentally re-shaped society.  By connecting distant locations with greater speed, they created new avenues for spreading goods and knowledge.  The result was increased prosperity, convenience, and efficiency.  The current revolution in data similarly allows us to make novel connections.  However, instead of connecting physical locations, we’re connecting data points to uncover new insights.  The result may be another leap forward in how knowledge develops and spreads.

But you know all this.  Today, I want to drill down a little and talk about how these developments are affecting the financial markets and the SEC in particular.  Specifically, I want to discuss four broad themes: the new opportunity data provides, why the SEC must keep up with data’s growing role in the markets, some of the challenges to keeping up, and some ideas for overcoming these challenges.  I am going to focus on my perspective as a Commissioner at the SEC, but these themes likely have relevance to other financial regulators as well.  Ultimately, regulators are being disrupted by new technology, and it is important to focus on what we should be doing about it.

However, before going further, let me say that my remarks today and the views I express are my own, and do not necessarily reflect the views of my fellow Commissioners or the staff of the SEC.

The new opportunity

Information – particularly fast and reliable information – has always been central to the financial markets.  For example, shortly after the development of the telegraph, brokers began leasing their own telegraph lines so they could receive pricing information faster.[4]

The securities laws, in large part, can be understood as a set of rules about information.  What information is useful for public dissemination?  How should we ensure that it is accurate and reliable?  Does fairness require everyone to have the information at the same time?  How do you protect nonpublic information?  What information is necessary for price discovery?  The federal securities laws speak to all of these questions.

In this sense, “big data” is a continuation of an old theme.  In another sense, the developments in data over the last 10 to 15 years represent a wholly new phenomenon, in the same way that satellite imaging is completely different from surveying a landscape from the top of a hill.  At that scale, patterns become evident that would have been impossible to piece together by considering one plot at a time.

This means that both market participants and regulators have new opportunities for developing knowledge.  Moreover, this is a qualitatively different kind of knowledge, encompassing entire data sets in one pass rather than slowly accumulating insight from individual experiences.

Market participants have already seized this opportunity.  They are using a wide range of data sources to cull signals about possible market movements.  Among these data sources is information that the SEC makes available, the demand for which is enormous.  In the last year, our website received over seven billion page views – that’s more than some major media sites.  We also delivered more than two petabytes of data to visitors.  I recall, not long ago, when a gigabyte seemed like a lot of data.

The SEC itself is also beginning to realize some of the potential of new data tools.  In a recent case, we obtained a settlement against a large broker-dealer for its failure to adequately train its representatives, when they were selling certain complex debt instruments.[5]  What made the case unique was that, instead of traditional investigative techniques, it was built on custom analytics.  SEC industry specialists, working with a team of tech experts, developed tools to sift millions of trading records.[6]  Using this technique, they were able to identify over 8,000 retail customers for whom the investment in the complex debt instruments was inappropriate.  A case like this may not have been possible in the past.

I believe, however, that enforcement is not the most important potential use of data for the SEC.  By the time we start building a case, the harm has been done.  I am much more interested in establishing rules of the road that can help prevent crashes than in waiting to deal with the aftermath.  Better investor protection is avoiding fraud and misconduct in the first place.  The key question is how can we design policies and monitoring systems that support healthy market function and aid in compliance on the front end?  Improved data tools have the potential to be uniquely powerful in this way.  They can allow us to make better, more tailored policy choices that focus on actual risks to investors and the market.  This approach will never replace the need for humans and human judgment, but it can improve the markets and help us make smart use of our limited resources.

The risk of being left behind

Data and technology present tremendous opportunities and benefits – but they have also opened the door to new and exceedingly complicated risks.  Data is distributed across a range of electronic platforms, complicating the task of monitoring and examining market participants.  Moreover, the variety of data has increased dramatically.  This includes highly structured derivative transactions that are reported in competing taxonomies, such as FIX and FpML, as well as unstructured information, like social media posts and narrative reports.[7]  As a result, in addition to being an exciting opportunity, the spread of data and data tools also requires the SEC to make changes to keep up.

A number of recent developments highlight this need.  Today’s electronic trading environment has significantly changed the capital markets.  Algorithms called “matching engines” match electronic limit orders with electronic market orders.  High-speed trading dominates, representing over 55% of US equity markets.[8]  And liquidity provision has largely shifted from traditional market-makers to computerized systems that trade in fractions of a second across different trading venues and securities.[9]

When the flash crash happened on May 6, 2010, equities markets suddenly plunged and then rebounded.  In contrast to the incredible speed of this disruption, it was months before the SEC and CFTC were able to gather the necessary information, churn through the data, and produce an analysis of trading on that one day.[10]  I was working in the Senate at the time, and I remember the uncertainty as we waited to understand whether the disruption signaled a vulnerability and whether it would happen again.  Since then, the financial markets have experienced other temporary disruptions and mini-flash crashes.

These events implicate data both in their causes and in the ability of regulators to understand and respond.  They also highlight the risk for regulators of driving a carriage in the age of Tesla – by the time you’re pulling out of the stable, everyone else’s autopilot will have passed you by.

Since the flash crash, the SEC has made some steps toward developing enhanced monitoring capabilities.  The SEC has, for instance, created the “Market Information Data Analytics System,” or MIDAS.  MIDAS combines information from the consolidated tape and separate proprietary feeds to create a more complete picture of equity market activity.[11]  We need to go further, though.  The SEC soon will consider a plan to create the largest data repository of securities trading activities that has ever existed.  This is widely known as the “consolidated audit trail,” or CAT.[12]  This unprecedented data effort will help us, finally, move at highway speeds.

The SEC’s statutory mission involves three core objectives – to protect investors, to maintain fair and orderly capital markets, and to facilitate capital formation.  The SEC’s mission is not changing in the Digital Age, but our tools for carrying out that mission must.  We simply cannot be effective or efficient without a strategic approach to our mission, financial markets, and data.

Challenges to keeping up

So, recognizing that the growth in data represents both an opportunity and a necessity, how can the SEC best position itself to respond?  There are a number of challenges.  I am not going to address these exhaustively, but I want to talk about several that are critical.

The first condition to success is acquiring the right data.  We need data that is relevant, timely, and high quality.  This is not about simply increasing the volume of data – this requires being smart about the data we gather.  When you want an apple, chopping up the tree usually isn’t the most efficient way to get it.  We must instead carefully consider our possible sources, data gaps, and reporting methods.  Where we mandate reporting, how can we ensure that our requirements keep pace with a quickly evolving market?  Can we design reporting requirements so that our resources are spent on analysis instead of cleaning data sets?  These are challenging, but important, questions that require a forward-looking approach.

Another condition to success is ensuring that computers can quickly and reliably interpret the data.  Structured data can be an important part of this.  SEC reporting in the last few years has begun to embrace better practices for structured data.  For instance, we recently adopted reporting requirements for mutual funds and ETFs that will require the use of XML.[13]  Our existing Form PF, on which hedge fund managers report, also uses XML.  Where structured data is not available or reliable, we should continue to explore techniques that allow better parsing of unstructured data.

We should also embrace identifiers, like the “legal entity identifier,” or LEI.  I remember vividly the uncertainty following Lehman’s collapse.  Regulators and counterparties were left to sort through the rubble, trying to piece together the consequences.[14]  It was a problem of modern complexity but without an equivalently modern solution.  LEI helps solve that problem by providing a uniform and reliable way to identify counterparties.[15]  This frees regulators to focus on the financial risks instead of data issues.  The new mutual fund reporting forms also include an important new requirement for funds to obtain an LEI.

Growing use of XML and LEI are important steps.  However, we can still do more to ensure that we have data that is ready for efficient analysis.

Another significant challenge is limited resources.  Using data effectively depends both on having people with specialized skills and sophisticated systems.  In addition to our excellent staff of lawyers and accountants, we need more professionals with the right technical skills.  Our systems and software also need to keep up with the speed and volume of today’s markets.  Our main information reporting system, EDGAR, was a huge leap forward 20 years ago, but it is ancient in tech years.  With a limited budget and an ever-evolving market, we may never drive the latest model.  We must, however, find a way to keep pace.

We also need to remain vigilant about protecting proprietary information.  Cybersecurity is a constantly evolving risk – the latest large-scale attacks in the news, directed at certain internet utilities, may have been launched using webcams.[16]  As a result, we have to be creative and dynamic in developing responses.

We must also ask how new data tools can improve our ability to deliver decision-useful information to investors.  I have spoken before on the need to create a Digital Disclosure Task Force to help us reimagine how the SEC acquires and provides data to investors and market participants.[17]  I believe that we have an opportunity to reduce the burden on companies while at the same time providing better disclosure to investors.

Another condition to success is that we never lose sight of the human element.  No matter how powerful the processor, at the end of the day, humans develop the assumptions and metrics, design the analyses, program the algorithms, and interpret the results.[18]  The housing crisis forcefully reminded us that models are built from assumptions chosen by humans, and those can be fallible.  Human biases are as much a part of digital databases and computer analysis as they are any other source of knowledge.  Accordingly, we must approach them with the same judgment, caution, and safeguards.

The final challenge I want to touch on is one of leadership.  Success here depends on drawing together an array of expertise and making decisions with limited resources and within limited budgets.  This cannot be done without a vision.  The vision needs to be accompanied by a detailed roadmap and effective management.  Without these, we risk missing the opportunity that data can provide.

Meeting the challenges

How can the SEC meet the challenges of developing and using data effectively?  In recent years, we have made some progress.  An important part of this has been the growth of our Division of Economic Research and Analysis, or DERA, as well as several other groups that include analysts, quants, and economists (and even a physicist).  These include talented folks in the Risk and Examinations Office in Investment Management, the Risk Analysis Examination Team in our exams office, and the Center for Risk and Quantitative Analytics in Enforcement.  These groups have advanced our ability to handle data with rigor.  They have also played an important role in everything from identifying risk to informing policy and conducting investigations.  In addition, we have made some progress on the systems front with the development of MIDAS and, hopefully, in the near future, the advancement of CAT.

But more needs to be done, and it needs to be smart.

An important part of defining our vision should be the creation of an Office of Data Strategy.[19]  For some time, I have asked that the SEC develop an executive team responsible for creating and overseeing such an office.  The office would be responsible for coordinating the creation of a data strategy addressing how we collect, manage, use, and provide data.  This is a critical next step in turning our ad hoc growth as data users into a deliberate plan.  The office could lend its expertise to, and would coordinate with, our policy, exam, and enforcement offices.  Having a data strategy, and a team dedicated to it, is especially important in light of our limited resources.

Just as the telegraph ushered in a new information era, the spread of data and data tools is changing how information is used and shared.  The promise is tremendous, and if the SEC can successfully harness the new technology, investor protection, financial stability, and the markets will all benefit.

Thank you again for inviting me to talk with you all.  You are engaged in a fascinating and important conversation, and I look forward to hearing about your new ideas in this area.

ENDNOTES

[1] See Daniel Walker Howe, What Hath God Wrought: The Transformation of America, 1815-1848 (Oxford History of the United States) (2007).

[2] Id.

[3] See Travis M. Andrews, Big Debate About Shakespeare Finally Settled by Big Data: Marlowe Gets His Due, The Washington Post (Oct. 25, 2016), available at https://www.washingtonpost.com/news/morning-mix/wp/2016/10/25/big-data-helps-put-centuries-old-shakespearean-debate-to-rest/.

[4] The first telegraph lines became operational in 1844.  The first stock ticker followed in 1867. “In 1873, brokers began leasing private telegraph lines to obtain pricing data faster and execute trades earlier.” Jason Zweig, Wall Street, 1889: The Telegraph Ramps Up Trading Speed, The Wall Street Journal (Jul. 7, 2014), available at http://www.wsj.com/articles/wall-street-1889-the-telegraph-ramps-up-trading-speed-1404765917.  See also Tom Standage, The Victorian Internet:  The Remarkable Story of the Telegraph and the Nineteenth Century’s On-Line Pioneers (1998).

[5] See SEC Charges UBS with Supervisory Failures in Sale of Complex Products to Retail Investors (Sept. 28, 2016), available at https://www.sec.gov/news/pressrelease/2016-197.html. See also In the Matter of UBS Financial Services, SEC Release No. 78958 (Sept. 28, 2016), available at https://www.sec.gov/litigation/admin/2016/34-78958.pdf.

[6] Id. (“We can now analyze literally hundreds of millions of trading records using sophisticated coding techniques that allow us to build platform wide cases rather than cases built investor by investor.”).

[7] See Establishing the Form and Manner with which Security-Based Swap Data Repositories Must Make Security-Based Swap Data Available to the Commission, SEC Release No. 34-76624 (Dec. 11, 2015), available at https://www.sec.gov/rules/proposed/2015/34-76624.pdf.

[8] Austin Gerig, High-Frequency Trading Synchronizes Prices in Financial Markets, DERA Working Paper Series (Jan. 2015), available at  http://www.sec.gov/dera/staff-papers/working-papers/dera-wp-hft-synchronizes.pdf.

[9] Austin Gerig & David Michayluk, Automated Liquidity Provision, DERA Working Paper Series (Dec. 2014), available at  http://www.sec.gov/dera/staff-papers/working-papers/dera-wp-automated-liquidity-provision.pdf.

[10] See Findings Regarding the Market Events of May 6, 2010, Report of the Staffs of the CFTC and SEC to the Joint Advisory Committee on Emerging Regulatory Issues (Sept. 30, 2010), available at https://www.sec.gov/news/studies/2010/marketevents-report.pdf.

[11] See https://www.sec.gov/marketstructure/midas.html.

[12] See Joint Industry Plan; Notice of Filing of the National Market System Plan Governing the Consolidated Audit Trail by…, SEC Release No. 34-77724 (Apr. 27, 2016), available at https://www.sec.gov/rules/sro/nms/2016/34-77724.pdf.

[13] See Investment Company Reporting Modernization, SEC Release No. IC-32314 (Oct. 13, 2016), available at https://www.sec.gov/rules/final/2016/33-10231.pdf.

[14] See Data & Standards, Legal Entity Identifier (LEI), Office of Financial Research, available at https://www.financialresearch.gov/data/legal-entity-identifier/.

[15] https://www.treasury.gov/initiatives/wsr/ofr/Documents/LEI_FAQs_August2012_FINAL.pdf

[16] See Nate Lanxon, et al., Connected Gadgets Blamed as Internet Recovers From Friday Attack, Bloomberg (Oct. 22, 2016), available at https://www.bloomberg.com/news/articles/2016-10-22/connected-gadgets-blamed-as-internet-recovers-from-friday-attack.

[17] See, for example, Disclosure in the Digital Age: Time for a New Revolution (May 6, 2016), available at https://www.sec.gov/news/speech/speech-stein-05062016.html.

[18] See Nanette Byrnes, Why We Should Expect Algorithms to Be Biased, MIT Technology Review (Jun. 24, 2016), available at https://www.technologyreview.com/s/601775/why-we-should-expect-algorithms-to-be-biased/?set=601766; Claire Cain Miller, When Algorithms Discriminate, New York Times (Jul. 9, 2015), available at http://www.nytimes.com/2015/07/10/upshot/when-algorithms-discriminate.html?_r=0.

[19] See, for example, The Dominance of Data and the Need for New Tools: Remarks at the SIFMA Operations Conference (Apr. 14, 2015), available at https://www.sec.gov/news/speech/2015-spch041415kms.html.

The preceding remarks were delivered by SEC Commissioner Kara M. Stein on October 28, 2016, as the keynote address to the Big Data in Finance Conference. A copy of the remarks is available here.

Categories
Corporate Governance The Dodd-Frank Act

Latham & Watkins Discusses New SEC Guidance on CEO Pay Ratio Rules

The staff of the Division of Corporation Finance of the Securities and Exchange Commission (SEC) has issued new guidance on the SEC’s rules requiring companies to disclose the pay ratio between their CEO and median compensated employee. The staff’s new Compliance and Disclosure Interpretations (the C&DIs) provide helpful clarity on how to determine the relevant employee population and the median employee for purposes of the ratio, although questions remain.

Background

In  August 2015, pursuant to Section 953(b) of the Dodd Frank Act, the SEC adopted the CEO pay ratio rules (the Rules), which added a new Item 402(u) of Regulation S-K requiring companies to disclose annually the:

  • Median of the annual total compensation for all employees of the company except the CEO
  • Annual total compensation of the chief executive officer (the CEO)
  • Ratio of the two

The Rules are effective for fiscal years beginning on or after January 1, 2017, so the CEO pay ratio disclosure will be required in the 2018 proxy season. Companies subject to the Rules should begin to evaluate their ability to comply and their disclosure strategies.

Emerging growth companies, smaller reporting companies, foreign private issuers, registered investment companies and US-Canadian Multijurisdictional Disclosure System filers are exempted from this disclosure requirement.

Key Determinations and Impact of the C&DIs

Determining the employee population

For purposes of calculating the pay ratio, companies are required to determine the relevant employee population from which to find the median employee based on all employees (including all worldwide full-time, part-time, seasonal or temporary workers, subject to certain limited exceptions) employed as of a date selected by the company within the last three months of the company’s last completed fiscal year.

Under the Rules, independent contractors and “leased” workers who are employed by, and whose compensation is determined by, an unaffiliated third party are excluded from the determination of “all employees” for purposes of the pay ratio calculation.

  • Guidance on inclusion of independent contractors. The C&DIs clarify that the services of workers obtained by contracting with an unaffiliated third party may be excluded even if the company specifies that those workers receive a minimum level of compensation.

The C&DIs also clarify that an individual who contracts directly with the company as an independent contractor may also be excluded, if the individual determines his or her own compensation. However, contractors whose pay is pre-set by the company, without deviation, likely cannot be excluded. The rules are ambiguous on how to treat contractors who negotiate their compensation, and whether or not a particular contractor or set of contractors is excluded is likely a case-by-case facts-based determination.

Finding the “median employee”

The Rules do not mandate any specific method for identifying the median employee. The median employee may be identified using annual total compensation or any other consistently applied compensation measure (CACM) to all employees included in the calculation, such as information derived from tax or payroll records (e.g., W-2 reportable wages). Also, in determining the employees from which the median is identified, a company is permitted to use its employee population, statistical sampling or other reasonable methods.

Under the Rules, companies may annualize the compensation for all permanent employees (other than those in temporary or seasonal positions) who were not employed for the entire fiscal year, such as a new hire or an employee who took an unpaid leave of absence during the period. However, the Rules do not permit full-time equivalent adjustments for part-time employees, or annualizing adjustments for temporary or seasonal employees.

  • Guidance on consistently applied compensation measure or CACM. The C&DIs provide that any measure that reasonably reflects the annual compensation of employees can serve as a CACM, and that the appropriateness of the measure will depend on the company’s particular facts and circumstances. The C&DIs provide two examples: (1) total cash compensation could be a CACM unless the company distributed annual equity awards widely among its employees; and (2) Social Security taxes withheld would not be a CACM unless all employees earned less than the Social Security wage base.
  • Period for measuring CACM. The C&DIs also clarify that a CACM used to identify the median employee may cover a time period that is not a full annual period, and does not need to include the date on which the employee population was determined. In addition, the CACM may cover the company’s prior fiscal year so long as there has not been a change in the company’s employee population or employee compensation arrangements that would result in a significant change of its pay distribution to its workforce. This helps clarify that companies may use shorter periods than annual periods for determining the CACM. For example, based on this guidance an employer could choose a selected representative month’s payroll as a CACM, as long as the month is reasonably reflective of the annual compensation of the employees.
  • Hourly or annual rates of pay not an appropriate CACM. The C&DIs provide that a company may not use an hourly rate of pay as a CACM without taking into account the number of hours actually worked as that would be similar to making a full-time equivalent adjustment for part-time employees, which is not permitted by the Rules. Similarly, a company may not use an annual rate of pay without taking into account whether the employees worked the entire year and the amount actually paid during that time, as this is similar to annualizing pay, which is only permitted in the limited circumstances described above.
  • Adjustments to pay for furloughed employees. The C&DIs provide that the treatment of furloughed employees depends on the categorization of the employee (e., full-time, part-time, temporary or seasonal). A company may annualize the total compensation for all permanent employees (full-time or part-time) that were employed by the registrant for less than the full fiscal year, or who were on an unpaid leave of absence during the period. In contrast, a company may not annualize the total compensation for employees in temporary or seasonal positions.

Determining the median employee’s and the CEO’s total compensation per Item 402 of Regulation S-K, and disclosing the CEO pay ratio

Although a CACM can be used to determine the median employee, once the median employee is identified, the company then needs to calculate that one median employee’s annual “total compensation” in accordance with the requirements of Item 402 of Regulation S-K in order to determine the pay ratio. A CACM cannot be used for this purpose.

This post comes to us from Latham & Watkins LLP. It is based on the firm’s client alert, “New SEC Staff Guidance on CEO Pay Ratio Disclosure Rules – Determining the Median Employee,” dated October 31, 2016, and available here.

Categories
Finance & Economics The Dodd-Frank Act

Morrison & Foerster explains why CFPB Makes FinTech Headlines

The Consumer Financial Protection Bureau (the “CFPB” or “Bureau”) made headlines in FinTech on October 24, 2016. First, the Bureau released its first-ever Project Catalyst report on promoting consumer-friendly innovation (the “Report”). The Report summarizes the work conducted by Project Catalyst to date and sets forth in broad strokes some of the financial innovations that the CFPB is encouraging. While the Report does not represent new policy, it provides a helpful glimpse into the key developments in financial services that the Bureau is encouraging or monitoring.

On the same day, Director Richard Cordray addressed Money 20/20 in Las Vegas, Nevada, covering a range of FinTech issues that affect consumers. Key points from the Director’s remarks are identified below.

The CFPB launched Project Catalyst in November 2012 as a means of achieving Congress’ statutory directive to the agency to “operate transparently and efficiently to facilitate access and innovation.” The Report highlights Project Catalyst’s work to date and describes a number of innovative market developments that have the potential to benefit consumers. The Report also highlights Catalyst’s efforts to engage with industry stakeholders and government agencies through Project outreach and conversations, including through its “office hours” program. The Report notes the “Trial Disclosure Waiver Policy” and “No-Action Letter Policy” as two initiatives developed by the CFPB to help facilitate innovation, but does not provide empirical data about the effectiveness of these policies. The Report, however, does highlight a number of collaborative research and testing projects that the Bureau has conducted with various companies, such as testing methods of promoting consumer saving among prepaid card users. The CFPB said that it welcomes additional testing of innovations that have the potential to serve consumers’ financial needs, either with or without CFPB collaboration.

