Corruption Crime & Compliance: Recent Episodes

Michael Volkov

Michael Volkov tackles the current and hot topics in the legal realms of corruption, crime, and compliance.

View Details

If you’re looking at the Justice Department and only at FCPA cases, you’re looking in the wrong place.

Everyone’s talking about the DOJ going soft on corporate crime. I want to push back on that narrative because I think it’s incomplete and, honestly, a little dangerous if compliance officers believe it.

Yes, traditional FCPA and bribery prosecutions have slowed. But look at where the resources are actually going.

Trade enforcement is exploding. Sanctions enforcement is aggressive and getting more aggressive by the month.

And here’s the one that should really get your attention: the False Claims Act is now being used against companies for tariff circumvention and customs fraud, with qui tam relators and lawyers lining up to bring those cases.

This isn’t a retreat. It’s a reallocation.

DOJ has simply moved its firepower to where the current priorities sit: national security, trade, tariffs, sanctions, and export controls.

If your compliance program is still built around FCPA risk and you haven’t retooled for trade and sanctions exposure, you are exposed right now, today.

Update your risk assessment. This is not the moment to stand down.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode of Corruption, Crime and Compliance, Michael Volkov sits down with Christian Focacci, founder of Threat Digital, for their annual check-in on AI's evolving role in due diligence and compliance. Focacci traces how AI adoption has matured from early hype and generic chatbot rollouts to more disciplined, use-case-specific tooling, while cautioning that the underlying models still hallucinate and should never be treated as an authoritative source rather than a reviewer of externally cited, verifiable information. The conversation covers the widespread problem of "shadow AI" use inside organizations without governance, the risks of letting AI creep into discretionary decision-making without human accountability, and emerging third-party risk questions as companies must now vet how vendors themselves are using AI. Volkov and Focacci also discuss the rapid rise of open-weight Chinese models, the regulatory patchwork forming at the state level (particularly around HR uses of AI), and the risk of regulatory capture favoring large AI incumbents over smaller innovators. The episode closes on a balanced note: AI is genuinely valuable for processing large data sets, triaging sanctions alerts, and boosting productivity, but only when paired with rigorous human oversight, clear documentation, and citations traceable back to verifiable source material.

View Details

Everyone’s talking about the DOJ going soft on crime.

I want to push back on that narrative because I think it’s incomplete and, honestly, a little dangerous if compliance officers believe it.

Yes, traditional FCPA and bribery prosecutions have slowed, but look at where the resources actually went. Trade enforcement is exploding. Sanctions enforcement is aggressive and getting more aggressive by the month.

And here’s the one that should really get your attention: the False Claims Act is now being used aggressively against companies for tariff circumvention and customs fraud, with qui tam relators lining up to bring those cases.

This isn’t a retreat. It’s a reallocation.

DOJ has simply moved its firepower to where the current priorities sit: trade, tariffs, sanctions, export controls, and national security.

If your compliance program is still built entirely around FCPA risk and you haven’t retooled for trade and sanctions exposure, you are exposed right now, today.

Update your risk assessment. This is not the moment to stand down.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode of Corruption, Crime and Compliance, Michael Volkov breaks down the Justice Department's $10.2 million foreign bribery resolution with The Scoular Company, an Omaha-based agricultural supply chain company that used customs brokers to pay more than $400,000 in bribes to Mexican officials over six years so that contaminated grain shipments could cross the U.S.-Mexico border despite failed inspections. Volkov walks through the mechanics of the scheme, a strikingly simple pattern of $2,000 per-train payments disguised on invoices as "reinspection fees," and explains why DOJ treated the case as an aggravated national security matter after determining that some of the bribe money ultimately reached individuals tied to a border cartel, even though Scoular itself had no knowledge of that connection. The episode also unpacks how DOJ applied its Corporate Enforcement and Voluntary Self-Disclosure Policy to the resolution, distinguishing between the voluntary disclosure credit Scoular did not earn and the cooperation and remediation credit it did, resulting in a three-year deferred prosecution agreement, a 25 percent reduction off the bottom of the sentencing guidelines, and no independent monitor. Volkov closes with practical takeaways for compliance officers on managing customs brokers as high-risk third parties, testing the substance behind recurring payments, and moving quickly on voluntary disclosure decisions once potential misconduct surfaces internally.

View Details

When it comes to DOJ enforcement, the pendulum swings, and it always returns. Don’t let it knock you off your feet.

I’ve been watching the headlines, and so have you. Fewer corporate guilty pleas, non-prosecution agreements for Alibaba and Eagle Bank, charges dropped against Boeing and Halkbank from Turkey.

The word from Main Justice is: hold individuals accountable, go easier on companies. I get why some executives are breathing a sigh of relief.

But here’s my message to every compliance officer out there: do not read this as permission to relax.

Enforcement priorities are cyclical. Administrations change. Statutes of limitations run long. The conduct you tolerate today under a lenient DOJ can absolutely come back across your desk in the future, with a lookback period that reaches right back to right now.

And let’s not forget: non-prosecution agreements still require admissions, still require massive fines, and still require you to fix your program. They’re not a free pass. That’s a warning shot.

Stay vigilant. Keep building your program like the next administration is already watching, because eventually it will be.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this update episode of Corruption, Crime and Compliance, Michael Volkov speaks with Erica Hanichak of the FACT Coalition and Frank Russo of Modern Fortis about the current fight over the Corporate Transparency Act, the 2021 law requiring companies to report their beneficial owners to a secure Treasury Department database in order to close off the U.S.'s longstanding status as an easy jurisdiction for setting up anonymous shell companies used in money laundering, human trafficking, and fraud. Hanichak and Russo describe how the law's implementation has faced litigation and a legislative repeal push that narrowly cleared the House Financial Services Committee despite broad, bipartisan, cross-sector opposition from law enforcement groups, financial institutions, and anti-trafficking organizations, all of whom view beneficial ownership data as a foundational tool for tracing who truly finances and benefits from organized criminal networks. The conversation also flags the administration's forthcoming final rule, which reportedly would exempt more than 99.98% of the entities Congress originally intended to cover, and closes with a direct call for the compliance community to engage with lawmakers to preserve and strengthen, rather than gut, the beneficial ownership reporting framework that due diligence programs increasingly depend on.

View Details

Is your compliance program being demoted?

Let’s talk about something that should worry every compliance officer. The stature of the profession is slipping.

For years, the trend line was clear. Compliance officers moved out from under the general counsel, got direct lines of reporting to the CEO, and direct lines to the board.

That mattered. It wasn’t just symbolic. It meant compliance had real influence before decisions got made, not after.

Now look at the data. The latest Compliance Week survey found reporting lines are sliding back toward legal. Fewer CCOs sitting with the board, fewer with a direct line to the CEO, and compliance officers are telling us off the record that they feel pushed to the side.

Here’s my worry. When you add a layer between compliance and leadership, you’re sending a message to your employees, to your regulators, to the market about how much this function actually matters to you.

Don’t let that message be sent on your watch. Fight for your seat. Your organization needs it more than ever.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Michael Volkov examines a troubling backslide in corporate governance: the quiet movement of chief compliance officers back under the general counsel after years of progress toward direct CEO reporting lines. Michael explains why the CCO's reporting structure is the single clearest signal a company sends about the value it places on compliance — shaping whether compliance influences business strategy at the design stage or is reduced to an after-the-fact cleanup function. He makes the case for a direct CCO reporting line to the CEO paired with a formal dotted line to the audit committee, including guaranteed executive sessions and unrestricted escalation authority, and warns that subordinating compliance to legal fosters a "mere compliance" mindset — meeting minimum legal requirements rather than building an ethical culture that drives employee retention, customer trust, and long-term business success. Michael closes with concrete action items for boards and compliance leaders, reminding listeners that regulators scrutinize CCO empowerment and that demoting compliance to save a line item is like canceling insurance to improve quarterly cash flow.

View Details

In the compliance world, no news is not good news.

Let me ask you a question every CCO should be asking right now: Are your employees actually reporting and using your hotline to report legitimate concerns?

Too many compliance officers look at a quiet hotline and breathe a sigh of relief. No calls, no complaints. Must mean everything’s fine.

I’m here to tell you that’s backward. A silent speak-up line isn’t good news. It’s a red flag.

Here’s why: misconduct doesn’t disappear just because nobody’s reporting it. What disappears is trust. Trust that raising an issue will be taken seriously. Trust that there’s no retaliation waiting on the other side.

When that trust is gone, people don’t stop seeing problems. They just stop telling you about them, and that’s exactly when whistleblower risk goes up, not down, because the next person who sees something is going straight to the regulator instead of you.

So benchmark your reporting volume against your industry. Look at your trends over time. If your numbers are flat or falling while everyone around you is seeing increases, don’t celebrate. Investigate.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Michael Volkov examines how artificial intelligence is transforming internal investigations — and what the Justice Department now expects from companies navigating this new landscape. Michael breaks down DOJ's updated Evaluation of Corporate Compliance Programs, which directs prosecutors to scrutinize how companies assess AI risks, whether compliance functions have adequate access to data and analytics resources, and what controls prevent the reckless misuse of new technologies. He then walks through the five most dangerous failure modes when AI meets internal investigations — hallucinated witness summaries, missed hot documents, privilege waiver through third-party AI tools, discoverable prompt trails, and investigator overreliance — before turning to the emerging frontier: investigations where AI itself is the subject, including employee AI misuse, deepfake and synthetic evidence, and the growing class of AI whistleblowers protected under SOX and Dodd-Frank. Michael closes with six concrete action items for building an AI-ready investigation protocol that will withstand regulatory scrutiny.

View Details

The root of every strong compliance program is a strong culture.

I say this on every episode, and I’m going to keep saying it. Culture is the single most important control that your compliance program builds. It’s at the heart of every compliance program—not the policy binder, not the training module. Culture.

Here’s what the research really shows: companies with strong ethical cultures perform better financially. They’re more sustainable because employees believe in the mission. They don’t cut corners when nobody’s watching. And employee engagement and satisfaction go up—way up—when people trust that their company will do the right thing, even under pressure.

Think about what this means practically: lower turnover, higher productivity, fewer whistleblower complaints turning into full-blown investigations because people raise issues early instead of burying them.

That’s the ethics premium, and it’s real.

So, if you’re a CCO fighting for budget, stop pitching compliance as a cost center. Pitch it as what it really is: the thing that makes your business more successful, more sustainable, and a place people actually want to work.

Culture isn’t a soft metric. It’s your bottom line.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode of Corruption, Crime and Compliance, Michael Volkov talks with Aaron Nicodemus, editor-in-chief of Compliance Week, about the state of the compliance profession and the findings of Compliance Week's latest "Inside the Mind of the CCO" survey. They discuss a troubling reversal in reporting lines, with more compliance officers now reporting through general counsel rather than directly to CEOs or boards after several years of progress toward greater independence, and what that structural shift signals about how seriously organizations value the function amid shifting political winds and uneven federal enforcement priorities. The conversation turns to artificial intelligence as both the defining opportunity and risk of the moment: survey data shows AI use across organizations has jumped to roughly 85%, yet a significant share of compliance officers report no governance plan is in place, leaving gaps around data privacy, algorithmic decision-making, hallucinated outputs, and "shadow AI" used by employees and third-party vendors alike. Nicodemus and Volkov agree that compliance is uniquely positioned to build the guardrails that let organizations use AI productively rather than recklessly, and they close by identifying data privacy, third-party risk management, and responsible AI adoption as the three pillars compliance officers should be watching most closely in the years ahead.

View Details

Some third parties create real legal risks.

Other third parties create reputational risk.

Not all third parties are the same.

One of the most important concepts in modern third-party risk management is distinguishing between acting vendors and incidental vendors.

An acting vendor performs services on your behalf.

Think customer service providers, recruiters, customs brokers, distributors, and payment processors.

When these vendors use AI or engage in misconduct, liability flows to your company.

Incidental vendors present a different risk profile.

Their primary exposure may be reputational rather than direct legal liability.

This distinction is critical and allows companies to focus their resources where they matter most when it comes to mitigating risk.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode of Corruption, Crime and Compliance, Michael Volkov sits down with Dan Greenberg, founder of Greenberg Corporate Intelligence, to unpack how due diligence and corporate investigations have evolved over Dan's fifteen-plus years in the field. They cover the uneven state of corporate transparency worldwide, from the UK's Companies House registry to persistent secrecy havens in the BVI, Cayman Islands, and even certain U.S. states, and discuss how generative AI now lets fraudsters build convincing fake websites, executive bios, and LinkedIn profiles with minimal effort, raising the bar for investigators who must verify rather than trust what they find online. Dan walks through his three-bucket approach to gathering intelligence (traditional public records, advanced open-source and social media analysis, and human sources), and the conversation turns to the unique challenges of investigating counterparties tied to China and Russia, where nuance and thoroughness are essential to avoid overbroad assumptions. The episode closes on a practical note for compliance professionals: as supply chain, sanctions, trade, cybersecurity, and AI-vendor risks pile onto traditional FCPA-driven due diligence, resolving red flags and documenting the process remain the non-negotiable foundations of an effective program.

View Details

When it comes to foreign bribery, borders provide no protection.

The European Union just approved one of the most significant anti-corruption initiatives in decades, and multinational companies have to pay attention.

The EU's Anti-Corruption Directive is designed to harmonize anti-corruption enforcement across the member states.

It expands corruption offenses, strengthens enforcement tools, and increases accountability for both individuals and organizations.

Companies operating in Europe can expect greater scrutiny of gifts, hospitality, conflicts of interest, influence peddling, and bribery schemes.

The overall message is clear.

Europe is moving toward a more aggressive and coordinated anti-corruption enforcement system.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

How many red flags is your company missing?

We've seen this pattern repeatedly.

A third-party red flag appears.

No one knows who owns the escalation process.

Business pressure overrides compliance concerns.

Documentation is incomplete. Monitoring never occurs.

When the regulators arrive, the company can't demonstrate effective oversight.

The problem is not simply the underlying misconduct.

The problem is the inability to prove that the company exercised reasonable oversight.

Enforcement agencies punish misconduct, but they often punish weak governance even more.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Government corruption is often viewed as a political problem, but its consequences extend far beyond government institutions. Corruption distorts economies, undermines democratic legitimacy, destroys public trust, and weakens the social fabric upon which civil society depends. In this episode, Michael Volkov explores the full impact of corruption across economic, political, and social dimensions and explains why anti-corruption compliance efforts represent far more than regulatory risk management. They are essential tools in defending the institutions and values that support free markets, democracy, and the rule of law.

View Details

If your third-party risk management program uses annual questionnaires and spreadsheets, your program is already obsolete.

The third-party risk environment has fundamentally changed.

It used to focus on financial stability, insurance, and basic due diligence.

Today, your vendors create exposures to AI risks, cybersecurity threats, sanctions violations, privacy failures, supply chain disruptions, and regulatory enforcement.

Regulators are no longer asking whether you have a third-party risk program.

They're asking whether your program actually works.

Annual reviews are no longer enough.

Risks change daily.

Vendors deploy new AI tools. Ownership changes. Sanctions risks emerge overnight.

The future belongs to those companies that embrace continuous monitoring, automated screening, and dynamic risk management.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) and the UK's Office of Financial Sanctions Implementation (OFSI) recently issued joint guidance comparing their respective sanctions regimes. While the document provides a useful overview of similarities and differences, it also sends a much broader message: international sanctions enforcement is becoming increasingly coordinated. In this episode, Michael Volkov examines why multinational companies should move beyond country-by-country compliance programs and build integrated, enterprise-wide sanctions compliance frameworks. He discusses key differences involving ownership and control, reporting obligations, voluntary disclosures, and strict liability standards, while offering practical recommendations for strengthening global sanctions compliance. As always, the discussion emphasizes practical solutions, ethical leadership, and building compliance programs that work in the real world—because effective compliance is more than following rules; it's earning trust and protecting enterprise value.

View Details

Many companies carefully review each and every vendor.

Almost none review their vendor's vendor.

This creates one of the biggest blind spots in modern risk management.

Your payroll vendor may use a third-party AI provider.

Your software company may rely on multiple subcontractors.

Your logistics provider may depend on dozens of suppliers across the globe.

Every one of these relationships creates additional risk.

Cybercriminals are exploiting fourth-party relationships to gain access to enterprise systems.

Regulators are paying attention as well.

You need to turn your attention to your vendors' vendors.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Bosch agreed to pay more than $43 million in penalties and disgorgement for illegally exporting products and software to Huawei in violation of U.S. export control laws, while simultaneously receiving the first declination issued under DOJ's revised National Security Division Corporate Enforcement Policy. In this episode, Michael Volkov examines the enforcement action, the compliance failures that led Bosch to misunderstand and misapply the Foreign Direct Product Rule, the warning signs the company failed to recognize, and the lessons organizations can learn about export controls compliance, compliance staffing, escalation procedures, and risk management. The episode also highlights the significant benefits of voluntary self-disclosure, cooperation, and remediation in reducing criminal enforcement risk in today's increasingly aggressive national security enforcement environment.

View Details

When it comes to third-party vendors, what you don't know is hurting you.

Third parties rely on AI for customer service, recruiting, compliance screening, marketing, and decision making.

But when a third party uses AI, your organization is on the hook for legal, regulatory, contractual, and reputational risks.

Organizations need to understand which third parties use AI, what tools they use, what data is being shared, what controls exist, and who is responsible when something inevitably goes wrong.

Third-party AI governance is a critical component of vendor management.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

This episode examines OFAC’s new Iran General License X and why it may represent one of the most significant Iran sanctions developments in years. Michael Volkov explains what the license authorizes, why it matters amid ongoing diplomatic negotiations, and why companies should not mistake temporary sanctions relief for a permanent policy shift. The episode highlights practical compliance steps, including careful transaction analysis, documentation, due diligence, screening updates, and close monitoring before the license expires. As always, the focus is on practical, risk-based compliance: helping companies identify legitimate business opportunities while protecting ethics, integrity, and trust.

View Details

Not all sanctions violations are willful.

Some companies just don't know any better.

An effective trade compliance program needs three critical elements.

First, in addition to the two we spoke about in the last episode, organizations and companies have to monitor transactions, shipping documents, vessels, payment flows, and escalation of red flags.

Employee training is critical.

OFAC's compliance framework specifically identifies training as a core compliance expectation.

And finally, organizations need to monitor, audit, and test whether their controls are actually working.

A compliance program that is never tested is simply operating on assumptions.

The best trade compliance programs don't just detect violations, they prevent them.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Artificial intelligence has created one of the most significant governance challenges organizations have faced in decades. Business leaders are under intense pressure to deploy AI quickly, while legal and compliance teams are warning about mounting regulatory, legal, operational, and reputational risks. In this episode, Michael Volkov explains why both sides are right, identifies the most dangerous AI governance gaps emerging across organizations today, and outlines a practical roadmap for responsible AI adoption. The message is clear: the companies that will succeed in the AI era will not be those that move fastest—they will be those that build sustainable AI programs grounded in governance, accountability, and trust.

View Details

Most companies think they have a handle on AI. Most don't.

Compliance attorney Michael Volkov has sat across the table from Fortune 500 compliance teams, major law firms, and Berkshire Hathaway subsidiaries — and what he keeps finding is "shadow AI": people using AI at work that leadership has no idea about. In this conversation with host Collin McKee, he breaks down where the real legal risk lives, how to protect your business, and why the smart move isn't to slow down — it's to deploy AI the right way.

We get into:

"Shadow AI" — why your team is already using it and what it exposes you to

The vendor due-diligence checklist before you sign with any AI provider

Why AI hallucinations are a liability you can be sued over

HR, hiring bias, and high-risk algorithmic decisions

Writing an AI acceptable-use policy that protects you without slowing you down

The EU AI Act, litigation risk, and AI insurance

Why you won't be replaced by AI — but by people who know how to use it

A practical playbook for any business adopting AI, especially law firms and regulated industries.

Chapters

0:00 Why most companies don't actually have a handle on AI

0:38 The CEO email that shows how NOT to deploy AI

4:09 Shadow AI: a Fortune 100 example

6:42 The real risk — hiring, HR & algorithmic decisions

9:34 Why AI hallucinations are a legal liability

10:03 The vendor due-diligence checklist before you sign

12:50 Why companies still won't write an AI use policy

16:24 The "double-checking wastes my time" trap

18:39 The EU AI Act, litigation & AI insurance

19:27 What small & mid-size businesses actually need

23:39 You won't be replaced by AI — but by people who use it

26:19 AI as a force multiplier, not a headcount cut

28:04 Where to find Michael Volkov

About the guest — Michael Volkov

Compliance attorney and AI governance expert. Founder of The Volkov Law Group.

YouTube: / @volkovlawtv

Blog & podcast (Corruption, Crime & Compliance): https://blog.volkovlaw.com/

LinkedIn: / michael-volkov-9716b45

About Endeavor's AI

If this episode hit home and your company needs help with implementation, automations, workflows, and the AI infrastructure to do this right — that's what we do.

Website: https://www.endeavorsai.com/

Book a 30-min call: https://calendly.com/collin-endeavors...

Instagram: / endeavorsai

LinkedIn: / endeavors-ai

View Details

Michael Volkov delivers the operational compliance program guidance companies must implement to execute safely within OFAC's new Venezuela general license framework, structured around five program pillars: transaction scoping with mandatory lifecycle revalidation at each critical deal stage; beneficial ownership-based counterparty due diligence that goes beyond standard SDN screening to identify Russia, Iran, Cuba, North Korea, and PRC-connected ownership structures; contract review and modification to incorporate mandatory U.S. governing law provisions, sanctions representations, FGDF payment mechanics clauses, and robust termination rights; pre-built Foreign Government Deposit Fund payment procedures requiring documented legal and compliance approval, a standardized State Department submission package, and advance coordination before payment deadlines arrive; and a transaction-specific reporting compliance program with calendar-tracked deadlines under GL 52, GL 46B, and GL 51B. Michael concludes that the new Venezuela framework creates genuine commercial opportunity but demands purpose-built compliance architecture—companies that proceed without it are not operating within the authorization.

View Details

What separates effective trade compliance programs from ineffective ones?

It starts at the top.

Good, bad, or ugly, it all trickles down from the top.

Here are the five keys to an effective trade compliance program.

The first two are building blocks for leadership and due diligence.

First, senior executives and boards must actively support trade compliance.

Without leadership engagement, compliance programs become check-the-box exercises.

Second, organizations need robust screening and due diligence processes.

This includes customers, distributors, suppliers, beneficial owners, intermediaries, and other third parties.

Trade compliance failures often begin with poor due diligence.

Strong leadership and strong due diligence create the foundation for every trade compliance program.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Are your employees whispering corporate secrets into the greedy ears of public-facing AI?

Many organizations have no visibility into how their employees are using AI.

The solution is not to ban AI.

The solution is AI governance.

Organizations need approved AI tools, acceptable use policies, employee training, and ongoing monitoring.

The question is no longer whether your employees are using AI.

The question is whether you know how they are using it.

AI risk is no longer a future issue. It is a governance challenge happening right now.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Michael Volkov examines OFAC's new Venezuela general license framework—including General License 52, General License 46B, and the newly effective General License 51B covering Venezuelan-origin minerals—analyzing how these authorizations create conditional pathways for otherwise-prohibited energy and minerals transactions while preserving the underlying blocking regime applicable to PdVSA and the Government of Venezuela. Michael explains the established U.S. entity eligibility requirement, the mandatory contractual conditions requiring U.S. governing law and U.S. dispute resolution in agreements with Venezuelan governmental counterparties, and the critical jurisdictional restrictions excluding transactions with Russia, Iran, Cuba, North Korea, and China-connected entities. The episode provides a detailed operational breakdown of the Foreign Government Deposit Fund payment mechanism established under Executive Order 14373—including the DepositorInquiries@state.gov submission process and documentary requirements—and concludes with an analysis of the multi-agency reporting obligations triggered under each applicable authorization.

View Details

If AI were a real employee and made mistakes, would you fire it?

AI is transforming business operations, but organizations often overlook one fundamental problem.

They hallucinate.

AI can generate fake information, fake legal citations, inaccurate regulatory interpretations, incorrect sanctions screening results, and fabricated facts.

The danger is not that AI makes mistakes.

The danger is that it makes mistakes confidently.

Employees frequently assume AI-generated information is accurate because it sounds authoritative and professional.

That's why every organization needs clear governance controls.

Require human review, validate critical outputs, and document your procedures for high-risk decisions.

AI can improve efficiency, but without oversight, AI errors can quickly become a compliance disaster.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Michael Volkov examines USTR's unprecedented Section 301 forced labor tariff proposal, analyzing how the Trump Administration is leveraging a decades-old trade statute to rebuild broad tariff coverage following the Supreme Court's invalidation of IEEPA emergency tariffs in Learning Resources, Inc. v. Trump. Covering economies that account for an estimated 99.4% of U.S. imports, the proposal would impose 10% duties on 14 economies with partial forced labor import regimes—including Canada, Mexico, the EU, and the UK—and 12.5% duties on 46 economies with no meaningful forced labor prohibition, including China, Japan, Brazil, and South Korea, with all new duties stacked on top of existing tariffs. Michael details the critical July 6, 2026 comment deadline, outlines the compliance action items companies must execute now—supply chain exposure mapping, HTS-level Annex A exclusion analysis, UFLPA interaction assessment, and tariff stacking modeling—and explains why this proceeding represents both a trade enforcement initiative and a deliberate legal architecture strategy designed to produce the robust administrative record that emergency tariff authority lacked.

View Details

Michael Volkov analyzes the Commerce Department Bureau of Industry and Security's June 12, 2026 export control directive ordering Anthropic to suspend all access to its Fable 5 and Mythos 5 AI models for any foreign national—a directive that, because Anthropic cannot segment its global user base by nationality in real time, resulted in a complete worldwide shutoff of both models for every customer. Michael places the directive in its full context: the months-long conflict between Anthropic and the Trump Administration stemming from the Pentagon's demand that Anthropic waive its contractual restrictions on the use of Claude for mass domestic surveillance and autonomous weapons, the unprecedented supply chain risk designation applied to Anthropic in March 2026, the active federal litigation challenging that designation in two courts, and the government's stated rationale that a third-party company had reported a jailbreak of Mythos. Michael examines the contested legal authority underlying the BIS directive, the compliance implications for enterprise AI users—including third-party AI operational risk, foreign-national access control requirements, and the inadequacy of existing SLA frameworks—and the fundamental AI governance gap that Friday's action exposed: the absence of a comprehensive statutory framework governing government authority to restrict commercial AI model access on national security grounds.

View Details

Compliance isn't a cost, it's a business advantage.

Compliance officers often make one critical mistake, they sell compliance as a legal requirement instead of a business advantage.

Executive support grows when compliance leaders connect ethics to operational resilience, revenue protection, and enhancement, reputation, employee retention, and strategic growth.

Successful compliance leaders use data, demonstrate value, communicate clearly, and align with business priorities.

Employees then support the program when they see fairness, consistency, responsiveness, and leadership commitment.

The best compliance programs are not built through fear, they are built through credibility.

Ethics and compliance succeeds when leadership sees it as essential to business performance, not separate from it.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

As artificial intelligence becomes embedded in third-party business operations, companies face a new and largely unexamined compliance challenge: when does a vendor's use of AI become your legal or reputational problem? In this episode, Michael Volkov unpacks the critical agency principle distinction at the heart of third-party AI risk — explaining how acting third parties who deploy AI on a company's behalf can create direct legal liability for the principal, drawing on the same legal framework that governs FCPA third-party liability, while incidental service providers who supply goods or services without acting on the company's behalf present a different but equally serious reputational risk. Michael also examines what robust AI-focused third-party due diligence must include, how to build a risk-tiered compliance framework that allocates resources proportionately, and why reduced legal liability is never the same as reduced risk in an environment where vendor AI controversies generate brand association damage regardless of legal culpability.

View Details

If you want to give your compliance team superpowers, then give them the power of automation.

If your compliance program is still operating primarily through spreadsheets, emails, and manual tracking, regulators already view your program as ineffective.

Modern compliance risks move too fast for manual systems.

You need to have sanction screening, third-party monitoring, transaction testing, hotline analytics, policy certifications, and training program metrics.

The Justice Department evaluates whether compliance programs have access to data, testing capability, and real-time monitoring.

Manual systems create blind spots, delayed escalation, inconsistent oversight. And weak documentation.

Automation does not replace human judgment, it enhances it.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

On May 18, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) announced that Adani Enterprises Limited (AEL), an India-based multinational, agreed to pay $275 million to settle 32 apparent violations of Iran-related sanctions — specifically for causing U.S. financial institutions to process approximately $192 million in payments for liquified petroleum gas (LPG) that originated from Iran, not from Oman or Iraq as represented by AEL's Dubai-based supplier. OFAC found the violations egregious and non-voluntarily disclosed, citing multiple red flags that AEL either missed or dismissed without adequate investigation: third-party warnings about Iranian-origin cargo, vessels routinely engaging in AIS manipulation and suspicious routing, certificates of origin bearing signs of falsification, and prices so far below market that they could only be commercially explained by Iranian sourcing. The case stands as a landmark reminder that sanctions compliance is not a box-checking exercise — companies must proactively investigate, formally document, and genuinely resolve red flags rather than accept supplier assurances at face value, and that failure to do so carries nine-figure consequences.

View Details

The biggest cases of corruption and fraud often have their roots in the soil of conflicts of interest.

Many major corruption cases begin with something companies initially dismiss as just a conflicts issue.

Conflicts of interest though are early warning signs for fraud, bribery, procurement manipulation, favoritism, and self-dealing.

Weak disclosure systems allow undisclosed relationships, hidden ownership interests, and vendor manipulation.

Effective programs require annual certifications, ongoing disclosure obligations, manager accountability, and independent review processes.

A conflict of interest program is not about policing relationships. It's about protecting integrity.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Artificial intelligence tools remind us every day that they can make mistakes — but in the rush to embrace AI's extraordinary capabilities, the professional and compliance communities are not taking that warning seriously enough. In this episode, Michael Volkov draws on his own extensive experience in compliance, white-collar defense, and corporate governance to examine the real and serious dangers of AI inaccuracy in high-stakes professional environments, including fabricated case citations, misstatements of legal holdings, and conflation of regulatory frameworks that are invisible to non-experts but potentially devastating in their consequences. Michael argues that AI output must be treated as a starting point rather than a finished product, that human expert verification must be built into AI workflows as a structural requirement rather than an occasional check, and that professional responsibility standards do not diminish simply because an AI tool was involved in producing the work — making the verification imperative not just a best practice, but a professional obligation.

View Details

Are you ready to navigate the risky waters of third-party pirates?

Most sanctions violations do not happen because companies intentionally want to evade and violate sanctions. They happen because companies trust the wrong third party.

The epsilon and elf enforcement matters, which I frequently speak about, demonstrate that companies get in trouble when they have weak distributor oversight, poor intermediary screening, inadequate beneficial ownership review, and failure to monitor diversion risks.

Regulators expect companies to understand counterparties, trace payment flows, identify transshipment risks, and monitor red flags continuously.

Third parties create the highest sanctions exposure because they operate beyond direct company control and visibility.

If your company cannot explain exactly who your third parties are doing business with, regulators are going to find you liable.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

The Department of Justice has announced a new West Coast Health Care Fraud Strike Force, signaling an expansion of federal enforcement efforts targeting health care fraud, telemedicine schemes, kickback arrangements, and technology-enabled billing misconduct. In this episode, Michael Volkov examines DOJ’s evolving enforcement strategy, including the growing use of data analytics and AI-driven investigations, increased scrutiny of private equity-backed health care entities, and heightened expectations for compliance oversight. Michael also discusses practical compliance lessons involving billing audits, telehealth controls, third-party risk management, and board-level governance in an increasingly aggressive enforcement environment

View Details

Recent insider trading charges connected to Polymarket highlight the Department of Justice and Commodity Futures Trading Commission’s evolving enforcement strategy toward prediction markets and digital trading platforms. In this episode, Michael Volkov analyzes how regulators are applying traditional insider trading, fraud, and market manipulation theories to emerging event-based trading ecosystems. Michael also explores the growing compliance expectations for prediction market operators, including surveillance systems, AML controls, information barriers, and governance frameworks as DOJ and the CFTC increase scrutiny of digital market integrity risks.

View Details

The European Union has formally approved its landmark Anti-Corruption Directive, creating the first comprehensive EU-wide anti-corruption framework. In this episode, Michael Volkov examines the Directive’s major provisions, including harmonized corruption offenses, expanded corporate liability, turnover-based penalties, whistleblower protections, and increased compliance expectations for multinational companies. Michael also discusses practical implications for compliance programs, third-party risk management, investigations procedures, and cross-border enforcement coordination as organizations prepare for implementation across EU Member States.

View Details

Venezuela is a tempting new business arena.

Many companies assume that Venezuela remained completely off limits. That is no longer accurate, the compliance risks are actually increasing.

OFAC has issued new Venezuela related general licenses in 2026 involving oil and gas, petrochemicals, mining, critical minerals, financial services, and contingent investment negotiations.

US companies are cautiously re-entering portions of the Venezuelan market under these specific licensing conditions.

But sanctions remain complex. SDN restrictions still apply. Reporting obligations are expanding, and dealings involving Russia, China, Iran, Cuba, and sanctioned intermediaries remain prohibited.

This is not a sanctions repeal.

It is a controlled opening with significant compliance expectations.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode of Volkov Law TV, Michael Volkov examines OFAC’s massive $275 million settlement with Adani Enterprises Limited arising from alleged imports of Iranian-origin LPG disguised as Omani and Iraqi product. The episode explores OFAC’s aggressive focus on maritime sanctions evasion, the risks created by U.S. dollar clearing transactions, the growing importance of intelligence-driven sanctions compliance, and the lessons multinational companies must learn regarding red flags, vessel monitoring, enhanced due diligence, escalation procedures, and internal investigations. The discussion also highlights OFAC’s continuing emphasis on cooperation and remediation in resolving major sanctions enforcement actions.

View Details

What if you worked at a company where whistleblowers were rewarded?

An internal investigation is often the result of a whistleblower concern.

And this is the most important test of a company's ethics and compliance program because employees watch exactly how leadership responds when misconduct surfaces.

Poor internal investigations destroy trust through delays, inconsistent discipline, retaliation, and lack of transparency.

Effective investigations require independence, speed, fairness, documentation, and consistency.

The Justice Department expects companies to maintain credible investigative systems and consistent disciplinary processes. Organizational justice matters. Employees judge fairness more than outcomes.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

The Justice Department unsealed a historic superseding indictment charging four of the world's largest shipping container manufacturers — CIMC, Singamas, Dong Fang, and CXIC — and seven senior executives for conspiring to restrict global container output and fix prices from November 2019 through at least January 2024, covering an estimated $35 billion in commerce and generating near-hundredfold profit increases during the COVID pandemic. In this episode, Michael Volkov examines the mechanics of the cartel, including factory surveillance cameras used to police production quotas, the dramatic "Operation Midnight in Paris" arrest of Singamas executive Vick Ma at Charles de Gaulle Airport, and the critical governance failure at the center of the case — that the cartel was built and operated by the companies' own CEOs and chairmen. Michael also discusses the essential elements of an effective antitrust cartel compliance program, including tone at the top, scenario-based antitrust training, competitor interaction policies, internal reporting mechanisms, communication hygiene, industry risk assessments, and the strategic importance of DOJ's Corporate Leniency Program as a first-mover immunity opportunity for companies that detect cartel conduct early.

View Details

What if the C-suite handed you a gold-plated whistle and asked you to blow it?

Here's the uncomfortable truth.

Most corporate scandals were discovered by employees long before management ever learned about it or acted.

The problem wasn't a lack of information.

It was a culture where people were afraid to speak up.

Companies with strong speak-up cultures detect misconduct earlier, reduce enforcement risk, and improve employee trust, which reduces misconduct rates.

Employees report concerns when they believe leadership listens, retaliation is prohibited, investigations are fair, and outcomes actually matter.

DOJ and regulators now evaluate whether employees trust the reporting system, not just whether a hotline exists.

A hotline without trust becomes a liability, not an asset.

Let's then talk about how do we get at internal investigations when we learn about misconduct.

Join me for part two.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Your company has uncovered a massive criminal scheme.

You want to get out of it - you serve up the mastermind on a silver platter for the Justice Department prosecutors.

You're working with the Justice Department and you have to deliver to them one key aspect - individuals who were responsible must be held accountable.

How do you do that?

You conduct a thorough internal investigation and you collect, analyze and present to the Justice Department the evidence that they need to prosecute those individuals at your company who were responsible for this criminal scheme.

Once you do that, the Justice Department prosecutors will evaluate the evidence and they'll let you know about the investigation.

And you need to work with them step by step to make sure that the individuals are held accountable for their criminal activity.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

The Department of Justice’s $549.5 million False Claims Act settlement with Perfectus Aluminum marks one of the largest customs fraud recoveries in recent years and signals an aggressive new era of tariff enforcement. In this episode, Michael Volkov examines DOJ’s expanding use of the False Claims Act to pursue alleged tariff circumvention schemes, the growing role of whistleblowers in customs enforcement, and the increasing overlap between trade compliance, national security, sanctions, and supply chain risk management. Michael also discusses the key compliance lessons for importers, manufacturers, and multinational companies facing heightened scrutiny of tariff classifications, country-of-origin determinations, and global sourcing practices.

View Details

Your company uncovers a massive criminal scheme.

Are you gonna go down with the ship or are you gonna grab onto the lifeboat that the Justice Department has sent your way?

The era of big corporate fines is over, and you have to make sure that you get your company through this without a big fine.

What do you do?

The Justice Department's corporate enforcement policy has been revised, and it makes it very clear you have to:

  1. Voluntarily disclose your criminal activity
  2. Cooperate with the Justice Department's investigation
  3. You have to remediate your corporate compliance program to make sure it doesn't happen again.

All of those things add up to a declination, meaning nothing happens to the company, and you have to only disgorge your ill-gotten gains.

But all of this is contingent on one issue, which we're gonna talk about in the next episode.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

So approximately 10-20% of your third parties are going to present serious AI risks. How do you mitigate those risks? Here's what you do.

One, you assess your needs and identify the risk calculation for each of your third parties, and then you seek two fundamental solutions.

Two, contractual provisions are critical, and there's 6 of them that you need. You have to restrict data use so that it's in accordance with:

  • The privacy laws
  • Confidentiality of information that you share with your third party
  • Audit rights
  • Representations and warranties
  • Security obligations
  • Indemnification with disclosures of any violations

This is the way we mitigate our risks and make sure that our third parties are not gonna create legal liability with their AI use.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode of Corruption, Crime, and Compliance, Michael Volkov interviews Kilby Macfadden, J.D., CCEP, Managing Director and Associate General Counsel at KPMG LLP, where she serves as Head of Investigations overseeing complex ethics, compliance, and enterprise risk matters. Drawing on her extensive experience in government enforcement and corporate compliance, Kilby discusses the growing importance of organizational justice, building employee trust in internal reporting systems, and creating fair, transparent, and consistent investigation processes. The conversation explores evolving expectations from the U.S. Department of Justice regarding speak-up cultures, investigative independence, and accountability, while also examining practical strategies for compliance leaders seeking to strengthen culture and reduce organizational risk. Kilby also reflects on lessons from her prior leadership roles, offering insights into how organizations can align ethics, investigations, and culture to build more resilient compliance programs.

View Details

In this episode, we examine how organizational justice and effective internal investigation systems sit at the core of the U.S. Department of Justice evaluation of corporate compliance programs. Drawing on benchmarking data from NAVEX Global and research from George Washington University, we explain why strong speak-up cultures generate more internal reports, detect misconduct earlier, and reduce enforcement risk. We also outline DOJ expectations for timely, independent, and consistent investigations, and provide practical guidance on building oversight, discipline frameworks, and monitoring systems that reinforce trust, fairness, and accountability across the organization.

View Details

Everyone is using AI, including your third parties. Could that land you into legal trouble? Absolutely.

So what are your third party AI risks?

These include the standard list, data privacy risks, lack of transparency, bias and discrimination, IP and content, and of course regulatory risks.

So, what can your third party do that gets you into the hot water?

Well, they could be a SAS provider who integrates generative AI into their platform.

It could be a vendor that uses AI for customer support.

It could be a sub-processor, subcontractor that incorporates AI functions, and most importantly, you could be getting API integrations of AI.

These are real and significant risks, but remember the key determinant at this point.

Do they represent you in their business activities?

If they do, you've got to listen to the next episode because we're gonna talk about how you mitigate those risks.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode, Michael Volkov analyzes the May 1 executive order signed by Donald Trump expanding U.S. sanctions targeting Cuba. The discussion highlights the order’s broad scope, including new authorities to sanction actors involved in key economic sectors, corruption, and human rights abuses, as well as its extension of secondary sanctions risk to foreign financial institutions. With increasing convergence between sanctions, anti-corruption, and human rights enforcement, the episode outlines key compliance challenges and practical steps companies must take to manage heightened global risk exposure.

View Details

When it comes to trade compliance, don't let the Justice Department make an example out of you and your company.

Build an effective trade compliance program. Here are the steps.

Step 1, get the buy-in from leadership. That means your board of directors and your senior executives.

Number 2, always do a risk assessment and update it. Look at your export and import risks, identify those that are significant.

And adopt and rebuild your policies and procedures. That's number 3.

Number 4 is put in internal controls, make sure you identify the risks as you're going along, and escalate for resolution.

Number 5, train. You need to train your employees to identify these issues, and there's an annual requirement of training imposed by OFAC.

And last, audit and monitor your program, find out issues, and then improve your program overall.

This is the way we keep the Justice Department and the regulators away.

The Ethics and Compliance Q and A show is produced byOne Stone Creative.

View Details

In this episode of the Corruption, Crime & Compliance podcast, Michael Volkov explores the growing risks associated with third-party use of artificial intelligence and why companies must update their vendor due diligence and onboarding processes. As AI becomes embedded in SaaS platforms, analytics tools, and service providers, organizations are increasingly exposed to risks they may not fully understand or control—including data leakage, lack of transparency, bias, regulatory liability, and intellectual property concerns. Volkov outlines practical steps to address these challenges, including enhancing due diligence with AI-specific inquiries, strengthening contractual protections, and implementing ongoing monitoring of vendor AI use. The key takeaway: companies are not only responsible for how they use AI internally, but also for how their vendors deploy AI on their behalf—making third-party AI risk a critical priority for modern compliance programs.

View Details

Is your trade compliance program low hanging fruit for the Department of Justice and the regulatory agencies?

The Justice Department and regulators are focused on enforcement.

Civil and criminal penalties are increasing on the import side, tariffs are now a regulatory focus and also a Justice Department focus with regard to the False Claims Act.

Criminal and civil penalties are coming.

On the export side, traditional regulatory requirements from OLFAC from BIS are now fertile ground for criminal cases for the Justice Department and for huge regulatory penalties from OLFAC and from BIS.

The solution? You've got to revise and build an enhanced trade compliance program.

And you can do that in several steps. Join us for part two on how to do that.



The Ethics and Compliance Q and A show is produced byOne Stone Creative.

View Details

In this episode of the Corruption, Crime & Compliance podcast, Michael Volkov examines how companies can design and implement a best-in-class AI Use Policy to manage the rapidly evolving risks associated with artificial intelligence. As organizations deploy AI tools across business functions, Volkov explains why traditional governance approaches fall short and outlines a practical framework for effective oversight, including risk-based classification of AI use cases, strict data protection controls, human accountability, and safeguards against bias and discrimination. He emphasizes the importance of cross-functional governance, employee training, and continuous monitoring, highlighting that AI policies must be operational, not theoretical. The episode’s key takeaway: companies can leverage AI to enhance productivity and innovation—but must maintain clear controls to ensure compliance, protect sensitive data, and preserve accountability.

View Details

It's tempting to cut ethics and compliance in this time. But that would be a mistake.

Ethics and compliance provide important fundamental values that in the end make a company more profitable.

They promote employee well-being, employee engagement, and makes sure that employees have a vested interest in their company.

This is not the time to start jeopardizing those important values.

So keep the message going - ethics and compliance are positive to the revenue bottom line.

