On October 19, 2021, the U.S. Securities and Exchange Commission (“SEC”) announced that Credit Suisse Group AG (Credit Suisse) agreed to pay $100 million to the SEC (among other penalties to other agencies) for violations of the Foreign Corrupt Practices Act’s (“FCPA”) internal controls and books and records provisions. The violations in the Credit Suisse case include a series of financial transactions involving the bank and Mozambican state-owned entities. As part of those transactions, the SEC found that Credit Suisse fraudulently misled investors and hid underlying corruption that included kickbacks to bankers and bribes to public officials. Although the conduct in the Credit Suisse case involves massive transactions, complicated networks of intermediaries, and Mozambique entities and government officials (which is not a typical scenario for most companies) there is a broader lesson applicable to all businesses – the importance of internal controls to protect reputational risk.
There is no single widely-accepted definition of reputational risk. For that reason, it is often left out of risk-based compliance processes. At its core, reputational risk is a threat to the name, standing, or image of an entity that can result in the reduction of revenues, value, or market share. Although reputation may be intangible, harm to an entity’s reputation can result in very tangible losses. When obvious red flags are ignored due to an inadequate focus on reputational risk, the results can be dollars and cents to your business.
The Credit Suisse Cease-and-Desist Order discusses failings applicable to all businesses large and small – not only international billion-dollar transactions. A key finding by the SEC was that Credit Suisse continued forward with these transactions after it discovered numerous irregularities, red flags, and risks. This was a result of a simple cause – the inadequate appreciation of the risk associated with the irregularities identified by the bank’s compliance groups. Every business should learn a lesson from this story. For example, the problematic scheme resulted in part from a basic failure in the bank’s internal controls. Credit Suisse’s compliance group received a third-party diligence report that identified a certain intermediary as a “master of kickbacks” and highlighted past involvement in bribery schemes and concerns about integrity. Yet, the bank failed to properly consider the totality of these risks surrounding the transactions and moved forward with the transactions despite these red flags. The SEC specifically noted the lack of attention to the bank’s reputational risk in making its findings.
An improved focus on reputational risk within the compliance and risk management process will help avoid basic pitfalls that may otherwise be ignored.
- Partner
Heather Hatfield represents clients in corporate investigations, white-collar crime investigations and defense involving the Foreign Corrupt Practices Act (FCPA), complex contract disputes, oil and gas litigation ...
- Partner
Blake Runions assists clients with broad range of business disputes and investigatory matters, including partnership disputes, internal investigations, and commercial litigation.
Prior to joining the Firm, Blake worked in the ...
- Associate
Jamie Godsey represents public and private corporations, partnerships, and small companies on a broad range of complex business and commercial litigation. Her experience includes a wide variety of matters such as contractual ...
Recent Posts
- Best Practices to Ensure Compliance with Upcoming Data Protection Regulations
- Government Signals Focus on AI Enforcement and Data Protection
- CSF 2.0 – An Expanded Cybersecurity Framework for all Organizations
- Anti-Corruption Enforcement: 2023 Year-In-Review
- ComEd Settlement Proves the Foreign Corrupt Practices Act Is Not Limited to Foreign Corruption
- Compliance Challenges Arising from the Use of ChatGPT and Artificial Intelligence
- Human Resources Compliance Audits (Part 2)
- Human Resources Compliance Audits (Part 1)
- U.S. Attorneys’ Offices Implement New Voluntary Self-Disclosure Policy
- Anti-Corruption Enforcement: 2022 Year-In-Review
TopicsSelect Category
ArchivesSelect Month
- June 2024
- April 2024
- March 2024
- February 2024
- October 2023
- September 2023
- August 2023
- June 2023
- March 2023
- February 2023
- November 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- November 2019
- October 2019
- September 2019
- August 2019
- July 2019
- June 2019
- May 2019
- April 2019
- March 2019
- February 2019
- January 2019