In her opinion last week, Vice Chancellor Zurn also made note of the lengthy tenure of many of Boeing’s directors and their skill-sets as “political insiders or executives with financial expertise.” She then discussed at length the transformation of the company from an organization run by engineers to one run by finance folks – recounting how the company moved its headquarters from Seattle 20 years ago in order to “escape the influence of the resident flight engineers.” The focus on cost-cutting allegedly impacted quality and resulted in more safety violations.
Our point today, however, is that 3G made cost-cutting a strategic goal for the company. It tied employees’ performance metrics and compensation to their ability to cut costs. Procurement division employees said internally that the former COO “push[ed] like crazy” for them to meet cost savings goals, and increased cost savings targets to unreasonable levels.
Faced with that relentless pressure to cut costs, employees then engaged in the prebate chicanery we mentioned above, and lots more.
That’s the lesson for internal control and compliance officers. If your business is based on a misguided strategic goal, eventually it will warp your corporate culture to the point where misconduct is the only way to execute the strategy — and then, all the internal controls in the world won’t do you any good.
The topics of board composition and director skills are huge right now. Tune in tomorrow for the free webcast – “The 21st Century Board: Changing Expectations For Diversity, Human Capital & Risk Oversight” – co-hosted by ISS Corporate Solutions and CCRcorp – to hear Digimarc Board Chair Alicia Syrett, Russell Reynolds’ Rusty O’Kelley, ISS Corporate Solutions’ Ben Magarik, and our very own Lawrence Heim of PracticalESG.com. They’ll be talking about the changing expectations of investors & stakeholders – and how boards are responding.
On Friday, the SEC announced a $62 million settlement with The Kraft Heinz Company. The settlement resolved an alleged expense management scheme that the SEC says happened when the company was trying to aggressively cut costs after its 2015 merger.
The case underscores the importance of having strong internal controls that can catch irregularities. According to the SEC, the company had inadequate internal controls for its procurement division that caused gatekeepers to overlook warning signs of manipulated supply agreements and inaccurate reporting. The SEC also announcedcharges against the company’s former COO and former Chief Procurement Officer. Here’s more detail from the press release:
According to the SEC’s order, from the last quarter of 2015 to the end of 2018, Kraft engaged in various types of accounting misconduct, including recognizing unearned discounts from suppliers and maintaining false and misleading supplier contracts, which improperly reduced the company’s cost of goods sold and allegedly achieved “cost savings.” Kraft, in turn, touted these purported savings to the market, which were widely covered by financial analysts.
The accounting improprieties resulted in Kraft reporting inflated adjusted “EBITDA,” a key earnings performance metric for investors. In June 2019, after the SEC investigation commenced, Kraft restated its financials, correcting a total of $208 million in improperly-recognized cost savings arising out of nearly 300 transactions.
The company disclosed the investigation in an earnings release over two years ago. On Friday, it reported the settlement in a Form 8-K, under Item 8.01. The Form 8-K says that it recorded an accrual for the full amount of the penalty in the second quarter of this year.
In a statement published on Friday, SEC Commissioner Caroline Crenshaw says that the Kraft Heinz settlement shows why “corporate benefits” shouldn’t be part of SEC Enforcement’s penalty equation. She first caused a stir with this position at a March CII speech that called into question the 15-year enforcement policy.
Commissioner Crenshaw says that when Kraft announced the SEC investigation back in February 2019, it “bundled” that news with other negative information – a dividend cut and a $15.4 billion write down of goodwill. That makes it hard to tell whether any part of the resulting stock price drop was a reaction to the investigation news. She also says that the company initially estimated that the procurement issues would only increase cost of products sold by $25 million, but by mid-2019, the reporting errors ended up totaling $208 million.
Because this chain of events could make it more difficult for private litigants to recover damages, Commissioner Crenshaw believes that the SEC’s penalties should be more closely linked to misconduct & deterrence. Here’s her conclusion:
A recent analysis determined that it results in dramatically fewer successful recoveries by private securities litigants who, unlike the SEC, must prove that corporate stock price losses were directly attributable to the specific bad news. In this study researchers also concluded that information bundling resulted on average in $21.17 to $23.45 million lower recoveries for shareholders.
In considering the appropriate penalty to impose in actions brought by the SEC, I am concerned about corporate issuers benefiting from information bundling. To the extent corporations thereby make it more difficult to measure corporate benefit, that merely reinforces my inclination in setting penalties to focus more heavily on other factors, such as punishing misconduct and effectively deterring future violations.
The Center for Audit Quality recently published this analysis of S&P 500 ESG reporting. Here are some key takeaways:
– 95% of S&P 500 companies had detailed ESG information publicly available.