If ethics and compliance are your passion, we need to talk - reach out at mvolkov@volkvlaw.com.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

FinCEN’s April 2026 proposed rule marks a major shift in AML/CFT compliance by redefining how programs are evaluated, enforced, and managed under the Bank Secrecy Act. In this episode, Michael Volkov breaks down the proposal’s most significant changes, including the new two-pronged framework distinguishing program design from implementation, a higher threshold for enforcement focused on systemic failures, and expanded expectations for risk-based compliance and governance. The rule also encourages the use of innovative technologies like artificial intelligence while requiring stronger board oversight and U.S.-based compliance leadership. With a 12-month implementation timeline and a clear push toward outcome-driven compliance, this proposal signals a fundamental transformation in how financial institutions should approach AML risk management.

View Details

Your board thinks compliance is a cost center. Here's the research that proves them wrong and how to make sure they know it.

Want help making the case for compliance at the top? Visit volkovlaw.com

View Details

Here are 3 more reasons you may think twice about letting ChatGPT run your compliance program.

First, content monitoring.

The content that you generate through ChatGPT or any AI service can raise real risks with regard to improper intellectual property, data privacy risks where you name certain individuals or name certain identifiers, and most importantly, remember your third-party risks.

When it comes to AI, you're using vendors, and those vendors have their own AI policies, and you need to analyze and mitigate those risks as part of the due diligence process and as part of the monitoring process once you've onboarded them.

So be careful, take all our six steps and hold them together and mitigate your risks.



The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

Artificial intelligence is rapidly transforming business operations—but it is also introducing a new generation of legal, ethical, and compliance risks. In this episode, we explore how AI risk is accelerating across organizations, from data leakage and bias to over-reliance on flawed outputs and hidden third-party exposure. Drawing on real enforcement trends and practical examples, we explain why AI risk is fundamentally a human and governance issue—not just a technology challenge—and why companies must adopt a risk-based approach that distinguishes between high- and low-risk AI use cases. This episode outlines the core elements of an effective AI compliance program, including governance structures, employee training, vendor oversight, and regulatory readiness in an increasingly scrutinized environment.

View Details

Are you actually thinking of turning over your compliance program to ChatGPT? If so, you need to listen to this.

AI has to be implemented in a methodical way, a step-by-step program. So let's talk about those steps.

First, you need a governance structure, meaning you have to have an organization responsible across the entire organization for all your uses of AI.

Second, like every issue that we deal with in ethics and compliance, you need a risk assessment. And you need to look at specific use cases and how those are going to impact your risk profile. This is critical. Only then you can start to tailor your program.

Third, you need to decide and investigate what exactly your risks are.

Is it algorithmic, meaning you're using it for your business purpose, or non-algorithmic?

Stay tuned to part two, and we're gonna talk about the rest of the steps.

The Ethics and Compliance Q and A show is produced by One Stone Creative.

View Details

In this episode, we examine the Department of Justice’s declination in the Balt Medical case—a textbook example of how DOJ is applying its Corporate Enforcement Policy in practice. Despite a multi-year foreign bribery scheme involving payments to a physician at a state-owned hospital, DOJ declined to prosecute the company based on its timely self-disclosure, full cooperation, and effective remediation. But the real story lies in DOJ’s simultaneous prosecution of two individuals who allegedly orchestrated the scheme, highlighting the central role of individual accountability in earning cooperation credit. This episode unpacks how companies must now “connect the dots” for prosecutors—identifying responsible actors and providing actionable evidence—if they hope to secure favorable outcomes.

View Details

In this episode, we break down the sweeping shift in U.S. sanctions policy toward Venezuela following the 2026 political transition and the issuance of multiple new general licenses by the Office of Foreign Assets Control. While the U.S. has opened the door to significant commercial activity—particularly in oil, gas, and minerals—this is not a full lifting of sanctions but a highly conditional framework with strict compliance guardrails. Companies can now engage in transactions involving Venezuelan energy and infrastructure, but must navigate complex restrictions, reporting obligations, and geopolitical limitations, including prohibitions involving Russia, Iran, and China-linked entities. This episode explores the opportunities, risks, and compliance challenges created by this carefully calibrated reopening of the Venezuelan economy.

View Details

The final quarter of 2025 produced a modest resurgence in Foreign Corrupt Practices Act (FCPA) activity following the administration’s June 2025 FCPA guidelines. Whether that uptick signals a sustained enforcement trend remains uncertain.

But one theme remains clear: individual FCPA enforcement is alive and well.

While corporate resolutions may benefit from evolving DOJ policy and a renewed emphasis on negotiated dispositions, individuals continue to face indictment, trial, sentencing, forfeiture, and reputational destruction

View Details

In this episode of Corruption, Crime and Compliance, Michael Volkov sits down with entrepreneur and innovator Paul Allen, founder of Ancestry.com and Soar.com, to explore the evolving intersection of artificial intelligence, governance, and public trust. Paul shares insights from his latest venture, CitizenPortal.ai, an AI-powered civic intelligence platform aimed at making government activity more transparent, accessible, and accountable to everyday citizens. The conversation moves beyond hype, focusing on how AI can strengthen—not replace—democratic institutions through constrained, verifiable systems that enhance understanding and engagement. With a thoughtful and pragmatic lens, Paul discusses the risks, opportunities, and responsibilities that come with deploying AI in the public sphere, offering listeners a compelling vision for how technology can rebuild trust in institutions at a critical moment.

View Details

The U.S Department of Commerce announced two settlements recently involving export control enforcement actions.

First, the Department of Commerce’s Bureau of Industry and Security (BIS) imposed a $374,474 civil penalty against California-based satellite technology supplier Vizocom for unlawfully exporting controlled technical data related to military antennas to a Chinese manufacturer.

Second, (BIS) imposed a $1 million civil penalty against Teledyne FLIR, a U.S. manufacturer of thermal imaging cameras, for multiple violations of the Export Administration Regulations (EAR) involving exports to China and Hong Kong. The enforcement action highlights a recurring compliance challenge for multinational exporters: the complex application of the EAR’s de minimis rules, as well as the importance of careful screening and strict adherence to license conditions.

View Details

In this episode, I sit down with Matthew Campbell, whose decades-long effort to seek answers about the death of his brother in the World Trade Center has now reached the doorstep of the Supreme Court of the United Kingdom.

This is not a case about liability for the September 11 attacks. Instead, it raises a fundamental constitutional question: can the UK government refuse to reopen an inquest—without meaningful judicial oversight? After the Attorney General denied Campbell’s request for a fresh inquest based on what he argues is new evidence, UK courts largely closed the door on review. Now, the Supreme Court will decide whether that decision is beyond challenge or subject to legal scrutiny.

At stake is more than a single case. This litigation tests the boundaries of executive power, the scope of judicial review, and the rights of families seeking to revisit official findings long after tragedy strikes. It also highlights the tension between finality in legal determinations and the pursuit of truth.

In our conversation, Matt Campbell explains what has driven his persistence, how the legal battle has evolved, and why this case could have broader implications for accountability in the UK legal system.

Whether you approach this from a legal, historical, or human perspective, this episode explores a compelling intersection of law and loss—and the enduring question of when a case is truly closed.

View Details

Vera is a Chartered Accountant, Certified Internal Auditor, and award-winning Ethics and Compliance expert who writes and speaks about philosophy, business ethics, compliance, risk, and governance.

She is the Executive Director of Boards of the Future™, a non-profit that works with corporate boards globally to advocate for stronger ethics, risk, and compliance backgrounds.

She spends time between Milan and Los Angeles and serves as a Chair, director, and ethics advisor for global professional bodies, corporations, and international nonprofits.

View Details

Anik A. Shah is Director & Sr. Legal Counsel, Anti-Bribery and Anti-Corruption, at Sandisk, a global semiconductor manufacturer. Anik has more than 15 years of compliance, investigations, regulatory, and law enforcement experience.

Anik started his career at the U.S. Securities and Exchange Commission (SEC), where he investigated anti-fraud, anti-bribery, and other violations by multi-national financial institutions and technology companies and their executives.

At the SEC, Anik routinely partnered with law enforcement and regulatory authorities throughout the U.S. and in Europe, Africa, and Asia on multi-jurisdictional investigations and enforcement. He was also selected for a special detail assignment as a federal prosecutor with the U.S. Department of Justice.

Prior to joining Sandisk, Anik worked on compliance, regulatory, and corporate governance issues at multi-national financial institutions. As a leading anti-bribery and anti-corruption practitioner, Anik routinely presents at industry, professional, and trade association events.

View Details

Each year, LRN’s Ethics & Compliance Program Effectiveness Report provides one of the most useful snapshots of the global compliance profession. The 2026 report—“The Next Leap: Technology, Trust, and the Transformation of Compliance”—again offers valuable insight into how corporate ethics and compliance programs are evolving amid rapid technological change, new regulatory expectations, and shifting workplace culture.

Based on surveys of more than 2,500 compliance professionals and employees worldwide, the report paints a picture of a profession that is progressing—but unevenly. Compliance programs are becoming more sophisticated and technologically enabled, yet many organizations are still struggling to translate technology investments into measurable improvements in culture, risk detection, and program effectiveness.

View Details

The Commerce Department’s Bureau of Industry and Security (BIS) has sent an unmistakable message to the semiconductor industry: creative interpretations of the Export Administration Regulations (EAR) will not shield companies from significant enforcement risk.

BIS imposed a $252 million penalty against Applied Materials — the second-largest fine in the agency’s history — for illegally exporting semiconductor manufacturing equipment to China’s Semiconductor Manufacturing International Corp. (SMIC), an Entity List company since 2020. The size of the penalty alone warrants attention. But the facts and legal analysis underlying the case provide even more important compliance lessons.

View Details

Episode 395 of Corruption, Crime and Compliance features an in-depth conversation with Bob Lemmond, the new CEO of LRN, on the evolving role of ethics and compliance in today’s risk environment. In this episode, Bob discusses how organizations can move beyond “check-the-box” compliance to embed a culture of integrity that drives performance, mitigates misconduct risk, and strengthens stakeholder trust. He shares his perspective on the growing complexity of global regulatory expectations, the importance of leadership tone and middle-management engagement, the integration of technology and data analytics into compliance programs, and the measurable business value of ethical culture. The discussion offers practical insights for compliance officers, boards, and senior executives navigating enforcement uncertainty while maintaining high standards of corporate accountability.

View Details

FCPA enforcement in 2025 was defined by what did not happen as much as what did. Compared to prior years, the number of publicly announced cases declined sharply, corporate resolutions were fewer, and the overall enforcement posture appeared more restrained. This slowdown, however, reflects a policy recalibration—not a dismantling—of the FCPA enforcement regime.

Early in the year, DOJ paused FCPA enforcement activity while it reviewed policy priorities. That pause, followed by the issuance of revised enforcement guidance mid-year, produced a measurable decline in announced actions. Several investigations slowed, at least one long-running prosecution was dismissed, and the SEC brought no new FCPA cases during the year.

DOJ’s revised guidance emphasized selectivity, signaling that enforcement would focus on higher-impact cases—large bribe payments, clear evidence of corrupt intent, sophisticated concealment, and conduct implicating U.S. national security or competitiveness. Lower-value cases and routine “business courtesy” fact patterns were explicitly deprioritized.

The public numbers reflect that shift. 2025 was one of the lightest FCPA enforcement years in more than a decade. DOJ announced only a small handful of corporate outcomes, while continuing to emphasize voluntary self-disclosure and cooperation through declinations and deferred prosecution agreements.

View Details

Earlier this year, the Securities and Exchange Commission (SEC) charged Archer-Daniels-Midland Company (ADM) and three of its former executives with accounting and disclosure fraud, in what has become one of the most significant financial reporting enforcement actions of 2026. The case underscores a fundamental compliance truth: strong internal controls and transparent disclosures are not optional — they are core risk mitigants that protect investors, markets, and corporate reputations.

At its core, the ADM matter highlights how breakdowns in accounting controls and disclosure practices — even when aimed at projecting performance — can quickly spiral into regulatory enforcement, civil penalties, and individual liability.

On January 27, 2026, the SEC announced a settlement against ADM, as well as actions against two former executives, and a litigated complaint against a third. The SEC found that ADM materially overstated the performance of its nutrition business segment by recording intersegment transactions on terms that did not approximate market, thereby misleading investors about the segment’s profitability and growth.

According to the order, executives directed “adjustments” to nutrition’s results — including retroactive rebates and price changes not available to third parties — to hit targeted profit levels and mask underperformance in key fiscal years. These adjustments were inconsistent with ADM’s internal policies and its public representations, creating materially false and misleading financial statements for multiple annual and quarterly reporting periods.

ADM settled the matter and agreed to pay a $40 million civil penalty. Two former executives agreed to pay civil penalties and disgorgement, and one agreed to an officer and director bar. Meanwhile, the SEC is pursuing litigation against a third executive for fraud-based claims.

Regulators do not view financial reporting risk as an isolated technical issue. The SEC’s enforcement approach in this case reflects several core priorities that every compliance leader should internalize.

View Details

Conflicts of interest are not abstract compliance niceties. They are serious risks to integrity that, if left unidentified or unmitigated, can erode employee trust, compromise decision-making, and expose organizations to regulatory enforcement, litigation, and reputational harm. Recent high-profile scandals involving relationships between supervisors and subordinates have underscored how personal conflicts can quickly morph into enterprise-wide compliance failures when controls, oversight, and ethical culture are weak.

A conflict of interest program, when thoughtfully designed and actively managed, is far more than a static policy on a shelf. It is a risk identification and mitigation engine that anticipates where incentives might diverge from organizational interests, assesses control effectiveness, and embeds ethical decision-making into everyday business processes.

Conflicts of interest arise wherever personal interests have the potential to interfere — or appear to interfere — with the objective performance of professional duties. Classic examples include financial interests in third parties, personal relationships that influence work decisions, and outside employment that competes with an employer’s interests.

View Details

The Justice Department has increased False Claims Act prosecutions, reflecting a continued focus on healthcare fraud and a new initiative on trade fraud. DOJ announced the largest annual recovery figure in the FCA's history -- $6.8 billion in settlements and recoveries.

FCA whistleblowers filed a record number of new cases -- 1,297 lawsuits and the government initiated 401 investigations. Since 1986, DOJ has recovered a total in excess of $85 billion.

DOJ is taking full advantage of the power provisions of the FCA that include treble damages, broad liability coverage, and favorable amendments adopted to increase government leverage.

Health care fraud remained the primary source of FCA settlements. Approximately $5.7 billion of the total $6.8 billion related to actions against healthcare companies. Notably, DOJ continued and expanded its success in three major areas: Managed Care, Prescription Drugs, and Medically Unnecessary Care.

View Details

From my perspective, hopefully a reasonable one, there is a little too much AI-Risk Hype. Not to belittle the experts or ignore potential risk concerns but this is getting a little carried away.

The compliance industry appears to be taken over by AI-this and AI-that. Third party risk bleeds into major AI risks, corporate governance needs to incorporate AI risks, and policies and procedures have to incorporate AI risks, while of course no risk assessment is worth its sale unless there is a discussion of dramatic AI risks.

My first response is whoa -- let's all take a deep breath. The best self-help tactic when experiencing anxiety is to take a deep breath, a proven remedy. The AI discussion is veering off into a racing brain phenomena where the compliance profession is sprinting to keep up with the newest hypothetical risk.

So let's take a calm and deliberate review of some of the key issues.

View Details

The most significant compliance and enforcement issue remains trade enforcement -- sanctions and export controls. In the second posting, I want to focus on the new and interesting development in this area: the use of the False Claims Act to capture violations of tariffs and customs duties.

With all the hype on the trade compliance front, when you calculate the numbers relating to criminal enforcement, 2025 was a slower year than 2024. That is understandable since there is always a hiccup or delay when a new Administration takes power.

From the administrative standpoint, however, OFAC and Commerce's Bureau of industry and Security ("BIS") posted increased in 2025 over 2024. For OFAC, 2024 was a relatively slow year, and 2025 showed an uptick in numbers of cases. Notwithstanding these increases, OFAC brought big cases involving Russian oligarchs.

For the year, OFAC brought 14 cases and recovered over $265 million in penalties. What was missing, however, was OFAC's steady enforcement against a variety of industries -- the spread of OFAC cases was fairly limited.

From the numbers, for 2025, DOJ indicted, took guilty pleas or participated in sentencing proceedings in a total of forty-one (41) cases. For 26 of these cases, the illegal exports were intended to customers in Russia (16) and China (10); after that, Iran was involved in 5 cases, and Haiti was involved in 4, and Venezuela and North Korea had only 2 cases respectively.

In this Episode, Michael Volkov reviews overall trade enforcement activities for 2025.

View Details

Scott Greytak, Transparency International, and Nate Sibley, Hudson Institute, join Michael Volkov for a review of anti-corruption issues and a look forward to the next year.

View Details

Tom Fox joins Michael Volkov to discuss ethics and compliance issues for the year 2025. Tom and Mike focus on the importance of ethics, conflict of interest, trade compliance, organizational justice and other issues.

This is Part 2 of a 2-Part Episode.

View Details

Tom Fox joins Michael Volkov to discuss ethics and compliance issues for the year 2025. Tom and Mike focus on the importance of ethics, conflict of interest, trade compliance, organizational justice and other issues.

This is Part 1 of a 2-Part episode.

View Details

What do you do when the headlines shift faster than your risk matrix can keep up? In this episode, Michael Volkov dives into the challenge of adapting compliance programs in the face of volatile and fast-changing global risks—from tariffs and trade controls to supply chain disruptions and third-party exposures. While the pressure to react is constant, the real key is staying anchored in your company’s values while making smart, timely adjustments.



Legal and compliance officers are used to adjustments and continuous improvement of their compliance programs. Building and maintaining an effective ethics and compliance program never ends — it is a continuous process. In a climate of rapid change, the strategies may feel familiar, but the risks themselves are taking new shape. To that end, Michael outlines five specific strategies for evolving your compliance program without losing your footing.

You'll hear him discuss:

  • Why culture isn't just a buzzword—it's the first and most critical line of defense in volatile times
  • How to run a quick-turn, focused risk assessment to identify new hotspots like sanctions, tariffs, and supply chain gaps
  • The rising danger of indirect exposure to foreign terrorist organizations and cartels through third parties
  • What companies need to know about tariff classification, scope, and enforcement to avoid legal and economic penalties
  • Why sanctions and export controls enforcement is heating up—and what that means for your global operations
  • How to recalibrate third-party risk management to account for trade-based threats and hidden ownership structures

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

With the beginning of the “New FCPA” era coined by DOJ’s Deputy Attorney General Lisa Monaco, we now need to focus on third-party risk and sanctions enforcement. The law, the practice, and the risks are important and not just the same as FCPA legal requirements. As we embark on a new criminal enforcement era surrounding sanctions violations, companies have to address this issue and do it correctly.

In this episode, Michael Volkov takes a comprehensive look at third-party risks from the distribution and supply sides and outlines appropriate strategies to manage these risks.

  • Epsilon Electronics serves as a stark reminder of the financial consequences of non-compliance. The company faced an OFAC enforcement action due to a shipment to Iran, resulting in a staggering penalty of over $4 million.
  • Apollo Aviation Group settled with OFAC for $210,600 for leasing aircraft engines which ultimately ended up being placed in to aircraft of a prohibited entity, Sudan Airways, violating sanctions regulations.
  • ELF Cosmetics settled with OFAC for $996,000 for importing false eyelash kits containing materials sourced from North Korea, highlighting supply chain due diligence failures.
  • The ELF Cosmetics case underscores the crucial role of supply chain due diligence in preventing sanctions violations. Instead of sticking their heads in the sand, companies must undertake basic supply chain due diligence when sourcing products from regions close to high-risk countries or regions.
  • “Reason to know” is now the key phrase guiding the New FCPA era. OFAC does not need to prove goods ultimately end up in a sanctioned country. When you see red flags, you must resolve them or they could be considered a “reason to know” in OFAC’s eyes.
  • Seven essential elements to boost your compliance program and effectively mitigate third-party sanctions risks include risk assessment, varying levels of due diligence, end-user documentation, monitoring, training, and red flag identification.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Is the DOJ really changing its playbook on FCPA enforcement, or is it business as usual under a new administration? In this episode, Michael digs into two headline developments that say a lot about where things are headed - the first FCPA declination under the Trump Administration and the first indictment. Both shed light on how DOJ is applying its policies in practice, what companies should expect, and why individuals are squarely in the crosshairs. Taken together, these cases remind listeners that while priorities may shift, the fundamentals of disclosure, cooperation, and accountability remain very much alive.

You’ll hear him discuss:

  • Why Liberty Mutual’s $4.7 million disgorgement shows DOJ is sticking closely to its Corporate Enforcement Policy
  • How voluntary disclosure and cooperation continue to all but guarantee a declination
  • The details behind Liberty Mutual’s misconduct in India and the factors DOJ weighed in its decision
  • What the Pemex indictment tells us about DOJ’s push to hold individuals accountable
  • The role of disgorgement in DOJ resolutions and whether the policy might be applied with more flexibility going forward
  • How luxury goods and personal perks were used in the Pemex scheme and why DOJ zeroed in on those details
  • What these developments signal for companies trying to strengthen compliance programs in a shifting enforcement landscape

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

AI promises efficiency, innovation, and new opportunities - but are companies moving too fast in the rush to adopt it? The risks are very real, from false content to flawed decision-making, and the global regulatory patchwork is only getting more complex. The challenge now is building governance and compliance frameworks that keep pace without stifling progress.



In this episode of Corruption, Crime, and Compliance, Michael Volkov explains why an AI compliance program is essential to corporate governance today.

You’ll hear him discuss:

  • Why companies need to start with a clear use case and weigh benefits against potential legal and compliance risks before rolling out AI
  • The evolving patchwork of regulations, including the FTC, state-level laws in the US, and the EU’s AI Act
  • How sector-specific rules in healthcare, financial services, and defense add new layers of complexity
  • The two biggest risks: AI-generated false content that can cause liability and reputational harm, and decision-making systems that create unfair or discriminatory results
  • What strong AI governance looks like, from board oversight and compliance officers to clear policies and cross-functional committees
  • The role of training, documentation, and incident reporting in ensuring responsible, transparent AI use
  • Why embedding responsible AI into company values and employee performance reviews helps build a culture of accountability

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

What happens when a company tries to outsmart the system - and gets caught red-handed by the DOJ in a $140 million export control scheme tied to Chinese military supercomputers?

In this episode, Michael dives into the DOJ’s criminal enforcement action against Cadence Design Systems - a case that marks yet another major step in the DOJ’s rapidly unfolding trade enforcement strategy. We’re no longer in the FCPA era. This is a whole new ballgame, where national security and trade compliance have collided, and companies that haven’t adjusted are already behind.

You’ll hear him discuss:

  • Why Cadence’s plea deal - not a DPA or NPA - is such a big deal
  • How the DOJ and BIS coordinated to secure over $140 million in criminal and civil penalties
  • The simple, sloppy scheme that involved fake names, hidden aliases, and blatant attempts to skirt export controls
  • Why partial cooperation didn’t earn Cadence a full credit reduction - and what they failed to do
  • The shocking compliance gap: only one export control officer handling global risk
  • What this case signals about the DOJ’s growing focus on national security and semiconductor enforcement
  • Why ethics, due diligence, and transaction monitoring are still your best defense
  • How companies can avoid getting blindsided by embracing the new trade enforcement landscape

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Is your internal reporting program keeping up or falling behind the curve? With over 2.15 million reports analyzed from nearly 70 million employees worldwide, NAVEX's 2025 Regional Whistleblowing & Incident Management Benchmark Report offers a goldmine of insight into how companies are (and aren’t) managing employee concerns. In this episode, Michael Volkov breaks down the key findings, regional trends, and what they really mean for compliance officers trying to build a stronger speak-up culture. NAVEX dominates the hotline market, and its annual benchmark report gives compliance professionals an unparalleled look at reporting behaviors across the globe. From rising retaliation concerns to surprising substantiation rates, the numbers speak volumes.

You’ll hear him discuss:

  • Why Europe’s sharp spike in reporting rates is likely tied to the EU Whistleblower Directive
  • How North American companies resolve reports faster and what that says about handling HR-driven complaints
  • Why anonymous reporting is much higher in APAC, Europe, and South America and what it might reveal about employee trust
  • How retaliation claims are being substantiated at drastically different rates depending on geography and legal frameworks
  • What’s behind the higher substantiation rates at privately owned companies compared to public ones
  • How reporting channel preferences are shifting and why phone-based hotlines may be on the way out
  • What “time to report” stats reveal about fear, hesitation, and the need for cultural change in the workplace

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

A competitor could trigger a federal investigation against your company, just by filing a whistleblower complaint about your imports. In this episode, Michael Volkov explores how the Trump Administration is reshaping the enforcement landscape by linking trade compliance and the False Claims Act (FCA) in unprecedented ways. With “trade and customs fraud, including tariff evasion” now a DOJ national priority, companies engaged in international trade face growing legal and reputational risks. A recent Ninth Circuit ruling has only intensified the stakes.

You’ll hear him discuss:

  • Why DOJ is combining trade enforcement and FCA cases, and what that means for companies that import goods into the U.S.
  • How “reverse false claims” work in the trade context, and why import misclassification, undervaluation, or incorrect country-of-origin declarations are now high-risk areas.
  • Recent high-dollar settlements - including $45 million in one case - where companies paid the price for customs fraud violations.
  • The significance of the Ninth Circuit’s decision in Island Industries v. Sigma Corp., which confirmed DOJ’s ability to pursue customs fraud claims under the FCA in federal court.
  • How whistleblowers, including competitors, are using FCA claims as a strategic tool in the marketplace, leading to sealed complaints and increased litigation.
  • What companies should be doing now to evaluate and reinforce their trade compliance programs, from reviewing documentation and broker relationships to training and internal reporting.
  • Why ignoring tariff and duty obligations - or failing to investigate them thoroughly - could be seen as deliberate indifference, exposing companies to both civil and criminal liability.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What happens when companies ignore red flags, bypass legal advice, and underestimate the reach of U.S. export laws? In this episode, Michael Volkov unpacks two major enforcement actions from the Department of Commerce’s Bureau of Industry and Security (BIS) and the Treasury Department’s Office of Foreign Assets Control (OFAC). These cases serve as cautionary tales for companies navigating complex trade and sanctions landscapes, highlighting the steep costs of compliance failures, even when violations aren't willful.

You’ll hear him discuss:

  • BIS’s $4.25 million penalty against Alpha and Omega Semiconductor (AOS) for 15 violations of the Export Administration Regulations (EAR), including unauthorized shipments to Huawei
  • How AOS disregarded legal advice and internal compliance warnings while continuing to export EAR99 items from the U.S. to an Entity List company
  • The significance of BIS’s finding that even non-willful violations will trigger serious enforcement consequences
  • OFAC’s $608,825 settlement with Key Holding LLC over Cuban sanctions violations linked to its Colombian subsidiary, Key Colombia
  • How a failure to implement sanctions compliance after acquiring a foreign affiliate exposed Key Holding to U.S. jurisdiction - and liability
  • The importance of post-acquisition compliance integration and automated screening in mitigating enforcement risk
  • Why these cases mark a return to traditional administrative enforcement priorities and serve as stark reminders of jurisdictional reach

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Could your supply chain be funding cartels without you realizing it? In today’s complex global economy, companies are grappling with a dual challenge - the urgent need to unravel their supply chains and the immediate recalibration of due diligence systems to detect links to cartel and transnational criminal organizations (TCOs). With the Department of Justice sharpening its focus on both direct prosecutions and financial facilitators, global companies must prepare for heightened scrutiny. Michael breaks down the mounting risks, enforcement priorities, and practical steps companies must take to protect themselves from becoming unwitting participants in criminal operations.

You’ll hear him discuss:

  • How DOJ’s new two-pronged enforcement strategy is bringing corporate facilitators of cartels and TCOs into the crosshairs
  • Why traditional due diligence no longer goes far enough, especially with "Nth Party" risks buried deep in supply chains
  • How cartels and TCOs exploit legitimate businesses in sectors like logistics, agriculture, mining, and construction
  • The importance of identifying beneficial ownership and tracing complex corporate structures across jurisdictions
  • Red flags to watch for, from nominee arrangements and shell companies to unexplained wealth and layered financial flows
  • How cartels are adapting with fake websites, fake bios, and cryptocurrency to mask illicit activities
  • What companies must do to modernize their compliance systems with open-source tools and workflow automation
  • Why trade-based money laundering, remittance services, and decentralized platforms are growing areas of concern

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What happens when a company inherits a sanctions violation through acquisition, and acts fast to fix it? Can a robust post-acquisition response really save a parent company from prosecution? In this episode, Michael Volkov unpacks the fascinating DOJ-led global enforcement action against UNICAT Catalyst Technologies - a case that reflects the U.S. government's intensifying focus on trade enforcement across sanctions, export controls, and customs. This resolution marks the first declination under DOJ’s National Security Division M&A policy, showcasing the power of voluntary disclosure, cooperation, and remediation in today’s enforcement environment.

You’ll hear him discuss:

  • How DOJ, OFAC, BIS, and CBP coordinated parallel resolutions against UNICAT
  • The $3.3 million forfeiture and additional penalties tied to underpaid duties and unlawful exports
  • Why DOJ declined prosecution of UNICAT’s parent company, White Deer, under its M&A policy
  • The former CEO’s role in orchestrating 23 unlawful sales to Iran, Venezuela, and Cuba
  • The importance of identifying willful intent in sanctions violations — and when DOJ disclosure is required
  • The risks of failed pre-acquisition due diligence and the value of strong post-acquisition integration
  • How concealment tactics like falsified invoices and coded emails were used to hide dealings with sanctioned entities
  • Key lessons for global companies navigating the new era of trade compliance and enforcement

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Are your trade compliance programs truly airtight - or are they just good enough to get caught? In this episode, Michael breaks down why tariff and trade violations are now squarely on DOJ’s radar, and why the heat is rising fast for importers, especially those dealing with Chinese goods. With enforcement priorities shifting, companies are at increased risk of both regulatory investigations and full-blown criminal prosecutions. This episode is a wake-up call for compliance professionals and legal teams - if you think tariff enforcement is still a civil issue, think again.

You’ll hear him discuss:

  • Why Customs and Border Patrol and Homeland Security Investigations are stepping up referrals and actions
  • How companies try to gain a competitive advantage by evading tariffs - and why it’s an “inevitable result” regulators are watching closely
  • The most common tariff evasion schemes, including misclassification under HTS codes, transshipment, undervaluation, and false certification of origin
  • Why importing from China under Section 301 is now considered a high-risk activity
  • The specific risks surrounding steel and aluminum imports under Section 232 tariffs
  • Examples of recent DOJ cases, including plywood, flooring, and mosaic tile fraud, and what they signal for future enforcement
  • How AI and data analytics are being used by investigators to spot anomalies and build cases
  • The difference between Section 301 and 232 tariffs - and how they reflect different policy objectives
  • How rising tariffs and fewer exclusions under the Trump administration are reshaping the trade compliance landscape
  • The statutes DOJ is using for criminal charges, including 18 U.S.C. §§ 371, 545, and 1341

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Has the pendulum swung back on FCPA enforcement - and will companies be ready when it hits? Is the DOJ’s renewed push on FCPA enforcement a strategic shift - or just old wine in a new bottle?

In this episode, Michael discusses the return of the Justice Department to the FCPA enforcement arena. In a significant development, DOJ announced the resumption of FCPA enforcement, accompanied by a new set of enforcement guidance principles. This guidance is more than policy - it’s a statement of priorities and strategy that will shape how FCPA investigations and prosecutions unfold. While the number of attorneys in DOJ’s FCPA Unit has declined, U.S. Attorneys' Offices across 94 districts now have increased authority to investigate and prosecute FCPA cases with less oversight. The result? Potentially broader, faster, and more decentralized enforcement. As always, the devil is in the details - and the June 9 DOJ FCPA Guidance Memo delivers plenty.

You'll hear him discuss:

  • DOJ’s renewed emphasis on prosecuting individuals over corporations, especially when misconduct can’t be directly linked to senior leadership
  • How companies may now have stronger arguments to avoid liability if the wrongdoing is isolated to a small group
  • Expanded autonomy for U.S. Attorneys’ Offices and what this means for enforcement volume and consistency
  • The DOJ’s prioritization of cases that directly impact U.S. national interests and corporate competitiveness
  • Increased scrutiny of links to cartels and transnational criminal organizations, including risks hidden in supply chains and third-party relationships
  • The push for faster, more efficient investigations to avoid the years-long white-collar case backlog
  • Guidance on when facilitating payments, gifts, or travel fall under FCPA exceptions - and why these rarely matter in major prosecutions
  • Why cooperation, early disclosure, and individual accountability may now be companies’ best bet for avoiding charges altogether
  • The DOJ’s sharpened focus on national security sectors like defense, critical infrastructure, and technology

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Is AI a magic bullet - or just another tool in the compliance toolkit?

What really happens when you let algorithms near your risk decisions?



In this episode of Corruption, Crime and Compliance, Christian Focacci, founder and CEO of Threat.Digital, returns for a thoughtful and highly practical conversation about the state of artificial intelligence in compliance and third-party risk management. Christian’s platform is at the forefront of using large language models and real-time data to transform how companies identify and manage risk - without losing sight of the human judgment that still needs to guide every decision. He and Michael explore what's changed in the AI landscape over the past year, what’s misunderstood about the technology, and how compliance teams can strike the right balance between innovation and accountability.

You’ll hear them discuss:

  • Why Christian believes you shouldn’t use AI unless it’s truly the right tool for the job, and how this philosophy shapes how Threat.Digital builds and deploys its systems
  • What large language models actually are, how they function under the hood, and why most people fundamentally misunderstand how they learn and process information
  • The growing demand for corporate AI governance, how some risk committees are creating unnecessary delays, and why many internal processes are still focused on the wrong questions
  • How Threat.Digital uses AI to reduce noise in due diligence, replacing bloated, unfiltered search results with clear, high-quality summaries supported by verifiable sources
  • Why the real power of AI isn’t about replacing humans, but about expanding what can be reviewed - moving from 10 data points to 10,000, while helping compliance professionals focus only on what matters
  • The future of due diligence: chaining AI tasks to build multi-layered investigations that trace ownership, pull third-party records, and surface hidden risks in real time
  • How AI is revolutionizing name screening and sanctions checks by eliminating irrelevant fuzzy matches, freeing teams from chasing meaningless alerts and allowing them to act on true risks with confidence

Resources

Christian Focacci on theThreat.Digital |LinkedIn | Email: chris@threat.digital

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What if your trade compliance misstep became tomorrow’s federal prosecution headline? In this episode, Michael Volkov issues a powerful warning to corporate leaders and compliance professionals: the DOJ is no longer treating trade violations as minor infractions—they're targeting them as fraud under the False Claims Act. With trade compliance now framed as a national security issue, this administration is on a mission to protect domestic industries and punish companies that cut corners. If your organization engages in international trade—especially with China—this episode is a must-listen.

You’ll hear him discuss:

  • Why corporate leaders should not confuse the pause in FCPA enforcement with a wider drop in corporate prosecutions, as the DOJ is intensifying its focus on other high-risk areas like customs and trade compliance
  • How the False Claims Act is being used to prosecute companies for tariff evasion, misclassification of goods, and country-of-origin fraud, creating major new exposure for import-heavy businesses
  • The administration’s positioning of trade compliance as a national security priority, which signals tougher penalties and more aggressive enforcement tactics
  • Examples of recent DOJ cases, including multimillion-dollar settlements with Barco Uniforms, International Vitamins Corporation, and Danco Laboratories, that highlight how quickly companies can become targets
  • The expanding role of whistleblowers under new DOJ incentives, making it more likely that internal missteps will be reported and investigated
  • Why supply chains involving China and other flagged jurisdictions are under heightened scrutiny, and how companies can prepare for increased oversight
  • The risks of becoming a public example of trade fraud, and the steps companies should take now to stay ahead of enforcement and protect their brand and bottom line

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Is your company ready to bet its future on whether it can outpace a whistleblower to the DOJ’s door? In this episode, Michael Volkov takes a deep dive into the Department of Justice’s newly announced strategy to reshape corporate enforcement. With promises of greater clarity, reduced penalties, and fewer monitors, the DOJ wants companies to see voluntary disclosure as a smart and safe move - not a leap of faith. But behind the incentives lies a sharper edge: whistleblowers, shortened timelines, and a more assertive DOJ ready to move fast. Whether you’re in-house counsel, a compliance officer, or just trying to stay ahead of enforcement trends, this is a must-listen breakdown of what’s changed, why it matters, and what companies need to do now to avoid being caught off guard.

You’ll hear him discuss:

  • How companies that voluntarily disclose, cooperate, and remediate can now qualify for a declination, even with aggravating circumstances
  • Why the DOJ is promising greater transparency and fairness in enforcement to reduce fear and uncertainty around self-reporting
  • What changes have been made to limit when corporate monitors are imposed, and how DOJ will control their cost and scope
  • How the whistleblower program has been significantly expanded to include sanctions, tariffs, trade violations, and federal program fraud
  • What benefits may still be available for companies that report after DOJ has begun an investigation, including reduced fines and no monitorship
  • Why DOJ is pushing prosecutors to shorten the length of corporate investigations and avoid drawn-out resolutions
  • What’s at stake if a whistleblower reports first, and how companies could lose access to key benefits by waiting too long

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What happens when the world’s most influential anti-bribery law is abruptly paused? Is transparency merely a compliance box-tick—or the most powerful tool we have against global threats like kleptocracy, sanctions evasion, and illicit finance? In this eye-opening episode of Corruption, Crime, and Compliance, Michael Volkov is joined by two powerhouse experts in the global fight against corruption: Scott Greytak and Josh Birenbaum (*see ‘’About Guests below). Together, they break down the sweeping implications of the U.S. government’s pause on Foreign Corrupt Practices Act (FCPA)enforcement, the gutting of the Corporate Transparency Act (CTA), and what all of this means for business leaders, policymakers, and the international community.

When the United States hit pause on FCPA enforcement, the global anti-corruption landscape shifted. Scott and Josh explore how companies are reacting, how allies are stepping up enforcement, and why transparency is emerging as a national security imperative. They offer a forward-looking conversation filled with insights for compliance professionals, risk officers, and anyone committed to ethical business in a volatile world.

You’ll hear them discuss:

  • Why the U.S. government's pause on FCPA enforcement shocked the global anti-corruption community—and why companies should still stay the course with compliance regardless of political signals.
  • How the Corporate Transparency Act, once seen as the most significant U.S. anti-money laundering law in a generation, has been quietly gutted—leaving a dangerous gap in the fight against shell companies and financial crime.
  • What it means that U.S. companies are now incentivized to form anonymously domestically to avoid ownership disclosure—inviting kleptocrats, traffickers, and foreign adversaries to hide in plain sight.
  • Why global businesses must prepare for a sharp rise in trade compliance enforcement, as tariffs, export controls, and sanctions take center stage in economic security—and why transparency is essential to managing these risks.
  • How foreign enforcers, especially in Europe, are beginning to step up—but why no alliance or coalition can truly fill the vacuum left by a retreating United States.
  • What makes transparency not just a compliance tool, but a weapon against geopolitical threats—from Xinjiang’s forced labor camps to Russian shadow fleets and fentanyl trafficking.
  • How transparency can be hardwired into foreign aid policy to protect U.S. taxpayer money, prevent narco-state development, and give American businesses a fair shot abroad.
  • Why there’s still hope—from new bipartisan support for anti-corruption measures to the emergence of a national security lens on transparency across Congress, federal agencies, and the private sector.

About Guests

Scott Greytak is an anticorruption attorney and the Director of Advocacy for TI US. His work focuses on designing anticorruption laws and policies, organizing and leading ideologically inclusive coalitions, and lobbying the U.S. Congress and administration. Greytak was named a Top Lobbyist in 2021, 2023, and 2024 by the National Institute for Lobbying & Ethics.

Josh Birenbaum is the deputy director of FDD’s Center on Economic and Financial Power, focusing on illicit finance risks and global corruption. Previously, Josh was the research and policy analyst at TRACE International, producing articles, book chapters, op-eds, model policies, industry reports, and speeches on sanctions, export controls, corruption, conflict minerals, money laundering, human rights, illicit finance, and other topics.

Resources

Scott Greytak on LinkedIn | Email - sgreytak@us.transparency.org

Josh Birenbaum on LinkedIn | Email - jbirenbaum@fdd.org

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

What if your next import shipment becomes the centre of a federal enforcement action — not because of criminal intent, but because of a mistake? In today’s episode, Michael Volkov breaks down the expanding power and reach of U.S. Customs and Border Protection (CPB) and what it means for businesses navigating an increasingly aggressive trade enforcement landscape. With the Trump Administration’s re-defined objective of fair trade, companies across all sectors need to brace for scrutiny, adapt to evolving risks, and rethink their compliance strategies.

You’ll hear him discuss:

  • The Trump Administration’s focus on fair trade and why CPB has become a central enforcement agency under this new agenda
  • How CPB exercises its authority to impose regulatory penalties, seize goods, and refer serious cases for civil or criminal prosecution
  • The legal standards that determine the severity of violations — fraud, gross negligence, or negligence — and how each carries different penalty thresholds
  • Why the materiality of a false statement or omission is a key factor in determining whether a violation has occurred
  • The importance of voluntary disclosure and how it can significantly reduce potential penalties and protect company reputation
  • The step-by-step process of CPB administrative enforcement, including investigations, pre-penalty notices, appeals, and mitigation options
  • The expanding impact of the Enforce and Protect Act (EAPA), and how companies can be held accountable for evading anti-dumping and countervailing duties
  • Why businesses must now take a closer look at their import documentation, supply chain practices, and overall trade compliance posture

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Are you running a compliance program that’s making a real impact—or just checking the boxes? In this episode, Michael Volkov dives into LRN’s 2025 Program Effectiveness Report, an annual benchmark that separates the truly impactful compliance programs from those that are merely operational. Based on insights from 1,500 global ethics and compliance professionals, this year’s report draws a clear line between high-impact and medium-impact programs—and what it takes to bridge the gap. The conversation highlights urgent risks, cultural disconnects, and the strategic value of automation, data, and leadership alignment in shaping tomorrow’s compliance functions.

You’ll hear him discuss:

  • How high-impact programs are defined by their strategic use of automation, data analytics, and benchmarking tools to drive measurable compliance outcomes
  • Why third-party risk management—including due diligence and supply chain oversight—is a defining trait of the most effective programs today
  • The growing trust gap between Gen Z employees and middle managers, and why this generational shift poses a cultural red flag
  • The continued dominance of outdated internal systems, regulatory complexity, and budget pressure as top operational challenges facing compliance leaders
  • How high-impact programs are integrating AI into both their codes of conduct and employee training, preparing teams for emerging tech risks
  • What medium-impact programs can do to evolve: focus on training, automation, and peer collaboration to elevate impact and resilience

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

When The United States has hit pause on Foreign Corrupt Practices Act (FCPA) enforcement—it left many asking whether Europe will now be stepping up to lead the global anti-corruption charge. In this episode of Corruption, Crime and Compliance, Michael Volkov explores how European prosecutors are responding to the enforcement gap, why multinational companies can’t afford to slow down their compliance efforts, and how both state-level and international initiatives are reshaping the future of anti-bribery law.

You’ll hear him talk about:

  • The launch of a new International Anti-Corruption Prosecutorial Task Force formed by the UK, France, and Switzerland, designed to intensify cross-border enforcement and cooperation in bribery and corruption cases.
  • The task force’s formation as a direct response to the U.S. enforcement pause, signaling that European agencies are prepared to take a more prominent role in prosecuting international corruption, especially involving multinational corporations.
  • California’s bold move to pursue foreign bribery under its Unfair Competition Law (UCL), reinforcing that FCPA violations remain prosecutable at the state level despite federal hesitation.
  • A continued commitment by global companies to maintain strong compliance programs, reflecting awareness that international and local enforcement can still pose serious legal and financial risks.
  • The unexpected dismissal of the long-running FCPA case against Cognizant executives, contrasted with the DOJ's decision to move forward with prosecutions in other high-profile cases, suggesting a selective enforcement pattern under current policy shifts.
  • A landmark case by the UK Serious Fraud Office (SFO), charging a company with failure to prevent bribery—a first for the SFO to bring such a case before a jury, potentially setting a new standard for corporate liability in the UK.