Aside from reporting on Project Catalyst’s work, the Report also highlights market innovations that the CFPB believes have the potential to benefit consumers. The CFPB expressed a commitment to using its policies and programs to help facilitate innovation in the following areas:

  • Cash flow management, including tools and services that allow a consumer to “smooth” his or her income, access accrued wages earlier than his or her regular payday, or deduct a portion of his or her wages and set it aside for future recurring payments.
  • Improved credit assessment, including potential opportunities for creditors to use non-traditional underwriting data or machine learning to help create an effective credit scoring model for consumers who are “credit invisible,” while being mindful of potential risks associated with new underwriting methods.
  • Consumer financial data access, including tools that allow consumers to permit personal financial management tools to access data. In his Money 20/20 remarks, Director Cordray strongly endorsed open financial data, stating that the Bureau is “gravely concerned” that financial institutions are limiting or shutting off access to financial data, rather than “exploring ways to make sure that such access…is safe and secure.” The Director continued: “Let me state the matter as clearly as I can here: We believe consumers should be able to access this information and give their permission for third-party companies to access this information as well.”
  • Student lending and refinancing, noting that some FinTech companies have reported that incumbent servicers may create obstacles for new entrants to enter the student loan refinancing market, such as precluding such a lender from obtaining an accurate payoff balance from the originator.
  • Mortgage servicing platforms, specifically, servicer efforts to replace legacy systems with modern technology platforms that improve loan servicing through features such as automated reconciliations and user-friendly interfaces.
  • Credit reporting accuracy and transparency, acknowledging that industry participants ranging from incumbent banks to FinTech startups are offering consumers more information about their credit scores and credit reports on a more regular basis than has been the case historically. The Bureau also recognized that new tools and services are being used to help consumers understand how their actions may affect their credit standing and help prompt consumers to make beneficial changes in their behaviors.
  • Peer-to-peer payments, noting that many companies are working to develop services that allow consumers to make peer-to-peer transfers more quickly and at lower cost.
  • Savings, noting that some companies are creating tools to help consumers automate their choices to save money and help advise consumers as to how much they can afford to save.

Throughout the Report, the CFPB makes clear that the agency does not believe that FinTech companies receive special regulatory treatment as compared to industry incumbents. The Report states that it is “especially important for banks and non-banks to be held accountable to the same compliance standards and oversight, which is known as the level playing field that the Bureau is working to achieve.”

In his Money 20/20 remarks, Director Cordray reiterated this “equal treatment” point: “Everyone who provides consumers with financial products and services must adhere to the same standards and will be held to the same expectations. [The Bureau is] not looking to punish anyone merely for raising novel issues that present unsettled points of law or questions that fall into unforeseen cracks in the regulatory framework.”

Director Cordray’s remarks also are noteworthy because of the position he articulated for the Bureau related to safe and secure—but open—access to consumers’ financial data. Noting that some financial institutions have declined to permit third-party personal financial planning providers to access data concerning the accounts of consumers, the Director suggested that the burden of mitigating information security risks should rest with the financial institution. This approach stands in stark contrast to the approach prudential regulators have taken with respect to information security, under which financial institutions are directed to verify and validate third parties’ risk management and risk mitigation in connection with consumer information sharing and information security.

This post comes to us from Morrison & Foerster LLP. It is based on the firm’s client alert, “CFPB Makes FinTech Headlines,” dated October 26, 2016, and available here.

Categories
Finance & Economics The Dodd-Frank Act

Breaking Up (Banks) Is Hard to Do

The latest Wells Fargo bank scandal has rekindled debates about breaking up banks that are too big to fail, too big to manage or too big to comply.

Echoing the debate between Louis Brandeis and Teddy Roosevelt in the Progressive Era, politicians propose either to break up our huge banks — as Brandeis advocated — or to regulate them, which was Roosevelt’s position. Most Republican presidential primary candidates argued that, while the Dodd-Frank financial reform law overregulates small community banks, the law did not go far enough to eliminate the threat that the huge banks are too big to fail and will inevitably be bailed out in a future crisis. On the Democratic side, Bernie Sanders played the role of today’s Brandeis, while Clinton seems more aligned with TR. The candidates seemed unanimous in the belief that Dodd-Frank did not go far enough to address the hugeness of the megabanks.

Without new laws passed by Congress, what power would a new President and presidential appointees have to break up banks that are too big to fail?

The answer is, not much. Dodd-Frank limits additional growth and market power of the too-big banks, known as systemically important financial institutions (SIFIs), but grants the power to break up banks in only very limited situations. Most of that power is in the hands of the Federal Reserve Board or other bank regulators who serve fixed terms rather than being appointed at the will of the President. The Treasury Secretary is one of nine members of the Financial Stability Oversight Council (FSOC), but that body has mostly advisory powers.

Dodd-Frank allows involuntary breakups only for a financial institution in actual default, i.e. unable to pay its bondholders or depositors, under the orderly liquidation authority (OLA). The idea behind the OLA is that any bank, no matter how big, can be allowed to fail, and the OLA is a roadmap to reorganize or liquidate the failed bank. The OLA procedure does not offer any way to break up a bank that has not already failed.

Dodd-Frank does have a variety of industry concentration limits that affect additional bank growth.  One is embodied in the Fed’s new Reg XX, which prevents one bank from acquiring another  if the resulting bank would have more than 10 percent of the total deposits and other liabilities owed by all banks. Concentration limits, however, don’t provide any means for divesting past mergers and acquisitions.

Even before Dodd-Frank, the federal bank regulators had the power to order divestments, in the context of bank safety and soundness reviews, but only on the grounds of risk to the banks’ own depositors and creditors, not based on broader systemic risk (and certainly not based on repeated consumer protection violations, excessive political power or influence over regulators.)

The closest Dodd-Frank came to authorizing breakups of megabanks because they are too big to fail was Section 121 (the Kanjorski amendment). It allows the Federal Reserve Board, with the approval of two-thirds of the FSOC, to compel a break-up and divestiture of high-risk parts of a bank or financial institution if it poses a “grave threat” to the financial stability of the United States. The current Fed chair, Janet Yellen, is serving a four-year term that ends in 2018, and the other members of the Federal Reserve Board of Governors serve staggered 14-year terms. The FSOC has a few presidential appointees on it but a majority of its members cannot be removed at the will of the President. The President therefore has little ability to appoint those who have the power to enforce the Kanjorksi amendment, which was obviously the product of intense lobbying by the banks to make it extremely difficult to ever break up a bank solely because its size poses a systemic risk.

There are a few other possible tools to break up megabanks in Dodd-Frank.  A SIFI that fails repeatedly to submit its “living will” plan for orderly liquidation can be ordered to divest, under Section 165(d). Last April, regulators rejected the living wills of five major banks, and ordered them back to the drawing board, , and the banks resubmitted their new and improved plans on October 4..  It remains to be seen whether the regulators will accept these new plans, or resort to the nuclear option of ordering divestments.

Simply being designated a SIFI can nudge institutions (like General Electric or MetLife) to break themselves up to avoid stricter regulatory capital and other rules, but that depends mostly again on independent bank regulators toughening the rules that govern the SIFIs. The Fed recently suffered a setback when a federal district court overruled its designation of MetLife as a SIFI.

In short, breaking up the too-big-to-fail banks will probably require the new President to get new legislation through Congress.

In a recent article, available here, I make the case for rethinking bank regulation on a public utility law model, which would allow regulators to restructure the banking industry, including through vertical and horizontal break-ups. I argue that banks provide essential infrastructure services, are heavily dependent on a variety of taxpayer subsidies and guarantees, and should be subject to more intensive supervision, not just to insure safety and soundness but to advance other public goals, as we do now with energy, transportation, and telecommunications companies.

This post comes to us from Professor Alan M. White of CUNY School of Law. It is based on his recent paper, “Banks as Utilities,” available here.

Categories
Finance & Economics

PwC on Counterparty Credit Limits: Do You Know Where Your Exposures Are?

Over the summer, the Federal Reserve Board (Fed) concluded the comment period on its reproposed single counterparty credit limits (SCCL) rule issued in March 2016.[1] SCCL is intended to reduce systemic risk by limiting a banking organization’s credit exposure to any single unaffiliated counterparty as a percentage of the organization’s capital. The rulemaking applies to organizations with over $50 billion in total consolidated assets, including US bank holding companies (BHCs), intermediate holding companies (IHCs), and foreign banking organizations’ (FBOs)[2] US operations (collectively, “Covered Banks”).

The comments put forth by the industry mainly focus on the reproposed rule’s criteria for determining which affiliates of Covered Banks, as well as those of their counterparties, must be deemed to be one entity for limit setting purposes. Under the reproposal, affiliate consolidation is based on the Bank Holding Company Act’s (BHCA) broad “control test,”[3] a threshold that will combine more affiliates into one single entity than did prior proposals, thereby significantly increasing the likelihood of breaching the rule’s limits. In response, commenters have suggested that affiliate consolidation should instead be based on US GAAP’s higher threshold which is also used by the US’s risk-based capital rules.[4]

Further complicating matters, if a Covered Bank’s exposure to a counterparty exceeds 5% of the Covered Bank’s capital base, the Covered Bank is also required to aggregate its exposures with its other counterparties that are “economically interdependent” with that counterparty, based on an additional set of subjective criteria. Commenters uniformly objected to this requirement, citing the lack of an objective standard for determining economic interdependence. In addition, such a determination would require access to information that is not easily obtainable, as many of the counterparties that would have to be aggregated are not required to report data publicly (and would likely also face legal or competitive impediments by revealing such data).

Commenters also lamented certain other heightened requirements of the reproposal, including daily monitoring of SCCL limits and monthly attestation by the Chief Risk Officer (CRO) that such limits have not been breached. Most Covered Banks’ current processes and systems are not capable of satisfying this monitoring obligation.

We believe the Fed will finalize the reproposal late this year, but we expect it to push back the effective date in order to give Covered Banks more time to be able to comply.[5]

This post analyzes the SCCL reproposal and the most significant issues raised by the industry in comment letters.

SCCL reproposal

The SCCL reproposal was issued after two earlier versions in 2011 and 2012,[6] and almost two years after the related large exposures framework issued by the Basel Committee on Banking Supervision (BCBS).[7] The reproposal defines three tiers of Covered Banks, based on balance sheet assets or foreign exposures, which then determines: (1) limits on credit exposures to unaffiliated counterparties, and (2) types of capital needed to be held against such exposures.

Most restrictively, global systemically important banks (G-SIBs) would have exposures to another G-SIB capped at 15% of Tier 1 capital (T1C) and exposures to any other unaffiliated counterparty capped at 25% of T1C. The table below details these limits, compliance dates, and reporting frequency for exposures of the three tiers of Covered Banks (i.e., G-SIBs, Large Banks, and Small Banks) to unaffiliated counterparties.

Covered Bank Exposure to Exposure limit Compliance & reporting schedule
G-SIBs:

·   > $500Bn in Total Assets

G-SIB 15% of T1C 1 year from effective date:

·   Daily compliance

·   Monthly reporting

 

Non G-SIB 25% of T1C
Large Banks:

·   > $250Bn and < $500Bn in Total Assets or

·   > $10Bn in foreign on-balance-sheet exposures

G-SIB

or

Non G-SIB

25% of T1C
Small Banks:

·   >$50Bn and <$250Bn in Total Assets and

·   < $10Bn in foreign on-balance-sheet exposures

G-SIB

or

Non G-SIB

25% of total capital, plus ALLL[8] 2 years from effective date:

·   Quarterly compliance

·   Quarterly reporting

Analysis

The SCCL reproposal hit a nerve in the banking industry despite making several concessions from earlier proposals. Twenty-five comment letters were submitted, representing a broad array of the industry including industry groups, US BHCs, FBOs, insurance companies, custodians, foreign central banks, and central counterparties (CCPs).

The topics that received the most comments were:
(a) consolidation thresholds, (b) counterparty exposures (economic interdependence, sovereigns, and special purpose vehicles (SPVs)), and (c) other issues:

Consolidation thresholds

Under the reproposal, both Covered Banks and their counterparties are required to consolidate affiliates under their respective controls based on the Bank Holding Company Act’s (BHCA) broad control test.[9]
This consolidation results in an aggregation of the affiliates’ exposures into one larger exposure, for both the Covered Bank and the counterparty.

This BHCA standard for consolidation is broader and more complex than consolidation criteria under US risk-based capital rules and the BCBS’s large exposure framework, both of which are based on a 50% ownership threshold (consistent with US GAAP). As a result, commenters argued that affiliates should only be consolidated based on US GAAP because the BHCA definition would lead to significant operational challenges. Most notably, Covered Banks generally do not monitor exposures of their unconsolidated affiliates (under US GAAP), and often lack enough operational control over such entities to do so. We expect, however, that the Fed will keep the BHCA consolidation criteria in place for both Covered Banks and counterparties when it ultimately finalizes the rule.

In addition, commenters noted that the BHCA’s broad control test would exacerbate the issue of Covered Banks having to monitor counterparties that will not come close to approaching SCCL exposure limits (because Covered Banks and counterparties will have more affiliates to consider under the BHCA’s test). This is particularly true for those affiliates with exposures primarily to individual retail customers (e.g., credit cards, overdrafts) and small businesses (e.g., loans, revolving lines of credit).

Finally, commenters voiced concerns regarding the implications of having to determine control of affiliates under the BHCA’s broad control test. Non-bank counterparties will likely reject requests for information by Covered Banks, including on voting rights, joint venture terms and conditions, and personal family member connection information. This type of information would be needed to determine whether affiliates should be aggregated, but has the potential to lead to privacy or non-disclosure lawsuits. Accordingly, commenters suggested that exposures to small business and individual retail counterparties be exempted.

Counterparty exposures

Economic interdependence

In addition to the consolidation of affiliates based on the BHCA’s broad control test, a Covered Bank is required to aggregate its exposures to its counterparties that are “economically interdependent” with each other, if the Covered Bank’s exposures to one of the counterparties exceeds 5% of the Covered Bank’s capital. These counterparties might be customers of each other, suppliers, or connected in other ways. The review and qualitative determination to establish economic interdependence will be challenging as Covered Banks will have to acquire information about their counterparties that is not easily discernible or readily available from public sources.

Two counterparties are economically interdependent if the answer is “yes” to any of the following seven questions:

  1. Are 50% or more of one counterparty’s gross receipts or gross expenditures derived from transactions with the other counterparty?
  2. Has one counterparty fully or partly guaranteed the credit exposure of the other counterparty (or is liable by other means), and is the exposure so significant that the guarantor is likely to default if a claim occurs?
  3. Is 25% or more of one counterparty’s output/production sold to the other counterparty, and unable to be easily sold to other customers?
  4. Is the expected source of funds to repay loans between the counterparties the same? If so, does at least one of the counterparties have another source of income from which the loan may be fully repaid?
  5. Would financial problems of one counterparty cause difficulties for the other counterparty to fully and timely repay its liabilities?
  6. Would financial insolvency or default of one counterparty be associated with the insolvency or default of the other?
  7. Do the counterparties rely on the same source for the majority of their funding and, in the event of the source’s default, would they be unable to find an alternate provider?

In applying this qualitative determination of economic interdependence, commenters were particularly concerned about finding interdependence between private sector counterparties and public sector counterparties (e.g., states, municipalities, state owned enterprises, public-private enterprises), which would lead to outsized exposures. Furthermore, commenters thought it highly problematic to force Covered Banks, when calculating exposures to public entities, to aggregate exposures for all municipalities within a state with exposures to the state (the reproposal presumes economic interdependent between various public entities). As such, commenters suggested that economic interdependent analysis be limited to private sector counterparties, but that if public sector counterparties remain in scope, that municipal revenue bonds be exempted since they are supported by a specific stream of revenue.

Upon finalization of the reproposal, our view is that the Fed is unlikely to give ground on the BHCA’s consolidation criteria and on requiring aggregation of economically interdependent exposures. However, the Fed could adopt the somewhat more lenient approach proposed by the European Banking Authority (EBA).
The EBA calls for consolidation of affiliates of counterparties consistent with BCBS’s large exposure framework (i.e., a 50% consolidation threshold, thereby consolidating fewer affiliates), but reduces the economic interdependence threshold from 5% to 2% (thereby bringing in some more counterparties).

Sovereigns

The reproposal exempts exposures to sovereign entities from SCCL calculations, as long as the sovereign entities are assigned a zero risk weight under the US risk-based capital rules. This is a considerable easing from prior proposals, which only exempted a Covered Bank’s exposures to the US government (and to Government Sponsored Enterprises while in conservatorship) and FBOs’ exposures to their home country sovereign entities. G-SIBs with a global footprint will benefit the most from this change due to their exposure to non-US sovereign entities. This modification was welcomed by commenters, but commenters further suggested that exposures to sovereigns that are non-zero risk-weighted should not be presumed to be economically interdependent with public entities associated with the sovereign (e.g., government agencies and government-owned corporations), which the reproposal currently presumes. Rather, commenters suggested that exposures to these associated public entities should only be aggregated with the sovereign for public entities whose individual exposures exceed 5% of the Covered Bank’s capital.

Special Purpose Vehicles

Under the reproposal, G-SIBs and Large Covered Banks are generally required to recognize an exposure to an SPV in an amount equal to the value of its investment in the SPV, which is consistent with the BCBS’s large exposure framework. However, under the reproposal, if such a Covered Bank cannot demonstrate that its exposure to each underlying investment in an SPV is less than 0.25% of its T1C, the Covered Bank must “look-through” the SPV – i.e., recognize (and aggregate) exposures to the issuer of each individual asset held by the SPV.[10]

Commenters believe a better approach would be to limit the SCCL’s scope to SPVs that are under control of the Covered Bank, based on US GAAP thresholds. We don’t expect the Fed to agree, however, given the large number of SPVs that are effectively under a Covered Bank’s control where ownership is often much less than 50%. Commenters also suggested narrowing the scope of the “look-through” to only those investments (or equity-like exposure) of an SPV where access to daily updated information may be attainable. Again, we expect the Fed to hold firm in this regard.

Remaining issues

Securities Finance Transactions

The calculation methodology for Securities Finance Transactions (SFTs) under the reproposal excludes internal model approaches, which will cause exposure amounts to increase dramatically for securities lending and repo products. As such, commenters expressed their desire to allow firms to measure SFTs using any methodology permitted under the US risk-based capital framework, as is the case under the reproposal for measuring over-the-counter (OTC) derivatives exposure. However, it would be an uphill battle to get the Fed to concede this point as global regulators are moving away from internal models and towards standardized approaches for the risk-weighting of exposures.[11]

On the positive side for Covered Banks, the reproposal allows them to use risk mitigants to reduce net credit exposures by transferring risk to an unaffiliated counterparty. While the reproposal permits a range of risk mitigants (including eligible collateral, guarantees, credit and equity derivatives, other hedges, and bilateral netting agreements), the transferred exposure counts toward total exposure to the provider of the risk mitigant.

FBOs’ combined US operations

For FBOs, commenters requested excluding combined US operations (CUSO) for SCCL purposes as they will be subject to comparable home country regimes (CUSO would include the FBO’s IHC, branches in the US, and any subsidiaries in the US outside of the IHC). However, the Fed is likely to stand firm on including CUSO as this is consistent with its Enhanced Prudential Standards and its desire to improve the risk governance of FBOs’ US operations.[12] FBOs also requested the elimination of the cross-trigger mechanism between the IHC and the rest of the CUSO, which mandates that neither the IHC nor the rest of the CUSO be permitted to increase counterparty exposure if either breaches the SCCL limit.

Cost and Compliance Period Burden

In order to comply with SCCL , we believe a minimum of twelve months is needed for Covered Banks to perform a gap analysis, develop a system design, and implement standardized technology solutions that span legal entities and replace siloed systems,. In addition, user-acceptance testing of SCCL data integration solutions will require at least three months.

Commenters argued that that the compliance start date should be changed to coincide with BCBS’s large exposure standard compliance date of January 2019 in order to give G-SIBs and Large Banks the necessary time for process and technology re-engineering across functions, and to reduce the likelihood of market disruptions. FBOs also noted that although the compliance period for IHCs was extended to two years from the final SCCL rule’s effective date, FBOs with assets greater than $250 billion are offered no relief as they will still need to comply with the rule for CUSO (of which the IHC is the key component) within the shorter one year compliance period. We expect the Fed to give Covered Banks extra time to comply with the rule by delaying its effective date, even if the SCCL reproposal is finalized by the end of this year as we anticipate.

ENDNOTES

[1] See PwC’s First take: Ten key points from the Fed’s single-counterparty credit limits proposal (March 2016).

[2] The $50 billion asset threshold would be measured globally in the case of FBOs. Notably, the reproposal leaves out non-banks that are designated as systemically important by the Financial Stability Oversight Council, but indicates that similar requirements will be applied in the future.

[3] Based on this control test, an affiliate should be consolidated with its “parent” if the parent (a) directly or indirectly, controls, or has power to vote at least 25% of any class of voting securities of the entity, (b) controls the election of a majority of the directors or trustees of the entity, or (c) exercises a controlling influence over the management or policies of the entity.

[4] Consolidation under US GAAP is based on a 50% ownership threshold.

[5] Compliance will be required one year after the rule’s effective date for Covered Banks with greater than $250 billion in total consolidated assets (or greater than $10 billion in on-balance sheet foreign exposures), and two years after the effective date for Covered Banks with less than $250 billion in total assets.

[6] See PwC’s First take, Enhanced Prudential Standards (February 2014).

[7] See PwC’s First take, Ten key points from Basel’s new large exposure framework (April 2014).

[8] Allowance for Loan and Lease Losses (“ALLL”)

[9] See note 3.

[10] Separately, Covered Banks must also recognize exposures to collateral or credit protection issuers (e.g., credit enhancement providers) whose failure or distress would result in a reduction in the value of the Covered Bank’s investment in the SPV.