– The information the CAQ examined was primarily outside of an SEC submission in a standalone ESG, sustainability, corporate responsibility, or similar report. Of the remaining 5%, most companies published some high-level policy information on their website.
– A majority of companies referenced more than one reporting framework – CDP, SASB, GRI, TCFD and/or IR. Nearly 300 companies refer to using 3-5 frameworks.
– 264 companies said they had some form of assurance or verification over ESG metrics. Roughly 6% of S&P 500 companies received assurance from a public company auditing firm over some of their ESG information, and 47% had assurance from an engineering or consulting firm.
The CAQ goes on to compare different types of assurance and assurance terminology. This is definitely still an evolving area, and one that our colleague Lawrence will be continuing to write about on PracticalESG.com.
We’re regularly posting new podcasts for members! They’re perfect for drive-time if you’re traveling over these final summer weekends. Here are the latest episodes:
– Why the securities laws should impose an affirmative duty to disclose material information
– How market confidence would improve if insiders were required to make Section 16 filings *before* they trade, and if Rule 10b5-1 reforms were adopted
– Federal corporate governance concepts including independent board chairs, employee representatives on the compensation committee, and more
– Giving “say-on-pay” more teeth
– Why the SEC’s current focus on ESG disclosure is misplaced
– Marian’s career path from being a senior proxy research analyst at Glass Lewis, to Chevron, to Charles Schwab, to her current role as Head of ESG Strategy & Engagement at Uber
– What’s surprised Marian as she’s progressed in her career
– What major governance shifts Marian has noticed over the years in her different roles
– One thing Marian would like people to know about ESG and investor engagement isn’t typically discussed
– What Marian thinks women in the corporate governance field can add to the current conversation on the societal role of companies
I blogged last week about the SEC’s insider trading case against Medivation’s former biz dev guy – and I confess I struggled with the headline! I wasn’t really sure what to make of the allegations. Thankfully, a couple of members sent resources – and we’ve been posting additional memos in our “Insider Trading” Practice Area. This Wachtell Lipton memo expands on issues the case could turn on:
Most corporate insider trading policies include a provision similar to Medivation’s prohibition of trades in the securities of other companies on the basis of the employer’s information. But the Panuwat allegations are quite different from the concerns that usually animate such policies; for example, companies recognize that their employees may learn of confidential plans to enter into a material contract with a supplier, to acquire a target company, or to terminate a material relationship with a vendor, and accordingly, their policies prohibit trading in the securities of the supplier, target or vendor before the news becomes public.
By contrast, the connection between the information that Panuwat allegedly received and the company in whose securities he traded was indirect, and the information did not arise from any dealings between his employer and Incyte. As the Panuwat litigation proceeds, the issue of materiality is likely to be hard-fought. The courtroom battle can be expected to center on issues such as how likely or uncertain it was that the Medivation news would affect Incyte’s stock price, as well as on the indirect nature of the connection between Medivation’s information and the securities in which Panuwat traded. The case will likely also test the SEC’s assertion that Panuwat misappropriated Medivation’s information when he traded. The courts will ultimately need to determine whether the misappropriation theory of insider trading liability extends to these facts.
In this 20-year old article, Yale Law Prof Ian Ayres & Stanford Law Prof Joe Bankman call this type of transaction “trading in stock substitutes” – and say that it’s legal and somewhat common. A similar analysis from just last year by Mihir Mehta, David Reeb and Wanli Zhao calls it “shadow trading.” According to the authors, shadow trading remains pretty widespread. But it’s an untested legal theory because it’s almost never prosecuted – in part because it’s difficult to detect. This new case suggests that the SEC’s data analytics are getting more advanced, and now a court has a chance to weigh in on whether or not this activity is legal. Here’s another nugget from the study:
Firms have incentives to prohibit employees from using their private information to facilitate shadow trading as the public revelation of such activities could adversely affect their business relationships and thus, their operations and profits. … [F]irm-mandated prohibitions appear to be effective. Our results show that shadow trading is significantly higher when source firms do not prohibit employees from engaging in shadow trading relative to when they prohibit shadow trading. Although mostly untested in the U.S. judicial system, such company regulations arguably create a fiduciary responsibility for employees not to exploit their private information in economically-linked firms.
As I pointed out last week, Medivation’s policy did contain that type of broad prohibition, according to the SEC’s complaint. That could end up being an important fact. For more analysis, see this Cooley blog.