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Could your routine data transfers now violate federal law? The DOJ’s new Data Security Program (DSP) targets the flow of U.S. sensitive personal and government data to foreign adversaries — and the clock is ticking. In this episode of Corruption, Crime and Compliance, Michael Volkov breaks down the Justice Department’s sweeping new Data Security Program, enacted under Executive Order 14117 and finalized in January 2025.

You’ll hear him discuss:

  • The origins of the DSP, created through Executive Order 14117 under the Trump Administration, and the key national security concerns it addresses.
  • What constitutes a “covered data transaction” and the thresholds for U.S. personal and government data that trigger compliance obligations.
  • The list of “countries of concern” and what it means for companies doing business with entities tied to these regions.
  • The types of U.S. data covered by the DSP, including biometric, genomic, financial, and geolocation data, and the specific quantity thresholds that trigger restrictions.
  • Why data brokerage and bulk human genomic data transactions are prohibited outright, raising new compliance challenges for affected industries.
  • How “restricted transactions” like cloud computing services and vendor agreements are subject to conditional exceptions under the DSP.
  • The critical actions U.S. companies must take during the 90-day enforcement hiatus, including vendor assessments, renegotiations, and compliance system updates before the July 8th deadline.

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

How prepared is your organization to handle the evolving landscape of sanctions compliance? In this episode of Corruption, Crime and Compliance, Michael Volkov dives into critical sanctions compliance cases and their implications for global companies. He discusses four significant cases that underscore the necessity of robust compliance programs, particularly in light of increased DOJ enforcement actions. Through these examples, he breaks down the consequences of third-party liability, supply chain risks, and the dangers of inadequate compliance measures, offering valuable insights into how companies can proactively avoid similar pitfalls.

Cases discussed:

  • British American Tobacco (BAT): The company faced a staggering $629 million settlement for circumventing North Korean trade sanctions. This case illustrates how corporate prosecutions are evolving to resemble Foreign Corrupt Practices Act (FCPA) cases, emphasizing the growing scrutiny on multinational corporations.
  • Epsilon Electronics: This case clarifies the liabilities companies face when third-party distributors divert products to prohibited countries, such as Iran. Even if the company had no direct involvement in the diversion, it still bears responsibility, underscoring the importance of diligent monitoring of distribution channels.
  • ELF Cosmetics: The company received a $1 million fine for importing goods containing materials sourced from North Korea. This case underscores the critical importance of conducting thorough supply chain due diligence to ensure compliance with international sanctions.
  • Murad LLC: This case focuses on post-acquisition compliance failures, demonstrating the urgent need for thorough pre- and post-acquisition audits. These audits are essential to uncover potential sanctions violations and ensure that newly acquired companies adhere to compliance standards.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Links to the four cases: British American Tobacco |Epsilon Electronics IElf Cosmetics |Murad LLC

A Framework for OFAC Compliance Commitments (May 2019)

View Details

What do you do when the headlines shift faster than your risk matrix can keep up? In this episode, Michael Volkov dives into the challenge of adapting compliance programs in the face of volatile and fast-changing global risks—from tariffs and trade controls to supply chain disruptions and third-party exposures. While the pressure to react is constant, the real key is staying anchored in your company’s values while making smart, timely adjustments.

Legal and compliance officers are used to adjustments and continuous improvement of their compliance programs. Building and maintaining an effective ethics and compliance program never ends — it is a continuous process. In a climate of rapid change, the strategies may feel familiar, but the risks themselves are taking new shape. To that end, Michael outlines five specific strategies for evolving your compliance program without losing your footing.

You'll hear him discuss:

  • Why culture isn't just a buzzword—it's the first and most critical line of defense in volatile times
  • How to run a quick-turn, focused risk assessment to identify new hotspots like sanctions, tariffs, and supply chain gaps
  • The rising danger of indirect exposure to foreign terrorist organizations and cartels through third parties
  • What companies need to know about tariff classification, scope, and enforcement to avoid legal and economic penalties
  • Why sanctions and export controls enforcement is heating up—and what that means for your global operations
  • How to recalibrate third-party risk management to account for trade-based threats and hidden ownership structures

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

This week we are pleased to bring you one of our most popular episodes of 2024. Please enjoy, and we will be back next week with more insights from the Corruption, Crime, and Compliance podcast.

How can companies build trust and drive growth in a region as politically and economically volatile as Latin America? In this episode, Nicolas Garcia - Vice President, Legal, Regional and Compliance Manager for LATAM and Orica - joins Michael Volkov to discuss the complexities of navigating compliance and leadership in LATAM. The conversation highlights how regional dynamics, such as the crisis in Venezuela, influence business operations and how cultural shifts are changing the role of compliance officers. Nicolas provides valuable insights on the evolving compliance landscape, emphasizing the importance of trust, leadership, and a strong compliance culture in driving business success in challenging environments.

Listen in as Nicolas and Mike discuss:

  • The ongoing political and economic crisis in Venezuela has led to massive immigration into neighboring countries like Colombia, Chile, and Brazil, creating both economic challenges and opportunities in the region.
  • Guyana is experiencing rapid growth due to foreign investment, particularly in the oil and gas sectors, standing in stark contrast to Venezuela’s decline.
  • Nicholas emphasizes the shift from compliance officers being seen as enforcers to becoming strategic business partners. This transition helps companies not only meet regulatory requirements but also drive success.
  • Establishing a trust-based relationship between compliance officers and leadership is essential. When compliance is integrated into the business strategy, it becomes a tool for enabling growth rather than a barrier.
  • Trust in reporting systems is growing in Latin America, though fear of retaliation remains a concern. Anonymous reporting is on the rise, and substantiation rates are increasing as employees gain confidence in the system’s integrity.
  • Ensuring that investigations follow due process is critical to maintaining credibility in compliance programs. It also helps improve trust and the success rate in legal outcomes.

Resources:Nicolas Garcia onLinkedIn

Nicolas Garcia on Email: Nicolas.Garcia@Orica.com

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

This week, we are pleased to bring you one of our most popular episodes of 2024. Please enjoy, and we will be back next week with more insights from the Corruption, Crime, and Compliance podcast.

Carlos Villagrán is the Director of Compliance at CMPC, a 100-year-old Chilean-based holding company, one of the worldwide leading pulp, paper, packaging, personal care, and other forest products manufacturers. With more than 20,000 employees, CMPC has industrial operations in 9 countries (LatAm and the US) and commercial offices in the US, Europe, and China, selling and distributing its products to more than 45 countries around the world. Carlos joined CMPC to remediate and rebuild CMPC's culture and compliance program after a devastating scandal -- CMPC was prosecuted for its involvement in a decade-long conspiracy to fix prices in Peru and Chile for consumer paper products. Carlos discusses the challenges he faced in rebuilding CMPA's culture and commitment to compliance. His story is an inspiration to all legal and compliance professionals and provides important instructive lessons to corporate leaders and compliance professionals.

You'll hear Michael and Carlos discuss:

  • The importance of rebuilding and rediscovering the values and purpose of CMPC after a major corporate crisis.
  • The effects on market share quotas and sales prices when CMPC faced an investigation and found to be the leader of a cartel in Chile and Peru.
  • How the crisis significantly impacted CMPC's reputation, leading to public protests and consumer backlash in Chile and Peru.
  • CMPC’s compliance team addressed the company’s complex nature because of its diverse workforce, including data analytics experts, IT professionals, and engineers.
  • How the compliance program at CMPC shifted from a traditional approach to a more cultural and system-thinking perspective, aligning with the company's values and operations.
  • Success for the compliance program at CMPC is defined by the number of critical tables the team is seated on, indicating their value and integration within the business operations.

Resources

Carlos Villagran on the Web | LinkedIn

Email: carlos.villagran@cmpc.cl or cfvillagran@gmail.com

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

This week we are pleased to bring you one of our most popular episodes of 2024. Please enjoy, and we will be back next week with more insights from the Corruption, Crime, and Compliance podcast.

Have you heard of the recent controversies around Boeing 737 MAX and its safety? Have you wondered what is being done about the concerns around it? In this episode of Corruption, Crime, and Compliance, Michael Volkov delves into the latest developments in the Boeing 737 MAX case, highlighting the recent plea agreement proposed by the Department of Justice (DOJ). The Boeing 737 MAX case took another dramatic turn. On July 24, 2024, the Department of Justice filed with the United States District Court for the Northern District of Texas a proposed plea agreement with Boeing. Under the Plea Agreement, Boeing will plead guilty to the original Information filed in 2021 with the Deferred Prosecution Agreement ("DPA"). The discussion focuses on Boeing's alleged failure to implement adequate compliance measures, leading to significant risks and violations, and the ongoing legal and ethical implications of the case. Tune in to hear a detailed analysis of the complexities and legal ramifications of Boeing’s recent plea agreement and what it means for corporate compliance and accountability.

You’ll hear him talk about:

  • Certification Issues: Boeing failed to ensure its 737 MAX certifications were accurate, risking false certifications to the FAA.
  • DOJ Plea Deal: Boeing agreed to plead guilty to conspiracy to defraud the U.S., facing opposition from victims' families who find the resolution insufficient. The plea agreement, which has been filed under Federal Rule Criminal Procedure 11(c)(1)(C), requires the Court to approve and accept the deal. The Court can reject the plea deal and require the parties to renegotiate the terms.
  • Victims’ Rights: The proposed resolution has been controversial because of the opposition of the families of the victims, who have opposed the plea agreement and general disposition of DOJ's investigation and prior resolutions as insufficient to vindicate the public interest and their rights as victims of Boeing's malfeasance
  • Compliance Failures: Boeing breached its DPA by not implementing effective compliance controls, particularly in safety and quality processes.
  • Independent Monitor: Boeing will be monitored for three years and must invest $455 million in compliance and safety improvements.
  • Ongoing Challenges: Boeing’s anti-fraud measures still have gaps, with broader implications for industries where safety is critical.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

This week we are pleased to bring you one of our most popular episodes of 2024. Please enjoy, and we will be back next week with more insights from the Corruption, Crime, and Compliance podcast.

How do you manage risk when the vulnerabilities are outside your organization aren’t in your hands? In this episode of Corruption, Crime, and Compliance, we delve into the world of third-party risk management with our guest, Natalie Druckman, from Certa. As we discuss the regulatory landscape in EMEA and the US, Natalie highlights the higher regulatory burden faced by companies in EMEA, and how Certa uses AI to streamline workflows, provide intuitive data visualization, and enhance risk forecasting capabilities. AI is the future of third-party risk management, now and in the future.

  • Cybersecurity has become one of the top concerns for organizations. In 2012, Target worked with a third-party vendor and, as a result, suffered an attack that exposed their customers’ credit data. Since then, compliance departments have started working closely with IT to prevent such vulnerabilities.
  • Unlike the US, EU companies don’t benefit from gaps created between state and federal regulations. EMEA faces a mandatory and substantial regulatory burden, particularly in areas like ESG and compliance. A forced labor scandal can sink a company, so ESG’s importance is on par with cyber security.
  • Global companies are increasingly recognizing the importance of addressing ESG topics alongside cybersecurity and financial risks. ESG considerations, such as diversity, modern slavery, and gender pay gaps, have significant reputational and revenue impacts.
  • AI is changing the world in many ways, including compliance. Certa aims to provide a comprehensive solution for third-party risk management, compliance, and operational risks by streamlining processes and incorporating AI capabilities to enhance efficiency and effectiveness.
  • Certa utilizes various AI capabilities, including design AI, which allows users to create workflows using plain language. They don’t need to know anything about tech; they can simply dictate the process, and AI generates the necessary code and infrastructure for it. This allows the company to remain flexible and able to quickly adapt to change.
  • Insights AI is another capability that collects and analyzes data, making it far more accessible and efficient in managing up-to-the-minute risks and developments. This technology also uses design AI, allowing for plain language inputs to immediately create actionable, detailed reports.
  • Recall AI allows companies to guarantee rapid and consistent responses from suppliers and customers by recalling past interactions to create surveys, forms, workflows, and processes. This removes the back-and-forth burden on all parties while still retaining the human touch.
  • Smaller and midsize companies should prioritize their risk management processes and consider automated solutions like Certa. These companies can benefit from the efficiency and effectiveness of an automated platform, regardless of their industry or size.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Natalie Druckman on LinkedIn

Certa

Email Natalie: nat@certa.ai

View Details

This week, we bring you a replay of one of our most impactful podcasts from last year, featuring Alex Cotoia and Daniela Melendez. Listen in as we discuss the EU Whistleblower Directive of October 2019. We'll return next week with one of our regular updates.

Directive 2019/1937 of the European Parliament and Council dated 23 October 2019 on the “protection of persons who report breaches of Union law” (the “Directive”) is currently being implemented by EU Member States. The directive has broad applicability to organizations operating in the EU internal market and applies to both public and private sector organizations alike. Whistleblowers are guaranteed legal protection to the extent: (1) they have reasonable grounds to believe that the information reported was true at the time of the report; and (2) the whistleblower reported either internally to the organization, externally to a competent authority, or publicly. Private sector organizations with 50 or more workers are legally required to establish channels and procedures for internal reporting of EU law breaches and conduct appropriate follow-up.

In this episode, Mike Volkov is joined by Daniela Melendez and Alex Cotoia from the Volkov Law Group, who bring their expertise to the table as they delve into the EU Directive and its implementation by several member states. Listen to this discussion to understand and navigate the complexities of the EU Whistleblowing Directive.

  • The EU Whistleblower Directive shifts the burden of proof on retaliatory actions to the person taking the detrimental action, requiring them to demonstrate it was not linked to reporting concerns.
  • Global companies are taking a proactive stance by increasingly focusing on robust ethics and compliance programs. This strategic move is aimed at mitigating risks and promoting positive corporate citizenship in today's economy, where adherence to legal and ethical standards is paramount.
  • France signed the EU Directive into law on March 21, 2022, outlining protocols for gathering and handling whistleblower reports, including a two-month deadline for imposing disciplinary sanctions.
  • Germany enacted the EU Directive on May 12, 2023, allowing anonymous reports and setting a three-month investigation deadline after receiving the report.
  • Spain addressed the EU Directive on February 2023 by covering additional topics like occupational health and safety breaches. The directive established a three-month deadline for investigations and allowed anonymous reports.
  • Italy transposed the EU Directive on August 4, 2022, including administrative, financial, civil, and criminal offenses not covered by the Directive, with a 30-day deadline to conduct investigations upon receipt of reports.
  • Companies are advised to make resources available to conduct investigations quickly due to the short timeframes set by various countries' whistleblower protection laws.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Alex Cotoia on LinkedIn

Email: acotoia@volkovlaw.com

Daniela Melendez on LinkedIn

Email: dmelendez@volkovlaw.com

View Details

Is your company prepared for the compliance storm ahead? With tariffs shaking global trade, aggressive sanctions enforcement, and new risks from AI, businesses must rethink their strategies. Can your compliance program keep up, or will it be left scrambling?

In this episode of Corruption, Crime, and Compliance, Michael Volkov unpacks the rapidly shifting risk landscape facing businesses today. From trade compliance and supply chain disruptions to cybersecurity and government enforcement, he highlights the top legal and compliance challenges of the year and offers practical guidance on how companies can stay ahead. While the regulatory world is in flux, one thing remains certain—organizations that fail to adapt will face significant financial, legal, and reputational consequences.

You'll hear him discuss:

  • The evolving trade landscape, including tariff enforcement, import risks, and the potential economic fallout of aggressive trade policies
  • Why supply chain mapping is no longer optional, with companies needing to identify vulnerabilities, alternative sourcing strategies, and compliance risks to avoid costly disruptions
  • How businesses should approach the FCPA enforcement pause, what it signals about the government’s priorities, and why global companies remain committed to anti-corruption programs
  • Why compliance teams must elevate import control and export control programs, particularly as the US expands restrictions on advanced computing, AI, and semiconductor exports
  • How transnational criminal organizations are infiltrating legitimate supply chains for money laundering, and what companies must do to strengthen their due diligence efforts
  • The importance of a strong compliance culture in a time of regulatory uncertainty—how companies can remain flexible, proactive, and aligned with their core values despite the shifting landscape

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Are You Ready for the Next Wave of Corporate Risk? Corporate risks are shifting, and every board, C-suite, and compliance team must take a fresh look at their risk landscape. While some risks like cybersecurity, data privacy, and artificial intelligence remain high priorities, others—such as anti-corruption and antitrust enforcement—are evolving in unexpected ways. With regulatory changes and new enforcement priorities emerging, businesses must stay ahead of the curve to avoid costly missteps. In this episode of Corruption, Crime & Compliance, Michael Volkov unpacks the latest updates in FCPA enforcement, antitrust scrutiny, and trade compliance. With the DOJ shifting its focus, companies need to prepare for the new compliance reality.

You'll Hear Him Discuss:

  • Why companies must reassess their risk priorities in today’s unpredictable business environment, as corporate risks continue to shift in response to new regulatory and enforcement trends.
  • The impact of the FCPA enforcement pause, what it really means for global businesses, and why companies cannot afford to dismantle their anti-corruption programs despite the temporary halt in enforcement.
  • How the DOJ is shifting its focus toward prosecuting criminal cartels and transnational organizations, and what that means for businesses operating in high-risk regions or industries.
  • The evolving landscape of antitrust enforcement, including key takeaways from Gail Slater’s confirmation hearing and how the administration’s new approach may impact high-tech competition cases.
  • How businesses should prepare for heightened tariffs, trade compliance risks, and increased customs enforcement, particularly as the U.S. targets imports from China, Southeast Asia, Mexico, and Canada.
  • Why workplace immigration enforcement is becoming a bigger concern, with the government ramping up workplace raids, audits, and compliance checks for companies employing immigrant workers.
  • The growing scrutiny around government grants, the potential for fraud investigations, and how businesses receiving federal funds must ensure strict compliance with evolving regulatory requirements.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What happens when an entire era of anti-corruption enforcement is put on pause? Is this a strategic move to bolster American businesses or a dangerous rollback of corporate accountability? In an unprecedented move, the Trump administration has hit the brakes on FCPA enforcement for at least 180 days, citing concerns over U.S. economic competitiveness and national security. In this episode of Corruption, Crime, and Compliance, Michael Volkov breaks down the implications of this game-changing executive order. The executive order claims that FCPA enforcement has been stretched beyond its original intent, harming American businesses while benefiting foreign competitors. With the Department of Justice now ordered to reassess its approach to anti-bribery enforcement, the business and legal communities are left wondering—what happens next? Will companies adjust their compliance strategies, or will global enforcement trends keep them in check?

You'll hear him discuss:

  • The Trump administration’s rationale for halting FCPA enforcement and why the decision was both surprising and expected
  • The executive order’s directive to the Attorney General to reassess FCPA investigations and enforcement priorities
  • The shift in DOJ focus from corporate bribery cases to prosecuting cartels and transnational criminal organizations
  • The potential impact on global anti-corruption efforts, as countries like the UK, France, and Brazil continue enforcing their own bribery laws
  • The uncertainty surrounding DOJ’s forthcoming guidance and what companies should anticipate in the next 180 days
  • The broader implications for corporate compliance programs, risk assessments, and international business strategy
  • The historical context of past efforts to reform the FCPA and why similar arguments were made over a decade ago
  • The potential for companies to seek remedial measures for past FCPA enforcement actions and the challenges in implementing such a policy
  • How this shift in enforcement priorities may affect corporate ethics, internal investigations, and global compliance expectations

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

How do sanctioned Russian oligarchs continue to move their wealth despite international restrictions? The answer lies in real estate, shell companies, and complicit gatekeepers. In this episode of Corruption, Crime, and Compliance, Michael Volkov dives into one of the latest OFAC enforcement actions against Family International and its owner, Roman Sinyavsky, for facilitating sanctions evasion on behalf of Russian oligarchs. Through complex real estate transactions, Sinyavsky helped conceal luxury properties owned by Valeri Abramov and Viktor Perevalov, allowing them to continue generating revenue despite U.S. sanctions. This case highlights the growing risk of financial crime in the real estate sector and the increasing scrutiny on those who enable it.

You'll hear him discuss:

  • The $1.07 million OFAC settlement and the criminal charges against Roman Sinyavsky for sanctions evasion and money laundering
  • How sanctioned Russian oligarchs used non-sanctioned family members and shell companies to obscure their ownership of U.S. properties
  • The key role of real estate professionals, lawyers, and financial advisors in facilitating these schemes and why they should have raised red flags
  • The use of text messages as critical evidence proving intent and knowledge of sanctions violations
  • The specific techniques used to transfer property ownership and avoid detection by authorities
  • The increasing enforcement focus on commercial and residential real estate transactions as a high-risk area for financial crime
  • Predictions for 2024, including tighter sanctions enforcement on Russia and Iran and what it means for businesses and compliance professionals

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

The 1990s saw the explosion of the internet, transforming the global economy and social development in ways we could have never imagined. But will AI truly have the same impact? While its potential is undeniable, the road ahead is full of risks, challenges, and ethical concerns. Will AI drive efficiency and innovation, or will it create new vulnerabilities that companies must scramble to control?

In this episode of Corruption, Crime, and Compliance, Michael Volkov dives deep into the legal, ethical, and compliance challenges surrounding AI. He explores how businesses are navigating AI adoption, the risks they face, and the safeguards they must implement to protect themselves.

You’ll hear him discuss:

  • Why AI’s economic impact, while significant, may not match the transformative power of the internet
  • Goldman Sachs’ prediction that AI could add $7 trillion to global GDP over the next decade
  • The massive investments required to scale AI, from semiconductors and data centers to energy and infrastructure
  • How generative AI is reshaping industries by creating human-like content with limitless applications
  • The hidden dangers of AI, including misinformation, deepfakes, fraud, and identity theft risks
  • Why businesses are cautiously adopting AI while grappling with privacy, copyright, and security concerns
  • The importance of AI compliance programs to mitigate legal, ethical, and reputational risks
  • Best practices for companies to ensure AI-generated content is accurate, transparent, and responsibly used

Resources

Michael Volkov on LinkedIn | X (Twitter)

The Volkov Law Group

View Details

Can the DOJ’s commitment to holding individuals and corporations accountable under the FCPA survive the changing political climate in 2025? Will the push for innovation in corporate compliance programs be enough to maintain momentum, especially with emerging technologies like artificial intelligence? In this episode of Corruption, Crime and Compliance, Michael Volkov dives deep into the FCPA enforcement landscape of 2024, outlining key cases, changes in DOJ policies, and the evolving role of compliance programs. He highlights the significant rise in penalties and individual criminal prosecutions, as well as the continuation of major corporate settlements such as Raytheon, Trafigura, Gunvor, and SAP. The episode also explores DOJ's new whistleblower program and its continued push for companies to enhance their compliance frameworks.

You'll hear him discuss:



  • Key FCPA enforcement matters in 2024 including the Raytheon, Trafigura, Gunvor, and SAP cases.
  • The shift in DOJ’s approach, where individual prosecutions now play a larger role than ever before.
  • The rise in penalties: 2024 saw a significant jump, with a total of $1.7 billion in fines.
  • The return of travel, hospitality, and gifts as common bribery techniques, despite increased focus on compliance.
  • DOJ's major industry sweeps, particularly targeting the energy commodity trading industry.
  • The emergence of new compliance challenges with a focus on artificial intelligence and emerging technologies in corporate settings.
  • The controversial SAP settlement and the DOJ’s approach to a lack of voluntary disclosure.
  • The impact of mergers and acquisitions on compliance processes and the integration of acquired companies.
  • DOJ’s new whistleblower program designed to incentivize individuals to report misconduct.
  • How companies should approach merger and acquisition integration to ensure compliance and prevent risks.

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

How will your company withstand the heat of aggressive sanctions enforcement? Are you ready for the DOJ’s new priorities and OFAC’s expanding reach in 2025? In this episode of Corruption, Crime, and Compliance, Michael Volkov dives into the major sanctions enforcement trends from 2024 and the road ahead under the new Trump administration. From record-breaking DOJ prosecutions to OFAC’s innovative enforcement approaches, Michael explains how sanctions compliance is more critical than ever. He highlights the biggest cases of the year, uncovers common pitfalls that led to costly penalties, and outlines how businesses can navigate shifting regulatory priorities. Whether it’s integrating compliance in M&A or addressing the risks of evolving China and Iran sanctions, this episode delivers actionable insights for staying ahead of enforcement risks.

You’ll hear him discuss:

  • The DOJ’s record-breaking prosecution of 70 individuals in 2024 and predictions for a surge in enforcement in 2025.
  • OFAC’s evolving enforcement strategy, including secondary sanctions tied to U.S. dollar transactions and new compliance commitments.
  • Key lessons from major enforcement actions like SCG Plastics, Aotech, and MondoTV, which paid millions for sanctions violations.
  • The consequences of neglecting sanctions compliance during mergers and acquisitions, including inherited liabilities and enforcement risks.
  • Predictions for heightened scrutiny on trade with China, aggressive tariffs, and evolving Iran sanctions under the new administration.
  • How emerging issues like advanced computing, AI, and dual-use technologies are becoming focal points for sanctions enforcement.
  • The role of voluntary self-disclosure in mitigating penalties, with examples of companies that uncovered and corrected compliance gaps.

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

How did a high-stakes bribery scheme involving insider deals, Airbus planes, and secret payments bring down a global aviation giant? In this episode, Michael Volkov dives deep into the AAR Corporation FCPA case—a cautionary tale of bribery, insider deals, and compliance failures in high-risk sectors. The DOJ and the Securities and Exchange Commission (SEC) closed 2024 with a major coordinated settlement with AAR Corporation, a provider of aviation products and services. The case involved criminal and civil FCPA charges related to bribery schemes in Nepal and South Africa. Deepak Sharma, the CEO of an AAR subsidiary, orchestrated the schemes, securing insider information and paying bribes to government officials to win lucrative contracts. Despite AAR's late self-reporting, the DOJ credited the company for its cooperation and remediation efforts. The case highlights ongoing corruption risks in the aviation industry, especially where state-owned enterprises and third-party agents are involved.

You’ll hear him discuss:

  • The details of the Illinois-based provider of aviation products AAR Corporation FCPA settlement with the DOJ and SEC.
  • How Deepak Sharma orchestrated bribery schemes in Nepal and South Africa.
  • The separate civil resolution with Deepak Sharma under which Sharma agreed to pay a disgorgement of $130,835 plus prejudgment interest of $53,762.
  • The role of third-party agents in facilitating corrupt practices.
  • Julian Aires, a former third-party agent of AAR, pleaded guilty in the District of Columbia on July 15, 2024 to a conspiracy to violate the FCPA for his role in the South Africa scheme.
  • Why insider information from government officials is a "kiss of death" in compliance.
  • How bribes were disguised through sham invoices and shell companies.
  • The importance of robust compliance programs in high-risk industries like aviation.
  • Red flags to watch for in industries dealing with state-owned enterprises.
  • How the DOJ and SEC weigh cooperation and remediation in enforcement actions.
  • Key takeaways for compliance professionals from the AAR case.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What went wrong when McKinsey paid bribes to secure consulting contracts with South Africa's state-owned enterprises? In this episode, Michael Volkov dives into the December 2024 DOJ settlement with McKinsey & Company, which paid $122 million after being found guilty of paying bribes to officials at Transnet and Eskom to secure valuable consulting contracts. The case involved significant violations of the Foreign Corrupt Practices Act (FCPA) and highlights the risks companies face when failing to implement effective compliance programs.

You’ll hear him discuss:

  • The details of McKinsey's settlement with the DOJ for $122 million, including the 35% discount and the cooperation credits granted by the government.
  • The role of Vikas Sagar, McKinsey's former senior partner, and his guilty plea in 2022 for orchestrating bribery payments.
  • How McKinsey Africa used sensitive, non-public information obtained through bribes to secure multi-million dollar contracts with Transnet and Eskom.
  • The ongoing issue of engaging third-party intermediaries and the importance of conducting thorough due diligence before entering into business relationships.
  • The lessons learned from McKinsey’s lack of proper oversight and controls that allowed a small group of corrupt executives to facilitate bribery schemes.
  • The broader impact of local content requirements in international business and the associated risks of partnering with unqualified entities that have ties to corrupt government officials.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What happens when a Chief Executive Officer becomes the architect of a global bribery scheme? In this episode of Corruption, Crime, and Compliance, Michael Volkov delivers an in-depth analysis of the BIT Mining FCPA case — a landmark matter that underscores the severe consequences of C-suite misconduct. With CEO Zhengmin Pan at the center of the conspiracy, BIT Mining’s efforts to infiltrate Japan’s emerging casino market were built on fraudulent payments, sham contracts, and falsified financial records.

Michael examines the tactics used to conceal illicit payments, the role of Japanese authorities in uncovering the misconduct, and the broader implications for corporate compliance and executive accountability.

You’ll hear him discuss:

  • How BIT Mining’s former CEO, Zhengming Pan, supervised a $2 million bribery scheme targeting Japanese government officials to secure entry into Japan’s integrated resort (IR) market.
  • The specific tactics used to launder bribe payments, including the use of sham consulting agreements, inflated lecture fees, and misclassification of bribes as "management advisory fees" and "travel expenses" in company records.
  • The DOJ’s charges against Pan, which included conspiracy to violate the anti-bribery and books-and-records provisions of the FCPA, as well as multiple counts of books-and-records violations and substantive anti-bribery offenses.
  • The terms of Bit Mining’s three-year Deferred Prosecution Agreement (DPA) with the DOJ, which included an agreed-upon $10 million criminal penalty, reduced from an initial $54 million based on the company’s inability to pay.
  • The SEC’s parallel enforcement action, which resulted in a $4 million civil penalty, later credited against the DOJ’s settlement amount.
  • How Japanese enforcement authorities played a crucial role in uncovering the scheme and what ultimately led to Bit Mining’s failure to win the integrated resort bid.
  • Practical compliance takeaways for corporate boards and executive teams, including the importance of strong third-party due diligence, financial control safeguards, and executive oversight to prevent and detect misconduct at the top.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What does it take for a global telecom giant to get caught up in a bribery scheme involving over $85 million—and what can we learn from their mistakes? How do companies like Telefónica Venezolana manage to conceal millions in bribes through inflated contracts and shell companies, and why do these schemes so often fly under the radar?



This episode dives into Telefónica Venezolana's $85.2 million settlement with the DOJ for bribery violations under the FCPA. Michael Volkov unpacks how the Venezuelan subsidiary exploited a government-controlled currency auction system, paid nearly $29 million in bribes, and concealed it through inflated equipment purchases. The case reveals systemic flaws and offers essential lessons on preventing corporate misconduct.

You’ll hear him discuss:

  • How Telefónica Venezuela used inflated supplier contracts to fund $28.9 million in bribes
  • The role of shell companies and intermediaries in concealing bribery schemes
  • How bribery enabled access to $110 million in undervalued U.S. currency
  • DOJ's assessment of cooperation, compliance efforts, and penalty reductions
  • Telefónica’s failure to address red flags in its financial controls and due diligence processes
  • The importance of vetting third parties and managing high-risk transactions
  • How Telefónica implemented compliance reforms, including anti-corruption measures and internal audits
  • Lessons for compliance professionals on detecting and preventing similar schemes

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Have you ever wondered how different cultures and generations engage with a company's code of conduct? Do employees across the globe really follow ethical guidelines in the same way, or are there stark contrasts depending on where they are and what they do? In this episode of Corruption, Crime & Compliance, Michael Volkov explores LRN's latest Code of Conduct Report, which reveals vital benchmarks and trends that can help companies strengthen their ethics and compliance programs. As LRN consistently provides high-quality insights on ethics and compliance, this episode dives deep into the findings that highlight how the code of conduct can serve as the cornerstone of a company's ethics culture—if used effectively.

You’ll hear him discuss:

  • How the usage of codes of conduct differs across geographic regions, with India, China, and Australia showing the highest engagement rates.
  • The surprising statistic that 35% of employees in the Netherlands reported never consulting their company’s code of conduct.
  • The impact of training, with countries like China and India seeing the highest percentage of employees trained on their code of conduct.
  • The generational divide, with Gen Z employees consulting their codes of conduct more than Baby Boomers, despite prior reports suggesting Gen Z's tendency to bend rules.
  • The significant gap in perceptions of code usage between senior leaders, middle managers, and frontline employees.
  • The role of hybrid work in fostering higher engagement with codes of conduct, contrary to the common assumption that remote work leads to disengagement.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What does the new Trump administration mean for ethics, compliance, and enforcement? As the dust settles on the U.S. election, companies are evaluating the implications of President Trump’s return to the White House. With priorities such as spurring economic growth, reducing inflation, imposing stringent trade sanctions, and reforming the Department of Justice, businesses must prepare for significant changes. How will these initiatives impact compliance programs and enforcement priorities?

You’ll hear Michael discuss:

  • Key enforcement priorities under the second Trump administration, including changes to DOJ oversight and trade compliance.
  • The implications of aggressive foreign policy shifts, including potential changes to sanctions on Russia, Iran, and China.
  • The focus on immigration enforcement, workplace audits, and I-9 compliance.
  • The anticipated reduction in environmental and workplace safety enforcement.
  • Trends in corporate criminal enforcement, including a steady focus on healthcare fraud but limited activity in other areas.
  • Strategies for companies to enhance trade compliance and prepare for expanded tariffs and sanctions.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What happens when a major defense contractor faces scrutiny for ethics and compliance violations? In this episode of Corruption, Crime, and Compliance, Michael Volkov dives into the high-stakes world of corporate accountability, exploring Raytheon's recent $428 million settlement with the U.S. Department of Justice. From fraudulent pricing to bribery and compliance lapses, we uncover the impact of these violations and the tough questions they raise about corporate governance, oversight, and ethical responsibility in high-stakes industries.

Hear Michael talk about:

  • Raytheon Company (Raytheon) -- a subsidiary of defense contractor, RTX (formerly known as Raytheon Technologies Corporation) — agreed to pay over $950 million to resolve the Justice Department’s investigations into three areas of violation.
  • The settlement addresses three main issues:
  • A major government fraud scheme involving defective pricing on certain government contracts
  • Violations of the Foreign Corrupt Practices Act (FCPA)
  • the Arms Export Control Act (AECA) and its implementing regulations, the International Traffic in Arms Regulations (ITAR)
  • As part of the settlement, Raytheon entered into a three-year deferred prosecution agreement (DPA) and agreed to the filing of criminal information in the District of Massachusetts charging Raytheon with two counts of major fraud against the United States. Raytheon admitted to engaging in two separate schemes to defraud the Department of Defense (DOD) relating to the provision of defense articles and services, including PATRIOT missile systems and a radar system.
  • Separately, Raytheon entered into a three-year DPA in connection with a criminal information in the Eastern District of New York charging Raytheon with two counts: conspiracy to violate the anti-bribery provision of the FCPA for a scheme to bribe a government official in Qatar and conspiracy to violate the AECA for willfully failing to disclose the bribes in export licensing applications with the Department of State as required by part 130 of ITAR.
  • The Justice Department’s FCPA and ITAR resolution is coordinated with the Securities and Exchange Commission (SEC). Both DPAs require that Raytheon retain an independent compliance monitor for three years, enhance its internal compliance program, report evidence of additional misconduct to the Justice Department, and cooperate in any ongoing or future criminal investigations. Raytheon also reached a separate False Claims Act settlement with the Justice Department relating to the defective pricing schemes.

Resources

Michael Volkov onLinkedIn |X (Twitter)

The Volkov Law Group

View Details

The SEC notched another FCPA settlement, continuing its steady pursuit and resolution of FCPA cases. In the meantime, the Justice Department has been silent in the FCPA enforcement arena. In this episode of Corruption, Crime, and Compliance, Michael Volkov dives into the SEC’s recent FCPA settlement with Moog, a global manufacturer that faced severe bribery allegations within its Indian subsidiary. From navigating India's complex tender processes to revealing corrupt practices and hefty penalties, Michael dissects Moog's compliance failures and highlights the critical role of ethics in international business dealings.

Listen in as he discusses:



  • Moog, Inc. ("Moog"), a New York-based global manufacturer of motion controls systems for aerospace, defense, industrial, and medical markets, agreed to pay a civil penalty of $1.1 million and disgorge nearly $600,000 for a total of $1.7 million, to resolve FCPA charges arising out of bribes paid by its wholly owned Indian subsidiary, Moog Motion Controls Private Limited (Moog Motion Controls).
  • Moog India allegedly bribed officials from the South Central Railway (SCR) and Hindustan Aeronautics Limited (HAL) to influence tender processes and exclude competitors. These bribes were often disguised as “contractor services.”
  • From 2020 to 2022, Moog employees bribed various Indian officials to win business. Also, they used a variety of schemes to make improper payments, including funneling them through third-party agents and distributors. These same Moog employees also offered cash bribes to Indian officials in an attempt to cause public tenders in India to favor Moog’s products and exclude competitors.
  • The case highlights significant gaps in Moog’s internal controls, including improper invoice recording, inadequate oversight of third-party agents, and a lack of compliance training.
  • Moog self-reported the misconduct, terminated those involved, enhanced its compliance program, and strengthened accounting controls and auditing procedures for third-party interactions.

Resources

Michael Volkov onLinkedIn |X (Twitter)

The Volkov Law Group

View Details

How does a respected financial institution turn into a criminal operation? In this episode of Corruption, Crime, and Compliance, host Michael Volkov dives into the record-breaking $3 billion settlement between TD Bank and the Department of Justice over pervasive violations of the Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) laws. Highlighting TD Bank's systemic failures, Michael explores how the bank's compliance and oversight lapses led to criminal conduct within its operations, making it a case study on the dangers of prioritizing growth over legal compliance. From failed AML programs to enabling money laundering on a massive scale, this episode sheds light on the regulatory crackdown TD Bank now faces.



Hear him discuss:

  • TD Bank’s $3 billion penalty sets a new high for banking compliance cases. In yet another reminder of the scope of Justice Department enforcement powers, and an important demonstration of the risks of non-compliance, the Justice Department and relevant banking agencies announced a $3 billion settlement with TD Bank companies to resolve systemic and pervasive Bank Secrecy Act ("BSA") and money laundering violations.
  • TD Bank’s internal culture sidelined AML compliance, leading to massive oversights, including unmonitored transactions worth $18.3 trillion from 2018 to 2024.
  • TD Bank enforced a “flat-cost paradigm,” restricting the compliance budget, which prevented updates and adaptations needed to meet new risk levels.
  • TDBUSH pleaded guilty to causing TDBNA to fail to maintain an AML program that complies with the BSA and to fail to file accurate Currency Transaction Reports ("CTRs").
  • Despite multiple warnings from internal audits and third-party consultants, the bank maintained its flawed AML protocols without significant action.
  • TD Bank earned the ignominious record: TD Bank is the largest bank in U.S. history to plead guilty to Bank Secrecy Act program failures, and the first US bank in history to plead guilty to conspiracy to commit money laundering.
  • With this settlement, TD Bank joins a list of high-profile compliance failures alongside companies like Wells Fargo and Wirecard, furthering the call for financial institutions to prioritize ethical compliance in their growth models.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

How can companies ensure that their compliance programs are robust enough to handle today’s complex ethical challenges? In this episode, Michael Volkov dives into the critical components of conducting an internal compliance site visit and review. He highlights the significance of these visits in understanding operational risks and compliance culture. With real-world examples, Michael emphasizes the need for a proactive approach to compliance, ensuring that organizations are not only following regulations but also fostering an ethical environment.

Listen in as Michael talks about:

  • Conducting personal interviews with key staff to assess the compliance culture and operational challenges.
  • Reviewing and testing transactions across various vendor categories to ensure compliance with protocols.
  • Evaluating the effectiveness of training programs and employee understanding of ethical standards and compliance awareness.
  • Verifying compliance with internal policies and conduct due diligence on charitable contributions.
  • Assessing the compliance processes surrounding sponsorships and their alignment with company policies.
  • Implementing thorough due diligence practices for third-party vendors to mitigate risks.
  • Reviewing employee expense reports to ensure proper documentation and compliance with gift, meals, entertainment, and hospitality policies.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What happens when a single company dominates a crucial segment of the financial market? In this episode, Michael Volkov explores the Justice Department's recent antitrust lawsuit against Visa, highlighting allegations of monopolization and exclusionary practices in the debit card market. With Visa controlling over 60% of debit transactions in the U.S., the DOJ aims to restore competition and prevent further stifling of innovation in this vital financial sector. Tune in as Michael breaks down the case details, Visa’s strategic responses, and the implications for the broader financial landscape.

Listen in as Michael discusses:

  • The DOJ has charged Visa with monopolization and exclusionary conduct under Sections 1 and 2 of the Sherman Act.
  • Visa holds over 60% of the U.S. debit transaction market, with MasterCard as its closest competitor at 25%.
  • The complaint alleges Visa engages in exclusionary agreements that penalize banks and merchants for using alternative debit networks.
  • The 2010 Durbin Amendment aimed to increase competition but has had minimal effect on Visa’s dominance, leading to ongoing scrutiny.
  • Visa's strategies include partnering with potential competitors while leveraging significant market power to suppress competition.
  • Following successes in technology sector enforcement, the DOJ is now expanding its scrutiny into financial markets, indicating a potential shift in antitrust enforcement dynamics.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

How prepared is your company to handle the evolving risks of artificial intelligence and other emerging technologies in its compliance program? In this episode of Corruption, Crime and Compliance, Michael Volkov delves into the Department of Justice's 2024 updates to its evaluation of corporate compliance programs. As the DOJ continues to set global standards, Michael discusses key updates related to risk management, especially around AI and other technologies. He also covers important shifts in training, whistleblower protections, third-party management, and data analytics, offering a comprehensive overview of what businesses need to consider for effective compliance.

You’ll hear him discuss:

  • The DOJ raises the bar for corporate compliance, including technology risk management through their updated Compliance Guidance (2024).
  • Companies must evaluate AI in both business and compliance contexts, ensuring controls for trustworthiness and legal alignment.
  • Firms need to incorporate lessons from other companies and adapt policies and procedures to reflect emerging tech.
  • Employee training must now be interactive, tailored, and measured for effectiveness.
  • With their focus on whistleblower protection, the DOJ emphasizes tracking employee comfort in reporting issues and ensuring protection from retaliation.
  • Companies are encouraged to continuously monitor third-party relationships beyond the onboarding phase.
  • Stronger processes are needed for compliance audits and integration after mergers.
  • DOJ pushes for the use of data analytics tools in compliance and better coordination between HR and compliance teams.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

DOJ Evaluation of Corporate Compliance Programs

View Details

How prepared is your organization to handle the evolving landscape of sanctions compliance? In this episode of Corruption, Crime and Compliance, Michael Volkov dives into critical sanctions compliance cases and their implications for global companies. He discusses four significant cases that underscore the necessity of robust compliance programs, particularly in light of increased DOJ enforcement actions. Through these examples, he breaks down the consequences of third-party liability, supply chain risks, and the dangers of inadequate compliance measures, offering valuable insights into how companies can proactively avoid similar pitfalls.

Cases discussed:

  • British American Tobacco (BAT): The company faced a staggering $629 million settlement for circumventing North Korean trade sanctions. This case illustrates how corporate prosecutions are evolving to resemble Foreign Corrupt Practices Act (FCPA) cases, emphasizing the growing scrutiny on multinational corporations.
  • Epsilon Electronics: This case clarifies the liabilities companies face when third-party distributors divert products to prohibited countries, such as Iran. Even if the company had no direct involvement in the diversion, it still bears responsibility, underscoring the importance of diligent monitoring of distribution channels.
  • ELF Cosmetics: The company received a $1 million fine for importing goods containing materials sourced from North Korea. This case underscores the critical importance of conducting thorough supply chain due diligence to ensure compliance with international sanctions.
  • Murad LLC: This case focuses on post-acquisition compliance failures, demonstrating the urgent need for thorough pre- and post-acquisition audits. These audits are essential to uncover potential sanctions violations and ensure that newly acquired companies adhere to compliance standards.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Links to the four cases: British American Tobacco IEpsilon Electronics IElf Cosmetics IMurad LLC

A Framework for OFAC Compliance Commitments (May 2019)

View Details

The SEC's recent settlement with Deere & Company for $9.9 million for FCPA violations is another textbook example of bribery schemes, which revealed the absence of a culture of compliance, and the circumvention of basic entertainment, hospitality and travel expense controls. In this episode of Corruption, Crime, and Compliance, Michael Volkov breaks down the SEC’s $9.9 million settlement with Deere & Company following widespread FCPA violations by its subsidiary, Wirtgen Thailand. Michael discusses how the bribery schemes, involving government officials in Thailand, reveal significant failures in compliance oversight and corporate governance, while also highlighting the critical lessons for businesses aiming to avoid similar pitfalls.