[11] See PwC’s First take, Five key points from Basel’s proposed restrictions on internal models for credit risk (April 2016).

[12] See PwC’s Regulatory brief, Foreign Banks: Resolution plans meet IHCs (February 2016).

This post comes to us from PwC. It is based on the firm’s A Closer Look, “Counterparty credit limits: do you know where your exposures are?”, dated October 2016 and available here.

Categories
Corporate Governance

Shades of Gray in Board Independence

A well-functioning independent board of directors is a pillar of effective corporate governance.  However, establishing and maintaining a truly functioning board remains a challenge for many companies. In response to apparent breakdowns in corporate oversight, policymakers have taken steps to encourage strong and independent boards. Most notably, following a series of high-profile corporate scandals involving the likes of Enron and WorldCom, Congress passed the 2002 Sarbanes-Oxley Act (SOX).  SOX, coupled with the subsequent shift in the major stock exchanges’ listing requirements, put in place a number of initiatives to encourage the active monitoring of independent directors.

A large body of academic literature has also highlighted the importance of board independence and has explored its effects on various measures of firm performance.[1] Despite the strong push for greater director independence, the observed links between board independence and firm performance are often quite weak. Moreover, corporate fraud and misconduct still remain a significant problem in Corporate America (KPMG Forensic Integrity Survey, 2005-2006, 2009, and 2013) even after a decade of significant regulatory efforts that were designed to promote a board’s oversight function through director independence.[2]

Given this background, we have recently conducted an empirical study, available here, that takes a different approach to gauge a board’s true functioning independence Most studies have primarily focused on the directors who are classified as independent in the major director databases (ISS and BoardEx), and they often ignore directors who are not clearly insiders or outsiders, but are instead classified as “gray.” Gray directors are non-executive directors who have a linked affiliation with the company in some form or another, and thus cannot be easily classified as either independent or executive directors. These gray directors include former employees as well as some outsiders who have a financial connection to the firm beyond the payment they receive as board members. Despite their prevalence (51 percent of the S&P 500 firms from 2000 to 2012 had gray directors), their influence on the board monitoring function has not received much attention in the literature.[3]

In many cases, gray directors are indirectly classified as “non-independent,” regardless of their fundamental characteristics. However, we suspect that there are important “shades of gray,” in which different types of gray directors may influence board dynamics in very different ways.  Depending on the circumstances, we can envision scenarios where gray directors are aligned with executive directors and other scenarios where they may be very actively aligned with outside independent directors. In typical cases where executive transitions go smoothly, we expect that former-employee gray directors are more likely to be aligned with current executives on the board.  In stark contrast, other gray directors, including bankers and consultants who are outsiders, may not necessarily align with inside directors, particularly in circumstances where these outside gray directors have strong incentives to maintain their personal reputations in director labor markets. Notably, these outside gray directors may be quite informed about specific aspects of the firm due to their skills and experience and, therefore, may be acting more like informed outside directors who can provide effective checks and balances over the management team.

Further complicating matters, we find that firms sometimes have discretion in whether they choose to report their former-employee directors as gray or independent. Ultimately, how firms with discretion choose to classify these former-employee directors also provides a valuable window into the firm’s true desire for independence.

We argue that a true measure of board independence requires a careful disentangling of the functioning role of non-former employee, non-executive directors and the board’s decision on whether to conservatively report former employees as gray directors or to perhaps more aggressively classify them as independent directors. Given this perspective, we define the functioning level of board independence as the fraction of reported independent and gray directors minus the former employees on the board. It follows that the difference between our new measure of functioning board independence and the traditional board independence comprises two elements: 1) shades of gray, i.e., the inclusion of outside gray directors but exclusion of former-employee gray directors; and 2) reporting conservatism, i.e., the exclusion of former employees who are classified as independent.

Figure 1 visualizes the difference between the traditional independence measure (TI) and our measure of functional board independence (FI). The top graph illustrates the traditional director classifications, where the board consists of executive directors (E) and non-executive directors who are listed as either independent (I) or gray (G). The bottom graph provides a further decomposition of the director fundamentals. In this illustration, the non-executive directors are broken down into three categories: outside directors reported as independent (Group A), former employee directors who may be reported either as independent or gray (Group B), and outside directors who are reported as gray (Group C). Our measure of functional independence includes the complete set of outside directors, Group A + Group C (in Green), and excludes all directors who are either current or former employees, Group B + Group D (in Red).

houston

Our analysis concentrates on S&P 500 firms over the time period 2000-2012 and focuses explicitly on the various connections between board structure and the incidence of corporate fraud.[4]  We view corporate fraud as the manifestation of poorly functioning governance and use the Stanford Securities Class Action Clearinghouse website to collect incidences of corporate fraud among S&P 500 firms against which a securities class action lawsuit has been filed under the provisions of the federal securities acts.

Consistent with much of the literature that fails to find a strong link between board independence and firm performance, we first find that board composition as traditionally measured by the fraction of independent directors on the board has little effect on the incidence of corporate fraud. However, consistent with our hypotheses, we show that our new measure of “functioning” independence is negatively correlated with corporate fraud. This negative relationship is both economically and statistically significant and also robust to various alternative specifications. We find that a 1 percent increase in the percentage of functioning independence level is associated with 0.2 percent decrease in the likelihood of fraud. This finding suggests that a newly elected former-employee director serving on a board of 10 directors (replacing another non-executive director while holding other board compositions the same) would account for a 2 percent increase in the fraud likelihood, which is quite notable given that the average fraud likelihood in our sample is just 10 percent.

We find that these effects are particularly pronounced in the cases where a firm’s board uses its discretion to aggressively classify their former employees as independent directors. We also find that gray directors who are outside consultants significantly reduce corporate fraud intensity, whereas gray former-employee directors significantly increase the fraud likelihood. The gray consultant directors’ effects are particularly strong when these directors have significant external connections. Altogether, these findings lend support to both the shades of gray and reporting conservatism effects.

We also construct a series of conditional tests to explore the types of former employee directors who are more likely to exacerbate internal corporate governance. We find that fraud is more likely to occur if a former-employee director did not serve as CEO[5], if a former employee serves on the audit or compensation committee, and if a former employee previously served coincidentally as an executive director on the board with the current CEO. Interestingly, however, we find that former employee board members are more independent and less associated with fraud if they share broader social and professional connections with board members outside of their firm.

Overall, our study highlights the importance of employee career concerns and the key role of former employees in discussing the functioning level of board independence. We apply these important within-firm labor dynamics to promote a further understanding of what determines misconduct in Corporate America.

ENDNOTES

[1] See for example: Fama and Jensen (1983), Bhagat and Black (2002), Yermack (1996), Harris and Raviv (2006), Nguyen and Nielsen (2010), Armstrong, Core and Guay (2014).

[2] The 2013 KPMG Integrity Survey reports that 73% of the 3,500 surveyed employees witnessed misconduct over the prior year.  These numbers are very similar to those in the earlier 2005 and 2009 surveys.

[3] The percentage of gray directors is 47% if using ISS classification instead of BoardEx classification.

[4] While an extensive literature has explored the links between director independence and firm performance, very few studies have focused specifically on the relationship between fraud and director independence. Notable exceptions include Beasley (1996) and the 2010 report provided for the Treadway Commissions by Beasley et al.

[5] Fahlenbrach, Low and Stulz (2010) also find that retiring CEOs are more likely to join other companies as independent directors while lower-ranked former employees are more likely to stay on the board as former employee directors.

This post comes to us from Professor Joel Houston, Assistant Professor Jongsub Lee and Ph.D. candidate Hongyu Shan of the University of Florida. It is based on their paper, “In Search of Board Independence: Former Employees, Shades of Gray and Director Classifications Revisited,” available here.

 

Categories
The Dodd-Frank Act

Sullivan & Cromwell Discusses D.C. Circuit Ruling Invalidating CFPB Structure

On October 11, 2016, a panel of the U.S. Court of Appeals for the D.C. Circuit held that the Consumer Financial Protection Bureau (the “CFPB”) is “unconstitutionally structured” because its authority is vested in a single appointee who can be removed by the President only for cause.  To remedy this constitutional flaw, the Court severed the unconstitutional “for-cause” provision in the legislation (Dodd-Frank) that created the CFPB.  “As a result, the CFPB now will operate as an executive agency.  The President of the United States now has the power to supervise and direct the Director of the CFPB, and may remove the Director at will at any time.”

In addition to the constitutional flaw, the Court held that the CFPB’s underlying decision suffered from several “statutory” flaws:  (1) the CFPB misinterpreted the statute at issue, section 8 of the Real Estate Settlement Procedures Act; (2) by retroactively applying a “new” interpretation to PHH’s past conduct and requiring PHH to pay $109 million for that conduct, the CFPB violated the “bedrock” principle of due process that the people should have fair notice of what conduct is prohibited; and (3) the CFPB’s administrative enforcement proceedings are subject to statutes of limitations.  Although the constitutional holding has received a great deal of attention, we see potentially more significant and immediate implications arising from the Court’s holding regarding statutes of limitations in enforcement proceedings.  That holding should be of substantial interest to both the federal banking agencies and the financial institutions they regulate.

Background

Title X of the Dodd-Frank Wall Street Reform and Consumer Protection Act (“Dodd-Frank”) created the CFPB as an “independent bureau” in the Federal Reserve System, headed by a single Director appointed by the President with the advice and consent of the Senate and removable by the President only for cause (i.e., inefficiency, neglect of duty, or malfeasance in office).[1]  Dodd-Frank confers broad authority on the CFPB, and hence the Director, to “regulate the offering and provision of consumer financial products or services under the Federal consumer financial laws,”[2] which include the Real Estate Settlement Procedures Act (“RESPA”), and to implement those laws through “rules, orders, guidance, interpretations, statements of policy, examinations, and enforcement actions.”[3]

In January 2014, the CFPB filed an administrative enforcement proceeding against PHH Corporation, a mortgage loan originator, and certain of its affiliates (collectively, “PHH”), alleging that PHH’s “captive reinsurance” arrangements with mortgage insurers violated the prohibition in section 8 of RESPA on payments for referrals—“kick-backs”—in connection with mortgage loans.  Under those arrangements, PHH referred mortgage loan borrowers to the insurers with which it had reinsurance arrangements, and those mortgage insurers in turn purchased mortgage reinsurance from PHH.[4]

The CFPB’s proceeding against PHH was heard in the first instance by an administrative law judge (“ALJ”), whose November 2014 decision recommending injunctive relief and disgorgement of $6.4 million fully satisfied neither the CFPB nor PHH.  Both parties appealed to the Director in the first appeal of a CFPB administrative enforcement proceeding.  In June 2015, the Director issued a widely publicized decision upholding the ALJ’s decision in part and reversing it in part.  Applying a de novo standard of review, the Director held, among other things, that (1) no statute of limitations applies when the CFPB pursues a RESPA violation in an administrative enforcement proceeding, (2) section 8 of RESPA bars captive reinsurance arrangements, and (3) a 1997 letter issued by the CFPB’s predecessor agency charged with implementing and enforcing RESPA, the Department of Housing and Urban Development (“HUD”), which stated that certain captive reinsurance arrangements are permissible under section 8, provides no protection to PHH because it was not a rule, regulation or interpretation published in the Federal Register.  The Director further ordered PHH to disgorge over $109 million in premiums it received pursuant to the captive reinsurance arrangements—a figure premised on the Director’s finding that PHH had violated RESPA every time it received a reinsurance premium from a mortgage insurer to which it had referred a borrower, and about 17 times the amount recommended by the ALJ.

PHH promptly petitioned the U.S. Court of Appeals for the D.C. Circuit for review of the CFPB’s decision and requested a stay pending judicial review arguing, among other things, that the CFPB is unconstitutionally structured and that the Director’s decision suffered from several statutory flaws.  A different panel of the Court granted the stay motion in August 2015, and the merits panel heard oral arguments in April 2016.

The Panel Decision

On October 11, 2016, in an eagerly awaited and very lengthy decision authored by Judge Brett Kavanaugh, the Court agreed with PHH that the CFPB is unconstitutionally structured and, as we previously suggested it might,[5] severed Dodd-Frank’s for-cause-removal provision from the remainder of the statute.[6]  The Court also agreed with PHH’s statutory objections to the Director’s decision.  Accordingly, the Court granted PHH’s petition for review, vacated the CFPB’s order against PHH, and remanded the case to the CFPB for further proceedings consistent with the opinion.  At the same time, the Court sua sponte ordered that issuance of the mandate be stayed until seven days after disposition of any timely petition for rehearing or petition for rehearing en banc.

Judge Raymond Randolph joined Judge Kavanaugh’s opinion in full and also filed a concurring opinion identifying what he believed to be an additional constitutional flaw based on the process by which the ALJ was appointed.

Judge Karen Lecraft Henderson concurred in part and dissented in part, agreeing with the majority as to the statutory flaws but explaining that she did not believe it was appropriate to reach the constitutional question (and thus expressing no opinion on the merits of that question).

Constitutional flaw

The bulk of the Court’s opinion is devoted to the rationale for concluding that the CFPB is unconstitutionally structured.  The majority opinion begins by tracing the evolution of independent agencies and their relationship to the executive power the Constitution vests in the President.  Traditionally, only “executive agencies” (or “non-independent agencies”) have been headed by a single official, as the CFPB is, and that official is subject to removal at the pleasure of the President.  This broad removal authority is necessary to ensure that the President can maintain control over the exercise of executive power.  As Judge Kavanaugh explains, over time, Congress began creating “independent agencies.”  These agencies exercised executive power independent of the President, and the President could remove their heads only for cause, but these agencies have traditionally been governed by multimember commissions or boards.  Questions about the constitutionality of these independent agencies were largely resolved by the Supreme Court in its 1935 Humphrey’s Executor decision.[7]  The question presented in this case, according to the majority, was whether Humphrey’s Executor extended to the CFPB structure:  an independent agency headed not by a multi-member commission but rather by a single Director.

In answering this question, the Court first presents a case for the CFPB as a “historical anomaly.”  Until the CFPB, “independent agencies exercising substantial executive authority have all been multi-member commissions or boards.”  Although there are a handful of examples of independent agencies headed by a single person removable only for cause, the Court said those agencies are different in kind from the CFPB in that they do not exercise the core executive power of bringing enforcement actions for violations of statues or agency rules and, in any event, lack “deep historical roots” or have been “constitutionally contested.”  Indeed, when viewed against the historical record of independent agencies, the CFPB is “exceptional in our constitutional structure and unprecedented in our constitutional history.”  Because in all other instances, heads of executive agencies either (i) are subject to the President’s direct control, (ii) share their authority with multiple co-heads, or (iii) lack the authority to bring enforcement actions against private individuals, the Court describes the CFPB Director as, “other than the President, . . . the single most powerful official in the entire United States Government, at least when measured in terms of unilateral power.”

Relying heavily on recent Supreme Court precedent,[8] Judge Kavanaugh explains that this departure is especially significant because, in separation-of-powers disputes like this one, which cannot be resolved by the constitutional text alone, historical practice plays a key role in defining constitutional limits.  Congress has traditionally required multi-member bodies at the helm of independent agencies as a “critical substitute check on the excesses of any individual independent agency head—a check that helps to prevent arbitrary decision making and abuse of power, and thereby to protect individual liberty.”  The Court concludes that because the CFPB departs so markedly from this “settled historical practice”—a departure that makes a significant difference for the individual liberty protected by the Constitution’s separation of powers—the CFPB’s structure is unconstitutional.

Turning to the remedy for the constitutional infirmity, the Court concludes that the for-cause removal provision should be severed from Dodd-Frank.  “As a result, the CFPB now will operate as an executive agency. The President of the United States now has the power to supervise and direct the Director of the CFPB, and may remove the Director at will at any time.”  The Court expressly declined to “consider the legal ramifications of [the] decision for past CFPB rules or for past agency enforcement actions.”  Instead, the Court left that question unresolved, noting that other agencies have recently been on the “receiving end of successful constitutional and statutory challenges to their structure and legality,” and that, “[w]ithout major tumult, the agencies and courts have managed to work through issues regarding the legality of past rules and of past or current enforcement actions.”

Statutory flaws

Turning to PHH’s statutory objections to the Director’s decision, the D.C. Circuit concluded that, contrary to the CFPB’s interpretation, section 8 of RESPA allows captive reinsurance arrangements so long as the mortgage insurance companies pay the reinsurers no more than reasonable market value for services provided.  No deference was afforded to the CFPB’s interpretation.

The Court also held that, even if the CFPB’s interpretation of section 8 were permissible, it would represent a “complete about-face” from HUD’s “consistent” interpretation, characterized in the opinion as “agency guidance provided by top HUD officials and . . . given repeatedly,” which was widely known and relied on in the mortgage lending industry.  PHH justifiably relied on that interpretation and did not have fair notice of the CFPB’s new interpretation at the time of the conduct at issue.  Applying another recent Supreme Court ruling,[9] the Court concluded that, by retroactively applying its changed interpretation to PHH’s past conduct and requiring PHH to pay $109 million for that conduct, the CFPB violated the “bedrock” principle of due process that the people should have fair notice of what conduct is prohibited.[10]  This conclusion is in our view not particularly groundbreaking.

We believe the Court’s other statutory holding could prove potentially significant.  Relying at least in part on “[t]he general working presumption in federal civil and criminal cases . . . that a federal civil cause of action or criminal offense must have some statute of limitations and must not allow suits to be brought forever and ever after the acts in question[,]” the Court held that the CFPB “misread” both Dodd-Frank and RESPA in concluding that no statute of limitations was applicable in this case.  As to Dodd-Frank, the Court held that the statute empowers the CFPB to conduct hearings and adjudication proceedings to enforce federal consumer protection laws, including RESPA, “‘unless such Federal law specifically limits the Bureau from conducting a hearing or adjudication proceeding.’  …  Obviously, one such ‘limit’ is a statute of limitations.”  The CFPB’s administrative adjudications, therefore, are subject to the statutes of limitations of the various federal consumer protection laws it is charged with enforcing.  As to RESPA, contrary to the CFPB’s interpretation, the Court held that the three-year statute of limitations in RESPA applies not only to “CFPB actions to enforce Section 8 that are brought in court, but also for CFPB actions to enforce Section 8 that are brought administratively.”

The Court cites two statutory provisions in support of the “general working presumption” that a statute of limitations applies in federal civil and criminal cases.  Although those statutory provisions, 28 U.S.C. § 2462 and 18 U.S.C. § 3282, relate to penal actions (civil fines, penalties or forfeitures and non-capital criminal offenses, respectively), the Court’s decision encompasses not just the penal aspects but also the remedial aspects of the CFPB’s decision.  Although the impact on extant enforcement actions consensually entered into with financial institutions remains to be determined, this ruling could have significant implications for institutions facing future enforcement actions brought not only by the CFPB but also by the federal banking agencies.  Historically, the federal banking agencies have not viewed their cease and desist authority, which includes the authority to order restitution to consumers or other remediation, as bound by any statute of limitations.  On this basis, they have ordered institutions to provide restitution for or otherwise remediate violations that occurred well outside of any potentially applicable statute of limitations.  And, indeed, since section 8 of the Federal Deposit Insurance Act—the provision under which the federal banking agencies issue cease and desist orders—includes no statute of limitations, it is unclear what statute of limitations would apply if not the general five-year statute of limitations in 28 U.S.C. § 2462.

Implications

We believe it highly likely that a petition for rehearing en banc will be filed, and, whatever the result, we would expect a petition for certiorari to the U.S. Supreme Court.[11]  Until the matter is resolved, the ultimate effect of the Court’s ruling will be uncertain.  If the ruling stands, however, its ramifications could be significant.  The Court’s constitutional holding is receiving a great deal of attention, and, indeed, could result in challenges to any enforcement or regulatory action taken at a time when the CFPB was unconstitutionally structured.  The debate around the constitutionality of the CFPB is not likely to be resolved any time soon given the various challenges at different stages of adjudication[12] and the continuing Congressional interest in the structure of the CFPB.  As noted above, however, we see potentially more significant and immediate implications stemming from the D.C. Circuit’s holding as to statutes of limitations in enforcement proceedings.  That holding should be of substantial interest to both the federal banking agencies and the financial institutions they regulate.

ENDNOTES

[1]   12 U.S.C. § 5491.

[2]   12 U.S.C. § 5491(a)

[3]   12 U.S.C. § 5492(a)(10).

[4]   The reinsurance was purchased from a PHH subsidiary, Atrium.

[5]   See Sullivan & Cromwell LLP Memo to Clients, D.C. Circuit Allows Challenges to the CFPB’s Constitutionality to Proceed: Separate Panels Reverse District Court Dismissal of Texas Bank’s Challenges on Standing and Ripeness Grounds and Grant Mortgage Servicer’s Motion to Stay CFPB Action Pending Judicial Review (August 7, 2015).

[6]   The Court specifically noted:  “Some have suggested that the CFPB Director is similar to the Comptroller of the Currency.  But unlike the Director, the Comptroller is not independent. The Comptroller is removable at will by the President.  See 12 U.S.C. § 2 (‘The Comptroller of the Currency shall be appointed by the President, by and with the advice and consent of the Senate, and shall hold his office for a term of five years unless sooner removed by the President, upon reasons to be communicated by him to the Senate.’).”

[7]   Humphrey’s Executor v. United States, 295 U.S. 602 (1935).

[8]   NLRB v. Noel Canning, 134 S. Ct. 2550 (2014) and Free Enterprise Fund v. Public Company Accounting Oversight Board, 561 U.S. 477 (2010).

[9]   Christopher v. SmithKline Beecham Corp., 132 S. Ct. 2156 (2012).

[10]  In a footnote, the Court states that its holdings as to the CFPB’s misinterpretation and retroactive application of section 8 represent alternative holdings and, as such, both constitute binding precedent of the Court.

[11]  The CFPB has authority under the Dodd-Frank Act to represent itself in the Supreme Court, as long as it makes a written request to the Attorney General, and the Attorney General concurs.  12 U.S.C. § 5564 (e).