SEC Enforcement has been busy on insider trading cases. Last week, they also announcedcharges against former employees of a popular streaming service who were allegedly tipping non-public info about subscription numbers to friends & family who traded in advance of earnings announcements – to the tune of $3 million in profits. In another recently announced case, the complaint alleges that the wife of a guy on a deal team traded in target stock unbeknownst to her spouse. All good fodder for your compliance programs…
Here’s something our colleague Lawrence Heim blogged last week on PracticalESG.com:
I’ve advocated for replacing outdated “sustainability” lingo with the more up-to-date (and perhaps better-marketed) term “ESG.” But according to this recent survey from the US Chamber of Commerce, NSADAQ, the Silicon Valley Leadership Group and other trade organizations, the initialism may be picking up some baggage of its own.
The survey – reflecting responses from 436 CEOs, CFOs, GCs, corporate secretaries, IR and sustainability folks at companies across industries and market caps – is aimed at influencing the SEC’s potential ESG disclosure proposals. Only 8% of the respondents feel that “ESG” encompasses a generally understood set of issues that can be easily defined by regulators. 61% said it’s a subjective term that means different things to different companies and can’t be easily defined by regulators.
Here are some of the other findings:
– 59% of the respondents have increased the amount of climate disclosure they provide since 2010, with half of those doing so in their Risk Factors disclosure (Item 105 of Regulation S-K).
– Half of the respondents think standard ESG disclosure frameworks are confusing and address immaterial information – but they use them anyway: 44% use SASB, 31% use GRI and 29% use TCFD. Surprisingly, 41% of respondents do not rely on any standard-setting body in developing their ESG disclosures for SEC or other communications.
– There is overwhelming agreement (95%) that shareholders are the intended audience of ESG disclosure. Other audiences receiving more than 80% of votes are employees, customers and ESG standards/ratings bodies.
– Despite effort put into the disclosures, one-third of the respondents “seldom” hear feedback from shareholders, with only 41% indicating they “sometimes” hear from shareholders.
– 63% communicate to shareholders about climate change.
– 89% support tailoring ESG disclosures for smaller and/or newly public companies.
– 24% of companies would support CEO/CFO certifications of climate change disclosures, with 22% supporting a requirement for third-party assurance. 47% oppose executive certifications and 57% oppose assurance. A mere 28% of respondents currently engage third parties for assurance or audits of their ESG disclosures.
What This Means
Regulators may take the report findings as weighing in favor of principles-based disclosure, which could simplify the SEC’s rulemaking effort. The downside of principles-based disclosure is that it may not provide the comparability that investors are looking for. And if it doesn’t, then companies might still find themselves wading through mountains of surveys and conflicting disclosure requests.
ESG and sustainability professionals should thoughtfully consider what I believe is a most important message: even though “ESG” has the attention of executives and management at the moment, that may be tenuous. Without a regulatory mandate, executives may question the value of costs/efforts that are voluntary, fractious, inconsistent, do not lend themselves to comparability with peers, and which result in limited feedback from intended recipients. Where ESG initiatives are clear and direct operational or strategic business imperatives, executives will support them as such.
The SEC announced last week that it’s releasing free “Application Programming Interfaces” that aggregate Edgar submission history and XBRL data. While institutional investors already use XBRL to analyze massive amounts of data, the retail crowd has largely ignored the resource. APIs could change that, because they’ll allow developers to create apps that directly cater to individuals.
The APIs are updated in real-time as filings are made – with submission APIs having a processing delay of less than a second and the xbrl APIs having a delay of under a minute (potentially longer during peak filing times). Time will tell whether the meme stock traders will take advantage of this new information flow. The SEC even has a page that shows how to program with these APIs. It could be a good time to learn how to code!
More than one-third of organizations worldwide have experienced a ransomware attack or breach in the last year, according to a survey announced recently by International Data Corporation. Thankfully, the incident rate is much lower in the US compared to the rest of the world – and the survey found that companies that are further along with their digital efforts are less likely to experience an event. That said, another attack on a sophisticated US company was also in the news earlier this month. The press release lays out some of the survey’s key findings:
– The incident rate was notably lower for companies based in the United States (7%) compared to the worldwide rate (37%).
– The Manufacturing and Finance industries reported the highest ransomware incident rates while the Transportation, Communication, and Utilities/Media industries reported the lowest rates.
– Only 13% of organizations reported experiencing a ransomware attack/breach and not paying a ransom.
– While the average ransom payment was almost a quarter million dollars, a few large ransom payments (more than $1 million) skewed the average.
Greater awareness of ransomware incidents has prompted organizations to undertake a variety of actions in response. These include reviewing and certifying security and data protection/recovery practices with partners and suppliers; periodically stress-testing cyber response procedures; and increased sharing of threat intelligence with other organizations and/or government agencies. Greater incident awareness has similarly prompted requests from boards of directors to review security practices and ransomware response procedures.