Key Insights:

  • Deere’s subsidiary, Wirtgen Thailand, secured government tenders through cash bribes, entertainment at massage parlors, and lavish trips for officials from the Royal Thai Air Force (RTAF), Department of Highways (DOH), and Department of Rural Roads (DRR).
  • Wirtgen disguised entertainment and bribe payments in expense reports with vague descriptions and round-number amounts, which were improperly approved by regional managers.
  • Wirtgen organized extravagant trips disguised as factory visits for Thai officials, which included sightseeing and luxury hotels in Europe. These trips were arranged to win government tenders but involved no legitimate business activities.
  • Bribes were also funneled through a third-party consultant via sham commission agreements. This consultant acted as a middleman, facilitating bribe payments to government officials to secure high-value tenders.
  • Deere's failure to fully integrate Wirtgen into its compliance program after acquisition allowed the bribery schemes to continue. This highlights the risks of not harmonizing compliance protocols in newly acquired subsidiaries.
  • In response to the SEC investigation, Deere terminated employees involved in the misconduct, revamped its compliance program, and introduced initiatives like a bi-monthly compliance newsletter and enhanced anti-bribery training.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

How can companies build trust and drive growth in a region as politically and economically volatile as Latin America? In this episode, Nicolas Garcia - Vice President, Legal, Regional and Compliance Manager for LATAM and Orica - joins Michael Volkov to discuss the complexities of navigating compliance and leadership in LATAM. The conversation highlights how regional dynamics, such as the crisis in Venezuela, influence business operations and how cultural shifts are changing the role of compliance officers. Nicolas provides valuable insights on the evolving compliance landscape, emphasizing the importance of trust, leadership, and a strong compliance culture in driving business success in challenging environments.

Listen in as Nicolas and Michael discuss:

  • The ongoing political and economic crisis in Venezuela has led to massive immigration into neighboring countries like Colombia, Chile, and Brazil, creating both economic challenges and opportunities in the region.
  • Guyana is experiencing rapid growth due to foreign investment, particularly in the oil and gas sectors, standing in stark contrast to Venezuela’s decline.
  • Nicholas emphasizes the shift from compliance officers being seen as enforcers to becoming strategic business partners. This transition helps companies not only meet regulatory requirements but also drive success.
  • Establishing a trust-based relationship between compliance officers and leadership is essential. When compliance is integrated into the business strategy, it becomes a tool for enabling growth rather than a barrier.
  • Trust in reporting systems is growing in Latin America, though fear of retaliation remains a concern. Anonymous reporting is on the rise, and substantiation rates are increasing as employees gain confidence in the system’s integrity.
  • Ensuring that investigations follow due process is critical to maintaining credibility in compliance programs. It also helps improve trust and the success rate in legal outcomes.

Resources:Nicolas Garcia onLinkedIn

Nicolas Garcia on Email: Nicolas.Garcia@Orica.com

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

What’s the real cost of keeping corporate misconduct hidden? In this episode of Corruption, Crime and Compliance, Michael Volkov explores how the DOJ's recent declinations highlight the risks and rewards of voluntary self-disclosure. By examining two key cases, Michael illustrates how companies can avoid prosecution through cooperation but still face significant penalties, like disgorgement. The episode underscores the importance of transparency and robust compliance programs in navigating DOJ enforcement strategies.



Key Points Covered:

  • Declinations Explained: While DOJ declinations allow companies to avoid criminal charges, they require disgorgement of illegal profits.
  • Boston Consulting Group Case: BCG reported bribery violations related to securing contracts in Angola. The company earned a declination by cooperating with DOJ, firing involved employees, and enhancing compliance. Total disgorgement: $14.4 million.
  • Hitachi Cable (Proterial) Case: Hitachi Cable disclosed fraudulent safety violations in its motorcycle brake hoses. The company’s proactive disclosure and internal reforms led to a declination. Disgorgement: $15.1 million, with partial credit for prior payments.
  • The Risk of Concealment: Companies that hide misconduct face higher penalties. Voluntary disclosure offers the potential for leniency through declinations.
  • DOJ’s Corporate Compliance Focus: DOJ continues to push for transparency and proactive corporate compliance, using declinations as a tool to incentivize self-reporting and improve internal controls.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

How will the DOJ's new corporate whistleblower pilot program reshape the enforcement of corporate criminal conduct? In this episode of Corruption, Crime, and Compliance, Michael Volkov explores the Department of Justice's (DOJ) new corporate whistleblower pilot program, highlighting its potential impact on corporate criminal enforcement. The program, which mirrors aspects of the SEC’s whistleblower program, is designed to incentivize individuals to report misconduct by offering financial rewards. The program is significant for privately held companies and financial institutions not covered by the SEC, marking a notable shift in DOJ's approach to corporate compliance and enforcement.



You’ll hear him discuss: DOJ’s Whistleblower Pilot Program: The DOJ introduced a three-year whistleblower pilot program that offers financial rewards to individuals who provide original information leading to significant criminal or civil forfeitures. This program, effective from August 1, 2024, mirrors aspects of the SEC’s program but is specifically tailored to corporate criminal enforcement. * Non-Appealable Rewards: Unlike the SEC’s program, decisions made under the DOJ’s whistleblower program are not appealable, minimizing litigation risks for the DOJ. * Focus on Privately Held Companies: The program significantly impacts privately held companies and non-public financial institutions, areas previously not covered by the SEC’s whistleblower program. This shift increases risks for these entities, particularly in cases involving foreign bribery, money laundering, and healthcare fraud related to private insurers. * Incentives for Internal Reporting: The program introduces a 120-day window for companies to act on internal reports of misconduct. If companies fail to take action within this period, whistleblowers can report directly to the DOJ, potentially earning financial rewards, while companies risk losing potential non-prosecution agreements. * Implications for Corporate Compliance: The new whistleblower program pressures companies to enhance their ethics and compliance programs. Companies must now navigate the risks associated with delayed reporting and the potential for whistleblowers to bypass internal controls in favor of DOJ reporting. * Impact on DOJ Enforcement:* The program is expected to bolster DOJ’s corporate enforcement actions by encouraging more reports of misconduct, particularly in areas not previously covered by similar programs. However, the adequacy of the reward fund to incentivize significant whistleblower reporting remains uncertain.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Whistleblower Awards Pilot Program

View Details

A New York federal district judge handed down a significant decision dismissing much of the SEC's securities fraud enforcement action against SolarWinds arising from its claims relating to SolarWinds' cybersecurity policies and disclosure of a significant cyberattack against the SolarWinds' network. In this episode of Corruption, Crime, and Compliance, Michael Volkov discusses the significant dismissal of most of the SEC's securities fraud claims against SolarWinds by a New York federal district court. The case highlights the ongoing challenges in balancing cybersecurity disclosures with regulatory requirements, and the implications this ruling might have for future SEC enforcement actions.



You’ll hear him discuss:

  • Judge's Decision: The court ruled that the SEC's claims were overly reliant on hindsight and speculation, particularly regarding SolarWinds’ early-stage disclosure during the investigation of cyber incidents.
  • Pre- and Post-Sunburst Disclosures: While the court upheld charges related to SolarWinds' pre-Sunburst cybersecurity statements, it dismissed the SEC’s claims about the company’s post-Sunburst disclosures, finding them not misleading under the circumstances.
  • Internal Controls vs. Cybersecurity: The court rejected the SEC's attempt to apply internal accounting controls provisions to cybersecurity policies, marking a significant limitation on the SEC's enforcement scope.
  • Implications for SEC's Approach: This decision contradicts the SEC's previous stance in cases like R.R. Donnelly, potentially influencing future SEC actions regarding cybersecurity and internal controls.
  • Broader Impact: The ruling may affect how cybersecurity risks are reported and how companies manage their disclosure obligations, particularly in light of potential appeals and further litigation by the SEC.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Have you heard of the recent controversies around Boeing 737 MAX and its safety? Have you wondered what is being done about the concerns around it? In this episode of Corruption, Crime, and Compliance, Michael Volkov delves into the latest developments in the Boeing 737 MAX case, highlighting the recent plea agreement proposed by the Department of Justice (DOJ). The Boeing 737 MAX case took another dramatic turn. On July 24, 2024, the Department of Justice filed with the United States District Court for the Northern District of Texas a proposed plea agreement with Boeing. Under the Plea Agreement, Boeing will plead guilty to the original Information filed in 2021 with the Deferred Prosecution Agreement ("DPA"). The discussion focuses on Boeing's alleged failure to implement adequate compliance measures, leading to significant risks and violations, and the ongoing legal and ethical implications of the case. Tune in to hear a detailed analysis of the complexities and legal ramifications of Boeing’s recent plea agreement and what it means for corporate compliance and accountability.

You’ll hear him talk about:

  • Certification Issues: Boeing failed to ensure its 737 MAX certifications were accurate, risking false certifications to the FAA.
  • DOJ Plea Deal: Boeing agreed to plead guilty to conspiracy to defraud the U.S., facing opposition from victims' families who find the resolution insufficient. The plea agreement, which has been filed under Federal Rule Criminal Procedure 11(c)(1)(C), requires the Court to approve and accept the deal. The Court can reject the plea deal and require the parties to renegotiate the terms.
  • Victims’ Rights: The proposed resolution has been controversial because of the opposition of the families of the victims, who have opposed the plea agreement and general disposition of DOJ's investigation and prior resolutions as insufficient to vindicate the public interest and their rights as victims of Boeing's malfeasance
  • Compliance Failures: Boeing breached its DPA by not implementing effective compliance controls, particularly in safety and quality processes.
  • Independent Monitor: Boeing will be monitored for three years and must invest $455 million in compliance and safety improvements.
  • Ongoing Challenges: Boeing’s anti-fraud measures still have gaps, with broader implications for industries where safety is critical.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

How does the SEC's recent settlement with R.R. Donnelly & Sons Company impact internal controls for cybersecurity incidents? In this episode of Corruption, Crime, and Compliance, Michael Volkow discusses a significant decision by the SEC involving a $2.1 million settlement with RR Donnelly & Sons Company (RRD) related to a 2021 ransomware attack. The SEC's decision marks the first time it applied its internal controls enforcement authority to cover cybersecurity policies and procedures, representing a substantial expansion of its enforcement reach.

The SEC criticized RRD for failing to prioritize the review of security alerts and implement an effective workflow for escalating such reports. This oversight led to delayed detection and response to the cyber attack, during which hackers exfiltrated 70 gigabytes of data, including personal and financial information tied to 29 clients.



You’ll hear him talk about:

  • The importance of robust internal controls to ensure prompt investigation and escalation of potential cybersecurity incidents.
  • The need for companies to allocate sufficient resources and personnel to monitor and respond to third-party security alerts.
  • The SEC's critique of RRD's internal incident response policies, particularly the lack of clear lines of responsibility and efficient workflows.
  • The dissenting opinions within the SEC regarding the broad application of internal controls to cybersecurity, highlighting the need for specific guidance on reasonable cybersecurity controls.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

SEC settlement

View Details

Is your HR department rolling their eyes at compliance? Does your company have a non-retaliation policy? The report, based on over 1,000 global responses, reveals growing maturity in compliance programs but notable gaps, such as only 61% having a hotline and 55% having a non-retaliation policy. Join us on this week’s Corruption Crime and Compliance to learn how cross-functional relationships are strong with data privacy and risk but weak with HR and finance. Michael Volkow highlights NavX's report, showing compliance's high engagement in processes like reputational harm and data breaches but often being involved late in mergers and acquisitions. Learn that common compliance issues include privacy, cybersecurity, and regulatory demands. The report also covers ESG programs and the need for better third-party risk management - tune in to hear more!

You’ll hear him talk about:

  • How compliance is often brought in late during mergers and acquisitions, with 20% of respondents noting no engagement in these processes.
  • Notable gaps that include only 61% of organizations having a hotline or whistleblower internal reporting channel and only 55% having a non-retaliation policy.
  • How the report shows progress in the maturity of compliance programs, with half of the respondents rating their programs in the top two tiers of maturity.
  • Compliance having strong relationships with data privacy and risk functions, but experiencing significant resistance from HR and finance departments.
  • Half of the organizations experiencing at least one compliance issue in the past three years, with privacy and cybersecurity being the most common issues.
  • Two-thirds of boards receiving periodic compliance reports, but one-third do not, highlighting a need for improved board engagement in compliance matters.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Navex State of Risk and Compliance Report

View Details

Is the progress itself enough to consider the battle won? Are the ongoing scandals casting a shadow over the hard work against corruption? Despite challenges (such as limited resources due to the ongoing war) and recent scandals (such as overpriced eggs for the military), Ukraine maintains multiple institutions committed to transparency and integrity, crucially supported by international partnerships aimed at enhancing its anti-corruption infrastructure.

Listen to this conversation between Michael Volkov and Halyna Senyk in which they focus on Ukraine's anti-corruption efforts amidst the backdrop of its ongoing war with Russia. Halyna Senyk, an expert from the CEELI Institute, details Ukraine's progress since 2014, highlighting the establishment of key anti-corruption agencies and reforms and how, over 10 years, it moved from 144 to 104 place in the Transparency International Corruption Perception Index.

You can listen to how, despite these advancements, Senyk acknowledges persistent challenges, including recent setbacks and scandals that have tested the country's resolve.

You’ll hear them discuss:

  • Historically pervasive and deeply rooted corruption at various levels of government and the reality of society that remains a critical challenge. Despite reforms and the establishment of anti-corruption agencies, the implementation and effectiveness of these measures are often undermined by systemic issues.
  • The conflict with Russia that started in 2014 leading to military, economic, and social destabilization. This conflict has strained Ukraine's resources and governance capabilities, posing obstacles to effective governance and reform efforts.
  • The volatile political landscape in Ukraine is characterized by frequent changes in leadership and political alliances that hamper consistent policy implementation and reform progress.
  • The ongoing conflict and systemic corruption and how they contribute to economic challenges, including reduced investor confidence, economic uncertainty, and financial strain on public institutions.
  • Ukraine's geopolitical position and how relations with neighboring countries and international allies, particularly with regard to Russia and the European Union, influence its ability to implement reforms and receive international support effectively.

Resources

  • Halyna Senyk on LinkedIn
  • Email: Halyna.Senyk@ceeli.eu
  • CEELI Institute (Central and Eastern European Law Initiative)
  • Michael Volkov onLinkedIn |Twitter
  • The Volkov Law Group

View Details

Bryn Sedlacek, Vice President and Product Manager at Aravo, joins us on the podcast to discuss third-party risk management focusing on holistic risks and unified visibility. In a wide-ranging discussion, Mike Volkov and Bryn Sedlacek discuss the challenges in implementing a third-party risk management program that captures holistic risks and maintains a consistent, unified line of sight across the organization's risk profile. They focus on sanctions, capturing the source and ultimate destination of products/services and including those in screening, leveraging how to handle conflict minerals as a model, and how data intelligence providers can help. Additionally, Bryn discusses unified visibility, which provides comprehensive visibility to executives and decision-makers across risk domains and performance. Finally, they discuss InfoSec risk with third parties, where to start, and the future of risk - technology and alternative risk strategies. Join Michael and Bryn as they navigate the complexities of compliance in today's corporate landscape.

  • Bryn discusses how crucial it is to start with a realistic approach to building a compliance program and continually improve compliance programs to mitigate risks effectively.
  • Having a platform like Arvao’s is valuable for companies as it is highly configurable and tailored to meet the unique needs of each client’s business structure and risk management requirements.
  • The partnership between IT and cyber security in a compliance program is vital for addressing cybersecurity risks effectively within organizations.
  • It is a growing trend for IT and cyber security to focus on collaboration and meeting the unique needs of each department.
  • Unified visibility across different risk domains and third-party activities is essential for making informed decisions and managing risks effectively.
  • Continuous monitoring and auditing are crucial in compliance programs, with a risk-based approach to optimize resources and ensure proactive risk management.
  • Sanctions compliance is a growing area of focus, requiring proactive monitoring, risk-based approaches, and continuous updates to mitigate risks effectively.

Resources

Bryn Sedlaceck on the Web

Email: bsedlacek@arvavo.com

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

In this episode of Corruption, Crime and Compliance, we delve into the complex world of sanctions compliance and enforcement. In this new era of aggressive sanctions enforcement, companies have to understand the red lines that define where criminal and civil enforcement risk increases. In contrast to the history of FCPA enforcement, DOJ and OFAC have provided helpful guidance to alert companies where risks are likely to increase. Join host Michael Volkov as he navigates the intricate landscape of voluntary disclosures, criminal and civil enforcement risks, and the evolving strategies of regulatory agencies like OFAC and the Department of Justice.

Hear Michael discuss:

  • Sanctions enforcement involves a mix of civil and criminal line drawing.
  • On the civil side, OFAC has explained that sanctions violations can be found based on strict liability with aggravating factors that turn the actor's state of mind.
  • Third-party liability for distributors extends to situations where a principal company knew or reasonably should have known that products sold to a third party were intended for shipment to a prohibited entity or individual or a prohibited country.
  • Third-party liability for violations occurring in a company's supply chain requires companies to break down its supply chain and learn the sourcing for all companies in its supply chain. It is clear that a failure to examine and assess your supply chain can lead to civil liability.
  • In defining where criminal enforcement picks up on the culpability spectrum, DOJ and OFAC have defined potential criminal conduct based on the term "willful," meaning when an actor knew that its conduct was wrong but did not necessarily know the specific law that her/she was violating.
  • Applying the "you know it when you see it" standard, companies have to weigh the evidence of surrounding circumstances to determine if an individual actor or actors possessed the requisite intent.
  • Criminal enforcement determination will turn on the attribution of individual conduct to a company based on respondeat superior principles -- that is, whether the conduct was committed in the course of an individual's duties and in furtherance of a legitimate business purpose.
  • Enforcement examples to track where the precise line falls between criminal and civil are few—a good start is by reviewing a meaningful record of DOJ enforcement actions against sanctions violations. The situation is akin to the early days of aggressive FCPA enforcement, where enforcement and settlement cases were reviewed for important precedents and explanations. DOJ's record here is about to be defined and companies, commentators and trade compliance professionals will be reading tea leaves and looking for patterns.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

LRN has issued another important report. In its latest report, The 2024 Benchmark of Ethical Culture Report, LRN has focused on the critical issue of corporate culture. LRN is a pacesetter and the leader in reliable studies on complex ethics and compliance issues. If not properly promoted or maintained, a defective culture can lead to serious misconduct, government investigation, reputational damage, and collateral harm. On the other hand, a positive and effective culture is a company's most valuable intangible asset, as it is tied directly to increased financial performance and sustainable growth. Over the past few years, business leaders have embraced what compliance and governance professionals already knew: companies with strong ethical cultures outperform other companies with weaker cultures. Employees at ethical companies are more productive, more satisfied, less likely to seek a new job, and more committed to the company's mission.

Hear Michael discuss:

  • LRN's 2024 Benchmark of Ethical Culture Report underscores the importance of ethical culture in driving financial performance and reducing misconduct rates.
  • Generation Z shows a higher tolerance for unethical conduct, with nearly a quarter admitting to engaging in such behavior to get the job done.
  • Hybrid workers who alternate between working from home and the office exhibit lower rates of misconduct and are more likely to report observed misconduct due to increased job satisfaction.
  • Organizations with strong ethical cultures outperform those with moderate to weak cultures by at least 50% across various business performance measures.
  • Employees at companies with strong ethical cultures are 1.5 times more likely to report observed misconduct, emphasizing the value of a positive work environment.
  • Senior leaders often have more favorable perceptions of their organization's culture than middle management and frontline workers, highlighting the need for consistent messaging.
  • LRN's research shows that nearly 70% of the variance in business performance is linked to an organization's ethical culture, emphasizing the critical role of culture in success.

Resources

LRN’s 2024 Benchmark of Ethical Culture Report

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Dottie Schindlinger is Executive Director of Diligent Institute, the global corporate governance research arm of Diligent - the largest SaaS software company in the Governance, Risk, Compliance (GRC), and ESG space. She co-authored the book Governance in the Digital Age: A Guide for the Modern Corporate Board Director, co-hosts “The Corporate Director Podcast,” and co-created Diligent Institute’s Certification programs for directors and executives, including AI Ethics & Board Oversight. Dottie was a founding team member of the tech start-up BoardEffect, acquired by Diligent in 2016. She graduated from the University of Pennsylvania and is a Fellow of the Salzburg Global Seminar Corporate Governance Forum. Diligent and Bitsight recently issued an important report on corporate board oversight of cybersecurity risks.

Dottie Schindlinger, Executive Director of Diligent Institute, joins Michael Volkov to discuss the important findings of Diligent's report.

You'll hear Dottie and Michael discuss:

  • Companies with advanced security ratings create nearly four times the amount of value for shareholders as companies with basic security ratings. On average, the Total Shareholders’ Return (TSR) over three and five years for companies in the advanced security performance range is approximately 372% and 91% higher, respectively, than their peers in the basic security performance range.
  • Companies with a specialized risk or audit committee had higher security performance ratings on average. Companies falling within these two categories have an average security rating of 710, whereas companies lacking both committees have an average security rating of 650.
  • The findings also suggest that the distribution of security ratings among companies with specialized risk and audit committees tends to skew towards the advanced security performance range, whereas companies lacking either of these committees tend to skew toward the basic security performance range.
  • Having a cybersecurity expert on the board is not enough. Integrating a cybersecurity expert into the board committee tasked with cybersecurity risk oversight makes a significant difference in an organization’s performance.
  • Merely having a cybersecurity expert on the board does not correlate to having a higher security performance rating. Highly regulated industries tend to outperform other industries in terms of cybersecurity performance.
  • Of the companies with advanced-level security performance ratings, a full third (33%) came from the financial services sector – with an average rating of 720. The sector with the highest average rating overall was healthcare at 730.
  • Nearly a quarter (24%) of companies with basic security performance ratings came from the industrial sector.

Resources

Dottie Schindlinger on LinkedIn

Diligent Institute | Diligent | Board Effect

The Report can be downloaded at: Cybersecurity, Audit and the Board Report

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

A new compliance cottage industry surrounds artificial intelligence. We are at such an early stage of AI development, and companies are still figuring out how they can employ the technology. However, some industries, such as financial institutions, have been using AI for fraud detection and other issues. These early adopters will likely set the tone for AI compliance practices. There is no question that AI holds terrific promise. The hype surrounding AI is just that -- hype. Until there is more certainty surrounding AI technology, we will witness a lot of bloviating. But this aside, corporate boards, senior executives, and business developers need to pay attention until the dust settles. The AI industry is moving so fast that the sooner we start to focus, the nimbler our response will be.

Luckily, ethics and compliance principles are easily adaptable to AI risks. In this episode of Corruption, Crime, and Compliance, Michael Volkov discusses how the compliance profession is more than capable of building effective compliance programs around AI operations.

  • Financial institutions have been using AI for fraud detection and other issues. They are at the forefront of developing compliance practices around AI.
  • Companies need to embrace AI's promise and not get overwhelmed by all the hype. Corporate boards, senior executives, and business developers must pay attention until the dust settles.
  • The AI industry is moving fast, and companies need to focus on what’s happening. Compliance has to be nimble and quick, just like the technology.
  • Like every aspect of a business, any new technology presents risks, and AI certainly presents risks that need to be mitigated. This, in turn, leads to the necessary question: How should a company structure its AI risk and compliance program?
  • AI can be a very productive tool. It can easily end up reducing costs and increasing efficiency. More efficient companies can help the economy expand and create new opportunities for growth.
  • Financial institutions, tech companies, pharmaceutical, medical device and transportation logistics industries are likely to be significant users of AI technology.
  • Generative AI use may increase the risk of fraud and will need to incorporate risk mitigation costs and capabilities.
  • Compliance professionals have the intelligence, professional capabilities, and integrity to rise to the challenge of AI technology and onboard a third party.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

With the beginning of the “New FCPA” era coined by DOJ’s Deputy Attorney General Lisa Monaco, we now need to focus on third-party risk and sanctions enforcement. The law, the practice, and the risks are important and not just the same as FCPA legal requirements. As we embark on a new criminal enforcement era surrounding sanctions violations, companies have to address this issue and do it correctly.

In this episode, Michael Volkov takes a comprehensive look at third-party risks from the distribution and supply sides and outlines appropriate strategies to manage these risks.

  • Epsilon Electronics serves as a stark reminder of the financial consequences of non-compliance. The company faced an OFAC enforcement action due to a shipment to Iran, resulting in a staggering penalty of over $4 million.
  • Apollo Aviation Group settled with OFAC for $210,600 for leasing aircraft engines which ultimately ended up being placed in to aircraft of a prohibited entity, Sudan Airways, violating sanctions regulations.
  • ELF Cosmetics settled with OFAC for $996,000 for importing false eyelash kits containing materials sourced from North Korea, highlighting supply chain due diligence failures.
  • The ELF Cosmetics case underscores the crucial role of supply chain due diligence in preventing sanctions violations. Instead of sticking their heads in the sand, companies must undertake basic supply chain due diligence when sourcing products from regions close to high-risk countries or regions.
  • “Reason to know” is now the key phrase guiding the New FCPA era. OFAC does not need to prove goods ultimately end up in a sanctioned country. When you see red flags, you must resolve them or they could be considered a “reason to know” in OFAC’s eyes.
  • Seven essential elements to boost your compliance program and effectively mitigate third-party sanctions risks include risk assessment, varying levels of due diligence, end-user documentation, monitoring, training, and red flag identification.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Carlos Villagrán is the Director of Compliance at CMPC, a 100-year-old Chilean-based holding company, one of the worldwide leading pulp, paper, packaging, personal care, and other forest products manufacturers. With more than 20,000 employees, CMPC has industrial operations in 9 countries (LatAm and the US) and commercial offices in the US, Europe, and China, selling and distributing its products to more than 45 countries around the world. Carlos joined CMPC to remediate and rebuild CMPC's culture and compliance program after a devastating scandal -- CMPC was prosecuted for its involvement in a decade-long conspiracy to fix prices in Peru and Chile for consumer paper products. Carlos discusses the challenges he faced in rebuilding CMPA's culture and commitment to compliance. His story is an inspiration to all legal and compliance professionals and provides important instructive lessons to corporate leaders and compliance professionals.

You'll hear Michael and Carlos discuss:

  • The importance of rebuilding and rediscovering the values and purpose of CMPC after a major corporate crisis.
  • The effects on market share quotas and sales prices when CMPC faced an investigation and found to be the leader of a cartel in Chile and Peru.
  • How the crisis significantly impacted CMPC's reputation, leading to public protests and consumer backlash in Chile and Peru.
  • CMPC’s compliance team addressed the company’s complex nature because of its diverse workforce, including data analytics experts, IT professionals, and engineers.
  • How the compliance program at CMPC shifted from a traditional approach to a more cultural and system-thinking perspective, aligning with the company's values and operations.
  • Success for the compliance program at CMPC is defined by the number of critical tables the team is seated on, indicating their value and integration within the business operations.

Resources

Carlos Villagran on the Web | LinkedIn

Email: carlos.villagran@cmpc.cl or cfvillagran@gmail.com

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Over the last ten years, we have seen a marked shift from the Delaware Chancery Court chipping away at corporate board member liability claims. In a number of seminal cases involving Boeing airplane crashes (In re the Boeing Co. Derivative Litig., No. 2019-0907 (Del. Ch. Sept 7, 2021)), and deadly listeria outbreaks from tainted ice cream (Marchand v. Barnhill, 212 A.3d 805 (Del. 2019)), Delaware Courts have upheld plaintiffs' cases against claims of failing to adequately plead violations of the standards set forth in Caremark, 698 A.2d 959 (Del. Ch. 1996), (establishing basic pleading requirements to withstand motions to dismiss).

In this episode, Mike Volkov provides a comprehensive update on the recent Caremark decisions issued by the Delaware Chancery Court, underscoring their importance for accountability and governance in the corporate world.

  • Caremark oversight duties stem from the well-established duty of loyalty and its subsidiary duty of good faith. To plead a Caremark claim, a plaintiff is required to put forth adequate facts from which a factfinder can make a reasonable inference that the fiduciary acted in bad faith.
  • Under Caremark, bad faith can be established when a fiduciary: “(1) utterly fail[s] to implement any reporting or information system or controls," or (2) having implemented such a system or controls, consciously fail to monitor or oversee its operations, which results in a failure to act or attend to a risk or problem requiring their attention or response.
  • Last year, the Chancery Court made a groundbreaking decision, extending the so-called Caremark oversight obligations and governance requirements to senior management in the McDonald's case. In re McDonald’s Corp. S’holder Derivative Litig., 289 A.3d 343 (Del. Ch. 2023). This ruling is one of the most significant developments in recent years, advocating for increased accountability for oversight and governance failures.
  • Recent cases, such as the Boeing 737 MAX crashes and the Listeria outbreak from tainted Blue Bell ice cream, have highlighted failures in proper board governance and oversight responsibilities.
  • In a case involving Segway, the Chancery Court dismissed a motion against an officer for failing to detect financial discrepancies, emphasizing the need to demonstrate a lack of good faith in monitoring central compliance risks.
  • The trend in Delaware Chancery Court decisions is moving towards holding directors and officers accountable for failures to act in response to indications of potential illegal conduct, with a focus on bad faith actions.
  • The Boeing case exemplifies the consequences of board members ignoring safety concerns and focusing solely on the bottom line, leading to tragic outcomes that could have been prevented with proper oversight and accountability.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Directive 2019/1937 of the European Parliament and Council dated 23 October 2019 on the “protection of persons who report breaches of Union law” (the “Directive”) is currently being implemented by EU Member States. The directive has broad applicability to organizations operating in the EU internal market and applies to both public and private sector organizations alike. Whistleblowers are guaranteed legal protection to the extent: (1) they have reasonable grounds to believe that the information reported was true at the time of the report; and (2) the whistleblower reported either internally to the organization, externally to a competent authority, or publicly. Private sector organizations with 50 or more workers are legally required to establish channels and procedures for internal reporting of EU law breaches and conduct appropriate follow-up.

In this episode, Mike Volkov is joined by Daniela Melendez and Alex Cotoia from the Volkov Law Group, who bring their expertise to the table as they delve into the EU Directive and its implementation by several member states. Listen to this discussion to understand and navigate the complexities of the EU Whistleblowing Directive.

  • The EU Whistleblower Directive shifts the burden of proof on retaliatory actions to the person taking the detrimental action, requiring them to demonstrate it was not linked to reporting concerns.
  • Global companies are taking a proactive stance by increasingly focusing on robust ethics and compliance programs. This strategic move is aimed at mitigating risks and promoting positive corporate citizenship in today's economy, where adherence to legal and ethical standards is paramount.
  • France signed the EU Directive into law on March 21, 2022, outlining protocols for gathering and handling whistleblower reports, including a two-month deadline for imposing disciplinary sanctions.
  • Germany enacted the EU Directive on May 12, 2023, allowing anonymous reports and setting a three-month investigation deadline after receiving the report.
  • Spain addressed the EU Directive on February 2023 by covering additional topics like occupational health and safety breaches. The directive established a three-month deadline for investigations and allowed anonymous reports.
  • Italy transposed the EU Directive on August 4, 2022, including administrative, financial, civil, and criminal offenses not covered by the Directive, with a 30-day deadline to conduct investigations upon receipt of reports.
  • Companies are advised to make resources available to conduct investigations quickly due to the short timeframes set by various countries' whistleblower protection laws.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Alex Cotoia on LinkedIn

Email: acotoia@volkovlaw.com

Daniela Melendez on LinkedIn

Email: dmelendez@volkovlaw.com

View Details

NAVEX continues to produce high-quality compliance reports, many of which are a must-read in the compliance industry. Its annual Whistleblower Report is of particular note -- NAVEX is the leading provider of hotline services in the world, and its data is invaluable as a source of trends in this industry. This year --2024 -- is no exception. NAVEX combed through the data from 3784 organizations for 2023. Its headline conclusion -- 2023 was a busy year, with a record level of use and the substantiation rate reaching an eleven-year high. More reports came in, and more were found to be true.

Listen in as Michael discusses the findings of these reports and why the increase is a good sign, not a bad sign. It means that employees trust their respective hotline reporting systems to produce results.

  • NAVX's 2024 Whistleblower Report revealed a record level of use and an 11-year high substantiation rate, indicating increased trust in employee reporting systems.
  • Accounting-related reports, comprising approximately 4.3% of all reports in 2023, had a significant impact. With a median substantiation rate of 50%, these reports often led to employment separation events, underscoring the seriousness of the issues raised.
  • Third-party reports were more likely to focus on business integrity and financial misconduct issues, accounting for 50% of reports compared to employees' 17%.
  • Reports of imminent threats had a high substantiation rate in 2023, with nearly 9 out of 10 reports proven to be substantiated, highlighting the seriousness of such issues.
  • Workplace civility complaints increased to 18% of reported cases, reflecting a growing concern within organizations about maintaining a respectful work environment and culture.
  • HR issues, a significant portion of all reports in 2023, accounted for 55% of the total. This underscores the importance of addressing internal workplace issues, such as workplace discord, discrimination, harassment, and retaliation, to maintain a healthy and productive work environment.
  • Clear Channel's extensive cooperation with the investigation, prompt sharing of facts, document production, and employee interviews demonstrated a commitment to transparency and accountability in addressing compliance issues.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

OFAC is capable of extending a long arm of enforcement, reaching sometimes non-U.S. companies that may "cause" another company to violate U.S. Sanctions laws. If you need to find an example of this long reach, look no further than OFAC's recent settlement with SCG Plastics ("SCG"). In this settlement, SCG, a Thai company that sells plastic resins, agreed to pay $20 million for violations of the Iran Sanctions Program.

In this episode, Michael Volkov explores the series of actions that led to that $20 million dollar settlement, and the consequences.

  • In a recent enforcement action, SCG Plastics paid OFAC $20 million to resolve violations of the Iran sanctions program, showcasing OFAC's far-reaching jurisdiction.
  • SCG Plastics caused U.S. financial institutions to process $291 million in wire transfer sales of High-Density Polyethylene Resin (HDPE) of Iranian origin from 2017 to 2018, which violated the Iran sanctions program.
  • SCG Plastics voluntarily disclosed 10 violations but did not disclose 457, which led to OFAC determining all 467 violations as egregious.
  • The size of the settlement was due to multiple aggravating factors: SCG Plastics willingly engaged in a multi-year pattern of conduct designed to circumvent the Iran sanctions program, causing significant harm to OFAC sanction policy objectives while earning substantial revenues.
  • Importantly, commercial activity that may fall outside the jurisdiction of OFAC sanctions can still result in a violation when the financial transactions related to the activity are processed through or involve U.S. financial institutions.
  • OFAC emphasized the risks for non-U.S. companies engaging in conduct that causes U.S. persons to violate sanctions, in this case processing the transactions, which would not have been done with adequate disclosure, highlighting the importance of compliance with U.S. sanctions and export control laws.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

LRN continues to set the standard for ethics and compliance program research. Volkov Law is a supporter of, and advocate for, LRN’s research because it has consistently confirmed what we all know and believe - ethical companies perform better in the marketplace over the long run. It is an intuitive fact that employees respond better to values-based leadership than a rules-based environment and culture. Volkov Law is committed to that mission with our clients, colleagues, partners, and thought leadership.

In this Episode Michael Volkov discusses LRN's latest PEI Report, a copy of which can be obtained at https://lrn.com/resources/ethics-compliance-program-effectiveness-report

  • LRN's 2024 Program Effectiveness Report highlights the importance of corporate values, culture, and accountability in mitigating risks and maximizing financial performance.
  • The report is based on a survey of over 1,400 ethics and compliance professionals from 19 countries and 26 industries.
  • 60% of organizations now incorporate ethical behavior into performance management, hiring decisions, promotions, and bonuses to elevate ethical conduct incentives.
  • Top priorities for 2024 include training content, measuring ethical culture, improving web-based compliance resources, internal controls, and audit and compliance monitoring plans.
  • Companies are adapting compliance programs to include remote and hybrid employees post-COVID-19, reflecting changing workplace needs.
  • Senior management engagement in risk mitigation controls and company values is crucial, with 52% of respondents confirming actions over words in fulfilling ethics and compliance responsibilities.
  • Nearly two-thirds of respondents stated their boards actively address misconduct by senior executives or excellent performers, relying on values to ensure ethical behavior.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

On the heels of the Gunvor FCPA settlement for $661 million, DOJ announced its settlement with Trafigura, the latest commodities trading company to fall under DOJ's FCPA Sweep against the industry. Trafigura joined the list of international commodity trading companies to suffer FCPA enforcement actions like Vitol, Sargeant Marine, Glencore, Freepoint, and Gunvor.

DOJ's corporate resolutions are connected to individual prosecutions and guilty pleas of 19 individuals, including six government officials, eight corrupt intermediaries, and five trading companies.

Trafigura Beheer B.V. ("Trafigura"), based in Switzerland, plead guilty and agreed to pay $126 million as part of a plea agreement to resolve FCPA violations in Brazil. Trafigura pleaded guilty to conspiracy to violate the anti-bribery provisions of the FCPA and agreed to pay a fine of over $80 million and forfeiture of $46 million. DOJ agreed to credit up to $26 million of the fine against the amounts Trafigura pays to resolve an ongoing Brazil investigation.

  • Trafigura, a global commodity trading company, pled guilty and agreed to pay $126 million to resolve FCPA violations in Brazil, involving a corrupt scheme to pay bribes to Brazilian officials to secure business with Petrobras.
  • DOJ cited Trafigura's cooperation and acceptance of responsibility, including providing timely updates, facilitating employee interviews, and producing relevant documents, but criticized their failure to preserve and produce certain evidence in a timely manner.
  • Trafigura's bribery scheme involved paying bribes to Petrobras officials from 2003 to 2014 to obtain and retain business, with payments ranging from 5 to 20 cents per barrel for oil transactions.
  • The bribery payments were facilitated through offshore bank accounts, U.S. banks, and coded language in emails, with Trafigura entities earning approximately $51 million in profits from the scheme.
  • DOJ's successful sweep of the commodities trading industry resulted in six corporate resolutions and 20 individual convictions, totaling over $1.7 billion in penalties, emphasizing the importance of robust compliance and surveillance strategies.
  • Trafigura's lack of compliance oversight and failure to maintain proper third-party due diligence or risk management programs allowed the bribery scheme to operate with impunity, highlighting the need for enhanced controls and monitoring in high-risk industries.
  • Despite the challenges faced during the investigation, Trafigura's guilty plea and cooperation with DOJ demonstrate a commitment to addressing corruption and compliance issues in the global commodity trading sector.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

In a recent speech on March 7, 2024, Deputy Attorney General Monaco announced that, in the next 90 days, DOJ would implement a new whistleblower program to reward reporting of criminal misconduct at public and private companies. In particular, DOJ will encourage reporting of potential violations of the Foreign Corrupt Practices Act ("FCPA") and the recently enacted Foreign Extortion Prevention Act ("FEPA"). AAG Monaco noted that DOJ will be particularly interested in "foreign corruption cases" involving "non-issuers and violations of the recently enacted FEPA," along with criminal abuses of the United States financial system and domestic corruption cases.

DAG Monaco also reiterated the importance of voluntary self-disclosures. DOJ employs a "mix of carrots and sticks" to incentivize companies to build stronger compliance programs that proactively mitigate risks and disclose misconduct to DOJ when appropriate. DAG Monaco underscored the fact that a corporate resolution "will always be more favorable with voluntary self-disclosure."

In this episode, Michael Volkov discusses DOJ's new initiatives on whistleblowing and encouraging voluntary self-disclosures.

  • DOJ's planned whistleblower program will significantly impact individual incentives to report financial misconduct and corporate decisions regarding voluntary self-disclosures.
  • The program's focus extends beyond FCPA violations, encompassing other significant financial abuse schemes and potential reporting against non-issuer companies.
  • Global companies are facing unprecedented risks and challenges in today's economy, leading them to prioritize robust ethics and compliance programs to promote positive corporate citizenship.
  • The SEC whistleblower program has been successful, resulting in serious prosecutions and the derailment of fraudulent schemes. However, only around 10% of reports involve FCPA anti-bribery allegations.
  • The Department of Justice recently announced its plan to create a whistleblower bounty program, which would fill gaps in existing programs and coordinate with voluntary self-disclosure policies.
  • DOJ's whistleblower program will reward reporting of criminal misconduct at both public and private companies, encouraging reporting of potential violations of the FCPA and the Foreign Extortion Prevention Act.
  • Companies are urged to disclose misconduct to earn valuable benefits, and the DOJ emphasizes the benefits of voluntary self-disclosure and cooperation to mitigate risks and maximize financial performance.

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Boeing continues to struggle with its core business activities. As troubles mount for Boeing, it is clear that it continues to suffer from real and pervasive culture issues that have been reflected in serious safety failures, financial difficulties, regulatory violations, and serious reputational damage. Boeing's troubles permeate every part of its organization -- from the board to senior executives to its operations and overall ethics and compliance commitment. As a result, Boeing stands at an important crossroads -- will it make a real commitment to change, reform, and ethics and compliance, or will it continue to limp along, suffering repeated incidents of harm?

In its latest (mis)adventure, Boeing fell victim to a State Department fine for $51 million for violations of a number of export controls, including basic licensing requirements for exports to China and Russia. Boeing voluntarily disclosed the violations to the Directorate of Defense Trade Controls ("DDTC") in the State Department.

The violations of the International Traffic in Arms Regulations ("ITAR") included illegal exports to foreign employees and contractors who work in more than 15 countries, a trade compliance specialist fabricating an export license to illegally ship defense items abroad, and violations of the terms and conditions of other export licenses, among other things.

The DDTC's $51 million penalty is the largest administrative penalty imposed for ITAR violations since it imposed a $79 million penalty against BAE Systems in 2011. Under the terms of the settlement, Boeing must pay $27 million to the DDTC within two years and use the remaining $24 million to improve its compliance program and procedures. In addition, Boeing is required to hire a DDTC-approved special compliance officer to oversee its compliance with ITAR for the next three years. That officer will regularly report to the DDTC on Boeing’s progress.

  • Boeing faced a $51 million settlement for ITAR violations, including unauthorized exports and re-transfers to foreign employees and contractors, notably in China.
  • Violations involved illegal downloads of ITAR-controlled technical data from Boeing's digital repository, which affected Pentagon platforms like the F-18, F-15, and F-22 aircraft and the AH-64 Apache helicopter.
  • Boeing voluntarily disclosed violations to the Directorate of Defense Trade Controls (DDTC) and the State Department, leading to the $51 million penalty, the largest for ITAR violations since 2011.
  • The settlement requires Boeing to pay the DDTC $27 million, improve its compliance program with the remaining $24 million, and hire a DDTC-approved special compliance officer for three years.
  • Boeing must introduce a new automated export compliance system, update the State Department on its progress every six months, and undergo two export control audits by State Department-approved consultants.
  • Despite the violations occurring mostly before 2020, Boeing made significant improvements to its trade compliance program, investigated issues, cooperated with authorities, and expressed regret.
  • The case highlights the State Department and DDTC's aggressive enforcement of administrative controls over military items, signaling a broader crackdown on export control and sanctions violations.

