Gregory A. Brower is Chief Global Compliance Officer for Wynn Resorts. He also serves on WLF’s Legal Policy Advisory Board and is a former U.S. Attorney. Emily R. Garnett is a Shareholder practicing in the Denver, CO office of Brownstein Hyatt Farber Schreck, LLP and a former enforcement attorney at the U.S. Securities and Exchange Commission. Her practice focuses on complex litigation with a specialty in the areas of securities, white collar, and antitrust.

* * *

On August 25, 2023, the Securities and Exchange Commission (“SEC”) announced that it had charged the 3M Company (“3M”) with violations of the books and records and internal control provisions of the Foreign Corrupt Practices Act (“FCPA”). 3M agreed to pay the SEC $6.5 million to resolve the charges.

The SEC’s Order (“Order”) is based on conduct from at least 2014, alleging that 3M’s Chinese subsidiary orchestrated plush overseas trips for Chinese government officials and hid the true purpose of those trips through fake travel itineraries and falsified internal compliance documents.1 Specifically, the SEC found that the marketing manager of 3M’s Chinese subsidiary colluded with two China-based travel agencies to secretly provide tourism activities to Chinese government officials under the guise that the officials would be traveling for overseas educational training sessions and legitimate 3M business activities. In reality, many of the officials who travelled to these English-language training sessions did not speak English, did not have a translator, and were instead given an alternate activity itinerary, which they were told to keep confidential. In some cases, the officials were accompanied by their spouses; in other cases, the officials arrived at the intended destination, skipped the organized events entirely and traveled on their own until they eventually returned to China. 3M recorded the costs of the trips in its books and records as a legitimate business expense. These trips resulted in a $3.5 million increase of sales for 3M China.

The SEC charged 3M with violations of the Exchange Act sections 13(b)(2)(A) and 13(b)(2)(B). The provisions, respectively, require companies to adequately maintain and keep books, records, and accounts; and to maintain a system of internal controls. The SEC required 3M to pay $3.5 million in disgorgement, $1 million in prejudgment interest and $2 million in penalties.

This enforcement action includes several potential lessons similarly situated companies should learn from, including:

1) Cooperation did not result in complete monetary relief. Arguably, the SEC has been less than perfectly clear about the benefits of cooperation.2  The SEC’s Enforcement Cooperation program highlights instances where companies that have self-reported have not faced prosecution and/or a penalty.3 Here, the Order recognized 3M’s efforts toward self-reporting, cooperation, and remediation. The company’s own public filings suggest it self-reported as early as July 2019.4 Nevertheless, the Order required 3M to pay $6.5 million total, for a net benefit of just $2.5 million in sales.

2) Monitoring Communications and Internal Controls. Companies may want to consider revisiting audit questionnaires, mandatory disclosure requirements and internal controls around employee communications with government officials, particularly for subsidiaries that reside in countries that rank high on Transparency International’s Corruption Perception Index.5 Here, the SEC found that a 3M marketing manager communicated with Chinese government officials through WeChat. A more robust anti-corruption internal control might have prohibited company employees from using such “off-channel” applications when conducting company business. Although in the age of “bring your own device” and remote work, such internal controls rely largely on employees to self-report, a company may be better served from a defensive perspective to have such policies in place. Companies may also consider monitoring certain websites that employees access from company-issued devices, where red flag communications are more likely to occur, including WeChat, Signal and WhatsApp.

3) Be Wary of Old Conduct. The fact that this conduct dated back to between 2014 and 2017, almost five years before the SEC’s Order, did not discount the company’s liability or create leverage for negotiating with the SEC for a lower penalty (if it did, it was not mentioned in the Order). The FCPA’s statute of limitations is five years from the last act taken to facilitate the violation. The SEC’s Order cites several trips that occurred in 2017 but does not provide the exact dates of those trips. To the extent a company’s internal controls are incomplete or deficient and in need of remediation, the company should consider a retrospective audit or look-back of past activity to ensure there have not been any prior acts within the last five years (or more) that may constitute a violation of the FCPA.

Looking ahead, it is reasonable to anticipate that the SEC may continue to target Asia-based subsidiaries of U.S.-based companies for FCPA enforcement. By one count, FCPA enforcement actions against Asia-based companies have made up only 4.8% of all FCPA corporate enforcement actions since the law’s enactment in 1977.6 Indeed, the total number of FCPA corporate enforcement actions since 2018 has declined. A variety of factors—COVID-19, an increased focus on sanctions enforcement and others—may explain these statistics, but no company subject to FCPA jurisdiction should assume that the SEC and DOJ have deprioritized FCPA enforcement in Asia or anywhere else. As a result, clear policies, adequate training, and robust internal controls should be compliance priorities for companies of all types.