[12]  On July 12, 2016, in a separate challenge to the CFPB’s constitutionality, State National Bank of Big Spring v. Lew, the U.S. District Court for the District of Columbia, following remand from the D.C. Circuit, deferred ruling on the plaintiffs’ attack on the CFPB on separation of powers grounds because PHH’s case was pending before the D.C. Circuit.  In that case, the plaintiffs lodged a separate attack on the CFPB:  that the recess appointment of the Director was unconstitutional and that his subsequent ratification of actions taken during the period between that recess appointment and his Senate confirmation were invalid.  While the district court appears to have agreed that the recess appointment was invalid—a conclusion consistent with the Supreme Court’s decision in Noel Canning—it disagreed as to the legal consequences, finding that the ratification after the Director was properly appointed resolved any constitutional deficiency.  Given the D.C. Circuit’s decision in PHH, the district court presumably now will rule on the plaintiffs’ separation of powers claim.  In reaching its conclusion, the court relied on an April 14, 2016 decision by a divided panel of the Ninth Circuit in CFPB v. Chance Edward Gordon.  There, the Court concluded that “Congress authorized the CFPB to bring the action in question. . . .  Because the CFPB had the authority to bring the action at the time Gordon was charged, Cordray’s August 2013 ratification, done after he was properly appointed as Director, resolves [the alleged constitutional] deficiencies.”  This decision was reached over the vocal dissent of Circuit Judge Ikuta, who explained that the Director was not properly appointed by the President and therefore could not exercise the executive power necessary to bring the enforcement action against Gordon.  On July 20, 2016, the full Ninth Circuit denied a petition for rehearing en banc.  On September 22, 2016, Justice Kennedy extended the time to file a petition with the Supreme Court to November 17, 2016.

This post comes to us from Sullivan & Cromwell LLP. It is based on the firm’s memorandum, “D.C. Circuit Invalidates CFPB Structure as Unconstitutional; Rejects ‘Flawed’ Statutory Application in Enforcement Proceeding,” dated October 13, 2016, and available here.

Categories
Finance & Economics International Developments

Shearman & Sterling discusses Brexit: a Financial Free Zone Within the City

The UK Government recently indicated that it intends to negotiate a unique EU-UK relationship post-Brexit. It is hoped that the arrangements will be appropriate for the UK and London’s position as a leading international financial centre. A number of existing models have been discussed and will no doubt be analysed, with variations, by the Government. This client note sets out a framework for new opportunities which could be developed in the UK post-Brexit, by establishing a “financial free zone” in London. This would enable the UK to take a bifurcated approach to financial services post-Brexit. The UK as a whole could take an equivalence-based approach or other route to financial services regulation enabling single market access such that financial institutions could continue to provide services cross-border into the EU in a similar way to the present. Separately, the financial free zone could adopt a far more free-market approach to regulation within the zone, subject to tight controls on systemic risk. This would provide optionality to market participants as to whether they wish to do business cross-border at all. We discuss the characteristics and purpose of financial free zones and a proposed framework for the establishment of a London zone.

A Financial Free Zone

Free zones have a number of characteristics in common, namely they are limited to a geographic region, have a single administration, offer benefits to participants, such as tax or investment incentives, and have separate streamlined procedures. Free zones have traditionally had a policy and infrastructure role in developing countries, as they can be used as a tool for economic growth and to attract foreign direct investment. Free zones have been in place in Gibraltar and Singapore from 1704 and 1819, respectively, with the first modern industrial free zone being established in Shannon, Ireland in 1959.

Whilst free zones have traditionally been set up to encourage trade exports and foreign direct investment, a more contemporary approach is the creation of a multi-sectoral zone. For example, the Chinese government is creating a special economic zone at Qianhai bay, Shenzhen, which specializes in financial services, logistics, technology and startups. Within the zone, firms will be given help to raise Yuan offshore, and banks established in Hong Kong will be able to enter the zone more easily than under the current set-up. These measures are designed to reduce the severity of China’s capital controls[1] and encourage financial cooperation with Hong Kong. Financial free zones are a similar concept. The zone is located in an area demarcated for financial activity to be conducted and is set up with its own legal and regulatory system. The United Arab Emirates (“UAE”) has several free zones, used for sectors as diverse as duty-free, shipping and financial services. Most recently, it established the Abu Dhabi Global Market (“ADGM”), a broad-based international financial centre for local, regional and international institutions, with the aim of it being a catalyst for the growth of a dynamic financial services sector in the UAE.[2] The Dubai International Finance Centre (“DIFC”) was established in 2004 to encourage businesses and financial institutions to tap into the emerging markets of the Middle East, Africa and South Asia and has also proven to be highly successful.

A London International Financial Centre

A London International Financial Centre (“LIFC”) could see the creation of a new, small territorial area within London demarcated for London-based financial institutions wishing to operate on an even more free-market based model than the rest of the market. The LIFC would have its own laws and regulations, based on the common law and UK statutes, but tailored for a high-growth, highly dynamic market subject to the main constraint that the laws must nevertheless (as with all modern financial services laws) minimize systemic risk and ensure clean markets. The LIFC could also create streamlined work visa processes, to ensure continuing ready access to a worldwide talent pool.

This LIFC would not seek equivalence, as a matter of course, with the EU except on topics it wished to or even, potentially, substituted compliance recognition with the US. It would have a stand-alone regime where institutions could operate in a highly deregulated environment but in the EU time zone.

Own Territory

The LIFC would need its own territory. Historically, the City of London housed the main financial businesses in the UK but the financial sector has spread as it has grown and a lot of the business is also located in Canary Wharf. A clearly demarcated area would be needed to bring certainty as to where certain activities could be undertaken within the free zone framework. We do not propose that London, the City or Canary Wharf be designated. Rather, such a proposal would work best in a significant area of new-build or regeneration-build real estate, such that those using the free zone freely choose to participate in it.

Separate Regulatory Framework

It is likely that separate regulators will be needed for the LIFC from the rest of the UK. For example, the Financial Services Regulatory Authority (“FSRA”) is the independent regulator for financial services in ADGM and the Dubai Financial Services Authority (“DFSA”) is the independent regulator for financial services in the DIFC, with the Central Bank of the UAE, the Securities & Commodities Authority and the Insurance Authority regulating financial services in the rest of the UAE. In establishing the LIFC, the current regulatory architecture could be maintained so that the Bank of England, the Financial Conduct Authority (“FCA”) and the Prudential Regulation Authority (“PRA”) would continue to regulate financial services in the UK more generally. The Bank of England would continue to be responsible for macro-prudential regulation of the UK economy as a whole. Due to the EU compliant infrastructure and rules that are already administered by the Bank, the FCA and PRA, as well as the existence of good working relationships with the EU authorities such as the European Central Bank and the European Supervisory Authorities (“ESAs”),[3] these relationships should be continued separately from the LIFC.

Independent Judicial System

Characteristically, financial free zones have independent judicial systems. Both ADGM and the DIFC, for example, have an independent judicial system and the special economic zone in Qianhai will also have its own separate legal system with a Shenzhen Court of International Arbitration and a Qianhai Tribunal.[4] The LIFC could establish either a separate judicial system or a designated court within the current judicial framework, to deal specifically with financial services issues arising within the LIFC regime.

Free Movement of People

An additional possible benefit of establishing an LIFC could be the introduction of preferential immigration laws, enabling foreign nationals to work in professional services within the LIFC and reside there. For example, the special economic zone being established in Qianhai has implemented a regime under which foreign nationals working within designated professional services can apply for permanent residence to live and work in the zone. A separate immigration regime for an LIFC could enable the UK to continue to benefit most easily from the international talent pool whilst implementing more stringent immigration controls for the rest of the UK.[5]

The Likely UK-EU Relationship: EU Equivalence Regimes

The introduction of the LIFC could allow the UK to develop within the LIFC financial services laws that differ more radically from those of the EU, giving London-based financial institutions a choice as to which regime best suits their business, whilst retaining the advantages of being based in London.

As set out in our previous client note,[6] the likely outcome for the UK as a whole is an equivalence-based relationship with the EU for financial services where financial market participants established in the UK can do business that is cross-border in law with counterparties and customers in the EU under UK laws that are equivalent to those in the relevant sector in the EU – and vice versa. A summary of the equivalence regimes is set out in our previous note. There are some holes in those regimes, many of which (if not all of them) we believe are likely to be plugged.

Conclusion

Whilst the future relationship between the UK and the EU remains to be negotiated, an LIFC is an exciting prospect for the UK’s future financial sector. It could serve to boost further the UK’s unparalleled position as a major financial centre and offer new opportunities to the UK, the EU economies and other markets around the world.

ENDNOTES

[1]   China Offshore, “Qianhai Bay Special Economic Zone to act as bridge between Hong Kong and the mainland,” available here.

[2]   You may like to see our client note, “Abu Dhabi Global Market: Financial Services Regulations and Rules,” available here.

[3]   The ESAs comprise the European Securities and Markets Authority, the European Banking Authority and the European Insurance and Occupational Pensions Authority.

[4]   Qianhai Website, “Legal Environment,” available here.

[5]   You may like to see our client note, “Brexit: Free Movement of Persons,” available here.

[6]   “Brexit and Equivalence: Review of the Financial Services Framework Across All Sectors,” available here.

This post comes to us from Shearman & Sterling LLP. It is based on the firm’s memorandum, “Brexit: a Financial Free Zone Within the City,” dated September 19, 2016, and available here.

Categories
Antitrust Securities Regulation

Regulatory Leveraging: Problem or Solution?

“Nice merger you’ve got here. It would be a shame if anything was to happen to it.”[1]

In antitrust and related areas of economic regulation, private leveraging is risky business.  Large firms that use substantial market power in one product to distort competition for a second product are attractive targets for claims of illegal tying or monopolization.

What if the actor leveraging its power is not a private company, but a government agency?  Leveraging enables a regulator to use its gatekeeping authority to secure concessions that it might not have been able to achieve otherwise.  Should we applaud or condemn regulators for using a strategy that can result in prosecution when private parties do the same thing?

What kind of gatekeeping power makes regulatory leveraging possible? The most obvious example is the authority to grant or withhold approvals over something the regulated entity needs to function, including a license to operate in a given market (e.g., the right to operate a radio station) or the right to introduce a product (e.g., a particular pharmaceutical).  A less obvious example is the requirement to obtain regulatory approval before consummating a proposed merger.  A regulator that can attach conditions to its approval may use that power to engage in regulatory leveraging.

Four Easy Pieces

Is regulatory leveraging a normal, legitimate, and perhaps inevitable feature of agency design? Or is it hostage taking that forces regulated entities to pay an often sizeable ransom to be left in peace? We present four brief case studies that give a sense of the circumstances in which regulators can engage in leveraging.

Bosch-SPX: Leveraging Across Two Antitrust Domains

A regulator can leverage its power across distinct areas within a single policy domain.  In 2012, the FTC resolved two matters involving Robert Bosch Gmbh.[2] The first matter involved Bosch’s proposed acquisition of SPX Service Solutions U.S. LLC (“SPX”), which would have given Bosch a “virtual monopoly in the market for air-conditioning recycling, recovery, and recharge devices.”  That issue was resolved with Bosch’s agreement to divest its automotive air-conditioner repair equipment business, and make some licensing commitments.

The same FTC press release that announced the FTC’s approval of the Bosch-SPX merger also announced that the FTC and Bosch had resolved a separate dispute, over whether SPX had harmed competition by reneging “on a commitment to license key, standard-essential patents on fair, reasonable, and non-discriminatory (FRAND) terms.” Bosch agreed to abandon SPX’s claims for injunctive relief in those other cases, thereby resolving an ancillary matter that long preceded the proposed merger. It is not clear from the FTC’s press release how these two entirely distinct issues came to be settled simultaneously – but their appearance in the same press release certainly inclines us to believe that they were resolved as a package deal. Bosch had a huge incentive to give in on the SPX matter in order to obtain speedy approval of the proposed merger—and FTC personnel knew that.

Data Protection/Privacy and Merger Approval: Cross-Domain Leveraging by a Multipurpose Regulator

In the second scenario, a multipurpose agency leverages power across distinct policy domains within its portfolio of duties. In recent years, the use of data about consumer behavior has become a major policy concern.  Some commentators have suggested that merger approval is a useful mechanism to force firms to strengthen their privacy protections. The FTC confronted this issue in two merger reviews involving Google—in 2007, when Google sought regulatory approval for its acquisition of DoubleClick, and in 2010, when the FTC reviewed Google’s purchase of AdMob.

The FTC had legal authority to review Google’s proposed acquisitions of DoubleClick and AdMob. It also had authority to investigate Google’s data protection and privacy policies. Agency personnel disagreed on whether the merger review should be used as an excuse/pretext/justification to delve into Google’s data protection and privacy policies. Ultimately, the FTC did not use the merger review process to extract concessions from Google regarding its data protection and privacy policies. Indeed, the FTC’s closing statement in DoubleClick explicitly disavowed such strategies, noting that “the sole purpose of federal antitrust review of mergers and acquisitions is to identify and remedy transactions that harm competition.”[3]

Leveraging Across Policy Domains Occupied by Other Regulators

In the third scenario, an agency leverages power to affect a policy domain it does not “own.” In 2013, Ally Financial was seeking approval from the Federal Reserve and the Federal Deposit Insurance Corporation to convert from a bank holding company to a financial holding company. It was also being investigated by the Consumer Financial Protection Bureau (“CFPB”), an independent bureau located within the Federal Reserve. Although the CFPB has no regulatory authority over auto dealers, it decided to investigate whether the loan portfolios of indirect auto lenders, such as Ally, indicated that auto dealers were offering less favorable terms to minority borrowers.[4]

According to Ally’s former CEO, the CFPB “threatened to derail [Ally’s] efforts to obtain key regulatory approvals if it didn’t agree to settle,” by paying $100 million, and begin offering below-market rates to minorities.[5] He complained that the CFPB “absolutely knew they had tremendous leverage over us,” and was trying to change the policies of an industry it did not have the authority to regulate with a trumped-up case. Internal CFPB memos confirm that agency personnel knew that Ally needed regulatory approval, and the impending deadline to obtain that approval gave Ally a strong incentive to settle its dispute with the CFPB.[6]

Leveraging with a “Public Interest” Mandate

In a fourth scenario, an agency can use a public interest mandate to achieve commitments that are not authorized by more specific legal commands. Many statutes delegate expansive regulatory authority by requiring an agency to consider the “public interest” in making decisions. For example, in evaluating proposed mergers, the Federal Communications Commission (FCC) is required to evaluate whether the transaction will serve “the public interest, convenience, and necessity.”[7]

Public interest standards are an open-ended invitation to engage in regulatory leveraging. The FCC recently used the merger review process to strong-arm Charter Communications to “live up to stringent requirements that don’t apply to its bigger rivals,” including net neutrality standards that the FCC had been (to that date) unable to impose through direct regulation.[8] Over the past decade, the FCC has used this strategy to impose net neutrality constraints on AT&T, Verizon, BellSouth, Comcast, and NBC.[9] In the 1990s, the FCC used regulatory leverage to strong-arm Westinghouse into increasing the number of hours devoted to children’s educational programming on CBS.[10]  State and local regulators can play the same game. In 2016, the District of Columbia Public Service Commission conditioned its approval of the Exelon-Pepco merger on a host of ancillary provisions, including a commitment to relocate certain offices to D.C.; the hiring of unionized workers; and at least $1.9 million in annual average charitable contributions to organizations located in D.C. or benefiting D.C. residents.[11]

Benefits and Costs of Regulatory Leveraging

The most obvious benefit of regulatory leveraging is that it promotes more comprehensive settlements. In Bosch-SPX, the FTC already had an open file on SPX, and Bosch then came to the FTC with the proposed merger. Isn’t it more efficient to adopt one global settlement instead of maintaining two separate proceedings? If there are benefits in settlement (and there are), more comprehensive settlements must be better still.

Second, depending on the statutory language that is employed, leveraging may be an authorized delegation of legislative authority to regulate in a flexible way. Stated differently, Congress used “public interest” language to give the agency a hammer that could be deployed when a regulated entity comes to the agency for merger approval. But the agency can only use the hammer in carefully defined circumstances. This structure keeps the agency from expanding its regulatory leverage beyond any given transaction, while giving it the flexibility to solve problems without going through the drudgery of rulemaking or starting a separate case. And, if the agency goes too far, the courts and the legislature stand ready to protect the rule of law.

Regulatory leveraging also involves real risks and disadvantages. For starters, regulatory leveraging leads to less disciplined decision-making by governmental agencies. Agencies have an incentive to ignore or downgrade the controls imposed by the substantive regulatory regime and use leverage to circumvent those restrictions.

Second, regulatory leveraging leads to less transparent and less accountable decision-making. Merger review rarely ends up in court, so agency leadership need only persuade itself that its “wish list” is worth pursuing. Firms badly want to obtain immediate approval of their mergers, so agencies have them over a barrel.

Third, regulatory leveraging can be used for “good” or “evil.” If an agency was run by your worst enemy, what use would he put regulatory leveraging to? Sauce for the gander, anyone?

Finally, because regulatory leveraging is firm-specific, it can create significant discontinuities in the applicable law. Only firms that have had a merger reviewed by the agency will be subject to regulatory leverage—and the details of the resulting settlements may well vary, depending on the priorities of agency leadership at the time the merger was reviewed, and the extent to which firm management was willing to give away the store to get the merger approved.

Squaring the Regulatory Leveraging Circle

Some of the time, regulatory leveraging is a problem. And, some of the time, regulatory leveraging is the only available solution. This is not the kind of scenario that lends itself to a simple fix. But we propose “a few modest suggestions that may make a small difference.”[12]

Clear Grants of Authority. If Congress wants agencies to engage in regulatory leveraging, it should explicitly authorize the process, and identify some boundaries. Should agencies only engage in leveraging for substantive areas of law within their zone of regulatory authority, or should they be allowed to range more widely? What criteria should an agency employ in deciding whether to engage in regulatory leveraging?  An express congressional delegation of authority would go a long way to legitimate an agency’s use of regulatory leverage.

More Transparency. Agencies should be more explicit about what and how they leverage. This will simultaneously discipline their use of regulatory leveraging, and force them to articulate and justify their conduct. If an agency believes that regulatory leveraging is a sensible way of solving a problem, it should forthrightly explain and justify its actions. If an agency isn’t willing to brag about what it is doing, it probably shouldn’t be doing it.

Fewer Gates. More gates mean more gatekeepers—and more opportunities for regulatory leveraging. The obvious solution is to be careful about creating new gates, and revisit the necessity of existing gates. Before creating new gates, legislators should decide whether they are necessary—and if so, whether the responsible agency may engage in regulatory leveraging, and the circumstances under which leveraging can occur. Legislators should also “sunset” all gates to force routine reconsideration of the need for each gate.

Better Norms. Regulatory leveraging is, at best, a third-best solution for dealing with policy problems. In some instances, internal agency dynamics will discourage the use of regulatory leveraging. But, a robust government-wide norm against the use of regulatory leveraging could play a useful backup role.

Ex Post Review. We don’t know how often regulatory leveraging takes place, the circumstances under which it occurs, and how effective (or ineffective) it actually is. We don’t know nearly enough about the prevalence and results of regulatory leverage. Only a consistent practice of ex post review can cast light on these issues.

Regulators like leverage—and some of the time, it is the only available solution to a particular problem. But regulatory leverage raises very real risks and costs, which counsel for considerably greater caution than regulatory agencies have shown to date. Unless properly disciplined, regulatory leveraging becomes lawlessness.

ENDNOTES

[1] See Barry Popik, “Nice Place You Got Here. Be a Shame if Anything Happened to It.” (July 15, 2009), http://www.barrypopik.com/index.php/new_york_city/entry/nice_place_you_got_here_be_a_shame_if_anything_happened_to_it (tracing historical usage of the phrase). See also Monty Python’s Flying Circus: Army Protection Racket, YouTube, 1:41–1:49 (Nov. 13, 2015) https://www.youtube.com/watch?v=pm5mtpPtW1Q [hereinafter Monty Python].

“Dino: You’ve . . . you’ve got a nice army base here, Colonel.

Colonel: Yes.

Dino: We wouldn’t want anything to happen to it.”

[2] Press Release, Federal Trade Commission, FTC Order Restores Competition in U.S. Market for Equipment Used to Recharge Vehicle Air Conditioning Systems (Nov. 26, 2012) https://www.ftc.gov/news-events/press-releases/2012/11/ftc-order-restores-competition-us-market-equipment-used-recharge.

[3] Statement of Federal Trade Commission Concerning Google/DoubleClick, FTC File No. 071-0170, at https://www.ftc.gov/system/files/documents/public_statements/418081/071220googledc-commstmt.pdf.

[4] Yuka Hayashi, Consumer Watchdog Pushed Discrimination Case on Vulnerable Firm: Report, Wall St. J. (Nov. 24, 2015, 7:09 PM), http://www.wsj.com/articles/consumer-watchdog-pushed-discrimination-case-on-vulnerable-firm-report-1448404301.

[5] Paul Sperry, Bank CEO Reveals How Obama Administration Shook Him Down, N.Y. Post (Feb. 21, 2016, 6:00 AM), http://nypost.com/2016/02/21/bank-ceo-reveals-how-obama-administration-shook-him-down.

[6] Hayashi, supra note 3.

[7] 47 U.S.C. §§ 214(e)(2) & 310(d).

[8] Shalini Ramachandran and John D. McKinnon, Regulators Recommend Approval of Charter-Time Warner Cable Deal, Wall St. J., (Apr. 25, 2016, 9:29 PM), http://www.wsj.com/articles/regulators-recommend-approval-of-charter-time-warner-cable-deal-1461611989.

[9] Marvin Ammori, Here’s How Charter Will Commit to an Open Internet, Wired (June 25, 2015, 12:00 PM) http://www.wired.com/2015/06/heres-charter-will-commit-open-internet.

[10] Edmund L. Andrews, FCC Approval Seen Today For Westinghouse-CBS Deal, N.Y. Times, (Nov. 22, 1995), http://www.nytimes.com/1995/11/22/business/the-media-business-fcc-approval-seen-today-for-westinghouse-cbs-deal.html. Interestingly, there was an internal dispute within the agency on this issue, with the chairman insisting on linking approval of the deal to the pledge to increase children’s programming, and three commissioners insisting that the FCC should make it clear that “it was in no way demanding that CBS or Westinghouse meet any quantitative requirements for children’s programming as a condition of approval.” Id.