Resources:

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

You have to give the Justice Department credit - after two slow enforcement years, DOJ is starting off 2024 with a relative "bang;" first, DOJ reached a large settlement with SAP in January, and now, DOJ has reached a blockbuster settlement with Gunvor S.A. for $661 million. Gunvor is one of the world's largest commodities trading companies. DOJ's settlement represents a "return" to its long-standing aggressive approach to FCPA enforcement. DOJ did not permit Gunvor to enter into a deferred or non-prosecution agreement. Instead, DOJ required Gunvor to plead guilty to one count of FCPA conspiracy. Following the plea agreement, the court sentenced Gunvor to pay a criminal monetary penalty of $374,560,071 and to forfeit $287,138,444 in ill-gotten gains. The sentence includes credits of up to one-quarter of the criminal fine each for amounts Gunvor pays to resolve investigations by Swiss and Ecuadorean authorities into the same misconduct so long as the payments are made within one year. The Office of the Attorney General of Switzerland simultaneously announced a parallel resolution of its investigation into Gunvor’s misconduct that involved the payment of approximately $98 million by Gunvor to Swiss authorities. Gunvor's conduct stretched over nearly a decade and involved systemic bribery payments to officials of the Ecuadorian Ministry of Hydrocarbons and Petroecuador, the Ecuadorian state-owned oil company, in exchange for valuable contracts to acquire oil products. In total, Gunvor earned more than $384 million in profits from the business it corruptly obtained related to Petroecuador. In this episode, Michael Volkov reviews the Gunvor FCPA settlement.

  • Gunvor's recent $661 million FCPA settlement with DOJ for bribery in Ecuador signifies a return to aggressive enforcement. The plea agreement and forfeiture highlight the consequences of anti-corruption violations for global companies.
  • Prior individual enforcement actions preceded Gunvor's corporate resolution, showcasing a pattern in FCPA cases. The company's cooperation, including document production and internal investigation, played a crucial role in the resolution.
  • Gunvor's implementation of remedial measures post-bribery scheme reflects a commitment to compliance. Enhancements to ethics programs and controls demonstrate a proactive approach to mitigating risks and ensuring regulatory compliance.
  • The bribery scheme involving corrupt third parties and shell companies underscores the importance of robust monitoring and due diligence. Gunvor's delayed response to red flags highlights the need for swift action in high-risk activities.
  • Gunvor's cooperation with the investigation, including sharing facts and facilitating interviews, showcases a commitment to transparency and accountability. Collaboration with authorities is essential in resolving compliance issues and maintaining credibility.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Whatever the cause, criminal sanctions enforcement will be an interesting area in 2024. The DOJ's planned aggressive push against companies and individuals for sanctions violations is about to be unleashed. There is no question that DOJ's enforcement initiative is coming—it is just a question of when.

We have already seen several examples of what aggressive sanctions enforcement will look like -- as the new "FCPA," we can expect several standard elements:

  • Large Penalties -- multi hundreds of millions, even reaching billions in more egregious cases.
  • Reward for Voluntary Disclosures
  • Criminal Indictments, Deferred or Non-Prosecution Agreements
  • Independent Compliance Monitors
  • Parallel Regulatory Resolutions with OFAC, BIS, and or DDTC
  • Enhanced Compliance Remediation Requirements
  • Individual Criminal Enforcement

In this episode, Michael Volkov reviews the soon-to-arrive sanctions enforcement regime, and steps companies should take to protect against enforcement actions. Hear him discuss:

  • The Department of Justice (DOJ) is signaling a shift towards aggressive corporate sanctions and export control enforcement, particularly focusing on national security issues like sanctions and export controls.
  • Recent cases, such as the British-American Tobacco and SAP cases, serve as examples of how the DOJ's sanctions-focused enforcement strategy is likely to unfold, including potential penalties and consequences that companies may face.
  • Companies are facing risks from various sources in the realm of sanctions and export control enforcement, including regulatory referrals from agencies like OFAC, BIS, and DDTC, as well as international intelligence relationships and whistleblowers.
  • Seagate's blatant violation of Huawei export controls could be a significant indicator of the DOJ's enforcement initiative in the sanctions arena. This case demonstrates the potential consequences of willful violations and the importance of compliance with export control regulations.
  • Common deficiencies in sanctions compliance programs, including corporate boards' lack of understanding, failure to address third-party risks, inadequate supply chain audits, weak internal controls, and insufficient training, highlight areas where companies need to improve to ensure compliance with sanctions regulations.

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Companies have a vested interest in preserving internal communications for a variety of reasons -- to hold actors accountable and to protect the organization from potential private and government claims or investigations that may have serious direct or collateral consequences. Companies that want to use ephemeral messaging systems can do so, but they have to understand the risks involved and tailor appropriate controls and procedures to avoid potential damage.

DOJ's Evaluation of Corporate Compliance Programs ("ECCP") released in March 2023 authorized companies to use ephemeral messaging but emphasized several important risk considerations and controls needed to preserve robust record-keeping requirements. DOJ's ECCP identifies three significant areas for consideration: employee use of personal devices, availability of communications platforms (e.g., Jabber, Slack, Teams, Google, Zoom), and messaging applications, including ephemeral messaging. DOJ's ECCP noted that a company's policies governing messaging applications "should be tailored to the corporation's risk profile and specific business needs and ensure that, as appropriate and to the greatest extent possible, business-related electronic data and communications are accessible and amenable to preservation by the company.")

In this podcast, Michael Volkov and Eddie Green, CEO of SnippetSentry, discuss current communications preservation requirements and technical solutions to meet them.

You’ll hear them discuss:

  • Companies are rapidly embracing and elevating the importance of robust ethics and compliance programs to promote positive corporate citizenship. This shift reflects a growing awareness of the significance of ethical practices in today's business landscape.
  • Eddie discusses the significance of preserving communications data in today's business landscape, given the evolving nature of communication technologies and the need for proactive data preservation strategies.
  • SnippetSentry's service allows users to seamlessly connect their phones to ensure all texts are archived without altering their day-to-day operations, allowing integration of compliance measures seamlessly into existing workflows.
  • The evolution of email preservation serves as a blueprint for understanding the importance of preserving text messages in modern business communication. Reflecting on past practices can provide valuable lessons for adapting to the changing landscape of communication data preservation.
  • Compliance mandates, such as those set by the SEC, emphasize the necessity of preserving text records to ensure regulatory adherence and mitigate risks, underscoring the critical role of data preservation in maintaining transparency and accountability in business operations.
  • The collaboration between compliance, IT, and information security professionals is crucial in developing policies and procedures to safeguard data and mitigate communication risks.
  • Financial institutions and other industries are increasingly adopting sophisticated data preservation strategies to protect intellectual property and ensure regulatory compliance. This proactive stance reflects a growing recognition of the importance of data security and compliance in safeguarding business interests.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Eddie Green on LinkedIn | SnippetSentry

View Details

In this special episode of Corruption, Crime, and Compliance, Michael Volkov joins colleague and long-time friend Tom Fox as they delve into the intricacies of recent FCPA enforcement actions, shedding light on the evolving landscape of corporate compliance. From the ABB case to the SAP settlement, Michael and Tom dissect the nuances of voluntary disclosure, extensive remediation, and the shifting priorities of the Department of Justice. Join them as they navigate the complexities of recidivism, cooperation, and the pivotal role of self-disclosure in today's compliance environment.

You’ll hear them discuss:

  • The Department of Justice (DOJ) faced a challenging situation with ABB, a three-time FCPA recidivist, raising questions about their enforcement actions and policies.
  • ABB's case highlighted the importance of voluntary disclosure, extensive cooperation, and remediation in mitigating penalties and demonstrating commitment to compliance.
  • The shift in DOJ's approach towards recidivism and self-disclosure signaled a new emphasis on data-driven compliance and the use of evidence to support remediation efforts.
  • Albemarle and SAP cases showcased the significance of data-driven compliance programs and proactive measures to address compliance deficiencies.
  • DOJ's focus on self-disclosure as a key factor in enforcement actions underscores the importance of transparency, cooperation, and timely reporting in compliance efforts.
  • The evolution of DOJ's policies and enforcement strategies in 2023 reflected a balance between tough enforcement on recidivism and incentivizing self-disclosure through reduced penalties.
  • The role of voluntary disclosure, remediation, and cooperation is critical in navigating FCPA enforcement actions and achieving favorable outcomes with the DOJ.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Tom Fox on LinkedIn

Compliance Podcast Network

View Details

Christian Focacci is a leader in the artificial intelligence world and harnesses the capabilities for risk management. He is the founder and CEO of Threat.Digital, which has launched a new product DiligenAI. Threat.Digital is leveraging large language models and real-time data feeds to empower organizations to identify risk information confidently and efficiently, setting a new standard in risk intelligence. Mike and Christian discuss AI and its use in compliance third-party risk management.

You'll hear them discuss:

  • AI should be viewed as a tool to enhance decision-making processes rather than a replacement for human judgment. It highlights the importance of leveraging AI to process vast amounts of data efficiently.
  • Organizations must strike a balance between recognizing the risks associated with AI, such as generative AI, and harnessing its potential benefits to improve productivity and decision-making within organizations.
  • Advancements in language models, particularly large language models like Chat GPT, have revolutionized the processing and understanding of unstructured text data, enabling more accurate and context-aware analysis.
  • Companies can use AI to significantly enhance due diligence processes, risk assessment, and compliance efforts by efficiently summarizing and analyzing vast amounts of information to support decision-making.
  • The use of AI in due diligence and compliance is a tool meant to empower human decision-makers by providing them with comprehensive and distilled information, allowing them to focus on critical analysis and decision-making rather than mundane tasks.
  • One major strength of AI, particularly large language models, is to improve monitoring processes by reducing false positives and providing real-time alerts based on predefined criteria, enabling more efficient risk identification and management.
  • AI has a bright future, including the expansion of context windows in language models, the rise of open-source models, and the potential for running AI models on personal devices, indicating a shift towards decentralized and accessible AI technology.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Christian Focacci on LinkedIn | Threat.Digital

View Details

On December 31, 2021, President Joseph R. Biden, Jr. signed the the Uyghur Forced Labor Prevention Act (“UFLPA”) into law to address the ongoing exploitation of the ethnic minority Uyghur population by the government of the People’s Republic of China (“PRC”). Among other things, the UFLPA creates a rebuttable presumption that all goods, wares, articles, and merchandise mined, produced, or manufactured wholly or in part in Xinjiang, or by entities designated for inclusion on the UFLPA Entity List, are prohibited from entry into the United States. To overcome the presumption, entities are required to demonstrate, by “clear and convincing evidence,” that such imports were not mined, produced, or manufactured in whole or in part by forced labor.

In this episode, Mike and Alex discuss practical steps to comply with the UFLPA.

  • The Uyghur Forced Labor Prevention Act, enacted by Congress, establishes a presumption that goods from Xinjiang are tied to forced labor. Importers must prove otherwise by providing extensive documentation, such as invoices, packing slips, and billing information, to demonstrate the origin of the goods and ensure compliance with the law.
  • The UFLPA has led to a significant increase in enforcement by CBP, resulting in the detention of billions of dollars worth of commodities. This heightened scrutiny has prompted global companies to prioritize robust ethics and compliance programs to mitigate legal and economic risks associated with forced labor.
  • Compliance with the UFLPA requires importers of record to furnish CBP with clear and convincing evidence that their goods were not produced using forced labor. This evidence includes supply chain tracing information, wage and payment records, credible audits, and attestations from every entity involved in the production process.
  • Chinese entities have been known to employ deceptive practices to avoid detection and documentation requirements. This includes creating separate companies outside the Uyghur area and providing misleading information to purchasers. Due diligence and thorough investigation of beneficial ownership are crucial to ensure compliance.
  • CBP's operational guidance for importers, published in 2022, provides essential information on navigating the complexities of the UFLPA. Importers should familiarize themselves with this guidance and engage in one-on-one discussions with their suppliers to communicate expectations and ensure compliance.
  • The UFLPA places a significant burden on organizations relying on imports from China, as they must provide extensive documentation and meet the clear and convincing evidence standard. Failure to meet these requirements can result in the detention of goods, leading to supply chain disruptions and potential financial losses.
  • Clear Channel, the former Chinese subsidiary of Clear Media, faced charges related to bribery violations. The bribes included expensive gifts, entertainment, and travel given to influence contract renewal negotiations with Chinese government officials. Clear Media engaged in deceptive practices, including falsifying payments and creating false invoices, to fund these illegal payments.

Resources

Alex Cotoia on LinkedIn | Email

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Gabrielle Griffith, Director BPE Global, is an expert in trade compliance issues. Gabrielle assists clients in implementing effective trade compliance programs by addressing improvements within organizations’ people, processes, and systems. In the area of U.S. export controls, she advises clients on compliance with the International Traffic in Arms Regulations, the U.S. Export Administration Regulations, and the various embargo and sanctions programs administered by the Office of Foreign Asset Controls. On import compliance matters, she advises on classification, country of origin, special duty programs such as USMCA, focused assessments, C-TPAT, antidumping/countervailing duty as well as Section 232 and 301 matters. Gabrielle joins Michael to discuss current trade compliance trends and expectations for 2024.

  • The increase in national security risk has heightened the need for creative thinking to identify potential threats that may not be designated within regulations. This means that companies must go beyond traditional compliance measures and think outside the box to proactively address emerging risks to national security.
  • Global companies are facing unprecedented risks and challenges in today's economy, leading to a greater emphasis on robust ethics and compliance programs. These programs are essential for promoting positive corporate citizenship and mitigating legal and economic risks associated with corruption and crime.
  • Trade compliance is no longer a silo within a compliance department but must be integrated into the entire operation of a company. This means that trade compliance considerations should be incorporated into all aspects of a company's business processes, from product development to supply chain management.
  • The Department of Justice is ramping up efforts to prosecute companies for trade compliance violations, particularly in relation to national security. This increased focus on enforcement means that companies need to be proactive in ensuring compliance with export control regulations and other trade compliance requirements.
  • Over-controlling trade compliance can hinder business operations while under-controlling can lead to violations. Finding the right balance is crucial. Companies should strive to implement effective trade compliance measures that align with their specific business needs, avoiding unnecessary restrictions while still ensuring compliance with applicable regulations.
  • The government should collaborate more with industry consultants to bridge the gap between enforcement agencies and companies, ensuring effective communication and guidance. This collaboration can help companies navigate the complex landscape of trade compliance and provide valuable insights to regulators on emerging technologies and industry practices.

Resources

Michael Volkov onLinkedIn |X(Twitter)

The Volkov Law Group

Gabrielle Griffith on LinkedIn

BPE Global

View Details

The Justice Department and the Office of Foreign Assets Control had a big year in 2023. Criminal and civil enforcement continue to increase. The DOJ has warned corporations that aggressive sanctions enforcement actions are coming -- to that end, the DOJ assigned 25 new prosecutors to the National Security Division to execute on its promise. Meanwhile, OFAC had a record year in collecting $1.539 billion in penalties, largely the result of two blockbuster settlements -- British American Tobacco and Binance, the cryptocurrency exchange.

  • It's important for companies to ensure they have U.S. expertise to effectively address potential violations of U.S. sanctions laws, as unfamiliarity with these laws can hinder prompt identification and response. Having a strong compliance program based in the United States is a valuable lesson learned from OFAC.
  • Global companies are facing unprecedented risks and challenges in today's economy, leading them to prioritize robust ethics and compliance programs. These programs play a crucial role in promoting positive corporate citizenship and mitigating legal and economic risks.
  • In 2023, there was a significant increase in sanctions enforcement by the DOJ and OFAC, with plans for even more aggressive actions in the future. With 17 enforcement cases and $1.5 billion in penalties, it is evident that compliance areas such as third parties and internal controls are of utmost importance.
  • Various countries, including Russia, Cuba, and Iran, continue to be the focus of global sanction schemes. While Venezuela's sanctions were temporarily relaxed, companies must stay vigilant and monitor the upcoming election. The British American Tobacco case, with its $629 million settlement, serves as a model for future enforcement actions.
  • The Binance case, involving a $4.3 billion settlement, shed light on criminal violations in the cryptocurrency industry. This highlights the critical importance of compliance in this rapidly evolving sector.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

For the Justice Department and the SEC, 2023 was a slow year in FCPA enforcement. Despite promises of aggressive enforcement, DOJ and the SEC failed to achieve increases in FCPA enforcement. DOJ and the SEC issued no blockbuster enforcement actions or settlements. The SEC's number of enforcement actions was steady and eclipsed its 2022 number by one. Equally significant was DOJ's reduction in individual criminal prosecutions, thereby raising legitimate questions as to its ability to deliver on its promise of aggressive enforcement against individual FCPA violators. Despite a slower enforcement year, DOJ dedicated significant resources to issuance of new policy statements encouraging voluntary disclosures, incentivizing clawbacks, elevating compliance programs and offering new safe harbors for mergers and acquisitions.

In this episode, Michael Volkov reviews FCPA enforcement in 2023 and outlines new compliance trends in the anti-corruption field.

  • Clear Channel's former Chinese subsidiary, Clear Media, was charged with bribery violations involving expensive gifts, entertainment, and travel given to influence contract renewal negotiations with Chinese government officials.
  • Clear Media engaged in deceptive practices, such as falsely documenting payments to cleaning and maintenance companies to fund illegal payments. They used oral agreements, omitted gift recipients, and created false invoices and tax records to disguise payments through shell company intermediaries.
  • Senior executive complicity was another trend observed in the cases discussed. In some instances, senior executives were aware of the bribery schemes but either turned a blind eye or actively participated in the misconduct.
  • Internal audits conducted from 2012 to 2017 identified deficiencies, red flags, and indicators of bribery within Clear Channel. However, the company failed to take aggressive remedial actions to address these issues.
  • Clear Media resisted internal auditors and even provided false information, hindering the detection and resolution of bribery-related problems.
  • Despite these challenges, Clear Channel cooperated extensively with the investigation. They promptly shared relevant facts, produced necessary documents, and facilitated interviews with current and former employees.

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

View Details

Bribery is rampant in many countries around the world, and in this episode of Corruption, Crime, and Compliance, we take a look at a recent FCPA case involving SAP, a global software company. SAP’s violations spanned multiple countries, including South Africa and Indonesia, and resulted in prosecution and a hefty $220 million dollar penalty. However, many people were baffled with the resolution of this case. The DOJ lacked aggressiveness and failed to impose an independent compliance monitor. Join the host, Michael Volkov, as he analyzes the intricacies of this case and the implications for FCPA enforcement in the coming years.

  • The SAP is a recidivist company, but DOJ’s enforcement action against them did not seem to take that into account when holding them accountable for instances of bribery that spanned the globe.
  • As the DOJ seemed to take a step back, the SEC made an aggressive push to hold companies accountable for violating internal controls, which is what happened in the SAP case.
  • SAP's repeated failure to follow internal control requirements governing third parties serves as a cautionary tale for companies to ensure that their procedures are not only in place but also actively implemented and monitored.
  • Clear Channel's former Chinese subsidiary, Clear Media, engaged in deceptive practices to fund illegal payments, including creating false invoices and tax records, but even after internal audits, Clear Channel failed to take aggressive remedial actions.
  • Clear Channel demonstrated a clear commitment to addressing the issues in the investigation that followed, highlighting the importance of cooperation, as it can lead to more favorable outcomes and potentially mitigate the severity of penalties imposed.

KEY QUOTES

"DOJ is turning its focus and pulling back on FCPA enforcement." - Michael Volkov

"The SAP resolution, which totals only $220 million, was far below the amount that a recidivist should have paid for its global bribery operations stretching into multiple countries." - Michael Volkov

"The SEC's approach demonstrates a more aggressive application of internal control enforcement." - Michael Volkov

"If a company is going to craft these internal controls, the company has to enforce those controls or face serious enforcement risks." - Speaker: Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

How do you manage risk when the vulnerabilities are outside your organization’t in your hands? In this episode of Corruption, Crime, and Compliance, we delve into the world of third-party risk management with our guest, Natalie Druckmann, from Certa. As we discuss the regulatory landscape in EMEA and the US, Natalie highlights the higher regulatory burden faced by companies in EMEA, and how Certa uses AI to streamline workflows, provide intuitive data visualization, and enhance risk forecasting capabilities. AI is the future of third-party risk management, now and in the future.



  • Cybersecurity has become one of the top concerns for organizations. In 2012, Target worked with a third-party vendor and, as a result, suffered an attack that exposed their customers’ credit data. Since then, compliance departments have started working closely with IT to prevent such vulnerabilities.
  • Unlike the US, EU companies don’t benefit from gaps created between state and federal regulations. EMEA faces a mandatory and substantial regulatory burden, particularly in areas like ESG and compliance. A forced labor scandal can sink a company, so ESG’s importance is on par with cyber security.
  • Global companies are increasingly recognizing the importance of addressing ESG topics alongside cybersecurity and financial risks. ESG considerations, such as diversity, modern slavery, and gender pay gaps, have significant reputational and revenue impacts.
  • AI is changing the world in many ways, including compliance. Certa aims to provide a comprehensive solution for third-party risk management, compliance, and operational risks by streamlining processes and incorporating AI capabilities to enhance efficiency and effectiveness.
  • Certa utilizes various AI capabilities, including design AI, which allows users to create workflows using plain language. They don’t need to know anything about tech; they can simply dictate the process, and AI generates the necessary code and infrastructure for it. This allows the company to remain flexible and able to quickly adapt to change.
  • Insights AI is another capability that collects and analyzes data, making it far more accessible and efficient in managing up-to-the-minute risks and developments. This technology also uses design AI, allowing for plain language inputs to immediately create actionable, detailed reports.
  • Recall AI allows companies to guarantee rapid and consistent responses from suppliers and customers by recalling past interactions to create surveys, forms, workflows, and processes. This removes the back-and-forth burden on all parties while still retaining the human touch.
  • Smaller and midsize companies should prioritize their risk management processes and consider automated solutions like Certa. These companies can benefit from the efficiency and effectiveness of an automated platform, regardless of their industry or size.

KEY QUOTE

“I think there is a very strong drive here for companies and stakeholders, not just to do the right thing… but doing the good thing as well.” - Natalie Druckman

Resources

Michael Volkov onLinkedIn |Twitter

The Volkov Law Group

Natalie Druckman on LinkedIn

Certa

Email Natalie: nat@certa.ai

View Details

In this week's episode of Corruption, Crime, and Compliance, we usher in the New Year with a deep dive into something that happened in November of last year. As we begin 2024, it's crucial to reflect on the substantial shifts in the healthcare industry's compliance framework. The HHS Office of Inspector General's Comprehensive Compliance Guidance, released late last year, has set a new standard for healthcare companies, reinforcing the importance of an independent compliance function and outlining a robust framework for effective compliance programs. Michael Volkov meticulously dissects the seven key elements of this groundbreaking guidance, emphasizing its relevance not just in healthcare, but across the spectrum of compliance practices.

You’ll hear Micheal discuss:

  • The HHS Office of Inspector General issued the Comprehensive Compliance Guidance (GCPG) in November 2023, a significant document for the healthcare industry, emphasizing the need for independent and robust compliance programs.
  • The guidance is structured around seven core elements: written policies and procedures, effective compliance leadership, training, open lines of communication, enforcing standards, risk assessment, and responsive corrective action for detected offenses.
  • The role of a Chief Compliance Officer is critical, and they should:
  • Report directly to the CEO or have independent access to the board,
  • Have sufficient stature within the entity equal to other leaders,
  • Demonstrate unimpeachable integrity, judgment, assertiveness and approachable demeanor, and
  • Have sufficient funding, resources and staff to operate the program.
  • Emphasizing the separation of legal and compliance functions, the GCPG recommends that compliance officers focus solely on compliance, avoiding roles in legal or financial departments.
  • The GCPG advises the establishment of a compliance committee, meeting quarterly, with responsibilities spanning legal regulation analysis, policy review, training effectiveness, and annual risk assessment.
  • The CEO should include a signed introduction in the code of conduct. The board should include a signed endorsement or similar written statement to support the compliance commitment, and entities should review their codes when a new CEO is hired.
  • Clear communication and board oversight is crucial, and they should be well-informed about compliance programs, and ensure that the compliance officer has sufficient access to them.
  • How compliance officers and boards should respond when compliance concerns are reported or discovered, and focus on the root causes of the misconduct to prevent recurrence.

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

What is the cost of ignoring compliance? For the world’s largest cryptocurrency exchange, it’s $4.3 billion dollars. In this episode of Corruption, Crime and Compliance, Michael Volkov and his guest, Matt Stankiewicz, delve into one of the most significant financial crime prosecutions in the history of the Justice Department: Binance Holdings. Under the direction of its CEO, Changpeng Zhao, Binance blatantly disregarded compliance, had no AML programs, and willfully put growth over regulations. Now, they must pay out a settlement split among various agencies, including the DOJ, OFAC, FinCEN, and CFTC. In addition to the settlement, Binance has destroyed their reputation at a time when customers are demanding companies they can trust.

Matt Stankiewicz is a compliance consultant, and currently a partner at The Volkov Law Group, specializing in anti-bribery, corruptions controls, and compliance programs. He previously served as a member of the Ethics and Compliance Monitoring Team, appointed by the DOJ and EPA, and his casework has included global audits of Fortune 100 companies, sanction violations investigations, risk-assessment for third party distributors, and much more.

You’ll hear Michael and Matt discuss:

  • Cryptocurrency companies allow customers to exchange government-backed currency for cryptocurrency, such as Bitcoin. Several major crypto companies, including FTX, Celsius, and BlockFi, have faced bankruptcy and legal issues due to non-compliance and shady practices, resulting in customers losing money.
  • Binance, the world's largest cryptocurrency exchange, recently settled with multiple agencies in the Justice Department for over $4 billion, with penalties split between forfeiture and criminal fines.
  • As part of the agreement, Binance’s main exchange is barred from operating in the US market, which accounts for a third of their revenue, and they also face increased scrutiny by two separate compliance monitors over the next several years.
  • Their circumvention of laws and regulations include violations of the Bank Secrecy Act, failure to register as a money transmitting business, and multiple sanctions transgressions.
  • Binance's founder and CEO, Changpeng Zhao (CZ), pled guilty to his own set of similar charges, including a failure to maintain an effective AML program, and is facing a multi-million penalty and a potential prison sentence of up to 18 months.
  • Binance was established in China, but regularly moved their headquarters from country to country to avoid regulations. Their lack of compliance was driven from the top, with senior leadership actively prioritizing growth over compliance.
  • Binance created its US-based exchange as “window dressing” to avoid regulations, and the customer service department assisted its customers in circumventing its own compliance controls, like using a VPN to get past IP blocking technology.
  • Though Binance is large enough to continue operating despite the fines, this settlement has sent a strong message to the crypto industry about the importance of reputation, compliance, and customer trust.
  • The cryptocurrency industry is currently lacking a “culture of compliance,” but it has reached an inflection point where lawlessness and shady practices are no longer acceptable. In addition to regulators cracking down on them, customers are also applying pressure for these companies to reform.
  • The use of blockchain technology in the crypto industry provides unique tools for transaction monitoring and tracking funds, which can help ensure compliance with AML regulations and detect suspicious activities.
  • Rogue countries like North Korea are experts in leveraging cryptocurrency in a way that threatens US National Security, so the DOJ must become more adept in investigating and taking action against those that violate US law.

Resources

Matt Stankiewicz on LinkedIn | X (Twitter)

Michael Volkov onLinkedIn |X (Twitter)

The Volkov Law Group

View Details

How can we build a culture that motivates people to do the right thing? In this episode of Corruption, Crime and Compliance, Michael Volkov and guest Steve Naughton, explore crucial questions about fostering ethical cultures within companies and practical steps compliance leaders can take to transform performance. Steve shares insights from his journey, detailing the evolution of compliance leadership roles and offering a glimpse into PepsiCo's growth in this area during his tenure as Chief Compliance Officer. For those considering careers in compliance, he emphasizes that expertise in this field can be developed without a law degree.

Steve Naughton currently oversees Compliance and Enterprise Risk Management programs at Loyola University Law School. He previously served as Pepsi's Chief Compliance Officer, guiding the growth of their compliance program over 8 years. He is passionate about making sure compliance functions can work independently.

You’ll hear Michael and Steve discuss:

  • Steve began his career at major law firms before going in-house to manage litigation and M&A deals during pivotal moments at Quaker Oats and Snapple.
  • PepsiCo’s iconic GC Larry Thompson asked Steve to build a new compliance program starting with just 3 people. Over 8 years, Steve grew Pepsi’s program from 3 to over 40 employees with global reach.
  • Larry saw compliance as preventative and empowered Steve with independent reporting to the Board. Steve remarks, “[Larry] viewed [compliance] as much more preventative than reactionary … his take on compliance has always been, to the extent that we can prevent something or to the extent that as soon as we detect it, we'll go in and check it out instead of waiting till everything was fully investigated.”
  • Pepsi has been on the World's Most Ethical Companies list for 15 years in a row, showcasing its success in following ethical practices.
  • Pepsi has never faced serious enforcement actions, and this is attributed to turning ethical practices into a value-add for the business.
  • Not every company has the resources or leadership seen at Pepsi, making it challenging to bring others along in the compliance profession.
  • Steve emphasizes the importance of a risk-based approach in compliance and recommends developing a strategic five-year plan to address top risks progressively.
  • He encourages companies to be disciplined and follow a plan, citing the Department of Justice's emphasis on showing work prospectively, not retroactively, to defend actions and maintain a strategic plan.
  • Michael and Steve discuss the challenges of implementing change in compliance programs, emphasizing the importance of building a team and garnering support from other functions.They recommend a realistic 3 to 5 year timeframe for implementing changes.
  • Cultures where people feel safe speaking up are foundational to compliance. This can aid in preventing and addressing ethical lapses and compliance challenges.
  • Steve cites examples from Wells Fargo, Volkswagen, General Motors, and Boeing. In these organizations, where you would expect people to be skilled and ethical, employees often didn't speak up. This was because they thought their concerns wouldn't be listened to, or the culture didn't encourage open communication.
  • Compliance is not just about following rules; it's about changing the culture in companies. We need to think differently and work towards making a culture where doing the right thing is not just accepted but encouraged.
  • Steve runs a highly respected compliance curriculum at Loyola University which has prepared many future Chief Compliance Officers. However, compliance expertise doesn’t strictly require legal training.

Resources

Steve Naughton on LinkedIn | Loyola School of Law | Email

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

In the 300th episode of Crime, Corruption and Compliance, Michael Volkov examines the recent FCPA settlements with two major UK reinsurance brokers - Tysers and H.W. Wood - for their involvement in a bribery scheme in Ecuador. The DOJ took an unorthodox approach by going after individual people before the companies. This helped them get cooperation and gather evidence, resulting in over $36 million in fines and forfeited money. However, it also highlights common issues in FCPA cases, such as a lack of supervision and effective controls that let corruption happen.

You’ll hear Michael discuss:

  • The settlements with Tysers ($36M fine + $10.5M forfeiture) and Wood ($508K fine + $2.3M forfeiture) resolve a multi-year FCPA investigation in Ecuador.
  • Several individuals were prosecuted first, including the chairman of two state-owned Ecuadorian insurance firms who pleaded guilty in 2020. This allowed the DOJ to build up cooperators and evidence.
  • A third-party intermediary played an instrumental role, serving as the "glue" that coordinated all aspects of the scheme in exchange for significant profits.
  • Neither Tysers nor Wood voluntarily disclosed. Tysers received a 25% discount for cooperation and remediation; Wood's fine was reduced to $508K based on inability to pay.
  • The intermediary demanded a large split of commissions to funnel payments to officials, which Tysers and Wood accepted, triggering disputes among Tysers' own employees.
  • The parties used coded language and fake investment contracts to disguise corrupt payments to officials' offshore accounts.
  • The lack of financial controls and oversight of third-party payment allocations enabled suspicious activity to occur unchecked. Massive "commissions" paid to intermediaries raised obvious red flags that went unheeded.
  • Going after individuals first and securing a declination for one company yielded major penalties for Tysers and Wood, proving the DOJ's strategy highly effective.
  • The facts underscore the need for vigorous third-party due diligence and monitoring controls to detect and halt potential corruption.

KEY QUOTES

“DOJ has had a slow year in FCPA enforcement. Everybody knows that we may see a few more coming in the next few weeks before the end of the year…” - Michael Volkov

“Unlike most third party FCPA cases, where a third party may be enlisted to further a bribery scheme by funneling payments directly to a foreign official, the intermediary in the Tysers and Wood cases played an instrumental role in arranging, managing and overseeing the bribery payments and overall scheme. The intermediary company truly operated as the glue that put together a large bribery operation from which it earned significant profits.” - Michael Volkov

“...the timing of the corporate individual resolutions is certainly a unique pattern for DOJ to execute on and certainly raises the prospect that we may see other cases where individuals get prosecuted first and then you see a corporate resolution coming towards the end. So DOJ clearly here built up a reservoir of cooperators and information and intelligence that resulted in them being able to impose significant penalties against Tysers and Wood.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Bobby Butler joins Michael Volkov on this episode of Corruption, Crime and Compliance, to explore the evolution of compliance over 20 years. While enforcement actions sparked major progress, Bobby contends compliance is moving firmly into the realm of competitive advantage and performance multiplier. Millennials and younger generations ‘vote with their feet’, demanding ethical cultures, so compliance may increasingly drive talent retention as well.

Bobby Butler has over 20 years of experience building world-class ethics and compliance programs. In his early career, he investigated export control issues and quickly became passionate about compliance. Known for his persistence and commitment to finding solutions, he is a pioneer who helped elevate compliance from an ad hoc function to a strategic asset.

You’ll hear Michael and Bobby discuss:

  • In the early 2000s, compliance programs were sparked by reactions to major DOJ enforcements rather than proactive investments. Companies finally dedicated ample resources when faced with "shock and awe" consequences.
  • Bobby got his start investigating export controls issues at Conoco after unlawful server exports to Syria. He quickly became passionate about trade compliance and then FCPA compliance during the explosion of enforcements in the mid-2000s.
  • Working at ground zero compliance teams at Vetco and Baker Hughes during monitorships gave Bobby deep experience with elements of gold standard compliance programs long before codified evaluation criteria.
  • Bobby argues justifying significant resources without an enforcement action catalyst remains extremely challenging. Compliance fights for a seat at the table and has to insert compliance considerations into business meetings.
  • Persistence and consistency in messaging are critical for credibility and influence as a compliance officer. Strong yet flexible personalities tend to thrive compared to introverts.
  • Compliance has to focus on finding creative solutions to enable opportunities: frame compliance as a competitive advantage and performance multiplier.
  • Tactics Bobby used to persuade executives include tying bonuses to compliance training completion, positioning compliance in sales materials and constant insertion into business meetings.
  • The compliance skill set has grown into a dedicated career path with specialized education channels, not just a secondary legal role.
  • Bobby sees government enforcements continuing to increase given complex technologies and geopolitics.

KEY QUOTES

“...we have to find ways for the business to grow. We've got to be sitting there at the table with them thinking of solutions. The more brain power you put at problem solving and doing it in a compliant way, that's how you build trust with people.” - Bobby Butler

“And every day that goes by, when there's not a compliance issue and you can certify that controls have passed and the elements are there and you have outside counsel come in and do an assessment of your program and you continuously improve and each day goes by and you don't have an issue. Well, there's another positive impact to the investment and the return on shareholder value and more importantly, the company brand.” - Bobby Butler

“...we're out there preaching the good news that compliance can be a good thing. Because at the end of the day, when the company does get in trouble, compliance sets policy, sets voluntary boundaries where the law sets mandatory boundaries.” - Bobby Butler

Resources

Bobby Butler on LinkedIn

View Details

Ephemeral messaging applications like Snapchat, WhatsApp, and Telegram have presented a complex challenge for compliance professionals and legal counsel. On one hand, these technologies can reduce data storage and preservation costs, minimize breach exposure, and allow prioritization of communications data. On the other hand, they can create blind spots by deleting communications records and seriously obstruct internal investigations. How can companies balance the benefits of ephemeral messaging against the risks of compliance program undermining? In this week's episode of Corruption, Crime and Compliance, Michael Volkov discusses recent DOJ guidance regarding ephemeral messaging risks and outlines practical steps organizations can take to strike the right balance.

You’ll hear him discuss:

  • Ephemeral messaging can reduce data storage and preservation costs, which can be significant for companies facing litigation or investigations. It also reduces potential breach exposure by deleting data.
  • However, ephemeral messaging can obstruct internal investigations and create corporate blind spots by deleting communications records before they can be reviewed. This undermines compliance programs.
  • DOJ's guidance outlines several steps companies can take to allow ephemeral messaging while mitigating risks:
  • Understand how the apps delete data and what types of data are stored;
  • Tailor policies on use to your specific risk profile and business needs;
  • Clearly communicate policies to employees and ensure regular enforcement;
  • Examine how policies impact the ability to conduct investigations and respond to subpoenas;
  • Evaluate the overall reasonableness of the risk mitigation strategy.
  • Practical steps to make ephemeral messaging safer include:
  • Restricting use to specific authorized purposes like scheduling;
  • Requiring employees to maintain deletion settings;
  • Conducting periodic audits of devices;
  • Requiring preservation and company access to work communications,
  • Coordinating ephemeral messaging policies with broader data preservation policies.
  • If a company provides devices to employees, it has more control and ability to restrict apps and access data, but even then, steps need to be taken to mitigate risks.
  • BYOD policies are more complex since consent and privacy restrictions may limit what companies can do. However, a BYOD policy still needs to address comprehensively:
  • Preserving data
  • Allowing corporate audits and access
  • Segregating work data where possible
  • Outlining consequences for violations
  • Respecting local privacy laws
  • Getting employee consent
  • With the right policy framework, BYOD can potentially allow ephemeral messaging while protecting data availability.

KEY QUOTES

“Companies have a vested interest in preserving their internal communications for a variety of reasons, to hold internal actors accountable, or even outside actors sometimes, and to protect the organization from potential private and government claims or investigations that may have serious direct or collateral consequences.” - Michael Volkov

“If the government issues a grand jury subpoena as part of a criminal investigation and the company fails to preserve data generated by use of an ephemeral messaging system, a company could be held liable for failing to preserve data relevant to the criminal investigation. Such consequences can be significant...” - Michael Volkov

“While a company may have limited access to employees' personal devices when it supplies devices to its employees, the company should regularly secure certifications by its employees that has not used its personal device for work-related purposes, with emergency exceptions, of course. Similarly, companies have to develop testing protocols for its BYOD policy and secure employee consent to examine the personal device limited solely to business data.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Is your company's compliance program truly effective, or is it just ticking boxes? In this episode of Corruption, Crime, and Compliance, Michael Volkov dives deep into LRN's PEI survey with Susan Divers. Susan sheds light on the global nature of ethics and compliance programs, challenging the misconception that they are solely US-centric. They discuss the power of values, the shift from a cop to a coach approach, and the revolutionary trends in employee-centric training, especially in the age of remote work.

Susan Divers is the Director of Thought, Leadership, and Best Practices at LRN. She has a wealth of experience as a former Chief Compliance Officer, and her emphasis on values over rules in compliance programs has made her a trailblazer in the industry.

You’ll hear Michael and Susan discuss:

  • The LRN PEI survey challenges the perception that ethics and compliance are US-centric; many programs worldwide share common features such as codes of conduct, training policies, and audits.
  • Examining a decade of data, the report delves into how ethics and compliance programs responded to the disruptions caused by the pandemic.
  • LRN's data reinforces the idea that ethics and compliance programs relying on values and ethical cultures are more effective than those solely based on rules. Shifting from a cop approach to a coach approach enhances program effectiveness.
  • Ethical companies experience lower employee misconduct rates, higher employee satisfaction and productivity, and achieve greater sustainable financial performance.
  • The pandemic prompted a shift in focus from content-driven training to employee-centric, relevant, and mobile-friendly modules. Shorter modules, just-in-time training, and tailored approaches are emerging as best practices.
  • Ensuring accessibility through web-based policies and procedures, coupled with interactive capabilities and data analytics, becomes crucial in bridging the gap between remote workers and compliance initiatives.
  • Gathering data on employee interactions provides insights into the effectiveness of compliance programs. Metrics such as completion times, pass rates, and group performance allow for targeted efforts to enhance the program's impact.
  • Michael emphasizes the challenge for compliance officers in handling the plethora of available data. Choosing the right metrics, setting standards, and ensuring the usability of metrics over time are crucial considerations.
  • The report highlights that high-performing ethics and compliance programs are integral to the decision-making processes of companies. 70% of respondents reported modifying or abandoning a business initiative due to an ethics and compliance risk assessment.
  • Susan introduces the concept of embedding a short Ethical Culture survey at the end of training courses. This real-time survey, known as the Ethical Pulse Culture survey, serves as a powerful tool to gauge and improve the ethical culture within organizations.
  • The Ethical Pulse Culture survey becomes a game-changer, operationalizing compliance by offering a moving average of data insights. This survey, incorporated into scorecards, provides business managers with valuable insights into their business unit's ethical culture over time.

Resources

Susan Divers on LinkedIn | Email

LRN

View Details

Clear Channel, a San Antonio based advertising company, is settling with the SEC for $26 million, for bribery violations committed by its former Chinese subsidiary, Clear Media. In this episode of Corruption, Crime and Compliance, Michael Volkov explores the details of this case, from covert cash funds to internal audit challenges, shedding light on the issues that led to this notable settlement.

You’ll hear him discuss:

  • The charges stemmed from bribery violations committed by Clear Channel’s former Chinese subsidiary, Clear Media. The bribes included expensive gifts, entertainment and travel, given to influence contract renewal negotiations with Chinese government officials.
  • Clear Media engaged in deceptive practices, falsely documenting payments to cleaning and maintenance companies to fund illegal payments. They cautioned employees to omit gift recipients and disguised payments through oral agreements. False invoices and tax records were created to justify cash payments to shell company intermediaries that provided no actual services.
  • Internal audits from 2012 to 2017 highlighted deficiencies, red flags, and indicators of bribery. Despite this, Clear Channel failed to pursue aggressive remedial actions.
  • Internal auditors faced resistance from Clear Media and even reported false information provided by them. The lack of diligence and follow-up allowed the issues to persist.
  • Clear Channel, however, cooperated extensively with the investigation. They promptly shared facts, produced relevant documents, and facilitated interviews with current and former employees.
  • Remediation efforts included disposing of Clear Media, enhancing anti-corruption compliance policies, and increasing resources for compliance.
  • The settlement serves as a cautionary tale, emphasizing the importance of robust internal audits and proactive remediation.

KEY QUOTES:

“Clear Channel received credit for its cooperation and remediation. Its cooperation included promptly sharing facts, proactively producing relevant documents, producing in real time documentation of audits of Clear Media's internal controls during the course of the investigation...” - Michael Volkov

“So from 2012 to 2017, Clear Channel auditors regularly cited Clear Media's deficiencies, red flags, indicators of bribery, and inadequate internal controls. The auditors cited numerous remedial measures, but Clear Channel failed to ensure that appropriate remedial steps were taken.” - Michael Vokov

“But given the level of resistance and the failure of the internal audit function to operate properly and to follow up specifically on the issues that they were uncovering, the resolution has to be viewed in a positive light and was only counterbalanced by the fact that what Clear Channel did was cooperate and provide extensive remediation and ultimately sold its Chinese subsidiary...” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Albemarle, a prominent specialty chemicals company, recently settled a case for $218 million, unraveling a web of bribery payments across Vietnam, Indonesia, and India. The repercussions of this case extend beyond the financial penalty, encompassing a three-year non-prosecution agreement and the application of the Compensation, Incentives, and Clawbacks pilot program. In this episode of Corruption, Crime and Compliance, Michael Volkov shares details of Albemarle’s FCPA settlement with the DOJ and SEC, exploring Albemarle’s voluntary disclosure, extensive remediation efforts, and a transformative shift in its business model.

