Syed Rahman of Rahman Ravelli outlines the main points contained in the Serious Fraud Office’s updated guidance on its evaluation of compliance programmes.
The Serious Fraud Office (SFO) has published updated guidance on its evaluation of compliance programmes.
This latest guidance comes in the wake of the updated joint SFO – Crown Prosecution Service (CPS) Corporate Prosecution Guidance, which was published in August, and the guidance the SFO published in April for corporates about self-reporting, co-operation and deferred prosecution agreements (DPAs).
Although the new guidance does not deviate hugely from previously-published SFO guidance, there are some aspects that are notable. The SFO has said the latest guidance is “setting out transparently when, why and how it will evaluate a compliance programme’’ and that it is part of a “a refreshed approach to working with cooperating businesses’’.
The refreshed guidance outlines the six scenarios in which the SFO may need to evaluate an organisation’s compliance programme: when considering prosecutions, deferred prosecution agreements (DPAs), compliance terms and monitorships, potential defences to corporate offences, and sentencing.
Significantly, it explains how any corporate will be assessed by the SFO in relation to the new failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023 (ECCTA), including examination of any potential defence of reasonable procedures.
Effective
The guidance emphasises that any SFO assessment of how effective a company’s compliance programme is will be based on that company’s individual circumstances. It makes it clear that having policies, procedures and controls in place does not automatically mean a compliance programme is meeting its objectives. The SFO, it says, “will examine how policies translate into conduct on the ground’’ and will aim to “get behind the pronouncements’’.
While time will tell exactly how the SFO goes about this - and how effective it proves to be – corporates can expect any examination by the agency to go beyond looking at documentation regarding compliance. Any scrutiny is likely to cover how the compliance programme is being carried out, with a possible focus on practical measures such as training, testing and monitoring.
The SFO has stated in the guidance that “isolated compliance failures’’ do not necessarily mean a compliance programme is ineffective or inadequate, it makes it clear that anti-circumvention measures need to be in place and (as with the rest of the compliance programme) subject to regular review.
Appropriate
The guidance is clear that a company’s compliance programme has to be appropriate for its situation; taking into account factors such as the size of the organisation, the nature of the business and the risks it faces. And it states that even small companies need to have compliance arrangements in place.
It adds that “organisations need to determine what is appropriate for the field in which they operate. Compliance arrangements for any particular organisation need to be specific to and effective for that organisation.”
It also refers to the guidance issued by the US Department of Justice and by the French Anti-Corruption Agency (AFA) as being relevant to any compliance programme devised and operated by a company that has dealings in those countries. This is a reminder to companies of the various compliance requirements they may face if they do business in more than one country – and of the need to ensure those requirements are part of their compliance programme.
Assessment
The guidance details the scenarios that will lead to the SFO assessing a compliance programme.
It states that it will be assessed when determining whether a prosecution is in the public interest under the aforementioned joint SFO-CPS Corporate Prosecution Guidance. A company’s compliance programme will also be examined if offering a DPA is being considered. It may also be a factor in the terms that are included in any DPA. If a company is prosecuted, its compliance will be considered as a factor in any sentence that is imposed.
Investigation
A company’s compliance programme will, according to the latest guidance, be assessed by the SFO in the early stages of an investigation.
The guidance details the SFO’s investigatory ‘tools’, including voluntary disclosures and interviews, section 2 compelled disclosure of documents or information, section 2 witness interviews, questions put directly to the organisation, and suspect interviews under the Police and Criminal Evidence Act 1984 (compliance material is considered to be “relevant information” for the purposes of offences under s.2 (16) of the Criminal Justice Act 1987.)
Any company that comes under SFO investigation can – or at least, should – expect the SFO to use any such powers to seek any evidence that can help it determine how well the company’s compliance programme was functioning at the time of the alleged wrongdoing. The onus will be on any company in such a situation to produce any documentation or other proof that shows how effective its compliance measures have been. Records of all aspects of a compliance programme and its operation must, therefore, be maintained and preserved.
Conclusion
This guidance is a further reminder, if one was needed, that compliance needs to be approached in a serious manner by all companies. It can be a defence to any prosecution. But it can also be a significant factor in whether a company is charged and the punishment it receives if found guilty. A company’s approach to compliance can also affect its chances of being offered a DPA and, if that happens, the terms within it.
But a company’s compliance, as the guidance makes clear, has to be of a sufficient standard if it is to help secure the most favourable outcome to an investigation. Taking an approach of going through the motions when it comes to compliance will be identified by the SFO and will do a company no favours.
Compliance cannot be treated as a tick-box, one-size-fits-all chore. Companies have to ensure their compliance addresses the risks they face.