[11] In re Joint Application of Exelon Corp. et al., Pub. Serv. Comm’n. of the Dist. of Columbia, Order No. 18148 ¶¶ CC, DD, HH (Mar. 23, 2016), available at http://wtop.com/wp-content/uploads/2016/03/PSC-order-Pepco-Exelon.pdf.

[12] James Q. Wilson, Bureaucracy: What Government Agencies Do and Why They Do It 369 (1989).

This post comes to us from William E. Kovacic, Visiting Professor, King’s College London, Global Competition Professor of Law and Policy, George Washington University Law School and Non-Executive Director, United Kingdom Competition and Markets Authority; and from David A. Hyman, H. Ross and Helen Workman Chair in Law, University of Illinois Colleges of Law and Medicine. It is based on their recent article, “Regulatory Leveraging: Problem or Solution?” available here.

Categories
Securities Regulation

SEC Announces Enforcement Results for 2016

The Securities and Exchange Commission announced on October 11 that, in fiscal year 2016, it filed 868 enforcement actions exposing financial reporting-related misconduct by companies and their executives and misconduct by registrants and gatekeepers, as the agency continued to enhance its use of data to detect illegal conduct and expedite investigations.

The new single year high for SEC enforcement actions for the fiscal year that ended September 30 included the most-ever cases involving investment advisers or investment companies (160) and the most-ever independent or standalone cases involving investment advisers or investment companies (98).  The agency also reached new highs for Foreign Corrupt Practices Act-related enforcement actions (21) and money distributed to whistleblowers ($57 million) in a single year.

The agency also brought a record 548 standalone or independent enforcement actions and obtained judgments and orders totaling more than $4 billion in disgorgement and penalties.

“By every measure the enforcement program continues to be a resounding success holding executives, companies and market participants accountable for their illegal actions,” said SEC Chair Mary Jo White.  “Over the last three years, we have changed the way we do business on the enforcement front by using new data analytics to uncover fraud, enhancing our ability to litigate tough cases, and expanding the playbook bringing novel and significant actions to better protect investors and our markets.”

The SEC’s most significant enforcement actions in fiscal year 2016 include:

“This has been a strong year for the Enforcement Division, with groundbreaking insider trading and FCPA cases and other important actions across the full spectrum of the securities laws,” added Andrew J. Ceresney, Director of the SEC’s Enforcement Division.  “Through their hard work and steadfast dedication to our mission, the Division’s committed staff have helped protect investors and made our markets fairer and more reliable.”

The agency also brought impactful first-of-their-kind actions in fiscal year 2016, including charges against: a firm solely for failing to file Suspicious Activity Reports when appropriate;  an audit firm for auditor independence failures predicated on close personal relationships with audit clients; municipal advisors for violating the fiduciary duty for municipal advisors created by the 2010 Dodd-Frank Act and the municipal advisor antifraud provisions of the Dodd-Frank Act; a private equity adviser for acting as an unregistered broker; and an issuer of retail structured notes for misstatements and omissions.  In addition, fiscal year 2016 included a first-of-its-kind trial victory: the first federal jury trial by the SEC against a municipality and one of its officers for violations of the federal securities laws. The SEC brought many other impactful actions in fiscal year 2016 spanning the entire spectrum of the marketplace, examples of which are discussed below.

Combating Financial Fraud and Enhancing Issuer Disclosure

  • The SEC continued to prioritize issuer reporting and disclosure matters in fiscal year 2016 and brought a number of significant matters, including actions against companies and executives. These actions included: Weatherford International plc and two of its employees; Monsanto Company and three of its accounting and sales executives; First Mortgage Corporation and six senior executives; Navistar International Corporation and its former CEO; Logitech International and three of its former executives and a former director of accounting; 11 former executives and board members at Superior Bank and its holding company; RPM International Inc. and its General Counsel; IEC Electronics Corp. and two former executives; Uni-Pixel, Inc. and its former CEO and CFO; Martin Shkreli; and The St. Joe Company and five of its former top executives.

Holding Gatekeepers Accountable

  • Held attorneys, accountants and other gatekeepers accountable for failures to comply with professional standards.
  • In the second non-independence case against a major audit firm since 2009, charged Grant Thornton LLP, which admitted wrongdoing, and two of its partners, with ignoring red flags and fraud risks while conducting deficient audits of two publicly traded companies that the SEC had separately charged with improper accounting and other violations.
  • Brought important actions against auditing firms for violating auditor independence rules, including two Grant Thornton firms and Ernst & Young LLP.
  • Charged a private fund administrator with missing or ignoring clear indications of fraud while it was contracted to keep records and prepare financial statements and investor account statements for two client funds that the SEC charged with fraud.
  • Sanctioned a consultant to a Texas-based oil company based on charges that he improperly evaluated the severity of the company’s internal control deficiencies (in addition to charges against the company, senior executives, and an outside auditor).
  • Charged lawyers with allegedly offering EB-5 investments while not registered to act as brokers.
Ensuring Fairness Among Market Participants
  • Sanctioned Barclays Capital Inc. and Credit Suisse Securities (USA) LLC for violating the federal securities laws while operating alternative trading systems (ATSs); Barclays admitted wrongdoing and agreed to pay a $35 million penalty – the largest penalty ever assessed against a dark pool – and Credit Suisse agreed to pay over $54 million in monetary sanctions, representing the largest overall settlement against an ATS.
  • Sanctioned Merrill Lynch for violations of the Market Access Rule, which requires firms to have adequate risk controls in place before providing customers with access to the market and imposed the largest penalty ever assessed in a Market Access Rule case ($12.5 million).
  • Imposed a $1 million penalty on Morgan Stanley Smith Barney LLC for the firm’s failure to adopt written policies and procedures reasonably designed to protect customer records and information.
Rooting Out Insider Trading Schemes Through Innovative Uses of Data and Analytics
Uncovering Misconduct by Investment Advisers and Investment Companies
Fighting Market Manipulation and Microcap Fraud
  • Suspended trading in the securities of 199 issuers in order to combat market manipulation and microcap fraud threats to investors, including 19 issuers arising from a microcap fraud-fighting initiative known as Operation Shell-Expel.
  • Obtained a court order freezing the profits of a foreign trader who allegedly manipulated the stock of a Silicon Valley technology firm through a false EDGAR filing traced to a computer in Pakistan.
  • Obtained an emergency court order to freeze the assets of a United Kingdom resident charged with allegedly intruding into the online brokerage accounts of U.S. investors to make unauthorized stock trades that allowed him to profit on trades in his own account.
  • Charged several alleged perpetrators behind a $78 million pump-and-dump scheme involving the stock of Jammin’ Java, a company that operates as Marley Coffee.
  • Charged proprietary trading firm Briargate Trading LLP and one of its co-founders with engaging in a manipulative trading strategy known as “spoofing.”
  • Sanctioned three traders for two fraudulent trading schemes involving the mismarking of option orders to obtain execution priority and avoid transaction fees charged by options exchanges and “spoofing” to generate liquidity rebates from an options exchange.
Halting International and Affinity-Based Investment Frauds
  • Charged and obtained asset freezes against the operator of a worldwide pyramid scheme that allegedly falsely promised investors would profit from a venture purportedly backed by the company’s massive amber holdings.
  • Charged Vu H. Le a/k/a Vinh H. Le and his company, TeamVinh.com LLC, in connection with their alleged fraudulent raising of more than $3 million from over 5,600 investors throughout the United States and in various foreign countries through a multi-level marketing scheme.
  • Charged entities and individuals with schemes targeting seniors and the elderly, including:
Policing the Public Finance Markets
Cracking Down on Misconduct Involving Complex Financial Instruments
Combating Foreign Corrupt Practices
Standing Up for Whistleblowers
Demanding Admissions in Important Cases Enhancing Public Accountability
Successful Litigation
Won five U.S. District Court jury or bench trials in fiscal year 2016.  Obtained favorable jury verdicts in the following cases:
  • Nan Huang was found liable for illegally insider trading on information he obtained while working as a data analyst for credit card issuer Capital One.
  • Former stock brokers Daryl Payton and Benjamin Durant were found liable for insider trading ahead of a $1.2 billion acquisition of SPSS Inc. by IBM Corporation.
  • Stephen Ferrone, the former CEO of biopharmaceutical company Immunosyn Corp., was found liable for fraudulently misleading investors about regulatory approval of the company’s sole product, and for signing and filing false certifications included with Immunosyn’s annual and quarterly reports.
  • The City of Miami and its former budget director Michael Boudreaux were found liable for multiple counts of antifraud violations of the federal securities laws in connection with the city’s disclosures concerning the deteriorating financial condition of the city during 2007 and 2008 and in three separate offerings of municipal securities in 2009.

sec2

This post comes to us from the Securities and Exchange Commission. It is based on the regulator’s press release, “SEC Announces Enforcement Results for FY 2016,” dated October 11, 2016, and available here.

Categories
White Collar Crime

America’s Corporate Crime Dilemma

Corporate crime has never been a more pressing, vexing, and at times infuriating topic for Americans than at present.  The subject’s many difficulties both are fascinating and, at every turn, defy easy answer.  The ambition of my new book, Capital Offenses: Business Crime and Punishment in America’s Corporate Age (W.W. Norton & Co.), is to illustrate and explain, in plain language accessible to all readers, the dilemma of corporate crime—as a means to point Americans beyond criminal law and into a deeper examination of our relationship with the large modern corporation.

Consider the case of Candice Anderson of Van Zandt County, Texas.  She was convicted of manslaughter and branded a felon for the 2004 death of her own fiancée, after her car went off the road into a tree and police detected a medication in her blood that she had taken the night before.  Ten years of grieving later, Anderson was exonerated when the truth emerged that General Motors, not Anderson, had killed her intended spouse—by manufacturing a cheap, faulty starter switch in her car that rotated out of position, shutting off the power steering and brakes, as well as the airbag.  At least 100 people have died due to the same defective part, one created by an engineer who was responding to cost-cutting pressures at GM.

Criminal responsibility for such a death—a straightforward matter if the issue is simply vehicular manslaughter—becomes exceedingly complicated when a corporation is to blame.  GM doesn’t think, it can’t drive a car, and it can’t even really be seen.  It’s an amalgam of people, factories, vehicles, images, and offices spread across the globe.  The company is an idea as much as it is a thing.

Everyone in a position of senior management responsibility at GM appears to have been ignorant of the engineering decisions involved in that starter switch—much less of any connection between those decisions and the many road deaths.  Even lower-level employees handling lawsuits against the company for some of the related crashes failed, for nearly nine years, to connect the accidents to the starter switch and raise the alarm with supervisors about a systemic problem.

Maybe the engineer should be charged with killing Anderson’s fiancée.  But, as that man toiled within the bowels of GM, did he realize his neglect might endanger lives?  Suppose he did.  Would a prosecution of this midlevel salaried worker, even for homicide, really be a way of saying GM was a killer and punishing the company for that?  It seems like GM’s managers, with their cost-cutting strategies and their failure to make sure the left hand in the company knew what the right was doing, are most responsible.

Could the government round up those managers and imprison them for their serious business failures?  Not in the American legal system, which strictly prohibits prosecuting a person without a clear law on the books at the time of his offensive conduct.  There is no crime of “bad management of a big company” and no good argument for legislating such a sweeping and amorphous power to revoke liberty.  The only conceivable criminal case against managers would be a prosecution for negligent homicide based on the long and attenuated chain running from their unawareness at GM’s headquarters all the way down to the road outside Dallas where Anderson’s fiancée died.

Even if the problem of the crime could be worked out—who committed it and what law he or she violated—what about punishment?  GM can’t be put in a prison, so it’s not clear what a prosecution of GM could add to the civil lawsuits for each of the driver deaths that the company will have to settle with the survivors, no doubt at steep cost.

Criminal fines could increase GM’s total bill for its transgressions.  But how big a fine would it take to get the GMs of the world not to make these kinds of mistakes again?  Would such a penalty be so large that it could put GM in dire straits, eliminating those manufacturing jobs that the government tried so hard to save when it rescued the huge auto company from the financial crisis of 2008 to 2009?  (In the end, the government prosecuted GM on a theory of fraud in the sale of the faulty cars but agreed to defer the case in exchange for a $900 million penalty that the company has absorbed.)

To take another example, consider the elephant in the room of corporate crime these days:  the enormously complex matter of criminal liability for mortgage-backed securities (MBS) trading at the world’s largest banks leading up to the market collapse of 2008—that is, the “why no bankers in jail” question.

Fraud requires deception.  And the kind of fraud that makes one eligible for prison requires the intent to deceive.  Deception is necessarily a contextual concept, based on the expectations that buyers and sellers bring with them when they enter a particular market.  The candor expected, and the trust given, are not the same on the used car lot as in the doctor or lawyer’s office.

When, late in the MBS game, sharp trader A sold lots of long positions to slightly less sharp trader B, both of whom were operating in a baroque market for custom-built derivatives products, a theory of fraud by nondisclosure of facts—for example, that A’s bank thought it a bad idea to keep going long and was itself loading up on short positions—is very hard to construct.

If trader A lied to trader B, that would be another story.  But such cases have been rare and hard to prove.  A’s silence in the midst of a bad deal for B is just arm’s length securities trading which, by definition, doesn’t happen unless there is disagreement about risk and there will be a winner and a loser.

When all these MBS deals, with all the doubled-down side bets in the form of CDOs and CDSs, added up, we had a systemic disaster on our hands in which most of the rest of us were victims.  But to be the victim of a disaster is not to be the victim of a criminal fraud.  Capital markets need rules of the road.  The law of fraud is one such rule.  Flexible as that body of law is, “we don’t like what happened” is no rule at all, and certainly not the law of fraud.  And without a basic theory of fraud there can be no legal charge to pursue against the managers of the MBS-trading banks, even before grappling with problems of managers’ lack of knowledge and direct involvement in trades.

Our relationship to corporations and capitalism guarantees the repetition of these dilemmas in one corporate scandal after another.  We celebrate economic innovation and risk-taking for the wealth they have given us.  We invented the limited liability corporation to fuel growth by guaranteeing reduced legal responsibility and limited economic exposure.  But when the project of American capitalism goes awry, we regret the results without having any idea how to live without those foundational choices in our legal and economic order.

It might seem easiest to dismiss corporate crime’s puzzles with a simplistic comeback:  Stories like Candice Anderson’s are typical in American criminal justice.  Working people suffer injustice while corporations and their executives get away with everything up to and including homicide.  The only reason any of these questions are difficult is because the law is not what it should be.  It’s the job of legislators and lawyers to fix that.

There is another comeback, less often heard but equally simplistic:  Criminal law has little or no place meddling in the ordinary and vital machinery of economic growth and competition.  That process necessarily involves risks that sometimes produce costs and harms.  But it benefits us all immeasurably and therefore, even when it sometimes goes awry, it does not deserve the special moral condemnation and often devastating consequences of criminal sanctions.

Capital Offenses shows how both of these facile responses to the puzzles of crime in corporate America are wrong.  The parade of corporate malfeasance, and the recent emergence of an entire legal industry around corporate crime, point to the need for a more fundamental conversation about Americans’ relationship to the large corporation.

It’s time to reexamine first principles:  the ground rules for limited liability corporations and their management and governance; where the authority rests for setting those rules within our federal system; what basic regulatory frameworks are essential to making large economic enterprises safe and manageable; and whether we must push the scale of the modern mega-firm down to a size at which it is realistic to think that human beings can control it.  Fixation with criminal punishment distracts us from that work.

This post comes to us from Samuel W. Buell, the Bernard M. Fishman Professor of Law at Duke University. It is based on his new book, Capital Offenses: Business Crime and Punishment in America’s Corporate Age.

Categories
Finance & Economics

How to Limit Opacity and Conflicts of Interest in Retirement Plans

Designing sensible defined-contribution retirement-plan rules is a challenging task since most Americans do not have sufficient financial acumen and self-discipline to manage their own retirement portfolio.  In spite of the fact that retirement plans constitute the bulk of their savings, most American families struggle with the management of defined contribution (DC) plans. Consequently their savings are inadequate to meet their retirement needs.  According to a recent report, 56 percent of Americans have less than $10,000 in their retirement accounts.  One in three Americans reported that they had no retirement savings.[1] Clearly, the current DC plans for retirement savings are not working very well for the typical American.  In this paper, we analyze simple and sensible rules that can help every American family get the most out of its DC retirement plan.

Since 1975, a structural change has occurred in our private retirement system away from defined benefit plans (DB) and into defined contribution plans (DC), which include self-directed Keogh and IRAs, and employer-sponsored 401(k) and 403(b) plans.  DC plans provide tax-advantaged retirement savings vehicles for individuals and typically represent a large portion of the individual’s savings.  In 2015, IRAs alone accounted for $7.6 trillion in assets.[2]  This massive shift from DB plans to DC plans has increased the urgency and importance of both transparency and sound investment advice regarding retirement savings.

The most important impediment for adequate savings in DC plans is the poor performance of trillions of dollars of investments in DC plans.  The poor performance itself is a consequence of the lack of investor sophistication and discipline, as well as the complexity of the investment instruments and investment concepts.  This problem can clearly be mitigated by prudent advice from financial experts. Instead the problem is compounded by current rules that do not require investment advice to be in the best interest of the plan beneficiaries.

To address these serious and growing problems, policy makers have recently targeted the “suitability rule” in providing investment advice.  Under the Department of Labor’s (DOL) recently instituted new rule,[3] investment advisers for retirement accounts would be subject to a higher fiduciary standard, and investment advisers must recommend investment products with the “best interest” of the beneficiaries in mind.  The new rule is prima facie laudable.  However, there are two provisions in the recently instituted standard that undermine its primary intent of ensuring that investors get unbiased investment advice at a reasonable cost. The first allows investment advisers to receive compensation such as commissions from financial institutions whose products they recommend for inclusion in the investor’s retirement portfolio. By allowing advisers to receive compensation from both the buyer (investor) and the seller (financial institutions), this provision creates an obvious conflict of interest between the investor and the adviser.

The second provision of concern allows advisers to include proprietary products in the retirement portfolio. These products suffer from greater informational asymmetry, with the seller holding an informational advantage, and have complex features that are difficult for the average investor to understand and analyze.  There is considerable evidence that the average investor is not as financially sophisticated as she needs to be to manage substantial retirement assets.   Furthermore, proprietary investment products are also likely to involve higher transaction costs. While either of the two issues of informational asymmetry and complexity is sufficient to put the investor at a significant disadvantage, the combination compounds the problem. Furthermore, the above two provisions in combination exacerbate the concern that investors might not get sound advice: Advisers who receive compensation from institutions have a greater incentive to recommend costly proprietary products that earn them greater commissions.  In summary, the provisions that create potential conflicts of interest between advisers and investors are further compounded by allowing proprietary products.

The relevant policy question is how significant these issues are.  That is, are these potential conflicts of interest likely to result in significant losses to investors due to poor advice?  And does the lack of transparency in proprietary products have adverse consequences to investors?  In this paper we provide evidence that the answer is “yes” to both questions.

To answer the first question on the effect of conflict of interest, we choose a unique setting in which a similar potential conflict of interest exists: namely, DB pension funds that were already subject to the fiduciary standard.  We analyze the performance of DB pension funds in which the fiduciary is also an executive of the firm that is the employer of the beneficiaries.   Such a set-up creates a conflict of interest, with the fiduciary-executive required to serve two principals: the beneficiaries of the DB fund and the shareholders of the firm.

Our evidence indicates that a simple requirement that investment advisers be subject to the fiduciary standard does not by itself address the conflict of interest issue in DB pension funds: In funds with conflict of interest, beneficiaries are short-changed for the benefit of the shareholders.   The one-year abnormal underperformance exceeds 10 pecent.  Based on this experience of DB pension funds with conflicts of interest, we can conclude that the effect of conflict of interest is real and significant and will very likely be to the detriment of the beneficiaries of the DC plans as well.  Therefore, without addressing the conflict of interest issue, the current rules for DC plans are not likely to be successful in addressing the issue of inadequate retirement savings.

To address the second question regarding proprietary products, we consider two representative products that would continue to be allowed as appropriate retirement investments.  We simulate the performance of these products and find that, on a risk-adjusted basis, the performance is inferior compared with both the risk-free rate and th S&P 500.  Hence our evidence suggests that without also addressing the transparency problem, the fiduciary standard rule for DC plans is not likely to be successful.

The current investment advisory rules are clearly deficient.  On the one hand, the current rules require that an investment adviser act in the best interest of a beneficiary, yet they allow the adviser to receive income from third parties.  In addition, the rules do not prohibit opaque, proprietary products, which would lead to uninformed and costly investment decisions.  In fact, the current rules are likely to lead to continued conflicted investment advice, confusion, and widespread litigation to sort out these internal conflicts.  We offer three policy recommendations to remedy these problems.

Based on our empirical evidence, our first policy recommendation addresses the current rule that allows advisers to receive income both from the investor as well as the sponsor of the investment product.  Any serious reform in retirement investment area must address the conflict of interest problem caused by this income exemption rule.  The key to eliminating conflicts of interest involves insuring that investment advisers serve, and therefore receive income from, only one principal.  Unfortunately, the current advisory rules and the associated exemptions simply fail to address the multiple-masters problem.

Second, any serious reform must eliminate the lack of transparency inherent in proprietary investment vehicles.  In this paper, we show that without transparency, retirement beneficiaries will be unable to make informed decisions about their choice of retirement vehicles. As we show, these investment vehicles are also likely to provide lower returns, thereby reducing the retirement savings of beneficiaries.   Furthermore, we show that by using proprietary products in IRA accounts, certain wealthy taxpayers can avoid paying any taxes on their income.  Thus, allowing proprietary products into IRA accounts does not make any sense either from the average beneficiary perspective or a public policy perspective. We recommend a very strict transparency rule in order for any investment to qualify as a retirement asset.

Overall, we conclude that simply requiring a fiduciary standard in itself is not going to solve retirement savings problems.  Instead, it is likely to lead to additional problems by creating an inconsistent set of rules.[4] To prevent conflicts of interests and lack of transparency from creeping back into the retirement-advice business, we also recommend a further streamlining of retirement accounts.  We recommend that only passive index funds, consisting of broadly diversified portfolios, be allowed the tax exemption as retirement accounts.   To this end, we further recommend the creation of standards requiring that certain percentages, based on the a beneficiary’s age, of common stocks and corporate and government bonds be held in defined contribution retirement accounts.