You’ll hear Michael talk about:

  • Albemarle agreed to pay over $218 million to settle investigations conducted by the DOJ and the SEC. This substantial financial penalty is a consequence of alleged bribery payments made by the company in multiple countries.
  • The investigations focused on bribery payments related to various business transactions and dealings made by Albemarle in Vietnam, Indonesia, and India.
  • As part of the settlement, Albemarle entered into a three-year non-prosecution agreement. While the company acknowledges certain wrongdoing, it avoids facing formal prosecution during the specified period if it complies with the agreed-upon terms and conditions.
  • The settlement includes the application of the Compensation, Incentives, and Clawbacks pilot program. This program outlines mechanisms to ensure that executives and employees involved in wrongdoing face appropriate consequences, including clawing back certain incentives and compensation.
  • Albemarle voluntarily disclosed information related to the potential FCPA violations. This proactive step is often a mitigating factor in settlements and reflects a willingness to cooperate with authorities.
  • Albemarle undertook extensive remediation efforts in response to the allegations. This included disciplining employees involved in the wrongdoing, strengthening its anti-corruption program, and making significant changes to its business model and risk management processes.
  • The investigations highlighted Albemarle's use of sales agents in Vietnam, Indonesia, and India. Control deficiencies with third parties in China and the United Arab Emirates (UAE) were also noted, raising concerns about the oversight and due diligence processes related to these external entities.
  • Michael shares details about specific bribery schemes involving state-owned entities such as Petro Vietnam in Vietnam, Pertamina in Indonesia, and IOCL in India. These schemes included practices like modifying tender requirements, providing nonpublic information, and directing agents not to include details in invoices concerning tips to foreign officials.
  • The case underscores the risks of relying on third-party agents to secure contracts, particularly through the example of Albemarle's failure to conduct due diligence on an agent in the UAE. The agent's close ties to the UAE government and royal family contradicted representations made during the due diligence process.

KEY QUOTES

“And in this case, they rewarded Albemarle with an NPA as opposed to a deferred prosecution agreement. So it's a three-year non-prosecution agreement, and doesn't get filed with the court. There's no information that's filed. And they agreed to pay a penalty of approximately $98.2 million and an administrative forfeiture of $98.5 million. Also, this is the first FCPA settlement where we applied the Compensation, Incentives, and Clawbacks pilot program, which the DOJ had announced in March of 2023.” - Michael Volkov

“With respect to remediation efforts, the DOJ cited Albemarle's extensive remedial measures, including that they started the remediation prior to the beginning of the DOJ's investigation. In other words, they started to remediate quickly upon starting their own internal investigation.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

3M faced a dual settlement, first with the SEC and then with OFAC, over alleged Iranian sanctions violations stemming from misconceptions and oversights in a license plate deal with a German intermediary. Despite the gravity of the case, 3M took proactive remedial actions, including voluntary disclosure and internal changes. Similarly, Emigrant Bank maintained a CD account for two Iranian residents for over two decades without proper screening, leading to a $31,000 settlement. In this episode of Corruption, Crime and Compliance, Michael Volkov shares details of both cases, underscoring the complexities of navigating sanctions regulations, the consequences of compliance failures, and the pivotal role of voluntary disclosure and proactive remediation in mitigating penalties.

You’ll hear Michael talk about:

  • 3M settled with the Securities and Exchange Commission (SEC) for $6.5 million and with the Office of Foreign Assets Control (OFAC) for $9.6 million over alleged violations of Iranian sanctions. 3M's Dubai-based subsidiary entered into a deal to manufacture reflective license plate sheeting for a German company, but it misunderstood the end user, believing it was a reseller when it was actually Iran.
  • Between 2016 and 2018, 3M sent 43 shipments to the German intermediary, who resold them to Iran, violating OFAC regulations. This led to 54 violations of the Iran sanctions program. 3M's compliance team approved the deal without realizing the true end user was in Iran. Suggestions to review the deal were ignored, and steps were taken to conceal its true nature.
  • 3M took remedial steps, including voluntary disclosure, termination or discipline of involved employees, leadership changes, revamped sanctions compliance training, and discontinuation of business with the German reseller.
  • In another case, Emigrant Bank maintained a certificate of deposit (CD) account for two Iranian residents from 1995 until 2021 without properly screening it for sanctions issues. In 2016, when the account holders requested a wire transfer, Emigrant became aware of potential sanctions issues but still approved the transfer.
  • In 2019, Emigrant's upgraded screening software flagged the account, but the compliance team overrode the alert based on erroneous guidance from the 2016 wire transfer. Emigrant recognized the account's status in 2021, closed it, and took steps to remediate compliance program shortcomings.
  • Emigrant settled the matter for $31,000, significantly lower than the maximum penalty applicable ($9.9 million), with voluntary disclosure and proactive remediation efforts considered mitigating factors by OFAC.

KEY QUOTES

“In the course of setting up this agreement, numerous managers at 3M suggested that trade compliance reviewed the deal. But these 60 suggestions were ignored by the deal's proponents. Even worse, a 3M subsidiary received an outside due diligence report, flagging the connection to Iranian law enforcement, and closed the matter without further investigation.” - Michael Volkov

“On September 21 of this year, OFAC announced that Emigrant agreed to pay $31,867 to resolve 30 violations of the Iran Sanctions Program. The violations all relate to a single CD account that Emigrant maintained for two Iranian residents from 1995 until it closed the account in 2021.” - Michael Volkov

“In 2019, Emigrant upgraded its screening software, sanctioned screening, and the new program flagged the account as problematic due to the account holder's Iranian residency. However, software is only effective as its operator. Upon review, Emigrant's compliance team overrode the alert, basing their decision on erroneous guidance from the 2016 wire transfer. Now, Emigrant finally recognized the account status in 2021 and took steps to remediate its compliance program shortcomings.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

California's data privacy regulations, primarily embodied in the California Consumer Privacy Act (CCPA) and its extension through the California Privacy Rights Act (CPRA), constitute a pioneering and influential framework. These regulations, effective from 2018 and further strengthened in 2020, set a standard for data protection not only within the state but also across the national and global economy. In this episode of Corruption, Crime and Compliance, Michael Volkov explores the nuances of the CCPA and CPRA, and the evolving data privacy landscape.

You’ll hear Michael talk about:

  • The lack of a federal data privacy law in the United States has led to a complex patchwork of state laws. Businesses are faced with the challenge of navigating these varied regulations, which contributes to compliance complexities.
  • California, through the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), is a leader in data privacy regulation in the United States, with implications for both the national and global economy. The CPRA, enacted in 2020, establishes the California Privacy Protection Agency (CPPA) to enforce the law robustly.
  • The CPRA introduces critical changes, including:
  • Protection of employee and business-to-business personal information, which is now subject to the same privacy protections as consumer personal information.
  • Enhanced consumer rights, such as the right to access, delete, and correct their personal information, and the right to opt out of the sale of their personal information.
  • Companies are now obligated to implement reasonable security precautions and undergo annual cybersecurity audits and risk assessments.
  • In addition to California, other states such as Virginia, Colorado, Utah, Iowa, and Connecticut have also enacted data privacy laws that echo the GDPR. Businesses must stay up-to-date on evolving compliance requirements and adapt their systems accordingly.
  • Compliance issues comprise risk assessments, impact assessments, adherence to data breach requirements, and compliance with notification standards. Companies are developing systems based on the most stringent set of laws to guarantee compliance.

KEY QUOTES

“We have a patchwork of laws that apply in the United States. Unfortunately, we continue to suffer from the absence of a federal data privacy and breach notification law. Congress has tried for years to broker a deal here, but it has never been able to overcome strong lobbying forces. Whether it's high tech trial lawyers, law enforcement, or other gadflies, the public continues to suffer.” - Michael Volkov

“Many commentators have suggested that California's data privacy laws and regulations are starting to look closer and closer to the EU's GDPR regime.” - Michael Volkov

“To me, we're getting into a more strict regulation. We already have, under the California Consumer Privacy Act, a requirement to have on your website: an ‘opt out’ in terms of any information that you may provide to a website, that it can't be used by the entity for sharing or selling or whatever consumer products purposes. So keep tabs on the California events.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

3M’s recent $6 million settlement with the SEC for violating the FCPA serves as a stark reminder of the risks global companies face in today's economy and underscores the crucial role of ethics and compliance programs. In this episode of Corruption, Crime and Compliance, Michael Volkov sheds light on the unethical conduct that led to legal repercussions and offers valuable insights into compliance, bribery mitigation, and the importance of tight control over official visits.

You’ll hear Michael talk about:

  • 3M Corporation, a global company, was found to have made improper payments to Chinese healthcare officials employed by state-owned enterprises. These payments were disguised as expenses for attending overseas conferences and educational events.
  • The scheme involved deceptive tactics where 3M presented these events as educational, but in reality, they included tourism and entertainment activities. This included creating fake agendas and hidden tourism components.
  • Employees at 3M's China operations colluded with travel agencies to set up alternative itineraries that combined tourism activities with the purported educational events. Chinese officials either did not attend the educational events or missed significant portions of them. 3M China employees tracked the impact of these events on the company's sales. The costs of these trips were improperly recorded as legitimate business expenses, resulting in 3M benefiting by at least $3.5 million in increased sales.
  • In the aftermath of this ethical breach, 3M took crucial steps towards remediation through self-reporting, cooperation with the investigation, and taking disciplinary actions such as terminating employees involved, severing relationships with travel agencies, and enhancing controls over cross-border fund transfers.

KEY QUOTES

“But 3M made payments to Chinese healthcare officials from state-owned enterprises or hospitals or healthcare delivery systems to attend overseas conferences, educational events, and healthcare facility visits. And these were paid for presumably as permissible educational events, but they actually were pretexts to provide overseas travel, sightseeing, and entertainment or tourism activities.” - Michael Volkov

“3M employees accompanied the Chinese officials on the tourism activities, and the tourism activities included guided tours, shopping visits, day trips to nearby sites, and other leisure activities.” - Michael Volkov

“This case also reminds me of a case several years ago called Johnson Controls, where the local China operation was able to secure funding and engaged in a sort of collusion process by which they sought funds and expenditures for less than $5,000. And they did that because it didn't require corporate approval above just the local level.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

CEOs play a pivotal role in shaping an organization's commitment to ethical practices. Involving CEOs in compliance training, having them share their experiences, and demonstrating a personal commitment to compliance initiatives sets a strong tone from the top. This engagement fosters a culture of ethics and compliance throughout the organization, reinforcing the importance of ethical conduct at all levels.

Mary Shirley is a highly regarded authority in the field of ethics, compliance, and corporate governance. She is widely recognized for her expertise in helping organizations navigate the complex landscape of compliance, mitigate risks, and promote ethical practices. With a wealth of experience and insights, Mary Shirley has become a sought-after thought leader, speaker, and author. Her book, Living Your Best Compliance Life: 65 Hacks and Cheat Codes to Level Up Your Ethics and Compliance Program, has earned acclaim for bridging gaps in existing literature on compliance programs.

You’ll hear Michael and Mary discuss:

  • Organizations can promote ethics and compliance by recognizing and rewarding individuals or teams who exhibit ethical behaviors. This creates a positive atmosphere throughout the company, as employees are more likely to behave ethically if they see that it is valued and rewarded. Additionally, recognizing and rewarding ethical behavior can help to set a good example for other employees and encourage them to behave ethically as well.
  • Engaging leaders from different regions and departments in compliance training programs ensures diverse perspectives and reinforces the importance of compliance at all levels. Leaders from different regions and departments will have different experiences and understanding of compliance issues. By engaging them in training programs, organizations can gain a more holistic view of compliance risks and how to mitigate them.
  • Practical solutions and problem-solving are essential for compliance initiatives. For example, shortening documentation requirements or providing training for HR on investigation best practices can be effective solutions. These solutions can help to reduce the burden of compliance on employees and make it easier for businesses to comply with regulations.
  • One of the critical elements Mary discusses is the significance of building strong relationships within the company. Collaboration and idea implementation are key to success in the compliance world.
  • Collaboration between legal, compliance, and HR teams, along with training for HR on investigation best practices, helps streamline compliance efforts.
  • CEOs play a critical role in setting the tone for compliance within an organization. They are the ones who set the example for their employees, and their actions and words can have a significant impact on whether or not employees comply with regulations. When CEOs are involved in compliance training, it demonstrates that they are committed to ethical practices and that they take compliance seriously.
  • Mary recommends forming task forces to validate compliance ideas at an early stage, fostering a culture of innovation and problem-solving.
  • Encouraging employees to share personal anecdotes related to compliance principles humanizes the process and fosters a culture of ethical work. When employees feel like they can share their own experiences with compliance, it helps them to understand the principles on a deeper level. It also helps to create a sense of community and belonging, as employees see that they are not alone in their commitment to ethical behavior.

KEY QUOTE

“One of the things that I learned way later that I wish I had was that when you involve people in the conceptualizing aspect [of] building a compliance initiative… and they feel [like they are] part of it… you’re in a much better position to get buy-in when you [implement].” - Mary Shirley

Resources

Mary Shirley on LinkedIn

Order Mary’s new book: Living Your Best Compliance Life

View Details

When operations span across borders, navigating local regulations and ethical standards becomes even more crucial. As evidenced by Corficolombiana's case, neglecting these measures can lead to hefty legal ramifications and significant economic repercussions. In this episode of Corruption, Crime and Compliance, Michael Volkov unravels the Corficolombiana and Group Aval scandal, shedding light on the importance of implementing and maintaining robust ethics and compliance programs for global companies.

You’ll hear Michael talk about:

  • Corfico is a subsidiary of the Colombian financial behemoth, Grupo Aval. The two entities agreed to substantial settlements with both the DOJ and SEC, stemming from allegations of a bribery scheme in Colombia.
  • It emerged that Corfico had conspired with Odebrecht, a Brazilian construction firm, to pay around $23 million in bribes to influential Colombian government officials to clinch the project. The DOJ's settlement with Odebrecht throws more light on the matter.
  • Corfico's forthcoming cooperation with both DOJ and Colombian authorities demonstrated their intent to amend their ways.
  • Corfico embarked on extensive remedial measures, which the DOJ acknowledged and appreciated. This included a comprehensive root cause analysis and subsequent enhancements to their corporate governance and controls.
  • Corfico also revamped its compliance program, introducing improved reporting, investigation, and disciplinary procedures and revisited its anti-corruption compliance program.
  • The DOJ extended a 30% fine reduction to Corfico, a significant reprieve. What stood out, however, was the decision against appointing an independent compliance monitor in this case.
  • Such international scandals accentuate the risks that large projects in foreign lands pose. Drawing parallels with the ABB case, it’s clear that ethics and compliance are non-negotiables for global firms.

KEY QUOTES

“The DOJ credited Corfico's cooperation, citing its production of facts obtained through the company's internal investigation, making numerous detailed factual presentations that distilled certain key factual information producing documents that the government may not have been able to get access to because of foreign data privacy laws providing sworn testimony from Columbia.” - Michael Volkov

“Corfico promptly engaged in extensive remedial measures, including, among other things, conducting a root cause analysis of the bribery scheme identified during the internal investigation. Promptly took the actions to enhance its corporate governance and controls and joint venture entities as well as improved its oversight of noncontrolled joint ventures and investments, overhauled its compliance program… As a result of this, the DOJ awarded Corfico a 30% reduction off the bottom of the applicable guidelines fine range.” - Michael Volkov

“It's always good to look at the underlying conduct, and imagine: If you're working in a company, with your compliance program, would you have been able to detect this? How would your compliance program have prevented this from occurring?” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Companies must take a proactive approach to sanctions and export control compliance to mitigate potential risks. This includes implementing rigorous compliance programs, cooperating with the DOJ, and promptly disclosing and remedying violations. In this episode of Corruption, Crime and Compliance, Michael Volkov explores the latest joint compliance notice issued by the DOJ, Department of Commerce, and Department of the Treasury. This notice provides crucial guidelines on voluntary disclosure for sanctions and export control violations, shedding light on the increasing enforcement of such controls. He discusses the intricate relationship between sanctions enforcement and the FCPA and offers a keen understanding of how businesses can safeguard their interests and comply with global standards.

You’ll hear Michael talk about:

  • The landscape of sanctions enforcement is rapidly evolving, with the Department of Justice (DOJ) and the National Security Division designating 25 prosecutors to handle sanctions compliance violations.
  • Corporate resolutions are becoming the driving force behind settlement processes, and these resolutions could become significant revenue streams for the DOJ. In light of these developments, companies must prioritize sanctions and export control compliance to mitigate potential risks.
  • The DOJ's Joint Criminal Enterprise (JCE) Guidance provides a detailed guideline for voluntary disclosures of possible violations. The JCE Guidance emphasizes the importance of prompt disclosure and swift remediation after uncovering potential violations.
  • Generally, the DOJ will not seek prosecution if a company fully discloses a violation, cooperates wholeheartedly, and takes remedial actions. However, this is not a blanket assurance; aggravating factors such as widespread criminal activity or attempts by upper management to conceal violations can influence this stance.
  • Voluntary self-disclosure is not merely a bureaucratic step; it can potentially be a shield, allowing companies to significantly reduce or even bypass criminal liability.
  • Full cooperation entails timely preservation of pertinent documents, streamlined witness interviews, and proactive identification of avenues for in-depth DOJ investigation.
  • Implementation of rigorous compliance programs, complemented by suitable disciplinary actions, can tilt the scales in favor of companies during evaluations.
  • The JCE Guidance underscores recent modifications to the disclosure and enforcement policies adopted by the Bureau of Industry and Security (BIS) and the Office of Foreign Assets Control (OFAC). Notably, the BIS has ramped up penalties for companies that remain tight-lipped about significant potential violations.
  • The efficacy of a compliance program, particularly its prowess in identifying and rectifying compliance gaps, plays a monumental role in BIS case resolutions.

KEY QUOTES

“Companies are about to face aggressive, coordinated prosecutions for sanctions and export control violations.” - Michael Volkov

“[The] DOJ noted that a prompt, voluntary self disclosure provides a means for a company to reduce, and in some cases, avoid altogether, the potential for criminal liability moving forward, where a company voluntarily self discloses potentially criminal violations, fully cooperates, and timely and appropriately remediates the violations.” - Michael Volkov

“The existence, nature, and adequacy of a company's compliance program, including its success at self identifying and rectifying compliance gaps, is itself considered a factor under settlement guidelines.” - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

Departments of Justice, Commerce and Treasury Issue Joint Compliance Note on Voluntary Self-Disclosure of Potential Violations

View Details

In this episode of Corruption, Crime and Compliance, Michael Volkov delves into the SEC’s groundbreaking adoption of robust cybersecurity disclosure rules. This pivotal change marks a significant shift in the compliance landscape, requiring public companies to not only disclose cybersecurity incidents but also unveil their governance policies and practices.

You’ll hear him discuss:

  • The SEC's adoption of new cybersecurity disclosure rules, a process spanning over a year, comes as a transformative step in the regulatory landscape.
  • One of the most noteworthy changes is the requirement for companies to file Form 8-K to disclose material cybersecurity incidents within four business days of determining materiality.
  • This significant change allows for a more measured assessment of materiality before disclosure, a departure from the previous trigger of four days from becoming aware of the incident.
  • Alongside incident disclosure, the new rules mandate that all public companies include comprehensive cybersecurity risk management and governance disclosures in their annual Form 10-K filings. This move underscores the necessity for companies to integrate cybersecurity into their broader enterprise risk management processes.
  • Companies are required to disclose the board committees or subcommittees responsible for cybersecurity oversight, outlining their processes for monitoring cybersecurity risks and reporting incidents.
  • The reach of these rules extends to third-party information systems, including those of vendors and suppliers. This amplifies the importance of thorough due diligence in assessing the information security systems and risks of external partners.

KEY QUOTES:

“You can't just sit on an incident and not make a determination, analyze it, and delay, delay as a way to avoid that materiality determination.” - Michael Volkov

“The SEC expects companies to analyze qualitative factors when assessing materiality, including harm to reputation, customer and vendor supply relationships, and the impact of regulatory actions and civil litigation.” - Michael Vokov

“Additionally, companies have to go even more comprehensive in their disclosures to …describe management procedures and practices for assessing and mitigating cybersecurity risks.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

As companies rapidly adopt artificial intelligence (AI), it becomes paramount to have robust governance frameworks in place. Not only can AI bring about vast business benefits, but it also carries significant risks—such as spreading disinformation, racial discrimination, and potential privacy invasions. In this episode of Corruption, Crime and Compliance, Michael Volkov dives deep into the urgent need for corporate boards to monitor, address, and incorporate AI into their compliance programs, and the many facets that this entails.

You’ll hear Michael talk about:

  • AI is spreading like wildfire across industries, and with it comes a whole new set of risks. Many boards don’t fully understand these risks. It's important to make sure that boards are educated about the potential and pitfalls of AI, and that they actively oversee the risks. This includes understanding their obligations under Caremark, which requires them to exercise diligent oversight and monitoring.
  • AI is a tantalizing prospect for businesses: faster, more accurate processes that can revolutionize operations. But with great power comes great responsibility. AI also comes with risks, like disinformation, bias, privacy invasion, and even mass layoffs. It's a delicate balancing act that businesses need to get right.
  • Companies can't just use AI, they have to be ready for it. That means adjusting their compliance policies and procedures to their specific AI risk profile, actively identifying and assessing those risks, and staying up-to-date on potential regulatory changes related to AI. As AI grows, the need for strong risk mitigation strategies before implementation becomes even more important.
  • The Caremark framework requires corporate boards to ensure that their companies comply with AI regulations. Recent cases, such as the Boeing safety oversight, demonstrate the severity of the consequences when boards fail to fulfill their responsibilities. As a result, boards must be proactive: ensure that board members have the technical expertise necessary, brief them on AI deployments, designate senior executives to be responsible for AI compliance, and ensure that there are clear channels for individuals to report issues.

KEY QUOTES

“Board members usually ask the Chief Information Security Officer or whoever is responsible for technology [at board meetings], ‘Are we doing okay?’ They don't want to hear or get into all of the details, and then they move on. That model has got to change.”

“In this uncertain environment, stakeholders are quickly discovering the real and significant risks generated by artificial intelligence, and companies have to develop risk mitigation strategies before implementing artificial intelligence tools and solutions.”

“Board members should be briefed on existing and planned artificial intelligence deployments to support the company's business and or support functions. In other words, they've got to be notified, brought along that this is going to be a new tool that we're using, ‘Here are the risks, here are the mitigation techniques.’”

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

According to critics, there are a lot of gray areas surrounding compliance and the SEC's position on cryptocurrency regulations. Such uncertainty poses challenges for legitimate crypto projects and creates room for fraudulent activities to thrive. Such is the case for Ripple and Celsius, two recent controversies making waves in the crypto world.

Matt Stankiewicz is a Managing Counsel at The Volkov Law Group. His expertise includes financial regulation and compliance, with a focus on securities, anti-money laundering (AML), and cryptocurrency regulation. Given his professional background and interest in crypto regulations, he is a frequent speaker on legal matters concerning cryptocurrency exchanges and the SEC.

You’ll hear Michael and Matt discuss:

  • The SEC faces criticism for its unclear stance on cryptocurrency regulations. Such uncertainty poses challenges for legitimate crypto projects and creates room for fraudulent activities to thrive.
  • The Ripple case offers a complex view into how cryptocurrencies are perceived legally. While some sales of XRP tokens were considered securities, others weren't, a distinction that has sent ripples through the crypto world. The case's broader implications, especially with the SEC's decision being appealed, hold immense importance for other companies in similar situations.
  • Bad actors can exploit innovative technologies and make things worse for everyone else. With the CEO and CRO of Celsius charged with fraud and numerous questionable practices coming to light, the importance of stringent regulations and monitoring becomes abundantly clear.
  • Strong compliance programs serve as bulwarks against fraudsters and those under sanctions, ultimately safeguarding both the platform and its users. However, regulating an asset as novel and dynamic as cryptocurrency is no easy feat. Critics claim the SEC's approach leans more toward enforcement than establishing clear rules.
  • Matt underscores the importance of erecting a sturdy compliance structure within the cryptocurrency industry. He emphasizes that such programs are not just regulatory measures but critical tools to ward off fraudsters and maintain the industry's reputation.

KEY QUOTES

“[Crypto] is a brand new asset. It’s virtually impossible to pigeonhole it to any other kind of real-world asset right now.” - Matt Stankiewicz

“Don't cripple the good projects because there’s some bad people out there.” - Matt Stankiewicz

“The SEC just says, well, ‘You should know. You’ve got to figure it out; we're not your attorneys.’ Which is fair in some regard, right? But that said, it's not helpful. The SEC needs to provide some kind of guidance here.” - Matt Stankiewicz

Resources

Matt Stankiewicz on LinkedIn

Email: mstekwitz@volkofflaw.com

View Details

Transparency, ethics, and compliance are more than just corporate buzzwords; they're foundational to building trust in today's global organizations. Consequence management systems encompass elements like transparency, robust employee reporting, protective measures for whistleblowers, and effective internal investigations. These are all essential for maintaining organizational justice, trust, and integrity. In this episode of Corruption, Crime and Compliance, Michael Volkov underscores the value of collecting and analyzing employee reports, the pivotal role of Chief Compliance Officers, and the integration of compliance compensation with consequence management.

You’ll hear Michael talk about:

  • Global companies now recognize the significance of robust consequence management systems, which encompass vital processes from internal investigations to disciplinary actions. A pivotal aspect of these systems is transparency, especially when designing and implementing employee reporting.
  • When it comes to effective employee reporting, a system is more than just a hotline; it involves tracking and addressing concerns in real-time. To foster trust, such systems must operate promptly, fairly, and consistently, ensuring that reporters are protected against obstruction and/or retaliation.
  • Key components of an effective reporting system include:
  • Clear internal communication, which ensures employees feel heard.
  • Foundational support, which bolsters efficiency.
  • Collated reports from diverse sources, which offers insights into the company's culture and potential risks.
  • Transparency and consistency, as sporadic disclosure can negatively influence employees' perceptions of a company's intentions.
  • A CCO’s commitment is reflected when issues are investigated and addressed swiftly and justly. They play a crucial role in collecting and analyzing employee reporting data, as well as educating senior management and boards on the significance of employee reports.
  • Companies need to establish written protocols for internal investigations to ensure that they are conducted fairly and impartially. These protocols should outline the steps that will be taken during an investigation, as well as the rights of the employees involved. The protection of employees and whistleblowers is paramount.
  • An internal oversight committee should be responsible for overseeing internal investigations. Regular reviews ensure that procedures are followed consistently and that there is a focus on quality. Additionally, all investigations should be properly documented and resolved in order to maintain integrity.



  • Compliance and consequence management systems should work together to meet the expectations of the DOJ, promoting corporate citizenship and financial success.

KEY QUOTES

“A true employee reporting system includes reports to supervisors, walk-ins to human resources, walk-ins to legal and compliance, and an automated reporting system.” - Michael Volkov

“The real question is whether the company backs up its statement through specific actions. This cannot be accomplished through words, but really only through deeds, through actions. All too often, companies get ahead of themselves. They make these broad pronouncements. They sound good, they pat each other on the back, and they don't build the essential foundations and infrastructure needed to establish an effective employee reporting system.” - Michael Volkov

“As a basic initial requirement, every company should adopt a written internal investigation protocol that is published internally, promoted internally to demonstrate a commitment to transparency, and those protocols and procedures should be followed to the T.” - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

The DOJ is advocating for increased consequences for individuals who engage in misconduct or fail to exercise proper oversight, via the implementation of compliance compensation programs that include financial penalties. Companies need to develop incentives and penalties in a balanced manner to maintain ethical performance, while ensuring the potential for accountability. A crucial aspect of enforcing these policies is the execution of robust clawback provisions as part of the executive's contract and bonus terms. These clawbacks can act as a deterrent for misconduct, and their enforceability largely depends on the clarity of their language, among other things. In this episode of Corruption, Crime and Compliance, Michael Volkov explores compliance compensation systems and their role in corporate governance in detail.

You’ll hear Michael talk about:

  • Clawback provisions are important rules that determine how executives' contracts and bonus terms can be enforced. Companies have a responsibility to execute robust clawback provisions to ensure accountability and deter misconduct.
  • Compliance programs are becoming increasingly vital to global companies as they grapple with complex legal and economic risks. These programs are crucial in reinforcing compliant behavior and promoting positive corporate citizenship.
  • The DOJ has emphasized the importance of compensation systems and consequence management in corporate compliance programs. Not being proactive in reviewing these systems is considered a serious mistake that requires urgent attention and correction.
  • DOJ's focus has expanded towards consequence management, seeking to escalate penalties for those involved in misconduct. Companies are required to implement compliance compensation programs focusing primarily on clawbacks.
  • Clawback policies, often limited to senior executives and specific conduct, need to be broadened in their scope and applicability. Notably, the Dodd-Frank Act mandates listed companies to have a written clawback policy for financial restatements resulting from accounting misconduct.
  • Compliance rewards act as a significant incentive for ethical behavior and compliance. Executives and managers who fulfill specific compliance requirements may become eligible for performance-related rewards.
  • Compliance compensation systems must be designed to hold individuals accountable for misconduct. Penalties, including retroactive discipline and financial penalties like clawbacks or deferred compensation systems, can be potent deterrents.
  • A comprehensive compliance compensation system requires careful crafting to minimize litigation and defense possibilities. It involves identifying the executives and managers to be included in the penalty system and determining the corresponding percentage penalties.
  • A company must balance its incentive structure, considering factors like large contingent payouts to executives and ethical performance requirements. Clarity in written policies and employment agreements fortify clawback provisions.
  • Collaboration between business, finance, legal, and HR is pivotal in the design and implementation of effective compliance reward and penalty systems.

KEY QUOTE:

“The DOJ wants to add to their risk calculation, and that's requiring companies to implement compliance compensation programs that include financial penalties against those actors who engage in misconduct, or supervisors that fail to rein in their underlings or conduct proper oversight to ensure compliance.” - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Bank of America joins the infamous club of consumer abusers in the banking industry, despite the alarm bells set off by the notorious Wells Fargo case. On this week's episode of Corruption, Crime and Compliance, host Michael Volkov explores the shocking details of Bank of America's recent $250 million settlement for account fraud and abuse with the Consumer Financial Protection Bureau (CFPB) and the Office of the Comptroller of the Currency (OCC). This episode shines a light on corporate complacency, the inherent risk of ill-conceived sales incentives, and the importance of internal risk assessment in the wake of industry scandals.

You’ll hear Michael discuss:

  • The fraudulent practices perpetrated by Bank of America, compared to the infamous Wells Fargo scandal. He examines the similarities in the unethical practices and failure to adhere to consumer protection laws, and the recurring patterns in the banking industry's consumer abuse cases.
  • The pitfalls of sales incentives structures, particularly when they lack appropriate checks and balances. Mike elaborates on how ill-considered incentives can encourage misconduct among salespeople.
  • The enforcement actions brought by the CFPB and OCC against Bank of America: fines amounted to $250 million—$190 million for consumer harms and penalties to the CFPB and $60 million in penalties to the OCC.
  • Unscrupulous methods adopted by Bank of America employees to reach their sales targets included illegally applying for and opening credit card accounts and charging customers multiple overdraft fees for the same transactions, significantly hurting consumers financially.
  • Michael dissects the bank's promotional tactics, particularly the false advertising of special offers and the denial of sign-up bonuses due to inherent failures in their business systems. He discusses the negative impact of these practices on customers and the bank's reputation.
  • Highlighting the current stringent regulatory environment, Michael stresses the need for organizations, especially banks, to maintain stringent internal audits and compliance measures.
  • Based on the recent enforcement actions, Michael makes informed predictions about potential regulatory actions against Bank of America and discusses the bank's responsibilities moving forward.

KEY QUOTES:

"You would think that Wells Fargo's case would have sent alarm bells throughout Bank of America to take a look at their own sales practices to make sure they don't suffer from the same type of abuse of conduct. And what's clear is Bank of America just kept its head down, blinders on, and then developed their own problem." - Michael Volkov

"Bank of America employees illegally applied for and then enrolled customers in credit card accounts in order to reach sales incentive goals." - Michael Volkov

"This is a tough regulatory environment, and you would think Bank of America would try to address that through some kind of mitigation and sort of risk analysis and conducting audits to make sure that they don't run into future abuses and practices like this." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

In today’s world data is the new gold, and protecting it has become imperative for businesses worldwide. On this week's episode of Corruption, Crime and Compliance, Michael Volkov navigates the cybersecurity landscape, unpacking the key threats haunting businesses and the elements of a robust cybersecurity compliance program. He underscores the importance of proactively managing these digital threats, to ensure your business remains protected.

You’ll hear him discuss:

  • The growing partnership between compliance and cybersecurity is a rapidly emerging issue in compliance, affecting companies and their risk management strategies. Cyber threats are not only external but also internal, resulting from employee behavior and cybersecurity hygiene.
  • Chief Information Security Officers (CISOs) are increasingly collaborating with Chief Compliance Officers (CCOs), leveraging the latter's expertise in governance, risk management, and training. This collaboration enables better education and training for employees on cybersecurity risks and the importance of good cybersecurity hygiene.
  • Approximately 50% of cyber or data breaches are the result of internal actors, either intentionally or through negligence. Thus, CCOs can play a crucial role in designing controls, conducting training, and monitoring employee behavior to mitigate such risks.
  • Major cybersecurity risks today include ransomware, cloud security, work from home security, phishing schemes, supply chain security, and identity and access management (IAM).
  • The rise of cyber threats: The digital landscape is rife with cybersecurity threats, including insider threats, DoS and DDoS attacks, AI and machine learning attacks, and cyber espionage.
  • Organizations need to be vigilant against disgruntled employees with access privileges who could intentionally or unintentionally harm systems. This emphasizes the need for robust access controls, regular monitoring, and comprehensive employee training.
  • While AI and machine learning can enhance cyber defenses, they can also be weaponized by cybercriminals to automate and scale their attacks.
  • A robust cybersecurity compliance program is necessary to protect a company's IT infrastructure and includes:
  • Application Security: Familiarity with cloud security policies and the implementation of multifactor controls and administration privileges can help strengthen application security.
  • Information Security: Companies must adhere to strict security standards and employ encryption among other strategies to protect data from possible breaches.
  • Disaster Recovery Planning: This requires implementing backup and recovery systems, incident response drills, and endpoint protections.
  • Network Security: Most companies use firewalls to monitor traffic for cyber threats and attacks. Companies must also secure their wireless networks and ensure that remote connections are encrypted.
  • End User Security: Since hackers often gain unauthorized access through endpoints, companies must ensure that devices are updated with security programs and antivirus applications.
  • Operational Security: This involves identifying any potential vulnerabilities that could be exploited by a hacker.
  • Given the prevalence of phishing attacks and insider threats, cyber training for employees is of paramount importance for an organization's cybersecurity.

KEY QUOTE:

“In the end, cybersecurity fails when there's a lack of adequate controls and security readiness, and companies have to make smart strategic decisions when developing their controls and cybersecurity protections; and always focus on the human element, common mistakes, effectiveness of controls and vulnerabilities to hacker strategies to exploit any weaknesses.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Dare we imagine a world where companies are driven by their compliance obligations as much as they are by their financial performance? In a progressively interconnected and fast-paced digital world, compliance matters more than ever. Non-compliance can swiftly result in reputational damage, punitive fines, and compromised stakeholder trust. As such, more organizations are beginning to embrace the importance of having mature, robust compliance programs. This episode of Corruption, Crime, and Compliance with Michael Volkov dives into NAVEX's 2023 State of Risk and Compliance report. The report delivers a comprehensive overview of the global compliance landscape and sheds light on critical trends that are reshaping the field.

You’ll hear him discuss:

  • We've seen a substantial increase in organizations with mature compliance programs - 53% in 2023, compared to 38% in 2022. This is a testament to organizations worldwide waking up to the importance of compliance in their everyday operations.
  • The power of leadership: robust leadership support is crucial when it comes to fostering a thriving compliance program. Strong board and executive-level engagement have proven instrumental in driving these changes.
  • As the world becomes more digitized, cybersecurity threats have increased exponentially. Consequently, cybersecurity has skyrocketed to the top of compliance concerns, indicating how cyber threats and breaches have a far-reaching impact on organizations.
  • Compliance and information security professionals are coming together like never before. This internal partnership proves crucial in managing cybersecurity risks and ensuring the safety of organizational data.
  • The NAVEX report identified five high-stake risks that organizations should keep on their radar: cybersecurity, regulatory compliance, harassment and discrimination, anti-bribery and corruption, and diversity, equity, and inclusion. Addressing these will require diligence and strategic planning.
  • There has been a decline in middle management's commitment to compliance compared to 2022. This dip stresses the need for targeted interventions to maintain the integrity of the compliance culture.
  • From HR to IT, effective compliance necessitates collaboration across all levels and departments.
  • With growing compliance demands, organizations are realizing the importance of purpose-built solutions. These platforms help manage third-party risks, policy management, and provide ethics and compliance training, making them indispensable in the modern compliance toolkit.

KEY QUOTES:

“So 53% stated that their organization had a mature compliance program and risk management program and that was compared to only 38% in 2022. Now that to me is a really welcome sign.” - Michael Volkov

“I think perhaps the most significant finding in this area to me was that in recognition of the rising threat level from cybersecurity attacks, ransomware, data privacy ethics and compliance professionals are forging new and lasting internal partnerships with information security professionals.” - Michael Vokov

“Three quarters of respondents reported that senior leaders encourage compliance in the organization, and nearly as many report that senior leaders demonstrate their commitment to compliance to employees. So it's not just words, but it's words and actions. However, there was one troubling concern, and that was with respect to middle management. …So NAVEX reported a lower commitment compared to the 2022 report with regard to middle management commitment to compliance.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

NAVEX State of Risk and Compliance Report

View Details

In this eye-opening episode of Corruption, Crime and Compliance, Michael Volkov takes a deep dive into the world of healthcare compliance and fraud. He explores the history, the transformation, and the unique challenges of healthcare compliance. He also sheds light on the alarming rate of fraud in the healthcare industry and the efforts to combat it.

You’ll hear him discuss:

  • Compliance in healthcare traces back to the 1990s. Its rise is largely due to aggressive federal enforcement programs and increasing regulation.
  • Four significant trends in healthcare compliance include:
  • Rising consumer demand, escalating prices, and increasing regulation during the era of HMO controversies.
  • The DOJ's use of criminal tools and prosecutions to combat healthcare fraud and circumvent government regulations.
  • The growing importance of the False Claims Act as an enforcement tool.
  • The establishment of a robust regulatory enforcement regime through the Center for Medicare Services and the HHS-OIG.
  • As the healthcare industry comes increasingly under federal government regulation and control, the risks of healthcare fraud are escalating. Despite the development of proactive compliance programs, the industry struggles to keep pace with the level of fraud, waste, and abuse.
  • Beyond the traditional elements of compliance programs, the healthcare industry faces unique challenges. These include managing interactions with physicians, ensuring data privacy, avoiding the employment of ineligible persons, and navigating the complexities of billing, coding, and overpayments.
  • The False Claims Act poses a significant risk for healthcare providers, with nearly 99% of all cases each year immediately settled. The Act has been applied beyond billing and reimbursement issues to include false representations incorporated into a product or a drug.
  • The DOJ regularly conducts nationwide crackdowns on healthcare fraud, arresting numerous defendants involved in healthcare fraud and opioid abuse schemes. A growing area of concern is telemedicine fraud, which has seen a surge with the rise of remote work during the pandemic.

KEY QUOTES:

“Healthcare is becoming increasingly under federal government regulation and control. And as this occurs, the federal health care risks of fraud are going to be increasing significantly. Private insurance companies are also experiencing continuous growth of fraud and the healthcare industry is really developing proactive compliance programs, but they struggle to keep up with the level of fraud, waste and abuse that they sort of have to pursue.” - Michael Volkov

“…one of the most significant risk areas is physician interactions.” - Michael Vokov

“Nearly 99% of all False Claims Act cases each year where the government decides to intervene are immediately settled.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

The complex relationship between digital currencies and global financial regulations is highlighted yet again with the SEC’s recent crack down on major crypto exchanges Binance and Coinbase. Michael Volkov welcomes Matt Stankiewicz, also known as Crypto Max, to share his insight on these ongoing cases. He discusses the implications these enforcement actions might have on the industry, the securities law-related legal issues, and the internal mechanics of these exchanges.

Matt Stankiewicz is a Managing Counsel at The Volkov Law Group. His expertise includes financial regulation and compliance, with a focus on securities, anti-money laundering (AML), and cryptocurrency regulation. Given his professional background and interest in crypto regulations, he is a frequent speaker on legal matters concerning cryptocurrency exchanges and the SEC.

You’ll hear Michael and Matt discuss:

  • The SEC's enforcement actions hinge on their assertion that Binance was serving US customers without the proper registration, thereby violating securities laws. They allege that Binance knowingly allowed and even encouraged US customers to utilize their offshore platform, enhancing their profits and trading volumes but breaching US regulations in the process.
  • Rather than directly challenging the status of specific tokens, the SEC is targeting exchanges like Binance and Coinbase. By regulating these exchanges, the SEC could effectively control the access points to the crypto industry, thus having a broader impact.
  • Binance is preparing for a legal fight with the SEC over these compliance issues, including allegations of wash trading to artificially inflate trading volume. The platform's potential troubles are linked to similar issues faced by FTX and their trading arm, Alimator Research.
  • Given the recent pattern of the SEC bringing complaints without the DOJ pursuing criminal cases, it’s unlikely that the DOJ will bring a criminal case against Binance.
  • Coinbase's IPO was approved by the SEC despite allegations that the company had engaged in illegal activities related to the trading of unregistered securities. The SEC argues that the approval of an IPO doesn't guarantee the legality of the company's underlying operations, but this could be seen as contradictory to the SEC's stated role of protecting investors.
  • Coinbase, in attempting to comply with securities regulations and being continuously rebuffed by the SEC, is the most compliant cryptocurrency exchange. However, should the SEC crack down on Coinbase and other major U.S. exchanges, it could push investors to offshore exchanges where the SEC has limited jurisdiction and where there is a higher risk of fraud.

KEY QUOTES

“The SEC is taking obvious actions to show that they are very aggressive in their enforcement actions.” - Matt Stankiewicz

“This is a perfect reminder for everyone listening, whether you're into crypto or not. If you are working internally with your email or you're in [a] corporate chat, that can all be discoverable in future litigation. And you need to be careful what you say.” - Matt Staniewicz

“It is a very poor look in the court of public opinion for the SEC to stand on the ground of saying, ‘We are here to protect investors,’ but [avoid] stopping this before investors have a chance to throw all their money in that IPO.” - Matt Stankiewicz

Resources

Matt Stankiewicz on LinkedIn

View Details

Unprecedented changes are imminent in sanctions and export control enforcement, as the U.S. government amplifies its focus on national security and corporate compliance. On this episode of Corruption, Crime and Compliance, Michael Volkov discusses the potential consequences of these developments. He dissects the “new FCPA”, the Department of Justice’s (DOJ) strategic approach, the critical role of sanctions and export control enforcement, and the intricacies of voluntary disclosure programs.

You’ll hear Michael talk about:

  • A significant shift is occurring in the DOJ's enforcement focus, with 75% of criminal cases against corporations now related to national security matters, including sanctions enforcement, money laundering, and terrorism.
  • The DOJ will collaborate with OFAC and BIS in a similar manner to the relationship between the DOJ and the SEC during FCPA enforcement.
  • Corporate resolutions are set to increase drastically, with steep penalties, deferred prosecution agreements, guilty pleas, and a surge in individual prosecutions. Heightened compliance expectations around export controls and sanctions compliance will necessitate a ramp-up of relevant compliance programs.
  • The enforcement actions will serve as guidance, similar to the initial stages of FCPA enforcement, providing cues about the DOJ's view on compliance and their expectations from compliance programs.
  • The DOJ plans to ramp up enforcement against global banks, investing heavily in the Bank Integrity Unit which is part of the anti money laundering operations for global banks, and sanctions enforcement.
  • The DOJ has forewarned corporations about the enforcement emphasis on sanctions and export controls. DOJ has ongoing investigations in various sectors including transportation, fintech, banking, defense, and agriculture.
  • Voluntary disclosure programs, such as those from OFAC and the National Security Division, play a significant role in mitigating enforcement actions. However, choosing between OFAC and DOJ disclosure can present a nuanced dilemma for corporations, hinging on whether a violation is willful. The number of voluntary disclosures involving both is expected to increase as corporate enforcement actions rise.
  • The case against British American Tobacco by DOJ and OFAC for illegal sales of cigarettes to North Korea, resulted in a combined penalty of $629M. This is a significant instance of enforcement action against a non-financial institution.
  • The Bureau of Industry and Security (BIS) and the Department of Commerce brought a case against Seagate Technology, resulting in a $300 million settlement. The DOJ seems to be investigating this matter further due to Seagate's blatant violations.
  • A case against Murad, a cosmetics company, was brought by OFAC for Iran sanctions violations worth approximately $11 million. Murad ended up paying a $3.3M fine. Murad's actions highlight the importance of sanctions compliance guidance and the significance of due diligence, especially during acquisition processes.
  • OFAC's enforcement action against Murad also emphasized the importance of having a local compliance structure when a foreign parent company is involved.
  • OFAC also stressed on the importance of pre- and post- acquisition due diligence and audits when acquiring companies. The failure to perform such activities may lead to unidentified sanctions issues, as illustrated in the Murad-Unilever case.
  • We may see larger fines against non-financial institutions in the near future, surpassing the current record of $508 million, indicating an uptick in enforcement actions.

KEY QUOTE:

"OFAC announced a separate civil settlement for $508M, which is the largest fine against a non-financial institution in OFAC's history. And that's what we're going to be seeing. Largest fines against the non-financial institution will eclipse $508M probably in the next couple of years." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

“This [Murad OFAC] enforcement action reflects the fact that OFAC, in recognition of the increasing seriousness of sanctions enforcement, is taking more time to provide guidance through some of their enforcement actions,” Michael Volkov tells listeners. In this episode of Corruption, Crime and Compliance, Michael unpacks the recent enforcement action by OFAC against California-based cosmetics company, Murad. He offers detailed insight into the case, going beyond the headlines and examining the underlying issues that led to the violations, and drawing out key compliance lessons.

You’ll hear Michael talk about:

  • The Murad enforcement action is significant because it highlights OFAC's increasing focus on sanctions enforcement and the need for global sanctions compliance organizations to have strong local oversight.
  • Over an eight-year period, Murad illegally exported goods and services to Iran in 62 transactions worth approximately $11 million. The company and a former senior executive were penalized, paying $3.3 million and $175,000 respectively.
  • OFAC acknowledged Murad's voluntary disclosure of the conduct but still categorized the violations as egregious.
  • The conspiracy involved an exclusive agreement to sell Murad's products in the Middle East, including Iran, and continued even after Murad's acquisition by Unilever.
  • The key compliance deficiencies cited by OFAC: These include absence of a specific sanctions compliance program, participation of high-level executives in illegal conduct, and lack of understanding of OFAC sanctions by staff based in the United Kingdom.
  • OFAC emphasizes the need for senior management to commit to a culture of compliance and advises against placing a U.S. entity under the compliance structure of a non-U.S. entity that may lack familiarity with U.S. sanctions.
  • Unilever's failure to uncover Murad's ongoing contracts with Iran demonstrates the need for robust due diligence and integration processes during acquisitions.

KEY QUOTES:

“OFAC specifically cited that, ‘In some circumstances, placement of a US entity under the compliance structure of a non-US entity that may lack familiarity with US sanctions could prevent prompt identification of and response to potentially prohibited conduct’. In other words, you have to have local boots on the ground, you have to have sanctions expertise in your US operations even though you're owned by a foreign global company." - Michael Volkov

"It's important to have people dedicated to the OFAC sanctions compliance process and to make sure that expertise is available to the business within the United States." - Michael Volkov

"To this end, OFAC stated that senior executives with managerial responsibilities should take particular care to ensure awareness of applicable prohibitions and refrain themselves from engaging in sanctions violations. " - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Koninklijke Philips manipulated tender processes for medical imaging equipment in China, which resulted in a substantial $62 million fine. On the other hand, Frank's International paid an $8 million settlement for its FCPA violations in Angola, involving questionable commissions to a sales agent. These two cases serve as potent reminders of the risks and challenges that global companies encounter in today's globalized economy, especially when dealing with high-risk countries such as China and Angola. They underline the need for robust ethics and compliance programs, vigilance against bribery and corruption, and strict adherence to local and international laws. In this episode of Corruption, Crime and Compliance, Michael Volkov uncovers the details of these cases that underline the risks and challenges faced by global companies in the contemporary economy.

You’ll hear Michael talk about:

  • Koninklijke Philips, a Dutch multinational corporation, was penalized with a $62 million fine for contriving multiple schemes to manipulate tender processes for medical imaging equipment in China.
  • These schemes included strategies like the manipulation of technical specifications, creation of counterfeit bids, and direct payments to state-owned hospital officials in China to restrict competition.
  • Frank's International, an oil and gas company, paid an $8 million settlement for FCPA violations in Angola. The company had been paying commissions to a sales agent in Angola, knowing there was a high likelihood that these funds would be used to bribe government officials.
  • Frank's International exhibited a lack of adequate internal accounting controls during this time period. This oversight permitted corrupt practices to proceed undetected.
  • Angola requires international companies to engage with local businesses. In Frank's case, this was used as a cover to facilitate bribery payments.
  • Frank's International was informed by a senior Sonangola executive that a restriction against them could be lifted if Frank's established a separate consulting company benefiting a high-ranking Sonangola official and offered 5% of the contract value to this company.
  • The cases highlight how crucial it is for companies operating in high-risk countries, such as Angola and China, to have comprehensive ethics and compliance programs in place.
  • These programs must be able to detect and prevent bribery schemes, manipulation of tender processes, and similar malpractices.
  • The financial records of these companies must accurately represent all transactions and should be reviewed regularly to detect and rectify discrepancies.
  • Companies should maintain a cooperative attitude with regulatory authorities, report potential violations, and take remedial actions for any identified issues.

KEY QUOTES:

"Koninklijke Philips played a dangerous game manipulating tender processes in China. The $62 million fine they paid is a stark reminder of the consequences." - Michael Volkov

"Frank's International's $8 million settlement is a potent example of what can happen when companies ignore the necessity of robust internal accounting controls." - Michael Volkov

"Operating in high-risk countries demands more than just good business sense. It requires stringent ethics and compliance programs to prevent disastrous legal and economic consequences." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Is your business prepared to effectively manage and mitigate the risks associated with sanctions compliance in today's global economic landscape? In today's increasingly interconnected global economy, sanctions compliance is more critical than ever. Companies around the world face complex regulatory environments and unprecedented risks, requiring a comprehensive and proactive approach to sanctions compliance. In this episode of Corruption, Crime and Compliance, Michael Volkov explores the pressing need to elevate corporate sanctions compliance programs, as well as the renewed focus on enforcement by the Department of Justice, and the practical steps every company must take to meet these evolving challenges head-on.

You’ll hear Michael talk about:

  • Companies must enhance their sanctions compliance programs. Basic programs that simply rely on screening tools are no longer sufficient. Companies need to incorporate comprehensive measures to ensure compliance with evolving sanctions laws.
  • The Department of Justice (DOJ) has escalated the enforcement of national security crimes, demonstrating a renewed focus on sanctions compliance. This shift necessitates a proactive response from companies to mitigate potential risks.
  • The OFAC has outlined five crucial elements for an effective sanctions compliance program: management commitment, risk assessment, internal controls, testing and audit, and training. Companies should familiarize themselves with these elements and incorporate them into their existing compliance programs.
  • Risk assessment is a crucial first step in compliance. Companies must review their operations holistically, assessing all touchpoints with international markets to identify potential vulnerabilities and risks.
  • Geoblocking technology is a valuable tool in sanctions compliance. Working with IT departments to develop comprehensive geoblocking capabilities can help prevent interactions with prohibited individuals or entities.
  • Thorough screening and due diligence processes are imperative, moving beyond just the results of screening tools. This ensures that companies identify and mitigate potential risks associated with sanctioned entities or countries.
  • Companies must implement effective escalation controls to ensure that any red flags identified through screening or due diligence are properly addressed and resolved.
  • End-user verifications and documentation are critical components of a robust sanctions compliance program. These procedures help ensure that the company's products or services are not being used by sanctioned entities.
  • Annual training for employees and personnel is essential. Tailoring this training to the company's specific risk profile ensures that all staff understand their responsibilities and the potential risks associated with non-compliance.

KEY QUOTES:

"Your company's survival may depend on your ability to navigate sanctions compliance in an increasingly complex global economy." - Michael Volkov

"It's not just about checking boxes. We have to understand our touchpoints to the international markets and assess the potential risks. That's the foundation of an effective compliance program." - Michael Volkov

"Training isn't a one-and-done task. It's an ongoing commitment to ensure our personnel understand and can navigate the complex world of sanctions compliance." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Cryptocurrency has become a popular way to invest and transact, but with that comes the need for sanctions compliance. In this episode, Michael Volkov and Matt Stankiewicz discuss the recent enforcement actions against Poloniex, Bittrex, and Kraken for violating US sanctions regulations with cryptocurrency transactions. Matt is a Partner at Volkov Law and a leading cryptocurrency expert. He and Michael dive into the common themes and basic failures that led to these enforcement actions, including IP blocking, transaction monitoring, and the use of screening tools. They also explore the challenges of compliance when dealing with regions like Crimea and Ukraine, as well as the importance of voluntary disclosure.

You’ll hear Michael and Matt talk about:

  • Cryptocurrency companies are struggling to implement KYC and geo-blocking controls, which is leading to violations involving sanctioned jurisdictions.
  • OFAC is taking an aggressive stance against cryptocurrency companies. Companies in the cryptocurrency industry need to implement effective sanctions compliance programs to avoid hefty fines and enforcement actions from regulatory authorities.
  • There is no materiality requirement for sanctions violations, and even small transactions can result in multimillion-dollar fines.
  • Retroactively applying controls to existing customers is important, and failing to do so can lead to violations.
  • Companies need to have a comprehensive and automated system in place to detect and prevent violations.
  • Companies need to be vigilant about screening individuals and transactions against the relevant sanctions lists, including screening field text, addresses, and ID cards.
  • Geo-blocking for IP addresses is a crucial compliance control, but it is not perfect and can be circumvented by VPNs.
  • Voluntary disclosure of violations can lead to more favorable outcomes and lower fines from regulatory authorities.
  • OFAC and other regulatory authorities are using analytical tools to monitor transactions and flag potential violations, so cryptocurrency companies should not assume they can go under the radar.
  • Companies can use the public blockchain to monitor transactions and identify potential sanctions risks.
  • Sanctions compliance programs should be regularly reviewed and updated to address new risks and changes in regulations.

KEY QUOTES

"There are a lot of tools available to these companies to monitor transactions, maybe better than in the traditional finance world, just because everything on the blockchain is public record essentially." - Matt Stankiewicz

"It's just interesting to see OFAC go so aggressively against these companies. Not too surprising considering the extreme sanctions risk that cryptocurrency poses. Very importantly, there's still a lot of takeaways that really any industry can take away from these enforcement actions." - Matt Stankiewicz

"If you find problems, obviously you want to remediate them, but figure out what you need to do in terms of voluntary disclosures, because typically you'll be much better off than if OFAC figures it out on their own, which they usually do." - Matt Stankiewicz

Resources:

Matt Stankiewicz on LinkedIn | Twitter

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

British American Tobacco (BAT) recently settled for $629 million for violating North Korea sanctions. This sends a clear message from the Department of Justice that enforcement against companies is the new FCPA. The settlement resulted from BAT's continued control of a joint venture in North Korea through a third-party company and its subsidiary's willful conspiracy to transfer hundreds of millions of dollars through US banks, which were aware that the transfers were blocked by US sanctions. In this week's episode of Corruption, Crime and Compliance, Michael Volkov delves into the facts of this important enforcement action and discusses the elaborate use of front companies and attempts to disguise North Korean connections, confirming the DOJ's new aggressive approach to sanctions and export enforcement.

You’ll hear Michael discuss:

  • Compliance professionals should review the BAT scheme for its elaborate use of front companies and attempts to disguise North Korean connections.
  • BAT controlled a joint venture in North Korea through a third-party company. Its subsidiary willfully conspired to transfer hundreds of millions of dollars through US banks while being aware that the transfers were blocked by US sanctions. This resulted in a $629 million settlement.
  • OFAC imposed a $508 million penalty against BAT, the largest fine against a non-financial institution in OFAC's history. This is equal to the statutory maximum that they would have been allowed to collect.
  • Cigarette trafficking generates significant revenue for North Korea's WMD program. Smuggled tobacco products generate a profit of 1900%.
  • Senior management needs to drive a culture of compliance and put relevant policies and controls in place to reduce the risk of engaging in violative conduct.
  • BAT's senior management decisions to approve or support arrangements that obscure dealings with sanctioned countries and parties were reflected throughout the organization, compounding sanctions risks and increasing the likelihood of committing potential violations.

KEY QUOTES:

"British American Tobacco's deceit and elevation of business over compliance permeates this blockbuster settlement for $629,000,000. The BAT settlement really confirms DOJ's new, aggressive approach to sanctions and export enforcement." - Mike Volkov

"Cigarette trafficking generates significant revenue for North Korea's WMD program. In addition, counterfeit cigarettes are a major source of income to the North Korean regime, since smuggled tobacco products generate revenue of up to $20 for every dollar spent in cost." - Mike Volkov

"OFAC noted that this enforcement matter demonstrates that without a culture of compliance driven by senior management and attendant policies and controls, firms increase the risk that they may engage in apparently violative conduct." - Mike Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Corporate culture is the most valuable intangible asset that a company owns. In this week's episode of Corruption, Crime and Compliance, Michael Volkov discusses the importance of corporate culture for ethics and compliance programs. He emphasizes the need for business leaders to understand the significance of corporate culture on the ground level and outlines steps and tasks needed to build and maintain a positive culture.

You’ll hear Michael discuss:

  • Corporate culture is an embodiment of a company's values and interactions with key stakeholders. Every company has a distinct culture that defines its purpose and motivations.
  • Senior leadership plays a critical role in embedding the culture and enforcing the message. Managers and employees take their cues from corporate leaders.
  • Companies have to hold leaders accountable for wrongdoing or failure to supervise. Leaders who promote ethical cultures should be rewarded, while those who engage in misconduct should suffer discipline up to termination and recoupment of financial benefits.
  • Transparency and publicizing corporate rewards and discipline are crucial to building trust, increasing employee engagement, and promoting a positive culture. A company's most significant reflection of its culture is employee perception and rates of misconduct.
  • CCOs have to redefine their media tasks and responsibilities to reflect the emphasis on corporate culture. They have to define specific ways to measure a company's culture, regularly report on these measures, and monitor indicators of culture misconduct, reporting issues, financial concerns, and HR issues.
  • Monitoring, intervention, and remediation require a real-time focus and constant questioning of trends, interventions, and measurement of results.
  • Working collaboratively with HR, legal, and finance can bring about real culture improvements with a joint mission focused on ethics and compliance.

KEY QUOTES

"Your corporate culture, your culture of ethics and compliance is your best control. It's your most effective and most important control, and it's your most valuable intangible asset." - Michael Volkov

"A robust reporting system with active participation is a positive, not a negative, reflection of a company's culture." - Michael Volkov

"Companies that wait for a scandal to occur before acting have failed to do their job. Proactive compliance means prevention and focusing on your company's culture." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Microsoft recently paid over $3 million for multiple sanctions violations involving illegal exports of services and software to sanctioned jurisdictions. The violations spanned seven years and involved prohibited Russian entities or persons located in the Crimea region of Ukraine. However, what makes this case particularly intriguing is the remedial actions taken by Microsoft, which offer best practices and insights into what can be done when resources are available. In this week's episode of Corruption, Crime, and Compliance, Michael Volkov takes a deep dive into the Microsoft OFAC enforcement action.

He discusses these ideas:

  • Microsoft committed 1339 transactions in violation of multiple sanctions programs over seven years, totaling over $12 million worth of sales and services.
  • Violations included the sale of software licenses and the provision of related services from servers and systems located in the US and Ireland to SDNs, blocked persons, and other end users located in Cuba, Iran, Syria, Russia, and the Crimea region of Ukraine.
  • The violations were due to Microsoft's failure to obtain complete or accurate information on the identities of end customers and shortcomings in its restricted party screening. At times, Microsoft Russia employees intentionally circumvented Microsoft screening controls to prevent other Microsoft affiliates from knowing the identity of the ultimate end customers.
  • Microsoft's significant remedial measures included enhancing its trade compliance program, improving its governance structure and screening resources, adopting a new three lines of defense model, and conducting a holistic risk assessment to identify and remediate instances of prohibited engagements.
  • Microsoft deployed a multidisciplinary internal investigation team proficient in 16 foreign languages, modified its procedures to respond to matches, and expanded the scope and volume of data screened.
  • “Companies with sophisticated technology operations and a global customer base should ensure that their sanctions compliance controls remain commensurate with risk.”
  • Companies should consider conducting a holistic risk assessment to identify and remediate prohibited engagements and ensure that employees adhere to the sanctions compliance program.
  • OFAC emphasized that companies conducting business through foreign-based subsidiaries, distributors, and resellers should have sufficient visibility into their end-users, including through the provision of services after an initial sale.

KEY QUOTES:

"Now, when Microsoft supported these third-party sales to prohibited parties, they provided prohibited software and services to SDNs and end customers in sanctioned jurisdictions, and the violations occurred. The root cause really was because Microsoft did not have complete or accurate information on the identities of the end customers for Microsoft's products." - Michael Volkov

"Companies with sophisticated technology operations and a global customer base should ensure that their sanctions compliance controls remain commensurate with that risk and leverage in appropriate technological compliance solutions." - Michael Volkov

"Testing or auditing, whether conducted on a specific element of a compliance program or enterprise-wide level, are important tools to ensure that the program is working as designed and weaknesses are promptly remediated." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

The relationship between compliance and HR can make or break a company's culture of ethics and integrity. The DOJ’s revised Evaluation of Corporate Compliance Program requirements are pushing for greater cooperation and coordination between these two departments to create a robust and effective consequence management system. In this episode, Michael Volkov discusses the implications of these new requirements and emphasizes the need for HR and compliance to work together to achieve a culture of compliance and ethics.

Here are some key ideas you’ll hear Michael discuss in this episode:

  • The Justice Department is taking a prescriptive approach to mandating greater cooperation between compliance and HR, as there have been too many problems between these departments in the past.
  • HR and Compliance have joint responsibilities and obligations to achieve a culture of compliance and ethics.
  • An effective HR and compliance partnership can leverage resources to ensure the overall advancement and success of the company.
  • Companies must comply with the DOJ's revised Evaluation of Corporate Compliance Programs and provide compliance with access to data generated across the organization. This is necessary to improve the effectiveness of the company's compliance program.
  • DOJ is now requiring companies to maintain a robust and enhanced investigation root cause system to address the specific elements required for a culture of ethics and integrity.
  • An effective consequence management system can only occur when there is active cooperation and effective coordination between HR and compliance.
  • The new consequence management system includes financial penalties resulting from clawbacks and deferred compensation schemes that are tied to compliance behaviors and requirements.
  • DOJ is focusing on incentives and disincentives to enhance individual compliant conduct and overall accountability. Positive incentives include promotions, rewards, and bonuses and disincentives include deferment or escrow of compensation. CCOs need to champion the creation of this system.
  • CCOs must be seated at the senior executive level of business operations to fulfill DOJ's expectations for overall consequence management in the disciplinary area.
  • Companies should consider cross-assignments of business managers to compliance and vice versa to promote career opportunities.
  • “I have always advocated on behalf of a committee approach or some kind of independent, objective reviewer or the institution that metes out disciplinary actions to ensure consistency,” Michael says.
  • Senior management must establish a framework for effective coordination and cooperation between HR, senior sales executives, legal, and compliance to achieve a culture of ethics and integrity.
  • This framework should be empowered to work on behalf of the company to establish organizational justice.

KEY QUOTES:

"The Justice Department is now taking on the role of marriage counselor, not with individual couples, but with the critical corporate relationship - Ethics and Compliance and Human Resources." - Michael Volkov

"With regard to disciplinary actions, there's nothing worse, folks, than a disciplinary system that treats similarly situated employees and executives in different ways based upon where they sit or what their sales performance is… Justice has to be blind and consistent here." - Michael Volkov

"Organizations that throw large contingent payouts for lucrative business contracts or for hitting specific targets should consider the impact of these incentives on sales employees and their ability and incentive to adhere to ethical requirements." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

Evaluation of Corporate Compliance Programs

View Details

Wells Fargo has settled with OFAC for $30 million for sanctions violations that occurred during a seven-year period from 2008 to 2015. The violations stemmed from its acquisition of Wachovia Bank, which had a trade relationship with a European bank that conducted transactions involving sanctioned entities and individuals. Despite concerns raised internally, Wells Fargo failed to exercise caution or care in identifying and preventing such transactions. The case serves as a reminder of the importance of corporate culture of ethics and compliance. In this episode of Corruption, Crime, and Compliance, Michael Volkov takes a deeper dive into the issue and outlines the missteps that occurred; he also gives practical advice for companies to avoid the same mistakes.

You’ll hear him discuss these key ideas in this episode:

  • Wells Fargo has a lengthy record of misconduct and failures to remediate. Its latest enforcement action involves a $30 million settlement with OFAC for sanctions violations that occurred from 2008 to 2015. These violations include three separate OFAC sanctions involving Iran, Sudan, and Syria.
  • Wells Fargo provided the European bank with trade finance software that was customized and used to conduct transactions that involved sanctioned entities and individuals, despite concerns raised internally on several occasions.
  • OFAC found that “Wells Fargo demonstrated reckless disregard for US sanctions requirements …and failed to exercise a minimal degree of caution or care in failing to identify and prevent such transactions for seven years after it acquired Wachovia…”
  • Wells Fargo's conduct highlights the importance of corporate culture of ethics and compliance.
  • Companies must have proper oversight when pursuing new business opportunities or preserving existing business relationships, and must promptly investigate and address sanctions compliance risks when raised internally, even in non-core business lines.
  • Comprehensive due diligence regarding potential sanctions risks is necessary when one entity acquires another through merger or acquisition.
  • Aside from this part of Wells Fargo's operations, the overall bank had a strong sanctions compliance program.
  • If Wells Fargo had invested in a culture of compliance, it could have turned around its organization with wholesale change and a real commitment to embedding, monitoring, and remediating its culture as needed.
  • The case serves as a reminder that companies must have a speak-up culture and respond to concerns as they are raised, as well as the importance of corporate culture, ethics, and compliance.

KEY QUOTES:

"If Wells Fargo had reduced its outside legal consulting and professional expenditures by half and took the money to invest and implement a culture of compliance, you can rest assured that Wells Fargo would be able to turn around its organization." - Michael Volkov

"Moreover, when sanctions compliance risks are raised internally, including concerns arising from smaller, non-core business lines, companies should promptly seek to thoroughly investigate and address those risks." - Michael Volkov

"Wells Fargo's conduct here, when exposed and considered, is not just inexplicable, but reminds all of us on the importance of corporate culture of ethics and compliance." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

The world of FCPA enforcement is always changing, and in this episode of Corruption, Crime and Compliance, Michael Volkov catches us up on three recent enforcement actions. From Corsa Coal's rare declination to SEC settlements with Flutter Entertainment and Rio Tinto, each case offers important insights into the current state of FCPA enforcement. He shares how voluntary self-disclosure, appropriate due diligence processes, and enhancements to compliance programs and accounting controls can help companies avoid penalties and strengthen their position.

You’ll hear Michael discuss these ideas:

  • Companies are encouraged to voluntarily self-disclose bad behavior to the DOJ, which may result in a declination and significant reductions in penalties.
  • Corsa Coal earned a rare declination from the DOJ after cooperating in the prosecution of two former executives and meeting their burden to establish inability to pay. Their disgorgement was significantly reduced from $31 million to $1.2 million.
  • Flutter Entertainment, which acquired PokerStars, was fined $4 million by the SEC for improper payments to Russian-based consultants made by Stars Group, its previous owner. Stars Group failed to conduct due diligence or maintain appropriate written contracts for third parties, leading to bribery violations.
  • Acquiring companies should conduct appropriate due diligence on the acquired company's FCPA compliance.
  • Rio Tinto paid $15 million to settle FCPA violations arising from a bribery scheme involving a senior Ghanaian government official. Despite red flags indicating that the consultant was advising the Ghanaian official and preserving Rio Tinto's ability to operate in Guinea, Rio Tinto eventually approved two lump sum payments totaling $10.5 million.
  • Companies should pay attention to red flags when paying high commissions to sales agents involved in extractive industries.
  • Rio Tinto implemented enhancements to their compliance programs and accounting controls after FCPA violations.

KEY QUOTES:

"As part of DOJ's push on voluntary self-disclosures in changes to its corporate enforcement policy, they really are encouraging companies to come in and voluntarily disclose when they find bad behavior." - Michael Volkov

"...when acquiring a company, you've got to conduct due diligence and make sure that you do not find any FCPA violations or any problems like that." - Michael Volkov

"Rio Tinto strengthened its ethics and compliance organization, enhanced its code of conduct, as well as its policies and procedures, gifts and hospitality, due diligence, and use of third parties. In addition, Rio Tinto enhanced its whistleblower program and improved its monitoring systems and internal controls related to payments to third parties. Finally, Rio Tinto enhanced its anti-corruption risk assessments and transactions testing and increased training of employees and third parties." - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

The Justice Department is raising the bar on corporate compliance, and Michael Volkov believes we are witnessing a watershed moment. In this episode of Corruption, Crime and Compliance, he explains the significant revisions to the evaluation of corporate compliance programs, the new corporate enforcement policy, and the criminal division's three-year pilot program on compensation incentives and clawbacks.

Some of the ideas discussed in this episode include:

  • DOJ is raising expectations for corporate compliance programs and incentivizing ethical behavior.
  • Companies must implement effective employee reporting systems, conduct timely internal investigations, and hold bad actors and weak supervisors accountable for their failures.
  • DOJ is frustrated with the lack of cooperation between HR and compliance departments and seeks to promote a new era of compliance cooperation and operationalization.
  • The evaluation of corporate compliance programs now includes a new section entitled Compensation Structures and Consequence Management, which mandates the design and implementation of compensation schemes to foster a compliance culture.
  • DOJ's three-year pilot program for corporate compensation systems and clawbacks aims to reduce the burden on corporate shareholders and punish individual wrongdoers.
  • Companies need to bring together senior leadership, business leaders, legal and compliance, and human resources to build together a set of incentives, disincentives and other structural changes to promote an ethical culture of compliance.
  • DOJ expects companies to implement an effective employee reporting system. The updated guidelines provide specific guidance on how that reporting system ties into the overall advancement of the corporate culture, timely internal investigations, careful root cause analyses, and a new term consequence management.
  • Companies can earn a fine reduction when they seek to recoup compensation from culpable employees, and prosecutors will have discretion in how to fashion the requirements for the compliance-related compensation and bonus systems.
  • DOJ's new policy includes important requirements for preservation of data from messaging applications and texting systems, and companies need to tailor communications data preservation policies to the specific risk, profile, and needs of their business.

KEY QUOTES:

"DOJ's intent here is just unmistakable. Companies have to monitor, detect, and prevent future wrongdoing, and they have to hold bad actors and weak supervisors accountable for their failures." - Michael Volkov

"To the extent that compliance and HR departments fail to coordinate and fight over turf, companies will face increased risks of a defective ethics and compliance program, employee misconduct rates will rise, and government investigation risks will rise as well." - Michael Volkov

"Finally, with respect to risk management, companies have to ensure that they are appropriate consequences to executives and employees who fail to comply with communications and data preservation requirements. " - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

In this insightful solo episode of Crime, Corruption, and Compliance, host Michael Volkov delves into the details of the first-of-its-kind Joint Compliance Note (JCN) regarding the evasion of Russia sanctions and export controls. This noteworthy document has been jointly issued by the United States Justice Department, the Department of Commerce, and the Treasury Department, highlighting its significance in the world of compliance.

Throughout the episode, Michael explores the critical red flag lists, government expectations, and alerts to common high-risk scenarios provided by the JCN, emphasizing the crucial role it plays in guiding organizations through potential compliance challenges. With the U.S. Russia Sanctions and Export Control Program being unprecedented in its scope and complexity, Michael sheds light on the challenges faced by trade compliance officers and the steps organizations can take to mitigate risks.

Key ideas you’ll hear in this episode:

  • The JCN is an essential resource for compliance professionals, detailing red flags and tactics used by organizations and individuals to evade applicable sanctions and export controls.
  • The joint issuance of this document by DOJ, OFAC, and BIS highlights the importance placed on organizations to implement and maintain risk-based compliance programs.
  • Third-party intermediaries and transshipment points are often exploited to disguise the involvement of specially designated nationals (SDNs) or parties on the BIS entity list in transactions, obscuring the true identities of end-users.
  • The JCN provides an invaluable list of red flags to watch for if a company suspects that a customer is using a third party to evade sanctions or export controls, with real-world examples for context. Some of the red flags to watch out for include:
  • Use of corporate vehicles, such as shell companies, to obscure ownership, source of funds, or countries involved.
  • A customer's reluctance to share information about the end use of a product.
  • Use of shell companies for international wire transfers.
  • Declining customary installation, training, or maintenance services.
  • Mismatched IP addresses that do not correspond to a customer's reported location data.
  • Last-minute changes to shipping instructions contrary to customer history or business practices.
  • Payments coming from a third-party country or business not listed on the end-user statement.
  • Use of personal email accounts instead of company email addresses.
  • Operation of complex and/or international businesses using residential addresses or addresses common to multiple closely held corporate entities.
  • Changes to standard letters of engagement that obscure the ultimate customer.
  • Transactions involving a change in shipments or payments previously scheduled for Russia or Belarus.
  • Transactions involving entities with little or no web presence.
  • Routing purchases through certain transshipment points commonly used to illegally redirect restricted items to Russia or Belarus.
  • In the face of potential violations, companies are encouraged to utilize voluntary disclosure programs maintained by DOJ, OFAC, and BIS.
  • Compliance and trade compliance professionals should review the JCN thoroughly to ensure overall trade compliance and be ready to conduct additional due diligence when confronted with any red flags.

KEY QUOTES:

"When multiple red flags come up, organizations are expected to screen the entities and persons involved and then conduct additional risk-based due diligence on customers, intermediaries, and counterparties." - Michael Volkov

"In other words, not only do you need to screen, but they're going to require you, and they're going to second guess you on the issue of whether you should have done additional due diligence. And that's important." - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

In this episode of the Crime, Corruption, and Compliance podcast, host Michael Volkov dives into the Ericsson FCPA Deferred Prosecution Agreement breach settlement. The case highlights important issues with conducting internal investigations, corporate culture, and dealing with the Justice Department in the event of a breach. The episode delves into the details of the case, discussing the lessons learned from this massive failure and nightmare scenario with regard to disclosures, and how it serves as a cautionary tale for all investigators, whether conducted by internal staff or outside counsel.

Here are some key ideas discussed in this episode:

  • Ericsson, the Swedish telecom company, breached its 2019 Deferred Prosecution Agreement and agreed to enter a guilty plea to the original charges in the DPA and pay a $206M penalty.
  • The breach was primarily due to Ericsson's failure to disclose its bribery payments or potential bribery payments to ISIS to facilitate transportation of telecom equipment in Iraq.
  • Ericsson used third-party agents and consultants to pay bribes to government officials in a number of countries to manage slush funds.
  • Ericsson's failures have undermined the integrity of its corporate commitment to compliance and ethical culture, damaged its reputation, and threatened its relationship with the Justice Department and overall government regulators.
  • The breach prevented the DOJ from bringing criminal charges against certain individuals and harmed the US's ongoing criminal investigation.
  • Ericsson's breach presents a laundry list of internal investigation errors, such as a failure to produce responsive documents for many years, omitting key details related to its investigative findings, and a lack of fundamental culture improvements.
  • Ericsson has significantly enhanced its compliance program and internal accounting controls through structural and leadership changes, including hiring a new Chief Legal Officer and Head of Corporate and Government Investigations.
  • The DOJ's calculation of the criminal penalty was for just over $727,000,000, reflecting the midpoint of the applicable guideline range, and Ericsson will be required to serve a term of probation, which can be revoked for further violations found.
  • Ericsson agreed to continue to enhance its program and to test these enhancements for effectiveness.
  • Ericsson's violations were pervasive and systemic, reflecting a rotten culture that promoted bribery as a means to make money.
  • Failures to disclose by outside counsel partially reflect failures of senior leadership responsible for oversight and direction of outside counsel.
  • Outside counsel must establish an effective working relationship with transparency, coordination, and full disclosure.
  • Senior executives must engage with outside counsel at each and every step of the investigation to check on the overall process.
  • The failure to produce certain documents underscores the need for a document retention policy.

KEY QUOTES:

"This breach really presents a laundry list of internal investigation errors. ...It is a cautionary tale for all investigators, whether conducted by internal staff or outside counsel." - Michael Volkov

"The failures to disclose, in my view, partially reflect failures of various actors, including outside counsel, but also senior leadership." - Michael Volkov

"Its culture was rotten, and it promoted bribery as a means to an important end that is just making money." - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

The contract to invoice to payment process may seem like a small part of a larger process, but it's at the core of many enforcement issues, particularly when it comes to the FCPA. In fact, we've seen some important cases that have highlighted the critical nature of this process, including the Oracle case from last year. This episode of Crime, Corruption and Compliance is not just a review of the FCPA, but rather an in-depth exploration of how companies can implement effective internal controls around their financial operations, and avoid potential problems that can arise from breakdowns in this process. I dive into the details of this important topic so you can learn how to build an effective control environment for your company's financial operations.

These are some key ideas I discuss in this episode:

  • Internal controls are critical to preventing fraud and corruption and must be established and maintained to ensure the proper use of corporate assets.
  • The accounting provisions of the FCPA include the books and records provision and the internal controls provision, which require issuers to keep accurate and detailed records of their transactions and maintain a system of internal accounting controls.
  • The contract to invoice to payment process is a key area where breakdowns in internal controls can occur, leading to illegal payments and bribery risks.
  • A robust due diligence process is required to confirm the ownership, legal compliance, reputation, and other important factors of potential vendors and suppliers.
  • Accounts payable and accounts receivable personnel are critical frontline actors in the procurement to pay process and should be trained in compliance to mitigate risks and elevate red flags when necessary.
  • The coordination and communication between finance, procurement, and compliance functions is crucial to establishing effective controls and preventing potential high-risk situations.
  • Contract and purchase order management systems should be established to link the contracting and purchasing process with invoicing and payment, ensuring proper review and verification of invoices and payments.
  • Invoicing and payment processes should be closely monitored and authorized in accordance with contractual and purchase order terms to avoid unauthorized use of corporate assets and reduce bribery risks.
  • Compliance programs should include a monitoring program and transaction testing program to regularly review and test the effectiveness of internal controls in the procurement to pay process.

KEY QUOTES:

“Compliance has to push their way into the environment here and start to take some responsibility for transaction testing, for monitoring, for partnerships related to high value or high-risk third parties, to make sure that we're monitoring and addressing that risk.” - Michael Volkov

“One of the things that has to go along with your third party due diligence program is what I would call a contract management system.” - Michael Volkov

“Accounts payable personnel should always be relied on in terms of natural allies and open communications. Having them elevate red flags to the business and the compliance functions has to be a key priority here because they are on the front lines.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

LRN's 2023 Ethics and Compliance Program Effectiveness Report provides valuable insights into the state of ethics and compliance programs in companies around the world, highlighting the importance of commitment, investment, and promotion of corporate ethics and compliance, especially during times of economic and geopolitical turbulence. Michael Volkov welcomes Susan Divers of LRN to discuss the implications of recent court decisions and DOJ regulations on corporate compliance programs. She also explores how these developments have increased the responsibility of senior management and boards, as well as the importance of data collection and analysis in order to ensure that a company is effectively managing its risks.

Susan Divers is a well-known lawyer and expert in the field of ethics and compliance. She currently serves as the Director of Thought Leadership at LRN, a leading ethics and compliance training and advisory firm. Prior to joining LRN, she was the Senior Advisor for Global Compliance at Baker Hughes, a GE Company. She has also worked as an Assistant Chief Counsel in the Division of Enforcement at the U.S. Securities and Exchange Commission, and as a litigator at several major law firms. Susan has extensive experience in designing and implementing effective ethics and compliance programs for organizations of all sizes and industries. She is a frequent speaker and author on topics related to ethics and compliance, and is widely respected as a thought leader in the field.

Key ideas you’ll hear Michael and Susan discuss:

  • Strengthening ethical culture during the pandemic. According to LRN, 82% of respondents reported that their ethical cultures had strengthened as a result of the challenges faced during the pandemic. This is the third year in a row that the survey has asked this question and received positive responses, indicating that the trend is not a fluke.
  • Values-based leadership. The report highlights the importance of values-based leadership and programs in meeting challenges effectively. Almost the same percentage of respondents reported that their companies operated based on values as opposed to a rules-based compliance program, emphasizing the critical role a company's values play in shaping its ethics and compliance culture.
  • Trade compliance. Trade compliance is an area of concern, with only 25% of respondents enhancing their trade control compliance and training. Due to increased export and sanctions regulations, this area poses a significant risk, especially in light of the Russia sanctions.
  • Inadequate internal systems, staff shortages, budget constraints, and employee disengagement are common challenges faced by ethics and compliance professionals.
  • The importance of data analytics. As the report points out, data analytics is essential for measuring ethics and compliance programs' effectiveness and addressing areas of concern. Data analytics can provide insights on how a program is actually doing today, not yesterday, and can point towards hotspot thoughts that need to be addressed. A good internal system is necessary for good data analytics.
  • The importance of investing in appropriate training and risk controls to stay up-to-date with the latest regulations. The regulatory environment is constantly evolving, and new risks are emerging all the time. Investing in appropriate training and risk controls enables organizations to identify and mitigate risks proactively, reducing the likelihood of a compliance breach or other negative event.

KEY QUOTE

"If you don't have a good internal system, you're not going to be able to get good data analytics which tell you how your program is actually doing today, not yesterday, and which point towards hot spots or areas of concern that you really need to address." - Susan Divers

Resources

Susan Divers on LinkedIn

Email: susan.divers@lrn.com

LRN 2023 PEI Report

View Details

On this episode of the Crime, Corruption and Compliance podcast, host Michael Volkov discusses the Department of Justice’s recent focus on incentives and disincentives as part of an effective ethics and compliance program. This includes awards for ethical conduct, clawbacks, and deferred payment schemes to hold officers and employees accountable for misconduct, and requirements for executives to be evaluated on their compliance with laws and regulations. Michael also talks about how companies can create appropriate policies and procedures to incentivize and monitor compliance and how to design and implement a compensation system that ensures compliance.

Key ideas you’ll hear in this episode:

  • DOJ stresses the need for positive incentives for ethical conduct, including awards and annual employee performance reviews.
  • Companies already have a strong disincentive for engaging in misconduct, which is termination.
  • Recent enforcement actions against companies like Novartis and Wells Fargo have highlighted the gap in the incentive-disincentive framework.
  • DOJ is examining the efficacy of clawbacks and deferred payment schemes as an important alternative to massive criminal fines against companies. This will hold the bad actors accountable, as well as those who had supervisory responsibilities and failed to act.
  • Clawbacks and punishments for bad actors will need to be incorporated into settlements and terminations. Company policies will need to include more protections and discretion to pull back benefits from bad actors.
  • There are a number of issues to consider when implementing a clawback program, including who it applies to, how it is triggered, and how much of the company's bonus payments should be subject to clawback.
  • DOJ anticipates requiring a wide clawback program that extends to senior management level. Crafting these measures will require a collaborative process within the company involving legal and business representatives, human resources, ethics and compliance, senior management, and potentially union representatives or work councils.
  • Danske Bank is the first to implement a compliance compensation requirement in their settlement papers with the Justice Department. The settlement includes a provision that executives will be evaluated on their compliance efforts and a failing score will make them ineligible for bonuses.
  • Companies need to design and implement compensation systems to incentivize compliance behavior and create disincentives for non-compliant conduct.

KEY QUOTES:

“Your company policies are going to have to incorporate more protections and more discretion for the company to pull back on benefits to bad actors. Bad actors here, I mean not just the actual bribe payer or scheme designer, but also those people who failed to conduct proper oversight and monitoring of the department that engaged in the misconduct.” - Michael Volkov

“In practice, companies need to formulate appropriate policies and procedures, document their system, and demonstrate commitment to enforcement of the policies to incentivize compliance behavior and create clear disincentives for noncompliant conduct.” - Michael Volkov

“A compliance-oriented compensation system has to be implemented along with other clawback and deferred payment systems.” - Michael Volkov

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

In this episode of the Crime, Corruption, and Compliance podcast, Michael Volkov forecasts the compliance and ethics trends that will be significant in 2023. He emphasizes the crucial role ethics and compliance play in the corporate governance landscape, the increasing relevance of ESG, and highlights the need for robust ethics and compliance programs even in the C suite.

Key ideas in this episode:

  • The need for robust ethics and compliance programs with adequate resources.
  • Boards and CEOs who fail to understand the importance of these programs are “doomed”.
  • Culture and ethics will be top priority in 2023.
  • The importance of C suite risk assessments and third-party risk management. “CCOs need to reach out to internal audit and their CFOs to enlist their support for a simple proposition, and that is that we need to design and implement financial controls applicable to the C Suite that are tailored to the relevant risks,” Michael says.
  • The evolution of third-party risk management to become a more holistic concept. “The ability to address, monitor and collect data on your third parties also with the evolving risk landscape led to this transformation,” Michael points out. “The fast pace of this transformation is going to continue.”
  • CCOs and compliance officers need to ask questions surrounding internal controls and accounting controls.
  • Compliance professionals will participate more deeply in financial control review and responsibility.

KEY QUOTES:

“CCOs need to reach out to internal audit and their CFOs to enlist their support for a simple proposition, and that is that we need to design and implement financial controls applicable to the C Suite that are tailored to the relevant risks.” - Michael Volkov

Resources:

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group

View Details

Trade compliance officers were recognized as the "Person of the Year" in 2022. Michael Volkov welcomes Alex Cotoia, Regulatory Manager, to discuss this development. Alex sheds light on the challenges faced by these professionals over the past year: from navigating the global pandemic to ensuring compliance with sanctions regulations, trade compliance officers have done it all.

Alex Cotoia, Regulatory Manager at The Volkov Law Group, is a seasoned trade compliance expert with extensive knowledge across ITAR compliance, BIS compliance of commerce, and opacity sanctions. She brings valuable insights on the crucial role of compliance in the world's rapidly changing landscape.

Key ideas you’ll hear Michael and Alex discuss:

  • The unprecedented challenges faced by trade compliance professionals. The global pandemic and the rapid and constant changes in the regulatory climate had a major impact on trade compliance professionals.
  • The importance of trade compliance professionals was demonstrated this year, as they were seen as unsung heroes who played a crucial role in ensuring compliance with regulations.
  • The invasion of Ukraine by Russia led to a more fulsome political response compared to the invasion of Crimea in 2014, which further highlights the significance of trade compliance in today's world.
  • The recommended approach for trade compliance is to consider the market exposure to sanctions risk and adopt measures that are reasonably designed to deter and detect infractions.
  • Increased importance of end-user certificates: The use of end-user certificates became more important in ensuring compliance with regulations in exports to Russia.
  • Michael and Alex emphasize the need for verifying the end use of products purchased from a third party to ensure it's for a permissible purpose.
  • Alex stresses the need for international organizations with broad exposure to invest heavily in trade compliance, including having a trade compliance officer and choosing the right tools. Michael highlights the importance of integrating the overall trade compliance function into the overall ethics and compliance function. This requires a strategic approach for trade compliance and sanctions risks, including education, internal controls, and technology solutions that integrate sanction screening, third-party risk management, incident reporting, and trade compliance.
  • The responsibility for internal controls lies with the leadership team and the board of directors.
  • Trade compliance should be part of compliance education.
  • Trade compliance is an industry that's here to stay.