ENDNOTES

[1] Elyssa Kirkham, 1 in 3 Americans Have Saved $0 for Retirement, Time (Mar. 14, 2016), http://time.com/money/4258451/retirement-savings-survey/.

[2] See Nick Thornton, Total Retirement Assets Near $25 Trillion Mark, Benefits Pro (Jun. 30, 2015), http://www.benefitspro.com/2015/06/30/total-retirement-assets-near-25-trillion-mark.

[3] Under the DOL’s definition, any individual receiving compensation for providing advice that is individualized or specifically directed to a particular plan sponsor (e.g., an employer with a retirement plan), plan participant, or IRA owner for consideration in making a retirement investment decision is a fiduciary. Such decisions can include, but are not limited to, what assets to purchase or sell and whether to rollover from an employer-based plan to an IRA. The fiduciary can be a broker, registered investment adviser, insurance agent, or other type of adviser (together referred to as “advisers” here). Some of these advisers are subject to federal securities laws and some are not. Being a fiduciary simply means that the adviser must provide impartial advice in their client’s best interest and cannot accept any payments creating conflicts of interest unless they qualify for an exemption intended to assure that the customer is adequately protected. DOL’s regulatory impact analysis estimates that the rule and related exemptions would save investors over $40 billion over 10 years, even if one focuses on just one subset of transactions that have been the most studied. The real savings from this new rule are likely much larger as conflicts and their effects are both pervasive and well hidden.  See Department of Labor Proposes Rule to Address Conflicts of Interest in Retirement Advice, Saving Middle-Class Families Billions of Dollars Every Year, U.S. Dep’t of Labor, https://www.dol.gov/ebsa/newsroom/fsconflictsofinterest.html.

[4] The new rules have already created a wave of lawsuits regarding conflicts of interests and opacity in defined contribution plans.  See for instance Wall Street Journal, August 6, 2016, “Self-Dealing with 401 (k),” and Wall Street Journal, September 14, 2016, “MIT, NYU, Yale Sued over Retirement-Plan Fes.” Also see, Wall Street Journal, September 7, 2016, “Wall Street Remakes the CD, Hitting Yields.” Furthermore, the U.S. Supreme Court recently ruled in favor of the Plaintiffs in 401(k) plans and rejected a strict six-year statute of limitations to bring a lawsuit.  See, http://www.wsj.com/articles/high-court-ruling-adds-protections-for-investors-in-401-k-plans-1431974139.

This post comes to us from S. Burcu Avci, a post-doctoral research scholar at the University of Michigan’s Ross School of Business, and from MP Narayanan and H. Nejat Seyhun, professors at the Ross School of Business. It is based on their recent article, “How Should Defined Contribution Retirement Plans Be Organized?” available here.

Categories
International Developments

Kirkland & Ellis Discusses Russia Sanctions Developments

The U.S. Treasury Department’s Office of Foreign Assets Control (“OFAC”) has significantly expanded the number of entities and individuals subject to Russia sanctions and separately censured U.S. insurance and financial institution entities for failing to keep current with OFAC’s sanctions list to prevent transactions with sanctioned parties. Economic sanctions continue to evolve as political situations change in the comprehensively sanctioned jurisdictions of Cuba, Crimea, Iran, North Korea, Sudan and Syria, as well as in countries targeted by more limited but often more complicated sanctions such as those relating to Russia, Burma/Myanmar and many other countries. The recent actions by OFAC highlight the need for continuous, active monitoring for compliance with U.S. sanctions developments by U.S. companies and non-U.S. companies with a U.S. nexus (e.g., co-investors, management, partnerships, shareholders, suppliers or service providers).

Russia Sanctions Expanded, Ivory Coast Sanctions Program Ended

Tensions between the United States and Russia remain high, and on September 1, 2016, OFAC announced expanded Russia sanctions targeting entities with a connection to existing sanctions — including entities that provided material assistance to or are owned by designated parties and 18 construction, transportation and defense entities that operate in Crimea. The European Union also announced recently the extension of Russia sanctions.

Since December 2014, OFAC has prohibited most transactions by U.S. persons and with a U.S. nexus involving Crimea following Russia’s annexation of this territory from Ukraine. A Russian shipping and logistics company, Sovfracht-Sovmortrans Group, was included in the recent designations. U.S. person dealings directly or indirectly with designated parties in general are prohibited. Affiliates of the Bank of Moscow and Gazprombank were explicitly named under more limited sectoral sanctions.

In addition, effective September 7, 2016, the U.S. Commerce Department’s Bureau of Industry and Security (“BIS”) placed 86 new entries on its Entity List pursuant to U.S. sanctions on persons contributing to the situation in Crimea. Notably, several of the entities identified on the Entity List are located outside Russia or Crimea, in destinations such as Hong Kong and India. Strict export control policies are applicable to persons on the entity list, and BIS severely limits exports from the United States or from third countries of U.S. goods, data or technology to such persons.

Sanctions programs do periodically come to an end, when the political situations that prompted the sanctions are resolved or substantially subside. On September 14, 2016, U.S. sanctions targeting Côte d’Ivoire, in place since 2006, were terminated by Executive Order. Companies will want to update compliance sanctions screening and other measures to reflect that this is no longer a high-risk jurisdiction for U.S. sanctions.

Pitfalls of Failing to Update Customer Diligence

On August 2, 2016, OFAC announced its findings of U.S. economic sanctions violations for two major insurance companies. Specifically, OFAC found that these companies violated the Foreign Narcotics Kingpin Sanctions Regulations (“Kingpin Regulations”) by providing, receiving premiums and servicing health insurance policies for three individuals sanctioned under the regulations. The Kingpin Regulations target foreign narcotics traffickers and their organizations throughout the world.

One insurance company provided health insurance policies to three individuals beginning in 1992, and another company’s subsidiary served as the Third Party Administrator (“TPA”) for the individuals’ policies. Seventeen years later, in 2009, OFAC added these three individuals to the list of Specially Designated Nationals and Blocked Persons List (the “SDN List”) under the authority of the Kingpin Regulations. According to OFAC, the insurance companies were unaware of their policyholders’ designation on the SDN List because the companies “failed to implement controls and measures to ensure [they] could identify, block and report insurance policies, premiums, or claims payments in which an OFAC sanctioned person had an interest.” After the policyholders were placed on the SDN List, the companies processed and received 34 premium payments from them. The violations were only discovered when a third health insurance company began providing TPA services for the policies in question and screened for restricted parties. At that point, the two insurance companies that originally issued and serviced the policies voluntarily disclosed the violations and fully cooperated with OFAC’s investigation.

Given the companies’ valid voluntary disclosure, the relatively low value of the transactions (below $15,000), and the fact that neither company had any history of sanctions violations, OFAC’s enforcement action did not impose financial penalties.  Nonetheless, the companies incurred substantial costs. Internal investigations, disclosure and remediation of these types of OFAC issues typically are costly and moreover the companies’ violations have been publicly announced.

Significantly, in its notice of findings, OFAC pointed out that the TPA had responsibility for screening the names of policyholders for sanctions compliance even though the company had not assumed financial responsibility for the policies. OFAC’s enforcement action demonstrates its expectation that companies will be thorough in developing and implementing their screening and sanctions compliance policies and practices, even if they are not the primary party in transactions with foreign persons.

On July 27, 2016, OFAC announced its finding that a bank branch office in Texas violated the Kingpin Regulations by maintaining bank accounts for two individuals placed on the SDN List. The bank accounts pre-dated the imposition of sanctions on the account holders. Nevertheless, OFAC found that the bank violated sanctions because it had not identified and blocked the accounts in question once sanctions were imposed. OFAC observed that the bank’s failure to comply with the Kingpin Regulations resulted from “a misconfiguration in the bank’s screening software . . . that prevented it from reviewing dormant or inactive accounts against additions or changes to the SDN List.” OFAC also found that bank personnel became aware of the account holders’ placement on the SDN List through a negative news report, but that the bank failed to take immediate steps to remedy the violation. In short, the bank’s compliance policies were not adequate to prevent the violation of economic sanctions.

OFAC did not impose a financial penalty on the bank because management-level employees had no knowledge of the violation, the SDN account holders did not receive any economic benefit, and the company promptly remedied the gaps in its compliance program. However, as already noted above, the process leading to a violation finding by OFAC and having the violation made public have significant costs for a company.

Take-Away Compliance Guidance

These companies’ sanctions violations provide useful guidance for practically any U.S. business:

  • Compliance with OFAC sanctions is subject to strict liability, so that violations occur even where a company inadvertently engages in prohibited activity.
  • It is not sufficient to screen only a subset of counterparties such as new customers. The SDN List is constantly updated and may be revised to include a company’s existing vendors, customers, or partners. Companies should regularly screen existing, as well as new, customers and other counterparties against the SDN List.
  • A company cannot rely on other parties to a transaction to verify compliance with sanctions. A company that knew or should have known of a potential violation can be held liable under sanctions laws. U.S. companies should implement their own policies for screening against restricted parties.
  • A business model focused on the U.S. market does not eliminate the need for active, robust sanctions compliance policy and practices. Transactions in the United States involving non-U.S. persons can result in the application of U.S. economic sanctions to business dealings.
  • Periodic internal audits of compliance practices can help avoid more serious liability under U.S. sanctions laws, as well as any reputational damage. Detecting and reporting potential violations as early as possible significantly reduces exposure to U.S. economic sanctions. Reviewing compliance practices on a regular basis can prevent ongoing or repetitive sanctions violations that can result in higher penalties.
  • Voluntarily disclosing violations to OFAC and fully cooperating with any follow-on investigation can greatly mitigate penalties assessed by the agency. OFAC’s guidelines specifically contemplate reduced liability for parties that self-report potential violations and assist the agency in its investigation.

This post comes to us from Kirkland & Ellis LLP. It is based on the firm’s client update, “Russia Sanctions Developments Highlight Need for Active Compliance Efforts,” dated September 15, 2016, and available here.

Categories
Uncategorized

Do Battleground States Get a Break from Regulators?

The question of whether government regulation is, on aggregate, helpful or harmful has been widely studied in economics.  However, an equally important question is whether or not regulation is selectively enforced, and this has received substantially less attention from academic researchers.  Because regulation can hurt voters as well as help them, the vigorous enforcement of government regulation can be costly to politicians and other government officials, including the regulators themselves.  Thus there are often a set of incentives that can result in politicians and other political actors being reluctant to enforce regulations among politically important constituents.

To examine whether or not regulation is selectively enforced in the U.S., we identify a set of regulations related to the enforcement of an economically important statute that applies uniformly to the 50 U.S. states: the Clean Water Act of 1972.  We also identify a source (which varies over time) of the state-level political importance of voters: whether or not a state is a “battleground” or “swing” state in presidential elections.  We find that the Environmental Protection Agency (EPA) is much less likely to find facilities in battleground states to be in violation of the CWA than facilities in non-battleground states, consistent with regulation being less stringently enforced among important voters.

The CWA requires that facilities which discharge water directly into the surface waters of the United States obtain a permit to do so, and these permits are tracked by the EPA’s National Pollutant Discharge Elimination System (NPDES).  The NPDES data is publicly available and goes back to at least 1976.  In addition to tracking permit information, the NPDES data also records several different categories of permit-related CWA violations (e.g., a facility emits water with pollutant levels above those allowed by their permit).

We hypothesize that, because of the importance of these states in presidential elections, regulatory agencies (whose leadership is typically appointed by the president) are more likely to exhibit leniency in the enforcement of government regulation in battleground states.  Thus, we wish to determine whether facilities in these states are less likely to be found in violation of the CWA by the EPA.  A key difficulty in these kinds of studies is establishing causality.  Specifically, we wish to show whether being located in a battleground state causes a reduction in violation rates.

A key feature of our data allows us to do this.  Specifically, the NPDES data includes the latitude and longitude of each facility that is registered with the system.  This locational data allows us to match facilities in battleground states with similar facilities that are located nearby in non-battleground states (and vice versa).  Thus we create a “border” sample of 11,398 unique and similar facilities that are located along the border of battleground and non-battleground states.  Aside from being located in different states, and since rivers and streams often serve as the border between states, this frequently means that these otherwise similar facilities differ only by being located across from each other along a river or stream (and thus are likely subject to similar economic and demographic trends and, importantly, ostensibly similar treatment under the CWA).  Thus, we argue, we are able to isolate effects that are driven by changes to a state’s battleground status.

In the most basic analysis, we find that, for any given year between 1976 and 2014, facilities have only an 11.3 percent chance of being found in violation of the CWA if they are located in a state that was a battleground state in the most recent presidential election, while facilities in non-battleground states have a 23.7 percent chance.  That is, facilities in battleground states experience a 51.9 percent (or 12.3 percentage point) decrease in the likelihood that they will be found to violate the CWA in a given year.  This effect is large and statistically significant.  Unless becoming a battleground state causes facilities to be more effective in their compliance with environmental regulation, this finding is more consistent with regulations being more loosely enforced.

We also examine the changes to violation rates among facilities that are located in states that change battleground state status after an election.  For example, after an election where a non-battleground state becomes a battleground state, the facilities in that state subsequently experience lower violation rates.  The reverse holds true for facilities located in battleground states that revert to non-battleground state status after an election.

We also examine this battleground state effect in several multivariate regressions where we control for additional factors that might affect violation rates.  In these regressions we include explanatory variables like the number of electoral votes allocated to the state in which the facility is located, state-level unemployment rates as well as state per-capita income levels.  We also include “fixed effects” to control for any other constant state effects (such as whether the state is generally Republican or Democrat), time effects (which capture any effects that vary by year, such as stock market returns, business cycle effects, etc.), and industry-by-year effects (such as regulatory changes that affect each industry differently or other industry-level trends).  We find results that are similar to those previously outlined: facilities located in battleground states have violation rates that are as much as 6.9 percentage points lower than similar nearby facilities located in non-battleground states.

We run a number of additional tests to examine the particulars of this effect.  Does it vary depending upon the party of the president?  We find that it does not; whether the president is a Republican or Democrat makes little difference.  Does it vary by the year in the elections cycle?  Perhaps the increased scrutiny of battleground states results in their being more compliant (and therefore experience lower violation rates) in election years.  We find that the effect is evenly spread out across a four-year presidential election cycle, and is not concentrated by effects in an election year only.  We also repeat the analysis using the full sample of 288,490 unique facilities (i.e., we include all NPDES facilities, and not just those located along state borders) and look at different types of NPDES violations.  We find that the general result holds in the full sample as well as across violation types: facilities in battleground states are significantly less likely to be found in violation of the CWA, and across different categories of NPDES violations.

Finally, we examine how likely it is that this effect is driven by our method of determining battleground states.  To do this, we run simulations where we randomly assign battleground state status to the fifty states and repeat some of our analysis.  We find that, in 10,000 simulations, between 0.0 to 1.5 percent of randomly assigned battleground states yield results similar to those we find.  It is thus very unlikely that this effect is driven by our method for assigning battleground state status.

Why would the EPA lightly enforce the CWA in battleground states?  We do not answer this question definitively, though we speculate it is related to the political incentives incident to presidential elections.  In particular, we argue that, because the perceived state of the economy plays a large role in the re-election of incumbent politicians (or their party), presidents have incentive to decrease regulatory burdens when they may have a negative economic impact, particularly on important constituents (which, in the Electoral College, includes voters in battleground states).  Consistent with this, we offer supportive (but limited) evidence that decreased CWA enforcement results in increased state-level votes to the party of the incumbent president.

We are also quick to observe that our study does not touch on the efficacy of environmental law.  Whether the lighter enforcement of the CWA results in a positive effect to the general welfare (e.g., avoidance of unnecessary regulatory costs) or a net negative effect (e.g, greater negative health and other environmental outcomes) is beyond the scope of our study.

These caveats notwithstanding, we demonstrate that, whatever the mechanism or the effect on public welfare, government regulation is selectively enforced among politically important constituents, this effect is large, and it is persistent.  We argue that the political debate over government regulation should not include discussions only about its anticipated effects but also whether it will be uniformly enforced.

This post comes to us from Professor Huseyin Gulen of Purdue University’s Krannert School of Management and Professor Brett W. Myers of Texas Tech’s Rawls College of Business. It is based on their paper, “The Selective Enforcement of Government Regulation: Battleground States and the EPA,” available here.

Categories
International Developments

Sullivan & Cromwell Discusses U.S. Tax Consequences of EU State Aid Recoupment

On September 15, the IRS and Treasury Department proposed, in Notice 2016-52 (the “Notice”), new rules that limit the ability of U.S. multinational groups to claim credits against U.S. taxes for significant foreign tax adjustments (i.e., adjustments of more than $10 million).  Foreign assessments within the scope of the Notice include (but are not limited to) those that may arise in connection with the state aid investigations that have been initiated by the European Commission over the last several years.

The Notice describes two categories of transactions that might otherwise allow a U.S. multinational to expedite its ability to claim foreign tax credits in respect of amounts paid to resolve a significant foreign assessment, and treats such structures as “splitter arrangements”.  Accordingly, the creditability of foreign taxes paid in connection with such transactions will generally be suspended until the “related income” is taken into account for U.S. tax purposes.  Because a U.S. multinational might consider paying a foreign assessment to be less burdensome if the additional foreign tax can be credited in the United States on an efficient basis, the new rules are intended to encourage U.S. multinationals to contest major foreign tax adjustments.

In addition, although the Notice was issued in the context of (and, in places, specifically refers to) the European Commission’s state aid investigations, the Notice states that “no inference” is intended as to whether amounts paid to resolve any particular tax proceeding are creditable foreign taxes.  Therefore, the IRS could still determine that some (or all) payments made in connection with the European Commission’s state aid investigations are not creditable foreign taxes for U.S. foreign tax credit purposes.

The Notice refers to the new categories of “splitter arrangements” as “covered transactions” and “covered distributions”.  Although the Notice’s definitions of “covered transactions” and “covered distributions” exclude transactions that are effected for a non-tax “principal purpose” (as demonstrated by clear and convincing evidence), these categories are otherwise very broad.  In particular, subject to this “principal purpose” exception (and a limited exception for transactions in which the “earnings and profits” of the target entity are also transferred), any transaction that causes a significant foreign tax assessment to be paid by a corporation other than the corporation that was treated as originally earning the taxed income (including, for example, an intra-group sale of a “disregarded entity”, a liquidation, or a reorganization) will generally be a “covered transaction”.  Similarly, any dividend that is paid to a foreign subsidiary of a U.S. multinational during or after the year when income to which a significant foreign assessment relates is earned (but before the year when a significant assessment is paid) may be a “covered distribution” (unless, again, the U.S. multinational group can demonstrate a non-tax “principal purpose” for the distribution by clear and convincing evidence).

The rules described in the Notice are proposed to be effective for foreign taxes paid on or after September 15, 2016.  However, the Notice does not appear to include a “grandfather” or similar rule for restructurings or distributions that have already been completed.  Accordingly, U.S. multinationals that have already entered into transactions described in the Notice may wish to consider their options in respect of such transactions.

Background

A.     Foreign Tax Credit “Splitter Arrangements”

Although the United States generally (subject to certain limitations) allows a domestic parent corporation to credit foreign taxes paid by its non-U.S. subsidiaries against the domestic parent’s U.S. tax liability, such foreign taxes are only “deemed paid” by a domestic parent to the extent the foreign subsidiary’s earnings are repatriated (or deemed repatriated) to the United States.  Therefore, for example, if the parent of a U.S. multinational group owned a foreign subsidiary with earnings of $100 (which had been subject to $10 in foreign tax), a $50 dividend from this foreign subsidiary would generally give rise to a foreign tax credit of no more than $5.  Because (at a 35% corporate federal tax rate) $17.50 in U.S. tax would be due on this dividend, the domestic parent would generally owe $12.50 in residual U.S. tax.  On the other hand, if the foreign subsidiary in the above example had been subject to $35 in foreign tax, a dividend of $50 could give rise to a foreign tax credit up to $17.50, potentially offsetting the domestic parent’s entire U.S. tax liability in respect of the dividend.

U.S. law has historically treated an entity as having paid a foreign tax if—under applicable foreign law—that entity is legally liable for the foreign tax.[1]  At times, this general principle can create a mismatch between the entity that recognizes an item of income (for U.S. tax purposes) and the entity that is treated as having paid an associated amount of creditable foreign tax (for U.S. tax purposes).  Strategic use of such “splitting” can concentrate a U.S. multinational group’s foreign taxes within a subset of the group’s foreign entities, each of which may be treated as having paid creditable foreign taxes at a high effective rate.  By selectively repatriating income from such entities (while not repatriating income of foreign entities that are considered subject to creditable foreign taxes at a low effective rate), a U.S. multinational group may then be able to expedite the rate at which foreign tax credits become available and reduce collateral increases in U.S. tax.

In August 2010 (and in response to perceived deficiencies in the rules governing the allocation of creditable foreign taxes), Congress enacted Section 909, which suspends foreign tax credits that arise in connection with a “foreign tax credit splitting event” until the “related income” is taken into account for U.S. tax purposes.  Although Section 909 grants the Treasury Department broad authority to identify “splitter arrangements”, regulations issued under Section 909 deliberately limit the applicability of this rule to four exclusive categories of “splitter arrangements”: (i) “reverse hybrids” (i.e., entities that are treated as corporations for U.S. tax purposes but are fiscally transparent for applicable foreign tax purposes); (ii) group-relief and loss-sharing regimes; (iii) hybrid instruments (i.e., in general, instruments that are treated as equity under U.S. tax law but characterized as debt under applicable foreign tax law, or vice versa); and (iv) certain partnership inter-branch payments.[2]

B.     EU State Aid Investigations

Since 2014, the European Commission has commenced a number of state aid investigations into tax rulings (including unilateral advance pricing agreements) granted to multinational groups operating within EU member states.  Under EU law, if the European Commission determines that state aid has been unlawfully granted, the European Commission can order the relevant member state to recover the aid from its beneficiary (plus compound interest)‎ going back up to ten years.

Although the European Commission has investigated rulings granted to at least two EU-headquartered multinationals (Fiat Chrysler and Engie), four of the six cases that have been officially opened to date (and four of the five cases opened before this week)[3] examined rulings granted to U.S. multinational groups (Amazon, Apple, McDonald’s and Starbucks).  The European Commission’s state aid investigations and proposed large assessments against U.S. taxpayers have become the subject of high-level disputes between the European Commission and the U.S. government.   For example, in February 2016, U.S. Treasury Secretary Jacob Lew sent a letter to Commission President Jean-Claude Juncker asserting, among other things, that the European Commission’s state aid investigations “appear to target . . . income that Member States have no right to tax under well-established international tax standards” and “appear to be targeting U.S. companies disproportionately”.[4]  Additionally, in January 2016, members of the Senate Finance Committee sent a letter to the U.S. Treasury Department expressing both similar apprehensions and a concern that the investigations “could give rise to U.S. companies paying EU Member States billions of dollars in tax assessments that may be creditable foreign taxes, resulting in U.S. taxpayers ‘footing the bill’”.[5]  In August 2016, the U.S. Treasury Department also published a white paper on the European Commission’s state aid investigations, in which the U.S. Treasury Department reiterated this background, outlined several legal and policy arguments against the approach used by the European Commission, and warned that “[t]he U.S. Treasury Department continues to consider potential responses should the [European] Commission continue its present course”.[6]

On August 30, the European Commission announced that two tax rulings granted by Ireland to Apple gave rise to undue tax benefits representing impermissible state aid.[7]  This determination—while subject to appeal—could require Ireland to recover up to €13 billion (plus interest) from Apple.  Statements from both U.S. government officials and trade associations since the Apple decision have sharply criticized the European Commission’s approach.  For example, on August 31, U.S. Treasury Secretary Jacob Lew remarked that, “[a]s the head of the U.S. tax agency, I’ve been concerned that [the European Commission’s approach] reflects an attempt to reach into the U.S. tax base to tax income that ought to be taxed in the U.S.” and that “we think that [the European Commission’s approach] undermines the environment in Europe for international business because it creates uncertainty and ultimately will not be good for the European economy”.[8]  On September 16, the Business Roundtable also released an open letter to leaders of the 28 EU member states, urging them to overturn the Apple decision.[9]  Although European Commission Competition Commissioner Margrethe Vestager recently met with U.S. officials and has denied that the European Commission’s state aid investigations are targeted at U.S. companies, reports indicate that both the appropriateness of and legal basis for these cases remain a significant point of contention between the European Commission and the U.S. Treasury Department.[10]

Discussion

Although paying any tax assessment necessarily involves a cost, a U.S. multinational group may find that paying a prior-year foreign adjustment is less burdensome if foreign tax credits arising from that assessment can be claimed on an expedited basis and / or without collateral increases in U.S. tax.  A U.S. multinational group may (in the absence of a rule to the contrary) be able to accomplish such a result by restructuring its foreign entities so any taxes paid in a significant foreign dispute arise in a foreign corporation with a significant “pool” of foreign taxes, relative to that foreign corporation’s earnings.  Such a reorganization could—for example—involve transferring a “disregarded entity” that anticipates resolving a major foreign tax liability to a newly organized foreign corporation, thereby causing any creditable taxes resulting from the assessment (but not the earnings on which those taxes were paid) to be paid or accrued by the new corporation.  A similar outcome could be achieved if a foreign corporate subsidiary within a U.S. multinational group were to pay an extraordinary dividend to another foreign corporation (thereby reducing the payor’s foreign earnings) before settling a foreign tax dispute.

Under the Notice, such restructuring transactions and distributions will—if they are undertaken in connection with a prior-year foreign tax assessment—generally be treated as “splitter arrangements”.  In particular, the Notice states that the IRS and Treasury Department intend to issue regulations that treat a payment of “covered taxes” as a “splitter arrangement” if that payment is made as a result of a “covered transaction” or a “covered distribution”.  “Covered taxes”, for this purpose, are generally defined as foreign income taxes that: (i) are reflected in the payor’s “pools” of foreign taxes in the taxable year when they are paid; and (ii) result from a “specified foreign-initiated adjustment” (in general, a prior-year foreign tax assessment of more than $10 million).  The preamble to the Notice specifically observes that assessments made to recoup EU state aid can fall within this definition “to the extent [such] payments result in creditable foreign taxes”, and the Notice therefore leaves open the possibility that the IRS will conclude that payments (or some payments) representing a recovery of state aid are not creditable taxes.  Of course, any other assessments of prior-year foreign income taxes (including taxes paid in connection with ordinary-course local tax audits) can also be treated as “covered taxes” if they exceed the $10 million threshold.

A “covered transaction” is generally defined by the Notice as any transaction (or series of related transactions) that results in “covered taxes” being paid by a foreign corporation other than the “predecessor entity” (i.e., the corporation that would have been liable for the “covered taxes” had such taxes been paid in the year to which such taxes relate), subject to limited exceptions for transactions between unrelated entities, tax-free reorganizations or liquidations that transfer the “earnings and profits” of the “predecessor entity” to the payor, and transactions that were not structured with a principal purpose of separating “covered taxes” from the undistributed earnings of the “predecessor entity” (as demonstrated by clear and convincing evidence).[11]

A “covered distribution” is, likewise, generally defined as any dividend or similar distribution to the extent such distribution: (i) is made during or after the taxable year of the payor to which the covered taxes relate but before the taxable year in which the covered taxes are paid; (ii) results in a distribution or allocation of the payor’s “post-1986 undistributed earnings” (other than a distribution or allocation of income that was subject to U.S. tax when such income was earned by the payor)[12] to a “section 902 covered person”;[13] and (iii) is made with a principal purpose of reducing the payor’s “post-1986 undistributed earnings” in advance of the payment of “covered taxes”.  In determining whether a distribution is made with such a “principal purpose”, the Notice states that a distribution will be rebuttably presumed to have been made with the required “principal purpose” if the sum of all distributions exceeds the payor’s “post-1986 undistributed earnings” as of the beginning of the taxable year in which the “covered tax” is paid.  A taxpayer may, however, rebut this presumption with clear and convincing evidence that the distribution was not made with the required “principal purpose”.[14]

According to the Notice, the IRS and Treasury Department expect that these new rules will apply to foreign income taxes paid on or after September 15, 2016.  It appears that this “grandfathering” provision applies to tax payments only, meaning that restructurings that took place and distributions that were made before September 15 may be characterized as “covered transactions” or “covered distributions”.  Given this possibility, it may be worthwhile for U.S.-based multinational groups that entered into “covered transactions” or made “covered distributions” before the Notice was released to evaluate their options in respect of such arrangements.

ENDNOTES

[1]     See Treas. Reg. § 1.901-2(f)(1).

[2]     See generally Treas. Reg. § 1.909-2.  Although the Section 909 regulations generally do not treat tax consolidation regimes as “splitter arrangements”, amendments that were made to the “technical taxpayer” rule after Section 909 was enacted reach a similar result.  See Treas. Reg. § 1.901-2(f)(3).  In addition, special (and generally slightly more permissive) rules within these regulations define “pre-2011 foreign tax credit splitting events” (i.e., circumstances in which foreign taxes paid or accrued in a taxable year beginning before January 1, 2011 are suspended under Section 909).  See generally Treas. Reg. § 1.909-6.

[3]     The European Commission’s investigation into Engie was officially opened on September 19, 2016.

[4]     See Letter from Jacob J. Lew, U.S. Secretary of the Treasury, to Jean-Claude Juncker, President of the European Commission (Feb. 11, 2016).

[5]     See Letter from U.S. Senate Committee on Finance to Jacob J. Lew, U.S. Secretary of the Treasury (Jan. 15, 2016).

[6]     See U.S. Dep’t of the Treasury, “The European Commission’s Recent State Aid Investigations of Transfer Pricing Rulings” (Aug. 24, 2016).

[7]     See European Commission, “State Aid: Ireland Gave Illegal Tax Benefits to Apple Worth up to €13 Billion” (press release, Aug. 30, 2016).

[8]     See Alex Lewis, “Apple’s Income Should Be Taxed in U.S., Not Ireland, Lew Says”, Tax Notes Today (Sept. 1, 2016).

[9]     See Business Roundtable, “Letter to EU Heads of State or Government Regarding State Aid Investigations” (Sept. 16, 2016).

[10]    See Alex Parker, “EU-U.S. Tensions Simmer Over Apple, State-Aid Tax Cases”, BNA Daily Tax Report (Sept. 20, 2016).

[11]    Although the Notice proposes that a subjective “principal purpose” test be used to determine whether a “covered transaction” has been entered into or a “covered distribution” has occurred, the Notice requests comments on whether an objective test would be more appropriate for these purposes.  The Notice also solicits feedback on whether, in lieu of creating new “splitter arrangements”, it would be more germane to prescribe guidance under Section 905(c) providing that additional payments of tax be accounted for through adjustments to the pools of foreign income taxes and undistributed earnings of non-U.S. corporations that are not the same entity as the payor of the tax.

[12]    Prior-year subpart F inclusions generally reduce “post-1986 undistributed earnings”, so a distribution of previously taxed income would generally not be considered a distribution of “post-1986 undistributed earnings”.  See T.D. 8708.

[13]    A “section 902 covered person” is a “Section 902 corporation” (i.e., in general, a non-U.S. corporation the foreign taxes of which could be creditable to a domestic corporation under the “deemed paid” rules of Section 902) that is at least 10% owned by (or bears certain other relationships to) the payor.

[14]    As one example, the Notice indicates that a taxpayer could rebut this presumption by demonstrating that the distributions were consistent with a pre-existing pattern of distributions. However, the Notice also states that in the case of a distribution from a pool of “post-1986 undistributed earnings” that included earnings to which the covered taxes relate and also earnings to which the covered taxes did not relate, a taxpayer may not rebut this presumption by claiming that the distribution reduced only the unrelated earnings.

This post comes to us from Sullivan & Cromwell LLP. It is based on the firm’s client alert, “U.S. Tax Consequences of EU State Aid Recoupment: IRS Issues Notice Treating Certain Payments of Prior-Year Foreign Taxes as ‘Splitter Arrangements’,” dated September 22, 2016, and available here.

Categories
White Collar Crime

Latham & Watkins Discusses Ruling that Bitcoins Are “Funds” Under Money Transmitting Laws

On September 19, 2016, U.S. District Judge Alison J. Nathan of the Southern District of New York denied defendant Anthony R. Murgio’s motion to dismiss charges brought against him for, among other things, operating a Bitcoin exchange in violation of federal and state money transmitting laws. The decision adds to a growing body of federal precedent upholding the application of money transmitting laws to Bitcoin exchange businesses.

Analysis

The indictment against Murgio specifically alleges that the Bitcoin exchange he allegedly ran — Coin.mx — was an “unlicensed money transmitting business” in violation of 18 U.S.C. § 1960 (Section 1960). Section 1960 defines “money transmitting” to include “transferring funds on behalf of the public by any and all means.” In moving to dismiss the indictment, Murgio argued that (i) Bitcoin does not qualify as “funds”; (ii) exchanging Bitcoin does not involve “transferring” customers’ funds to other persons or places; and (iii) operating a Bitcoin exchange in the state of Florida, where Coin.mx operated, does not require a license. Judge Nathan rejected each of Murgio’s arguments.

First, the court found that Bitcoin does constitute “funds” within the plain meaning of that term. Rejecting Murgio’s contention that “funds” refers only to “currency,” Judge Nathan found that the term instead encompasses any “pecuniary resources” that can be used as a “medium of exchange,” and that Bitcoin meets that description. In reaching this conclusion, Judge Nathan followed a consistent line of cases from the Southern District of New York — including U.S. v. Ross Ulbricht, U.S. v. Liberty Reserve and U.S. v. Robert Faiella and Charlie Shrem — all of which reached a similar holding.

Second, Judge Nathan refused to dismiss the indictment based on Murgio’s contention that Coin.mx acted merely as a seller of Bitcoin and not as a “transmitter” of funds. The indictment itself, the court held, need only to track the language of the statute in this regard — which it does, by alleging that Coin.mx engaged in “money transmitting.” The indictment is not required, the court explained, to lay out the government’s theory of how Coin.mx engaged in money transmitting. That can await trial. Judge Nathan noted that the government had represented in its briefs that the evidence at trial would show that Coin.mx did more than merely sell Bitcoin to “customers in two-party transactions.”  If at trial the government can show that Coin.mx not only sold customers Bitcoin for currency but also transferred their Bitcoin for them to third parties, then the government may be able to sidestep the defendant’s argument that merely selling Bitcoin to another party is not tantamount to money transmitting. Otherwise, however, there may be occasion for the court to revisit the question. In essence, Judge Nathan bracketed this issue for now.

Third, as for Murgio’s argument that Coin.mx did not require a license to operate, Murgio cited a recent trial court decision in a Florida case — Florida v. Espinoza — holding that Florida’s licensing requirement for money transmitters does not apply to Bitcoin exchangers. After carefully considering the analysis in Espinoza, Judge Nathan found it unpersuasive. Judge Nathan concluded that the Florida Supreme Court, if faced with the question, would hold that Florida’s money transmitting statute does indeed apply to Bitcoin exchange businesses. In support of this conclusion, Judge Nathan noted that the Espinoza court did not sufficiently analyze or explain why a Bitcoin exchanger would not qualify as a seller of “payment instruments” — one of the types of businesses to which Florida’s licensing requirement applies — given that the term is defined to include any type of “monetary value.” In addition, Judge Nathan noted that there are key factual differences between Murgio’s case and Espinoza’s, which cast doubt on the applicability of the Espinoza court’s holding.

Conclusion

The Murgio decision reflects a growing judicial consensus around the application of state and federal money transmitting laws to Bitcoin exchangers. The decision, however, does leave one issue open — whether merely exchanging Bitcoins for fiat currency involves the “transfer” of funds within the meaning of Section 1960. Depending on the government’s evidence, the issue may or may not prove significant at trial. Trial is set to begin on October 31, 2016.

This post comes to us from Latham & Watkins LLP. It is based on the firm’s client alert, “Bitcoin Again Held to Be “Funds” for Federal Money Transmitting Purposes,” dated September 23, 2016, and available here.

Categories
Securities Regulation White Collar Crime

Debevoise & Plimpton Discusses Disclosure of Government Investigations

Registrants, particularly those involved in highly regulated industries, frequently must determine whether and when a government investigation and related pending or threatened litigation must be disclosed in its periodic reports filed with the Securities and Exchange Commission (“SEC”).  On September 9, 2016, the SEC filed a complaint against a company and its general counsel that should serve as a reminder for any registrant subject to a government investigation to ensure that it has robust procedures in place to review disclosure requirements in connection with government investigations in light of the facts uncovered by any internal investigation and the course of settlement discussions with the government.

The SEC complaint alleges violations of the federal securities laws due to the company’s failure timely to disclose a loss contingency, or record an accrual for, a U.S. Department of Justice (“DOJ”) investigation into an alleged violation of the False Claims Act. In SEC v. RPM International Inc. and Edward W. Moore, filed in the District Court for the District of Columbia against RPM International Inc. (“RPM”) and its general counsel and chief compliance officer, Edward W. Moore, the SEC alleges that RPM and Moore violated the antifraud, books and records, and internal control provisions of the federal securities laws. The gravamen of the complaint is that, in light of its own review of the facts underlying the DOJ’s investigation and negotiations with the DOJ about a settlement, RPM knew that it faced, but failed to account for and disclose, a material loss that was probable and reasonably estimable and accordingly required both accrual and disclosure under the relevant accounting and financial reporting rules.

SEC Complaint’s Factual Assertions

One of RPM’s wholly owned subsidiaries, Tremco, Inc. (“Tremco”), provided roofing materials and services under a contract with the federal government. In 2011, the DOJ began an investigation after a qui tam complaint was filed under the False Claims Act against RPM and Tremco. The qui tam complaint alleged that Tremco overcharged the government under certain contracts by, in part, failing to provide required price discounts.

RPM became aware of the DOJ investigation in March 2011 when Tremco received a subpoena from the government. Mr. Moore, as RPM’s general counsel and chief compliance officer, was responsible for overseeing RPM’s response to the DOJ investigation.

In September 2012, RPM’s outside counsel met with the DOJ to discuss the investigation. During the meeting, RPM’s counsel informed the DOJ that, based on an analysis by a consultant, Tremco had overcharged the government by at least $11 million. In early October, RPM issued its earnings release and filed its 10-Q for the first quarter ended August 31, 2012. Neither the earnings release nor the 10-Q disclosed the existence of the DOJ investigation or reflected an accrual for the potential liability.

In December 2012, RPM and its outside counsel discussed a settlement offer that RPM planned to submit to the DOJ. The settlement offer totaled between $27 and $28 million, which reflected the amount RPM then believed it had overcharged the government. In early January 2013, RPM issued its earnings release and filed its 10-Q for the second quarter ended November 30, 2012 without any reference to the DOJ investigation. Less than a week later, RPM submitted a settlement proposal to the DOJ offering to settle the False Claims Act violation for $28.3 million.

On March 29, 2013, the DOJ countered RPM’s settlement offer with $71 million. Six days later, RPM issued its earnings release and filed its 10-Q for the third quarter ended February 28, 2013, which for the first time disclosed the existence of the DOJ investigation and recorded an accrual of $68.8 million for the potential liability with respect to the violation of the False Claims Act.

RPM’s annual report on Form 10-K for the year ended May 31, 2014, filed in July 2013, discussed the DOJ investigation and the related accrual that RPM had recorded in the third quarter. However, the 10-K indicated that the disclosure of the investigation and the recording of the accrual had been made in a timely manner and failed to disclose any material weakness in RPM’s internal control over financial reporting at any point during the prior fiscal year.

On August 28, 2013, the DOJ announced its settlement with RPM for $61 million.

The SEC complaint alleges that, in light of the DOJ’s investigation and RPM’s own review of the facts, RPM faced a material loss that was, at the time RPM issued its earnings release and filed its quarterly reports for the quarters ended August 31, 2012, November 30, 2012 and February 28, 2013, probable and reasonably estimable, which triggered a requirement that RPM disclose the loss contingency and record an accrual on its books. The SEC complaint further alleges that RPM’s 10-K was misleading because the disclosure of the DOJ investigation and the recording of the related accruals were not in fact timely and there had been a material weakness in internal control over financial reporting throughout the year.

In addition to RPM, the SEC names Moore as a defendant. The SEC complaint asserts that Moore oversaw RPM’s response to the DOJ investigation, but failed to disclose material facts about the investigation to fellow RPM officers, the audit committee, and the independent auditors. Specifically, Moore allegedly knew—but failed to timely inform RPM officers, the audit committee, and the independent auditors—that RPM was in settlement discussions with the DOJ or that RPM determined that Tremco had overcharged the government between $27-28 million. The complaint also asserts that Moore made material misrepresentations to the independent auditors about the investigation, including falsely telling the independent auditors that no claims had been asserted, even though the DOJ had sent him a copy of the qui tam complaint. According to the SEC’s complaint, these misrepresentations caused RPM to submit materially false and misleading filings to the SEC from October 2012 to December 2013.

Implications

The SEC takes the position that by acknowledging to the DOJ in September and October 2012 that Tremco had overcharged the government by at least $11.4 million, RPM was required under Accounting Standards Codification 450 (“ASC 450”) to disclose the loss contingency and to record an accrual of at least that amount. Furthermore, because that amount was material to RPM’s first quarter net income, the MD&A included in the 10-Q for the first quarter ended August 31, 2012 should have disclosed the existence of the investigation and that it would have a materially unfavorable impact on RPM’s net income.

By the time of the filing of RPM’s next 10-Q, the company’s internal analysis of the overcharges to the government reached between $27 and $28 million and it was planning to submit a settlement proposal for that amount. Although this analysis and proposed settlement had not been shared yet with the government at the time RPM filed its second quarter 10-Q, the SEC complaint charges that the failure to record an accrual of at least this amount was a further violation of ASC 450 and the failure to disclose the impact of the investigation in the MD&A was a violation of applicable disclosure requirements.

The obligation to disclose a government investigation and to record an accrual is a highly fact specific analysis. As in this case, the facts uncovered by any internal investigation and the discussions and settlement negotiations with the government can be some of the most critical pieces of the determination.

Conclusion

The SEC’s complaint against RPM serves as a reminder about the importance of transparency in the process around evaluating disclosures, particularly around areas of judgment such as accrual decisions. It also underscores the importance for internal transparency among general counsel, c-suite employees, and the audit committee when dealing with situations as dynamic and unpredictable as government investigations and settlement negotiations. Companies should keep in mind that decisions around recording accruals and disclosures of loss contingencies should be made in consultation with independent auditors as well as, in many cases, outside counsel. Finally, the RPM case is a reminder to those individuals—such as attorneys and compliance officers—who sit in “gatekeeper” roles at companies that the SEC will carefully scrutinize their conduct.

This post comes to us from Debevoise & Plimpton LLP. It is based on the firm’s client update, “SEC Complaint Serves as Reminder to Carefully Consider Disclosure Obligations Relating to Government Investigations,” dated September 23, 2016, and available here.

Categories
Corporate Governance Securities Regulation

PwC Discusses New York’s Proposed Cybersecurity Rules

On September 13, 2016, the New York State Department of Financial Services (DFS) proposed a broad set of cybersecurity regulations for banks, insurers, and other financial institutions.[1] The proposal is largely consistent with existing guidance (e.g., under the NIST Cybersecurity Framework or the FFIEC[2] IT Handbook), but it goes further in some ways.

The proposed rule is the result of DFS’ focus on cybersecurity over the past several years, in which DFS conducted three industry surveys, held cybersecurity discussions with various financial institutions, and issued a letter to US regulators asking for feedback on potential cyber-specific requirements.[3] The proposal contains several requirements that will be new or more expansive than most organizations currently practice. For example, the proposal’s call for encryption of all nonpublic information (including data both “in-transit” and “at-rest”) will be challenging for many organizations. While most entities encrypt data in-transit, they only encrypt data at-rest in more selective circumstances.[4] The proposal also expands the requirements for using multi-factor authentication in a variety of ways that will be new for most organizations.