KEY QUOTES:

“Consider where the greatest sanction risk lies from a market exposure perspective and then adopt measures that are reasonably designed to deter and detect inflections.” - Alex Cotoia

Resources:

Alex Cotoia on LinkedIn | Email

The Volkov Law Group

View Details

In this episode, host Michael Volkov takes a closer look at the Honeywell FCPA case. The Justice Department and the FCC had a strong year in FCPA enforcement; they closed out the year with two important cases, ABB and Honeywell. Last week's episode covered the ABB case, and this episode will focus on the Honeywell UOP case, which resulted in a $160,000,000 settlement.

  • Honeywell was involved in a bribery scheme in Brazil and Algeria to secure contracts with state-owned oil companies.
  • Honeywell conspired to offer a $4 million bribe to a high-ranking executive of Petrobras in Brazil in an attempt to secure a valuable $425 million contract to design and build a refinery.
  • Honeywell's use of third-party agents, such as sales agents, to facilitate bribery payments was done without proper controls and oversight, leading to a lack of proper invoicing, description of services, and confirmation of payment arrangements which facilitated illegal payments.
  • Honeywell's senior management was complicit in the scheme and there was a lack of commitment to corporate ethics and compliance culture within the company.
  • The case serves as a reminder of the risks to companies of engaging in bribery and the importance of having a strong compliance culture and third-party risk management program.

KEY QUOTE:

"Honeywell's actions occurred in an environment where no one raised a question about the bribery scheme. The … narrow focus on winning the project through whatever means possible was clear." - Michael Volkov

RESOURCES

Honeywell UOP to Pay Over $160 Million to Resolve Foreign Bribery Investigations in U.S. and Brazil

SEC Charges Honeywell with Bribery Schemes in Algeria and Brazil

Email Michael: mvolkov@volkovlaw.com

View Details

ABB is a three-time loser in foreign bribery enforcement, but still agreed to pay $315 million to settle FCPA charges. The company also resolved SEC charges for $75 million.



ABB's criminal history includes bid rigging and bribery violations in multiple countries. However, the DOJ cited ABB's extraordinary cooperation and extensive remediation when they announced the settlement. Michael Volkov explores ABB’s history of FCPA violations, leading up to their most recent, in this week’s show.

  • ABB paid a settlement of $315,000,000 for its extensive criminal history record, including multiple violations of the Foreign Corrupt Practices Act and a prior conviction for price fixing. The settlement raised questions about the effectiveness of the Justice Department's new FCPA enforcement program, which is designed to prevent benefits for recidivists.
  • The case involved two ABB subsidiaries in South Africa and Switzerland, and the parent company agreed to a three-year deferred prosecution agreement. The company also resolved SEC charges for $75 million and faced foreign prosecutions in South Africa, Switzerland, and Germany.
  • ABB was also involved in a bribery scheme between 2014 and 2017 to obtain confidential information and win lucrative contracts with South Korea's state-owned energy company, ESCOM Holdings. They engaged multiple subcontractors who were linked to a high-ranking ESCOM official and made payments to these subcontractors despite their poor qualifications and lack of experience. In exchange for these bribery payments, ABB secured improper confidential information needed for the bidding process and securing the valuable contracts.
  • ABB established a relationship with an additional subcontractor. This subcontractor failed various portions of the ABB due diligence process, including its financial stability and qualifications. ABB required a specific waiver of due diligence requirements to be approved, which they did. On its face, the approval of a waiver creates significant red flags.
  • ABB took important first steps on learning about the potential violation by immediately scheduling a meeting with the DOJ and committing to change. However, the settlement papers did not give any detail as to what made ABB's cooperation extraordinary.

KEY QUOTE

“For companies that have to decide whether to disclose and may hesitate because of their criminal histories, the answer now is fairly clear that it is a better idea in many cases to voluntarily disclose, remediate and cooperate.” - Michael Volkov

Resources

ABB Agrees to Pay Over $315 Million to Resolve Coordinated Global Foreign Bribery Case | OPA | Department of Justice

ABB Settles SEC Charges That It Engaged in Bribery Scheme in South Africa

Email Michael: mvolkov@volkovlaw.com

View Details

2022 saw higher numbers of FCPA enforcement actions, settlements, and criminal prosecutions of individuals. One of the most important developments was the update of policy in the Monaco Doctrine, which was elaborated on in the Monaco Memo, providing important guidance for compliance professionals. Tom Fox joins Michael Volkov to discuss some of the more interesting cases from the past year.

Tom Fox is hailed as the Voice of Compliance, serving and evangelizing for the compliance community for over 15 years. He is the founder and creator of the Compliance Podcast Network where he hosts various podcasts, such as Innovation In Compliance and the ESG Report, and the Executive Leader at the C-Suite Network.

Some ideas you’ll hear them explore are:

  • The DOJ is getting better at communicating with the compliance community through resolution documents like DPA, NPA, and, occasionally, declinations. These documents provide insight into the DOJ's thinking and approach to cases, which compliance professionals can use to gain a better understanding of how to approach compliance issues.
  • In Tom’s upcoming book, “FCPA Year in Review 2022,” he highlights the KT Corp bribery case, which went back to the basics in its old-school rendition of corruption: bags of cash money. The lesson here is that bribery can be as simple as a $50 slipped into a handshake.
  • In the curious case of Glencore, the FCPA enforcement action taken against them reflects the DOJ’s focus on defective cultures within companies. This case involved multiple enforcement agencies across multiple countries and multiple bribery schemes, rounding up fines and penalties totalling up to $1.1 billion, with $700M for FCPA violations, and $441M for price and market manipulation. Glencore had a culture that was committed to profit at any cost, and the company paid over $100M to third parties knowing that some of the money would be used to bribe officials in various countries.
  • The Oracle case involving bribery and corruption involving gifts, travel, and entertainment should serve as a reminder to companies to review their gift, travel, and entertainment policies and ensure they are aware of how their business officials are spending their travel, per diem, and entertainment money.
  • Avoid hiring third-parties recommended by or at the direction of a state-owned official or executive.
  • The Lisa Monaco memorandum emphasizes the need for effective compliance programs and the benefits of voluntary disclosure, full cooperation, and timely and appropriate remediation.

KEY QUOTE

“Internal controls are not simply due diligence, distributors, et cetera. It goes down to your payments, schemes and how you pay your vendors should all be a part of your internal controls.” - Tom Fox

Resources

Tom Fox on the Web | LinkedIn | Twitter | Blog

View Details

The cryptocurrency industry is a young and rapidly growing one fraught with legal and economic risks. These risks can be exploited by ill-intentioned parties to fill their pockets and fund their lavish lifestyles. One such party is the disgraced founder of FTX, Sam Bankman-Fried (commonly called “SBF”), former darling of Silicon Valley and Wall Street. The FTX exchange was hailed as the gold standard for cryptocurrency, but a series of events led to a bank run and exposed the fraudulent scheme behind-the-scenes. Matt Stankiewicz joins Michael Volkov to discuss the legal ramifications of the fall of FTX and SBF.

Matt Stankiewicz is Partner at the Volkov Law Group, specializing in anti-bribery & corruption controls and compliance programs. Recently, he was responsible for conducting a global anti-corruption compliance audit and testing of Fortune 100 medical device company's activities in ten countries.

Some ideas you’ll hear them explore are:

  • Having well over 100 subsidiaries across the globe, FTX was the go-to cryptocurrency exchange, even allowing users to trade various derivative products. At its height, the peak daily trading volume on FTX was over $20 billion.
  • As it turned out, FTX was closely linked to a crypto trading firm called Alameda Research, founded by SBF, who owned 90% of it when it collapsed. It was a crypto hedge fund, Matt comments.
  • Alameda used FTX to do all their trading and investments, and enjoyed special privileges that were not revealed to the public or to investors. One such privilege was exemption from FTX’s risk management software that required users to use some of their assets as collateral if they were trading on margin.
  • Lack of regulatory clarity is a major risk in the cryptocurrency industry. This lack of clarity creates opportunities for fraud, as well as challenges for companies trying to comply with regulations.
  • Companies that adopt strong ethics and compliance programs can mitigate the risks of cryptocurrency and be more successful than those who do not.
  • One of the biggest appeals of cryptocurrency is that you don't have to deal with an intermediary when transacting.



KEY QUOTE

“One of the benefits of cryptocurrency, which could have prevented a lot of this, is the fact that you can self-custody your assets.”

Resources

Matt Stankiewicz on LinkedIn

Email Matt: mstankiewicz@volkovlaw.com

The Fall of FTX: The Legal Ramifications of the Collapse of Sam Bankman-Fried’s Cryptocurrency Empire (I of IV)

View Details

The Curious FCPA Case of Asante Berko



In 2020, Asante Berko settled a case with the SEC by agreeing to pay $329,000. A criminal indictment was filed in Brooklyn, New York shortly after the settlement. In November of 2022, Berko arrived in London at Heathrow Airport and was then arrested; charged with conspiring with two Ghanaian officials and four other individuals to benefit Goldman Sachs, himself, and a Turkish energy company. The scheme began to unravel when Goldman Sachs discovered the payments. Join Michael Volkov as he examines the recidivist case of Asante Berko’s FCPA violations.

  • Berko orchestrated the bribery scheme between 2014 and 2017 to secure an electrical power contract from the Ghanaian government for the Turkish energy company. They were attempting to secure a power purchase agreement (PPA) or an emergency power agreement (EPA) with Ghana, which required the approval of certain Ghanian officials and entities, including a senior Ghanaian official as well as the Executive Cabinet and Parliament.
  • In seeking reimbursement for the bribes paid out by Berko and his conspirators, he falsified invoices for consulting services allegedly provided by a Ghanian consulting company, which were then paid by the Turkish energy company. The payments were routed through correspondent banks in the US.
  • Violators of FCPA often act with flagrant disregard of the laws and delusions that their obvious crimes will remain undiscovered and uninvestigated, Michael comments.
  • Goldman Sachs officials began questioning the Turkish energy company about the payments to the Ghana consulting Company that appeared in their financial analysis. Despite the reassurance of Co-conspirator Number 3, Goldman Sachs conducted a due diligence review of the transaction and various email accounts and communications, including personal accounts used by Berko and others for incriminating conversations.

Resources

Goldman Sachs Official Indicted Over Ghana Bribery Scheme

Email Michael: mvolkov@volkovlaw.com

View Details

In early October, the BIS announced two rules imposing significant export controls on semiconductor chips transactions for supercomputer end uses. This week’s show discusses recent developments in the sphere of export controls and sanctions. Alexander Cotoia, Regulatory Compliance Manager at the Volkov Law Group, joins Michael Volkov to explore the BIS’ ramping up of export control enforcement, including the new restrictions on China and Russia.

Some ideas you’ll hear them explore are:

  • The SQE route for experienced legal professionals aims to democratize the legal profession to include underrepresented minorities and other people who might not have access to the typical training contract required for being a solicitor.
  • In early October, the BIS announced two rules imposing significant export controls on semiconductor chips transactions for supercomputer end uses. Their aim is to obstruct China’s ability to use these supercomputers to upgrade their military capabilities and the propagation of WMDs. Within these new rules, controls on the export of semiconductor manufacturing technology in certain transactions for integrated circuitry were also imposed.
  • Much of the dissent from professionals over these new restrictions stems from a fundamental disagreement in terms of policy rather than implementation, Alexander shares. Many professionals have become accustomed to the free-trade arrangement with China to export sophisticated technologies for integration end uses, and fear that the more stringent controls will compromise that arrangement.
  • The aftermath of Russia’s invasion into Ukraine saw coordinated efforts at the highest levels of US government designed to prevent Russia from acquiring assets and commodities that could be used for military purposes.
  • Alexander believes Matt Axelrod’s guidance about changing the way some administrative violations of EAR99 will be viewed was very instructive. One of the premises underlying that change was using non-monetary resolutions for less serious violations, but also imposing more stringent financial penalties on those who engage in culpable acts.
  • If you have government contracts, or are in the telecommunications industry, you’re not allowed to have Huawei products on your premises.

Resources

Bureau of Industry Security Ramping Up Export Control Enforcement

Alexander Cotoia on LinkedIn

Email Alex: acotoia@volkovlaw.com

Email Michael: mvolkov@volkovlaw.com

Volkov Law Group

View Details

Oracle Corporation settled its second FCPA case in ten years. It agreed to pay the SEC $23 million to resolve allegations that its subsidiaries in Turkey, India and the United Arab Emirates maintained slush funds to bribe foreign officials. Ten years ago in 2012, Oracle paid the SEC $2 million for creating millions of dollars in off-the-books accounts at its India subsidiary. Join Michael Volkov as he takes a deep dive in the Oracle case and provides valuable lessons for managing third-party corruption risks.

  • In the SEC’s mind, Oracle is a recidivist, having its second enforcement action case in 10 years.
  • The settlement for $23 million underscored the power of the FCPA provisions, which mandate effective internal controls and accurate books and records, and can be applied to a wide range of conduct beyond foreign bribery, Michael remarks.
  • The controls that Oracle put in place to prevent improper use of discounts and marketing reimbursements were not effective because there was a lack of compliance culture within the business.
  • The Oracle case is one that should be studied by compliance professionals, Michael believes. It reminds you to look at your own controls that surround discounting and ensure that the necessary documentation is carried out. “No matter what controls you have in place, they still have to be adhered to with a true culture of compliance underneath it as a foundation,” he adds.

Resources

SEC Oracle Case

Email Michael: mvolkov@volkovlaw.com

View Details

In this episode, cryptocurrency expert Matt Stankiewicz discusses why sanctions and AML compliance need to be taken seriously in the cryptocurrency industry.

Matt Stankiewicz, a Partner at Volkov Law, is a leading industry expert on cryptocurrency. Bittrex, a leading cryptocurrency exchange, suffered twin enforcement actions for AML and Sanctions Compliance deficiencies. Matt takes a deep dive on the enforcement actions and outlines practical compliance steps that every cryptocurrency exchange should implement.

Join us as we discuss:

  • The enforcement action on Bittrex led by OFAC and FinCEN
  • Why compliance risks are increasing in the cryptocurrency industry
  • Practical steps that all cryptocurrency exchanges should implement

To reach Matt email him at: mstankiewicz@volkovlaw.com

View Details

Does compliance training have to be boring? Our guest explains how your organization can make compliance training engaging and fun for your employees.

Maria D’Avanzo is the Chief Evangelist Officer at Traliant. Maria provides key insights on corporate ethics and compliance training programs. Maria describes how to take your training program to the next level and tailor the content to deliver training on important issues based on your company’s risk assessment..

View Details

Financial institutions are rapidly moving their operations to the cloud. In response to this development, and the increasing risks of cyber breaches, legislators and regulators are gearing up to impose significant cybersecurity requirements.

Carlo Massimo is a journalist who covers Cyber Security and International Tech Policy. Carlo was a former contributing editor at the Wilson Center's Quarterly, writes Citizen Techs information week monthly policy column, and contributes to the Dark readings profile as a Features Writer.

In this episode, Carlo talks about the implications of financial institutions moving to the cloud, and the response by lawmakers and regulators to this significant trend.

Join us as we discuss:

  • Carlos's perspective on possible designation of financial institutions operating in the cloud as "critical infrastructure"
  • Are global financial institutions ready for new cybersecurity regulations aimed at mitigating the risks of a data breach
  • The perspective from both the United States and the European Union on this important issue

Carlo’s article on Information Week: Legislators Gear Up to Regulate Cloud Resiliency

View Details

The Biden Administration promised a new, aggressive approach to corporate crime. Well, the Justice Department just delivered a new, comprehensive policy that raises a number of issues, some of which are likely to be controversial. The new policy incorporates reforms announced last October that largely centered on prior corporate criminal and civil records; appointment of independent compliance monitors and expanding review of responsible persons in an internal investigation.

The Justice Department's new Corporate Enforcement Policy ("CEP"), however, expands on earlier policy changes but includes some new and far-reaching reforms that are intended to increase individual accountability and promote corporate culture through financial incentives and deterrence policies. This last idea is a significant expansion of DOJ's CEP and is sure to reverberate through the business and compliance community. Chief compliance officers face a new requirement for their companies -- creating an effective system of carrots and sticks to punish misconduct and increase rewards for ethical behavior.

DOJ's new CEP also lays the groundwork for further consideration of corporate responsibility for preserving electronic messaging, ephemeral services and other electronic data. DOJ's discussion in this area reflects DOJ's frustration with corporate internal investigation that omits access to electronic data, especially in those situations where employees use personal devices for business-related communications.

The revised CEP provides guidance to prosecutors and the business community to ensure individual and corporate accountability through the evaluation of various factors, including: (1) Corporate History of Misconduct; (2) Self-Disclosure and Cooperation; (3) the Strength of a Company's Compliance Program; (4) the Use and Monitoring of Corporate Monitors (including their selection and scope of a monitor's work).

View Details

The Department of Justice and the Securities and Exchange Commission reached a $41 million settlement with GOL Linhas Aéreas Inteligentes S.A. ("GOL") to resolve criminal and civil foreign bribery charges.

GOL entered into a three-year deferred prosecution agreement ("DPA") with DOJ in exchange for payment of a $17 million criminal penalty. DOJ credited $1.7 million of that penalty against a $3.4 million fine that GOL agreed to pay law enforcement authorities in Brazil to resolve charges in Brazil.

In a separate resolution, GOL agreed to pay $24.5 million over two years to the SEC. The SEC's initial settlement calculation was for $70 million, but it was reduced to $24.5 million based on GOL's financial condition.

In this Episode, Michael Volkov reviews the DOJ and SEC FCPA settlement actions.

View Details

Corporate culture is all the rage now, meaning it is an often used topic to signal commitment, sensitivity to issues of employee concern, and an awareness of governance trends. In practice, as we all know, culture is not just about words -- it is about action. As the often repeated phrase goes -- talk is cheap. 

In this Corporate Culture Roundup Episode, Michael Volkov examines some culture-related issues involving: Culture + Action Steps; Civility in the Workplace and What Happens when HR and Compliance are Disconnected.

View Details

As the leading hotline provider in the global market, NAVEX is in the unique position of collecting and analyzing employee reporting trends. Each year, NAVEX issues an important report on current trends in employee reporting, whistleblowers, internal investigations and potential retaliation.

NAVEX's database consists of 1.37 million reports made in 2021 at organizations around the world. 

In this Episode, Michael Volkov reviews the key findings from the 2022 report.

Here is a link to the report.

View Details

The Second Circuit Court of Appeals affirmed the district judge's post-conviction dismissal of FCPA counts against Lawrence Hoskins, a former Alston executive, for his involvement in bribery scheme to secure a $118 million energy contract in Indonesia. 

The Hoskins FCPA case has had a long and tortious path through the court system, and the Second Circuit's decision, which was decided by a 2 to 1 majority, ended with a fractured court decision that raised more questions than provided answers. The majority decision appeared to reflect a pre-ordained decision searching for legal and factual arguments to support the resolution. Indeed, the dissent presented a cogent and more defensible position.

In this Episode, Michael Volkov reviews the Second Circuit's decision.

View Details

Chief compliance officers have access to a vast amount of data generated by their compliance programs. CCOs have to establish effective monitoring processes. A critical part of this process is to build a compliance program dashboard. This is a practical issue of real importance. 

In this Episode, Michael Volkov reviews this important issue.

View Details

In a bipartisan success story, the House recently passed The Enablers Act, which is a far-reaching reform bill aimed at reducing AML and corrupt financial activity in the United States.

Scott Greytak, Advocacy Director at Transparency International USA, and Erica Hanichak, Director of Government Affairs, from the FACT Coalition, join Michael Volkov for a discussion of this legislative accomplishment and the implications for the battle against corruption.

View Details

LRN has released a new and informative report on Assessing Corporate Culture. LRN's report provides invaluable guidance and practical steps for corporate boards to lead in the management, oversight and monitoring of corporate culture. A link to the report is below, along with an earlier LRN report on Benchmarking Ethical Culture.

In this Episode, Michael Volkov interviews Ty Francis, Chief Advisory Officer at LRN, concerning LRN's recent report on Assessing Corporate Culture.

LRN Report Assessing Corporate Culture -- https://pages.lrn.com/-a-practical-guide-to-improving-board-oversight-tapestry

LRN Report on Benchmarking Ethical Culture -- https://blog.lrn.com/introducing-the-benchmark-of-ethical-culture-report

View Details

The Justice Department and various regulatory agencies continue to emphasize the importance of continuous improvement, testing and review as part of robust assessment procedures in an effective compliance program. The Treasury Department's Office of Foreign Asset Control has specifically stated that a sanctions compliance program should include "a comprehensive, independent, and objective testing or audit function" so that a company can determine "how their program[] [is] performing and should be updated, enhanced, or recalibrated to account for a changing risk assessment or sanctions environment." The Health and Human Services -- Office of Inspector General has made similar statements underscoring the need to conduct compliance audits and testing.

An important part of every compliance program focuses beyond the design and operation of the program to the important issue of whether the program itself is working. In this respect, DOJ and regulatory agencies have noted that CCOs should be striving to develop "continuous" monitoring systems and avoid "snapshots" in time. In order to execute such monitoring, compliance has to maintain broad access to operational data across all key functions in a company. This data has to be used to update regularly risk assessments, compliance policies and procedures and financial controls.

In this Episode, Michael Volkov takes a broad review of testing and auditing of ethics and compliance programs.

View Details

I have been -- and continue to be-- hyper-focused on the proper role and responsibilities for Chief Compliance Officers. Not that I see any cause for alarm, but it is easy to lose focus in the sea of so-called hot issues -- ESG, Diversity, Climate Change, Threats to Democracy, Cybersecurity and Data Privacy, each of which is an important component and focus for organizations. All of these issues intersect, are interdependent and should be addressed through organizational commitment.

But I want to take a step back and return to an issue of importance -- the proper role of CCOs. To do so, we need to remind everyone about basic requirements, lessons learned and ways forward to meet the fast-changing times. CCOs have to maintain and then advance their positions. In my view, given the interdependence of all of the important issues mentioned above, the role of the CCO has become even more critical.

In this Episode, Michael Volkov reviews the standards applicable to the CCOs function in an effective compliance program. 

View Details

The Department of Justice continues to respond to the compliance community's concerns about the new certification requirement adopted as part of the Glencore FCPA enforcement action. DOJ has adopted this new requirement to "empower" CCOs and to ensure that CCOs have a "seat at the [senior management] table." While these are all laudable goals, CCOs continue to question whether DOJ's new certification requirement will undermine their authority by opening CCOs to internal pressure to execute a certification despite concerns about the status of a company's compliance program.

In this Episode, Michael Volkov reviews DOJ's new CCO certification requirement.

View Details

In following the Justice Department and the Securities Exchange Commission FCPA enforcement actions, I am always reminded of the popular phrase — “reading the tea leaves.” (or “tasseography,” a fortune-telling method based on tea leave patterns in tea sediments). Despite a slow initial year in 2021, the Biden Administration’s stamp and push on FCPA enforcement is becoming clear. 

Keep in mind, DOJ and SEC officials have promised a new, tougher approach to FCPA enforcement. Change in government enforcement policies and results take time. However, no one expected the changes to take this long. In addition, the initial enforcement push has raised some interesting questions concerning the specific steps taken by enforcement officials.

In looking at the most recent FCPA enforcement actions (i.e., Stericycle, Glencore, and Tenaris), there are significant new trends and some important issues.

In this Episode, Michael Volkov reviews the important trends and issues surrounding FCPA Enforcement in 2022.

View Details

The SEC announced another FCPA settlement in 2022. FCPA enforcement, in general, is picking up. Tenaris, a global supplier of steel pipes and related services for the energy industry agreed to pay the SEC $78 million to resolve FCPA violations that occurred in Brazil. The US Department of Justice closed its investigation without bringing charges.

In this Episode, Michael Volkov reviews the SEC settlement.

View Details

In a long-anticipated and major enforcement action, the Justice Department and the Commodities and Futures Exchange Commission resolved a sprawling investigation with Glencore International A.G. and Glencore Ltd, a Swiss-based commodity trading and mining company.

Both companies entered guilty pleas for FCPA violations and a commodity price manipulation scheme. Glencore paid over $1.1 billion to resolve these two major investigations.

The resolution in the U.S. was part of a coordinated set of criminal and civil resolutions involving the United States, the United Kingdom and Brazil.

In this Episode, Michael Volkov reviews the settlement and the implications for future enforcement actions.

View Details

The global economy has suffered two significant shocks -- first, the pandemic sent shockwaves through every organization, and second, the war in Ukraine. Both of these events exposed the importance of risk management, especially with regard to supply chain and distribution operations. Hence, the renewed focus on third-party risk management and the repetitive description of "holistic" third-party risk management. 

Reality has a way of forcing change and we are now experiencing significant adjustments to overall risk management procedures. At the top of every list has to be third-party risk management beyond legal and compliance risks -- we have new disruptive risks that have to be identified, quantified or ranked, and then addressed.

In this Episode, Michael Volkov outlines the new reality and opportunities stemming from holistic third-party risk management.

View Details

The Justice Department ended its FCPA enforcement drought by announcing its first corporate settlement in 2022. In a parallel action, the SEC announced its settlement with Stericycle for $28 million for FCPA violations. The SEC’s settlement was its second with a company for 2022 (the first was KT Corp.).

Under the settlement, Stericycle resolved investigations being conducted by the Department of Justice, the Securities and Exchange Commission and Brazil. Stericycle agreed to enter into a three-year deferred prosecution agreement and pay more than $84 million. Stericycle will pay $52.5 million in criminal penalties, $28 million to the SEC in civil penalties and disgorgement, and approximately $9.3 million to Brazilian authorities. DOJ agreed credit up to one-third of the criminal penalty against fines the company pays to Brazil authorities.

Significantly, the DPA requires Stericycle to obtain an independent compliance monitor for a two-year period and then submit a self-report for the rest of the DPA term.

Stericycle is a global waste management company which is headquartered in Illinois. In its factual admission, Stericycle admitted a wide ranging scheme involving payment of bribes to foreign officials in Brazil, Mexico and Argentina. In total, Stericycle paid approximately $10.5 million in bribes to foreign officials in Brazil, Mexico and Argentina to secure business contracts from which Stericycle profited by at least $21.5 million.

In this Episode, Michael Volkov reviews the Stericycle FCPA enforcement action.

View Details

In this Episode Tom Fox and Mike Volkov review recent DOJ trial successes and stumbles -- Tom and Mike review DOJ trial strategy, successes and failures and approach of the antitrust division.

View Details

OFAC recently announced a settlement with OFAC for $78,750 for violations of the Ukraine-Russia Sanctions Program. The enforcement action provides important reminders relating to compliance with various "deby" maturity restrictions and how OFAC construes this restriction.

In this Episode, Michael Volkov reviews OFAC's enforcement action against S&P Global.

View Details

The SEC is a very busy agency. While promising more aggressive enforcement of securities rules, the SEC has issued two set of comprehensive rule amendments. The first proposes new rules governing cyber incident reporting, disclosures and governance. In the second major policy action, the SEC issued its long-awaited rules governing climate change and greenhouse gas emissions.

in this Episode, Michael Volkov reviews the two proposals.

View Details

The Antitrust Division’s Assistant Attorney General Jonathan Kanter promised a new era in antitrust enforcement. He won bi-partisan support from both Republicans and Democrats. Across the antitrust field, he promised aggressive merger enforcement, civil enforcement against digital markets, and constraint of market power in numerous industries. AAG Kanter promised a new approach and he is delivering.

In this Episode, Michael Volkov reviews two recent speeches and enforcement efforts by DOJ's Antitrust Division.

View Details

In another indication of DOJ's aggressive approach to enforcement of sanctions against Russia, DOJ announced the indictment of a TV producer for violations of the Crimea-Related Russian sanctions program. As outlined in the indictment, Jack Hanick, a former Fox News executive, was indicted for a sanctions violations stemming from his long-time relationship with a prohibited Russian oligarch (Specially Designated National) relating to the creation and promotion of the Russian Television Network.

In this Episode, Michael Volkov reviews DOJ's indictment and the facts surrounding Hanick's conduct.

View Details

The continuing crisis in Ukraine has resulted in additional sanctions and export controls. It is hard to keep up with new developments each day. In recent steps, the United States has adopted a comprehensive set of export controls and implemented a ban on import of Russian oil, gas and coal.

In this Episode, Michael Volkov reviews the recent changes to the Russia sanctions and export controls.

View Details

In an unprecedented and sweeping set of actions, the United States in coordination with its Allies and partners has implemented a robust set of sanctions and export controls against Russia designed to cripple Russia's economy. The unprecedented actions against Russia are intended to deter Russia from continuing its violent invasion of Ukraine and attacks against the Ukrainian people.

The Department of Treasury Office of Foreign Asset Control and the Department of Commerce Bureau of Industry and Security have issued comprehensive sanctions against Russia's financial industry, government investment funds, and oligarchs. In scope and complexity, the Russia sanctions and export controls raise significant compliance challenges for U.S. and global companies conducting business in Russia.

In this Episode, Michael Volkov surveys the sanctions and export controls.

View Details

The SEC announced the first FCPA enforcement action in 2022. South Korean telecommunications company, KT Corporation, agreed to pay $6.3 million to settle FCPA violations. As part of the settlement, KT Corp. agreed to pay $3.5 million in civil penalties and $2.8 million in disgorgement. KT Corp. is South Korea’s largest telecommunications company. 

KT Corp. violated the FCPA’s books and records and internal accounting controls provisions stemming from its activities in South Korea and Vietnam. As explained in the SEC’s Order, KT lacked sufficient internal accounting controls over its expenses, including executive bonuses and purchases of gift cards, which resulted in KT Corp. managers and executives generating slush funds for illegal purposes. Additionally, KT Corp. failed to adopt anti-corruption policies and procedures with respect to donations, employment candidates, vendors, subcontractors or third-party agents. As a result, KT Corp. employees were able to provide improper benefits to government officials and potential government customers.

In this Episode, Michael Volkov reviews the KT Corp. settlement.

View Details

Susan Divers, LRN Senior Advisor, reviews LRN's 2022 Ethics and Compliance Program Effectiveness Report. LRN conducts an annual Ethics and Compliance Program Effectiveness Report (“LRN Report”) that is a must-read for business leaders, managers, investors, compliance professionals and other stakeholders. LRN’s annual report has addressed key issues surrounding the impact of the COVID-19 pandemic on companies and ethics and compliance programs. 

View Details

Ethics and compliance professionals believe in their mission – if they did not, they would not be in the field. E&C professionals believe in the power of positive thinking, ethical conduct, and in the overall ability of an organization to operate as an “ethical” company. They work for their mission and it is a positive mission. 

The New Year is a great time for E&C professionals to take stock on their compliance programs and to plot out a path forward. Luckily for most compliance professionals, there are lots of opportunities to advance their objectives. E&C is poised for another big jump on the corporate governance ladder, and this is a big year for E&C professionals to push their respective companies to support such efforts.

There are three significant trends that will continue to play out this year that create opportunities. These three trends, which I will discuss in greater detail are: (1) the continued emphasis on the importance of corporate culture; (2) the importance of ESG and in particular the “G” element; and (3) the current Administration’s aggressive enforcement and regulatory initiatives.

In this Episode, Michael Volkov reviews these important ethics and compliance trends.

View Details

Even with the absence of any major DOJ FCPA enforcement actions, DOJ issued an interesting FCPA Opinion Letter last week addressing application of the FCPA in circumstances where organizations face imminent serious bodily harm. While the situation may appear to be unique, it is a factual scenario that occurs more often than DOJ recognizes.

In October 2021, a Requestor submitted an Opinion Letter application that presented compelling circumstances. The Requestor, an owner of a vessel, explained that a Foreign Country’s Navy had seized its vessel. Arrested and detained the captain and detained the vessel and its crew. Given the captain’s mental and physical health, the captain’s incarceration created an immediate threat of serious physical harm. A third-party acting on behalf other Country’s Navy demanded a cash payment of $175,000 to release the captain, the crew and the vessel. DOJ acted quickly and approved the Opinion Letter request. The payment was made and the captain and crew were released.

The Requestor submitted additional information to DOJ, and a more formal Opinion Letter was released last week containing the full story and analysis. While the circumstances are relatively unique, DOJ’s analysis provides additional clarity surrounding the definition of “corrupt intent” and the “business purpose” test.

In this Episode, Michael Volkov reviews this interesting FCPA Opinion Letter.

View Details

Economic sanctions enforcement is a fast-rising risk for global companies. For many years, the Treasury Department’s Office of Foreign Asset Control (“OFAC”) focused primarily on financial institutions. Over the last ten years, OFAC has stretched its enforcement eyes towards software, manufacturing, telecommunications and technology companies.

With this growth in sanctions enforcement, OFAC has embraced an aggressive view of third-party risks. Like the FCPA, under OFAC’s regime, third parties are not permitted to do what the primary company cannot do. As a result, we have witnessed a steady increase in OFAC enforcement actions against global companies for failing to ensure compliance by third-party agents, distributors and other intermediaries.

In this Episode, Michael Volkov takes a deep dive into third party sanctions risks and strategies to mitigate such risks.

View Details

One of my favorite New Year's reviews is under the title of “Person” of the Year. In the past, I have singled out Chief Compliance Officers, Chief Ethics Officers, Prosecutors, and Whistleblowers.

For 2021, the choice is obvious – the most important trend is the rise of Environmental, Social and Governance (“ESG”) programs. In second place, I would choose Supply Chain Management and Risks, given the importance of supply chain management in the post-pandemic world. 

In the end, ESG dominated the headlines and earned the annual recognition as the issue of the year. 

View Details

The Department of Justice secured a guilty plea from NatWest Markets, the newly-named Royal Bank of Scotland, for trade manipulation, referred to as “spoofing,” in U.S. Treasury markets. The NatWest resolution reflected new changes in DOJ’s white collar enforcement policies, including acknowledgement and consideration of NatWest’s prior misconduct (criminal and civil) and appointment of an independent compliance monitor. NatWest was not offered a deferred or non-prosecution agreement; instead it was required to plead guilty to a criminal charge of securities fraud and another charge of wire fraud.

Under the plea agreement, NatWest agreed that during the period of 2008 to 2014, traders in its Stamford and London offices spoofed the market for Treasury futures contracts. In addition, two traders at NatWest’s Singapore branch spoofed the secondary cash market for Treasury securities in 2018. The spoofing scheme violated a 2017 non-prosecution agreement between the United States and NatWest’s broker-dealer subsidiary, and occurred while NatWest was on probation for a separate conviction for manipulation of the foreign currency exchange market.

DOJ cited NatWest’s status as a repeat offenders as justification for requiring a criminal guilty plea to two counts. Under the plea agreement, NatWest Markets will pay $35 million in restitution, forfeiture and a criminal fine, serve three years’ probation and take on an independent compliance monitor.

In this Episode, Michael Volkov reviews the NatWest prosecution and settlement agreement.

View Details

In a major development, the Antitrust Division returned an indictment against six executives from aerospace engineering firms for an illegal conspiracy to restrict competition in the labor market for aerospace engineers.

After warning U.S. businesses, DOJ started bringing criminal cases against businesses that restrict competition for labor through illegal price-fixing or no-poach agreements. The Connecticut criminal case represents a major step in the Justice Department's focus on illegal agreements in labor markets.

In this Episode, Michael Volkov reviews the criminal case and the specific allegations.

View Details

The Biden Administration announced a new, comprehensive anti-corruption initiative, the United States Strategy on Countering Corruption. The new anti-corruption initiative is the follow on to the earlier announcement elevating the global anti-corruption battle to a national security concern. After that announcement, the Biden Administration conducted a 200-day inter-agency examination to develop a comprehensive government-wide anti-corruption initiative.

The 38-page plan released last week outlines steps for cracking down on criminal actors and their networks while improving cooperation among federal agencies and law enforcement. The Biden Administration announced plans to increase financial transparency and new regulations on U.S. real-estate purchases to prevent money laundering.

In this Episode, Michael Volkov reviews the new initiative and the important issues raised.

View Details

The Delaware Chancery Court is continuing its trend of permitting Caremark claims against corporate board members who fail to exercise proper oversight and monitoring of compliance programs. Over the past few years, the Delaware Chancery Court has consistently raised the stakes and expectation for Board member performance on corporate boards.

In this Episode, Michael Volkov reviews the current board member liability cases and the Court's recent rulings.

View Details

Tom Fox is a leader in the ethics and compliance field. He is regularly referred to as the "Compliance Evangelist."

Tom recently just released the Second Edition of The Compliance Handbook, a comprehensive review and guide to the elements of an effective ethics and compliance program. Tom is known for his practical and efficient approach to difficult ethics and compliance issues. His new Handbook is a must-have for ethics and compliance professionals but more importantly for business leaders and managers who understand the importance of implementing an effective ethics and compliance program.

In this Episode, Michael Volkov interviews Tom Fox about the Second Edition of The Compliance Handbook and the important issues addressed in the Handbook.

View Details

The Boeing 737 MAX scandal is a troublesome and disturbing case where corporate board oversight and responsibility was lacking. The implications of the board’s failure resulted in the killing of innocent passengers and the grounding of Boeing’s 737 MAX. Add to that a $2.5 billion settlement, a criminal case against a Chief Technical Pilot, and continuing safety and technical problems, and you have recipe for continuing disaster at Boeing.

The Delaware Chancery Court's recent decision denying Boeing's motion to dismiss shareholder derivative claims outlines a devastating picture of Board governance failures relating to Boeing's response to the Lion Air crash in October 2018 and the Ethiopian Airlines crash in March 2019. 

In this Episode, Tom Fox and Michael Volkov discuss the implications of this recent decision.

View Details

Credit Suisse Group AG (“Credit Suisse”), a global financial institution, and its London-based European subsidiary, Credit Suisse Securities (Europe) Limited (“CSSEL”) resolved a wide-ranging bribery and fraud scheme involving investments and financing arrangements for an $850 million loan for a tuna fishing project in Mozambique. To resolve the violations, Credit Suisse agreed to pay a total of $547 million in penalties, fines and disgorgement as part of comprehensive criminal and civil resolutions in the United States and the United Kingdom.

In this Episode, Michael Volkov reviews the Credit Suisse global fraud and bribery enforcement action.

View Details

As companies focus more on ESG, it is obvious that companies will achieve a significant number of benefits beyond that defined in the ESG acronym. A well-designed and tailored program will bring significant benefits to the overall company’s operations.

There are a number of important issues that design and implementation of an ESG program entail. It is hard to fill in many of the important issues given the SEC’s ongoing rulemaking on ESG disclosure issues. Obviously, SEC regulations will have a significant impact and everyone is anxiously awaiting the regulations. In the meantime, many companies are moving forward with planning and implementation. That is a good thing because it is unlikely that the SEC will alter the landscape to which many companies are moving.

Here is a list of issues, which I will explore in this podcast:

· Who should conduct oversight of the ESG program? A specific committee or the overall board?

· Who should be responsible for design and implementation of an effective ESG program?

·

· How should ESG reporting and disclosure occur? How should the talismanic standards of “materiality” be applied in this context?

How can technology be used to ensure proper oversight and reporting of ESG issues?

View Details

The Justice Department announced the indictment of Mark Forkner, a former Chief Technical Pilot for Boeing for his role in the 737 MAX scandal. Specifically, Forkner is charged with deceiving the FAA’s Aircraft Evaluation Group (“FAA AEG”) relating to Boeing’s 737 MAX airplane and defrauding Boeings U.S.-based airline customers to earn millions of dollars for Boeing.

Boeing’s 737 MAX scandal is tragic and disturbing. In January 2021, Boeing settled with the Justice Department and agreed to enter into a Deferred Prosecution Agreement in exchange for total payments of $2.5 billion. As you will recall, Boeing’s 737 Max was involved in two crashes in 2018 and 2019 before being grounded. 

In October 2018, Lion Air flight 610 crashed in the Java Sea, killing 189 people, and in March 2019, Ethiopian Airlines flight 302 crashed shortly after takeoff, killing 157 people. The United States ordered the planes grounded shortly after the Ethiopian Airlines crash.

In this Episode, Michael Volkov reviews the criminal indictment against Mark Forner and his role in the Boeing 737 MAX scandal.

View Details

The Biden Administration announced its commitment to the global battle against corruption as a new, national security issue. This policy represents a significant transformation in the U.S. commitment to the battle against corruption.

In this Episode, Scott Greytak from Transparency International USA joins us to discuss the current policy initiatives surrounding the global commitment to fight corruption.

View Details

The Justice Department’s Antitrust Division has targeted collusion in labor markets for criminal prosecution. This was not unexpected. Indeed, the Antitrust Division gave plenty of warning to the high-tech industry and other companies that criminal prosecutions were on the horizon.

DOJ handled initial prosecutions of labor market collusion in the high-tech sector by civil prosecutions and resolutions. Out of an abundance of caution, DOJ recognized that it wanted to provide “fair warning” of its intention. While it may not have been clear that the Sherman Act prohibition on cartel activity applied to labor markets, DOJ and the private sector should have realized that collusion, wage-fixing and agreements not to compete were illegal collusion agreements. It is hard (if not impossible) to identify procompetitive justifications for such blatant anti-competitive conduct. 

In this Episode, Michael Volkov outlines antitrust risks and compliance strategies to avoid DOJ enforcement actions in the labor market.

View Details

In a pair of enforcement actions, OFAC settled two separate actions involving Schlumberger Limited subsidiaries – the first involving Cameron International Corporation, and the second, Schlumberger Rod Lift, Inc., a former subsidiary, that was acquired by Lufkin Rod Lift, Inc.

In this Episode, MIchael Volkov reviews the two OFAC enforcement actions.

View Details

WPP, the Largest Global Advertising Group, Settles FCPA Charges with SEC for $19.2 Million. After a long hiatus, the SEC announced a settlement with WPP plc, the world’s largest advertising group, for FCPA violations in India, China, Brazil and Peru for $19.2 million. The SEC’s resolution charges WPP with violations of the anti-bribery, books and records and internal accounting controls provisions of the FCPA.

In this Episode, Michael Volkov reviews the WPP SEC FCPA settlement.

View Details

An internal investigation is like reading a good novel. You begin the journey with a general expectation of what the novel or the “investigation” is about. As you learn more, the investigation gains momentum filled with moments of discovery, surprise and ultimately a basis for understanding.

In some cases, the end of the story (e.g. an oil well explosion) or dramatic event is known. In others, for example, a hotline report of alleged misconduct is substantiated after a thorough investigation involving a slow but steady understanding of what occurred, who was involved and how the scheme was executed.

In this Episode, Michael Volkov reviews the 5 common pitfalls in conducting an internal investigation.

View Details

The Department of Treasury's Office of Foreign Asset Control ("OFAC") continues to bring sanctions enforcement actions. At the same time, OFAC is reiterating the importance of sanctions compliance program. Building on its May 2019 Framework for Sanctions Compliance Program, OFAC is sticking to its word -- setting forth sanctions compliance program requirements and holding companies accountable for sanctions program violations.

In this Episode, Michael Volkov reviews recent enforcement actions, expanded Belarus sanctions, and continuing compliance expectations.

View Details

Chief compliance officers recognize the importance of conducting robust audits of their compliance programs. The audit process requires a delicate balance between qualitative and quantitative measures.

As corporate compliance programs build data analytics and technological capabilities, CCOs have to tailor the audit program to incorporate data as an effective measure of a compliance program.

In this Episode, Michael Volkov reviews strategies for conducting compliance program audits.

View Details

The culture bandwagon is picking up steam. Everyone is citing its organization’s “culture” as the foundation for its activities in the hope of meeting a rapidly evolving standard for organizations. In its latest corporate compliance guidance, the Justice Department, along with numerous regulatory agencies continue to cite the importance of a company’s “culture of compliance.”

But when it comes to defining the terms, how to manage a company’s culture and how to measure, monitor and measure a company’s culture – everyone responds with a blank stare. That is when we hear the Justice Potter Stewart famous definition of obscenity, “I know it when I see it.”

To provide my own perspective on some of these issues, I am dedicating this podcast episode to corporate culture. My answers may not be “correct” or even “persuasive,” but the dialogue has to begin. I have long advocated for practical approaches to defining, managing and maintaining a company’s culture. As I often write, culture is a company’s most important “internal control.”