Additionally, DFS will require that the chairperson of the board or a senior officer submit an annual certification that the entity is complying with the regulation’s requirements. Those submitting the certification could potentially be exposed to individual liability if the organization’s cybersecurity program is found to be noncompliant.

The proposal is now in a 45-day comment period, ending on October 28, and many of its requirements have compliance deadlines as early as June 30, 2017. We recommend that organizations begin reviewing their cybersecurity programs for conformance. Those entities with less mature programs – including many smaller banks and insurers – should be enhancing their cybersecurity programs to align with other industry best practices such as the NIST Cybersecurity Framework, FFIEC guidance, or NAIC Model Data Security Law as appropriate.

It is clear that regulators across the financial services industry are focused on raising the bar for cybersecurity programs. As a result, we recommend that organizations holistically focus on developing a robust risk-based cybersecurity program rather than reactively responding to siloed regulatory guidance. Such an approach will make organizations well-equipped to comply with regulatory requirements while effectuating broader strategic objectives.[5]

What does the proposal require?

To start, DFS’ proposal codifies foundational cybersecurity requirements, which are consistent with existing guidance and leading industry practices:

Cybersecurity program

Organizations will be required to implement a cybersecurity program designed to perform the following core cybersecurity functions (in alignment with the NIST Cybersecurity Framework):

  • Identify internal and external threats
  • Use defense infrastructure to protect the covered entity
  • Detect cybersecurity events
  • Respond to cybersecurity events
  • Recover from cybersecurity events
  • Fulfill all regulatory reporting requirements

Cybersecurity policy

The proposal also calls for entities to implement and maintain a written cybersecurity policy, which must address the following areas (consistent with ISO 27001 standards and leading industry practices):

  1. Information security
  2. Data governance and classification
  3. Access controls and identity management
  4. Business continuity and disaster recovery planning and resources
  5. Capacity and performance planning
  6. Systems operations and availability concerns
  7. Systems and network security
  8. Systems and network monitoring
  9. Systems and application development and quality assurance
  10. Physical security and environmental controls
  11. Customer data privacy
  12. Vendor and third party service provider management
  13. Risk assessment
  14. Incident response

New challenges

However, the DFS’ proposal also introduces several requirements that extend beyond current regulatory guidance and industry practices. The most significant are:

Data encryption

The proposal calls for organizations to encrypt sensitive data both in-transit and at-rest. The suggestion for encryption of data at-rest is the most impactful because it is not a common industry practice and will be challenging for many organizations to implement.

Under the proposal, organizations will be required to include these enhanced data encryption standards in their contracts with third party service providers. This will be burdensome for organizations with large numbers of service providers, as they must take steps to confirm each service provider’s adherence to the encryption requirements.

Encryption requirements for in-transit data must be met by January 2018, while compliance for at-rest data must be met by January 2022. However, DFS expects that, prior to those dates, organizations secure nonpublic information using alternative controls that have been reviewed and approved by the Chief Information Security Officer (CISO).

Enhanced multi-factor authentication

The proposed multi-factor authentication requirements go beyond existing regulatory guidance, which only requires multi-factor authentication for internet banking channels. Under the proposal, multi-factor authentication would be required for any users accessing internal systems from an external network and for privileged access to database servers. Furthermore, the proposal requires risk-based and multi-factor authentication for web applications that contain nonpublic information.[6]

The proposed requirements are not standard industry practice as most organizations use multi-factor authentication for a more limited subset of external applications, but do not do so for internal access. Likewise, privileged access management solutions are still in their infancy of deployment in all but the largest firms.

Enhancing authentication programs will be an especially heavy lift for insurers, as some have not implemented multi-factor authentication due to the lack of specific insurance regulatory requirements within this space. Many banks have implemented some aspect of multi-factor authentication in order to comply with current FFIEC internet banking guidance.

Organizations will be required to comply with these requirements by June 30, 2017.

Annual certification

The proposed rule requires that either the chairperson of the board or a senior officer[7] certify annually that their cybersecurity program meets the proposal’s requirements. This certification is similar to the certification required by Sarbanes Oxley (SOX) for controls related to financial reporting. The Volcker Rule and last year’s instructions from the Federal Reserve regarding stress testing data include similar SOX-like certifications.[8]

Although not explicitly mentioned in the proposal, those submitting the certification could be held individually liable if the organization’s cybersecurity program is found to be deficient. The proposal notes that its requirements will be enforced “under any applicable laws,” which include laws (e.g., New York Banking Law, New York Insurance Law) that contain individual civil and criminal penalties for intentionally making false statements to DFS.[9]

Organizations will be required to submit their first certification by January 15, 2018.

Incident reporting

Under the proposal, entities would be required to notify DFS within 72 hours of the discovery of cyber incidents that either compromise nonpublic information (including unauthorized access of such information) or are likely to materially affect the business.

Although some existing regulations include requirements for reporting cybersecurity events, the proposed reporting requirements exceed the scope of what is currently required in other regulations. For example, New York State’s existing data notification requirements only mandate that organizations notify authorities when there is a loss of customer personally identifiable information. Additionally, the Securities and Exchange Commission’s cybersecurity reporting requirements under Regulation Systems Compliance and Integrity (Reg SCI) only apply to securities market infrastructure.[10]

To comply, entities should adjust their detection operations and response plans to include provisions for identifying and reporting incidents that fall under this requirement. Organizations will be required to comply with these requirements by June 30, 2017.

Additional provisions

In addition to the most significant areas highlighted above, other requirements of the proposal include:

  • Third party risk management – DFS’ proposal requires entities to conduct due diligence on third parties and perform annual assessments of third parties’ cybersecurity practices. Additionally, the proposal calls for organizations to include provisions around encryption, multi-factor authentication, and breach notification in their contracts with third parties. Conducting annual assessments on third parties and ensuring that third parties are following the required contractual provisions will be challenging for organizations that use a large number of service providers.[11]
  • Chief Information Security Officer (CISO) – Organizations will be required to appoint a CISO to implement and oversee its cybersecurity program. The CISO will be required to present a report to the board twice per year identifying cyber risks, evaluating the current effectiveness of the program, and summarizing material cybersecurity events. Many organizations already have a CISO or similar role, but producing a biannual report will be new for most entities.
  • Audit trail – Entities will be required to maintain audit trails of sensitive data, including logs of access to critical systems. The audit trail must be maintained for least six years, which is longer than many organizations currently maintain audit records.
  • Access privileges – Access to systems containing nonpublic information will need to be restricted to only those with a business need for such access. Many entities already address this requirement in their existing access controls, but may require additional investigation to identify all nonpublic information to successfully address the requirement.
  • Application security – The proposal requires that internally built applications follow secure development practices, and that organizations test the security of externally developed applications. Most organizations have policies for secure development of internal applications, but testing external application security is less common.
  • Testing requirements – The proposal calls for annual penetration testing and quarterly vulnerability testing, which are already common practices for most organizations.[12]
  • Risk assessments – Organizations will be required to conduct annual cybersecurity risk assessments. These assessments should identify cyber risks, evaluate existing controls, and have processes and provide mitigation procedures for such risks. Most organizations currently have policies in place to conduct regular risk assessments and should be well-equipped to meet this requirement.

ENDNOTES

[1] DFS’ proposal applies to banks that are chartered or licensed by New York State, insurers that are active in the state, and certain other financial institutions. The proposal exempts smaller institutions, including those with fewer than 1,000 customers over the last three calendar years, those with less than $5 million in gross annual revenue over the last three fiscal years, and those with less than $10 million in year-end total assets.

[2] The Federal Financial Institution Examination Council (FFIEC) is a regulatory council composed of the Federal Reserve Board, Office of the Comptroller of the Currency, Federal Deposit Insurance Corporation, Consumer Financial Protection Bureau, and the National Credit Union Administration.

[3] For additional information on DFS’s letter to US regulators, see PwC’s Financial crimes observer, Cyber: Is New York’s regulator upping the stakes? (November 2015).

[4] Data “in-transit” refers to data moving from one location to another, such as over the internet or through an internal network. Data “at-rest” refers to data that is not actively moving, such as data stored on a hard drive.

For our guidance on developing a robust cyber risk management program, see PwC’s A closer look, Cyber: Think risk, not IT (April 2015).

[6] For additional information regarding multi-factor authentication, see PwC’s Financial crimes observer, Fraud: Email compromise on the rise (February 2016).

[7] According to the proposed rule, a “senior officer” is someone responsible for the management, operations, security, information systems, or risk management of the institution.

[8] See PwC’s Regulatory brief, Matching SOX? CFO attestation for stress tests (October 2015) and PwC’s A closer look, Volcker rule clarity: Waiting for Godot (May 2014).

[9] DFS’s anti-money laundering rule issued in June contains a nearly identical certification requirement. For additional information, see PwC’s Financial crimes observer, AML monitoring: New York regulator gets prescriptive (July 2016).

[10] Reg SCI requires notice within 24 hours for certain cybersecurity incidents. For additional information regarding Reg SCI’s cybersecurity reporting requirements, see PwC’s First take, Ten key points from the SEC’s final Reg SCI (December 2014).

[11] See PwC’s A closer look, Outsourcing: How cyber resilient are you? (June 2015) for more information on third party cyber risk management, including an analysis of FFIEC guidance on the issue.

[12] The CFTC recently issued similar requirements for market infrastructure. For more information on the CFTC’s requirements or cybersecurity testing generally, see PwC’s Financial crimes observer, Cyber: Regulators putting market infrastructure to the test (September 2016).

This post comes to us from PwC. It is based on the firm’s Financial crimes observer for September 2016, which is available here.

Categories
Securities Regulation

What Happens When Technology Is Faster Than the Law?

Designing a regulatory framework that ensures the safety of users and the public while facilitating the commercial use and consumer enjoyment of disruptive innovation is a challenging undertaking. This is particularly true in contemporary settings, where innovation is quicker and the global dissemination of that technology is much faster. The so-called “pacing problem” between innovation and regulation suggests that innovation driven by science and technology is accelerating, yet, simultaneously, federal and state agencies’ regulatory processes have slowed down as I discuss here. Given the intensifying pacing problem between regulation and innovation, regulators often struggle to keep up. The last two decades offer multiple examples of such regulatory struggles: fintech, genetically modified food, artificial intelligence, and, of course, driverless cars. Some evidence exists that the regulators are falling even further behind than the historical average because of the unprecedented exponential nature of innovation in this decade.

But a less-documented aspect of this issue concerns what we might think of as the basis or foundation of any regulation, namely some empirical facts about the technology being regulated and its likely social, economic or health effects. In this respect, regulation is always premised on a selection of relevant facts about a particular technology. Crucially, the selected facts are those that are seen as relevant by the regulators in deciding what, when and how they should make a regulatory intervention.

The “what” question concerns identifying the disruptive technology that must be regulated or requires regulatory reform. Demarcating the scope of a technology may not always be self-evident. For example, when should a trading algorithm be thought of as autonomous, rather than merely providing trader assistance?  Facts about a particular technology are crucial for this kind of definitional judgment.

The “when” question concerns the timing of any regulatory intervention. This entails ensuring that regulation is not adopted so soon that it stifles or distorts technological development, but not adopted so late that problems arise as a result of the absence of effective regulation.

The “how” question is about the form and substance of the regulation. Should the technological innovation be encouraged, prohibited or restricted in some way? And what substantive rules or principles should be adopted to achieve this regulatory goal?

In each case, these policy judgments are made by politicians and bureaucrats based, in large part, on facts provided by experts. The delegation of regulatory decisions to a combination of democratically chosen politicians and bureaucrats/experts is one way of conceptualizing the distinctiveness of political modernity.

Policymakers are more interested in the identification of the relevant facts for rulemaking. Some of the relevant facts may be obvious. Other facts may be very difficult to empirically establish or may be contested, even by experts in that field. The task of establishing facts about new technology may be made difficult by the lack of an adequate sample or other reliable data on the effects of new technology. The “relevant facts” that form the basis of regulation are never going to be obvious or settled. The regulation of any disruptive new technology is always going to be reactive and based on an uncertain and politicized factual basis. Identification of relevant or irrelevant facts may also be distorted or otherwise influenced by the concerns of entrenched interests about new (and commercially threatening) technologies. To some degree, these kind of difficulties have always been around, at least since the rise of industrial capitalism and the acceleration in technological advancement that it facilitated.

An obvious solution to this regulatory dilemma might be to adopt some form of policy experimentation, i.e., testing different regulatory schemes and then comparing the results. But such experimentation poses a problem for regulators. Too often, “success” for regulators is defined in negative terms as the avoidance of catastrophe. Avoiding grounds for criticism inevitably results in an overly cautious approach (the “precautionary principle”).  However, from the perspective of entrepreneurs and consumers, such caution can be a disaster or at least less preferable. The result is that, all too often, there is a disconnect between regulation and commercial and consumer access to that innovation.

Increased reliance on different sources of data surrounding new technologies can provide some signals or clues about what, when and, to a certain extent, how to regulate.  Using such signals facilitates dynamic forms of regulation.

As I show here, of particular importance in this context is data relating to investment in new technology and innovation. A plethora of investment data is readily available to make accurate predictions regarding what the next “big thing” is likely to be.  Such data can be used as an index or proxy of the necessity of regulation. Because start-up companies are the ones that usually challenge existing rules, laws and regulations, private data sources are widely available. The proliferation of the better hand-collected global databases on the market, such as CB Insights, PitchBook and Mattermark, can make an important contribution to a “data-driven” regulatory approach.

Investment data can help to develop a list of technologies and issues that need to be the focus of regulatory attention. From such data, rulemakers can get a better — and earlier — sense of which technologies are developing and which technologies need regulatory attention. This might then allow regulators to be more pro-active and avoid wasting resources on technologies that are unlikely to make it to market. It would also allow regulators to more accurately define the scope of a technology by focusing on the type of firm that is attracting attention.

Britain’s Financial Conduct Authority (FCA), in April 2016, broke new ground by announcing the introduction of a “regulatory sandbox,” which allows both start-up and established companies to roll out and test new ideas, products and business models in the area of fintech (i.e., new technologies aimed at making financial services, ranging from online lending to digital currencies, more efficient).  The idea behind the sandbox is to provide a safe space for testing innovative products and services without being forced to comply with the applicable set of rules and regulations. With the sandbox, the regulator aims to foster innovation by lowering regulatory barriers and costs for testing disruptive innovative technologies, while ensuring that consumers will not be negatively affected.

This post comes to us from Wulf Kaal, an associate professor and the director of the Private Investment Fund Institute at the University of St. Thomas School of Law. It is based on a recent paper he wrote with Mark Fenwick and Eric P. M. Vermeulen, “Regulation Tomorrow: What Happens When Technology is Faster than the Law?”, which is available here.

Categories
Finance & Economics Uncategorized

Debevoise & Plimpton discusses New York’s Proposed Cyber Regulations

On September 13, 2016, the New York Department of Financial Services (“DFS” or the “Department”) issued proposed regulations (the “Proposed Regulations”) designed to guard against the onslaught of cyber-attacks faced by banks, insurance companies and other financial services providers.[1] Billed by Governor Andrew Cuomo as a means to assure that regulated banks and insurance companies “protect consumers and ensure that [their] systems are sufficiently constructed to prevent cyber-attacks to the fullest extent possible,” the Proposed Regulations provide a baseline with respect to companies’ cybersecurity practices regardless of the size, nature or complexity of the business.[2] Though they mirror expectations and guidance provided by the federal banking agencies and the Federal Financial Institutions Examination Council (“FFIEC”), they go well beyond any other existing state-level requirements and set an example for how other federal and state regulators may implement cybersecurity regulation.

The Proposed Regulations have a comment period of 45 days—ending on October 28, 2016—and are the culmination of a three-year effort by the Department that included surveys of the cybersecurity practices of nearly 200 banks and insurance companies. The Department summarized findings of those surveys in three reports focused on the banking and insurance sectors and their use of third-party service providers.[3]

Who’s covered?

The requirements would cover all entities that are licensed, required to be licensed, or subject to other registration requirements under the New York banking, insurance or financial services laws (“Regulated Entities”), but would exempt (i) institutions with less than 1000 customers in three calendar years; (ii) institutions with less than $5 million in gross annual revenue in three fiscal years; and (iii) institutions with less than $10 million in year-end total assets (including assets of affiliates).

What’s covered?

The Proposed Regulations would extend to all manner of “nonpublic information,” including business-related confidential information, customer nonpublic personal information, healthcare-related information and any other information that may be used to trace an individual’s identity (e.g., social security number, date of birth or biometric information). This is a significant expansion beyond the personally identifiable information that is the focus of most data breach laws and regulations.

What’s required?

The regulations are dense and merit careful consideration. We provide here a few of the highlights:

Administrative and Notification Requirements

  • The Proposed Regulations have an effective date of January 1, 2017, with phase-in periods for certain data encryption requirements.
  • If enacted, they would establish perhaps the most stringent timeline in the country for reporting cybersecurity events: notification to DFS within 72 hours of discovery of any cybersecurity event “that has a reasonable likelihood of materially affecting the normal operation of” the business or “that affects Nonpublic Information.”
  • This notification obligation is per se triggered if notice is provided to “any government or self-regulatory agency.” It is not clear whether “government agency” includes law enforcement.
  • Moreover, the obligation goes beyond unauthorized exfiltration of data and includes the “actual or potential unauthorized tampering with, or access to or use of, Nonpublic Information.”
  • The Proposed Regulations also would require annual certification by Regulated Entities that they have complied with the Regulations. This is particularly noteworthy given the imposition of granular requirements, described in more detail below.

Overall Cybersecurity Program, Policy, and Governance

  • The Proposed Regulations require that companies establish a comprehensive cybersecurity program that appropriately identifies cyber risks and documents the types of nonpublic information the company stores, together with how it protects that information.
  • The program must include a written cybersecurity policy covering 14 distinct categories, which must be reviewed at least annually by the board of directors (or equivalent body or Senior Management for entities without boards).
  • Other notable requirements include:
  • Appointment of a Chief Information Security Officer (“CISO”), who must provide biannual reports to the board covering six distinct categories of information;
  • Annual penetration testing and quarterly vulnerability scanning;
  • Annual risk assessments conducted in accordance with written procedures adopted by the company;
  • Development of guidelines for assessing security for applications, whether developed in-house or externally; and
  • Establishment of cybersecurity training for employees, with enhanced training for key cybersecurity personnel.

Access Controls

  • The Proposed Regulations also continue the trend of converting data security “best practices” into regulatory requirements, mandating that Regulated Entities:
  • Encrypt all “Nonpublic Information” that is at rest or in transit. (The Proposed Regulations contemplate a phase-in period of one year for data in transit and five years for data at rest if companies maintain suitable mitigating controls);
  • Adopt the principle of “need-to-know” access to sensitive data;
  • Deploy multi-factor authentication for all remote network access and privileged access to certain sensitive systems;
  • Implement and maintain robust auditing to enable detection and response to a cybersecurity event, to track privileged user access to critical systems, and to protect the integrity of the audit trail. These records must be maintained for at least 6 years; and
  • Develop data retention policies that mandate destruction of sensitive data when it is no longer needed.

Third-Party Vendor Management

  • Not surprisingly, the Proposed Regulations devote substantial attention to oversight of third-party vendors, requiring companies to:
  • Implement written policies and procedures for vendor management that include minimum cybersecurity practices that the vendors must follow;
  • Outline due diligence processes used to evaluate the vendors;
  • Review third-party vendors at least annually regarding the adequacy of their cybersecurity practices; and
  • Establish “preferred provisions” for inclusion in vendor contracts that address multi-factor authentication, use of encryption, vendor obligations to notify the company of data breaches, the rights of the company to audit the vendor’s cybersecurity, and representations and warranties from the vendor regarding its services or products.

Incident Response Planning

  • Regulated Entities would be required to implement a written incident response plan covering seven distinct topics including:
  • Defining clear roles, responsibilities, and levels of decision-making authority in response to a breach;
  • External and internal communications and information sharing;
  • Documentation and reporting of events; and
  • Evaluation and revision of the incident response plan at the conclusion of an incident.
  • This continues a trend of requiring continual improvement and incorporation of “lessons learned” from prior incidents into preparation for responses to future ones.

Takeaways

  • If enacted, the new DFS cybersecurity regulations would raise the bar significantly for banks, insurers and other financial services providers under the Department’s jurisdiction. The Proposed Regulations are far-ranging in scope, including not only specific technical safeguards but also requirements regarding governance, incident planning, data management and system testing, and an aggressive 72-hour time frame to notify DFS of certain cyber incidents.
  • Although the Proposed Regulations echo a growing chorus of other regulators calling for improved cybersecurity measures by banks and insurers (notably the Financial Stability Oversight Council, FFIEC and the Federal Reserve Board), they go much further than any set forth before by requiring a comprehensive approach to mitigating cybersecurity risks.
  • As cyber threats continue to increase in volume and complexity, DFS’s proposals likely will influence the approach taken by federal and state regulators as they consider further regulation in this area and as they review the practices of organizations under their jurisdiction.

ENDNOTES

[1] Cybersecurity Requirements for Financial Services Companies, 23 NYCRR Pt. 500 (Sept. 13, 2016), available at http://www.dfs.ny.gov/legal/regulations/proposed/rp500t.pdf.

[2] See Press Release, Governor Cuomo Announces Proposal of First-In-The-Nation Cybersecurity Regulation to Protect Consumers and Financial Institutions (Sept. 13, 2016), available at http://www.dfs.ny.gov/about/press/pr1609131.htm.

[3] See Report on Cyber Security in the Banking Sector (May 2014), available at http://www.dfs.ny.gov/reportpub/dfs_cyber_banking_report_052014.pdf; Report on Cyber Security in the Insurance Sector (Feb. 2015), available at http://www.dfs.ny.gov/reportpub/dfs_cyber_insurance_report_022015.pdf; Update on Cyber Security in the Banking Sector: Third Party Service Providers (Apr. 2015), available at http://www.dfs.ny.gov/reportpub/dfs_rpt_tpvendor_042015.pdf.

This post comes to us from Debevoise & Plimpton LLP. It is based on the firm’s client update, “New York’s Proposed Cyber Regulations: Implications and Challenges,” dated September 15, 2016, and available here.