Criminal law insights: December 2019

A round up of criminal case law updates, news, published guidance and market practice on white-collar and corporate crime, investigations and litigation.

09 December 2019

Publication

Our thoughts on the SFO’s updated Corporate Co-operation Guidance

On 18 August 2019, the SFO published its Corporate Co-operation Guidance (the “Guidance”), intended to provide “corporates and their legal advisers … with added transparency about what they might expect if they decide to self-report fraud or corruption”. For the first time, the Guidance provides a definition of co-operation: “providing assistance to the SFO that goes above and beyond what the law requires”. The SFO gives detailed guidance as to what such co-operation may look like, identifying a wide range of ‘good general practices’ in document and evidence management and its expectations for a company’s interactions with witnesses.

The Guidance also gives some insights into its position on waivers of privilege over witness accounts and investigation records, although it remains unclear how much ‘co-operation credit’ a company will lose if it elects not to take this course. It states that a company that chooses not to waive privilege simply will not attain the “factor against prosecution” in the Deferred Prosecution Agreements (“DPA”) Code of Practice and will not be “penalised”. Nonetheless, the SFO and, to some degree, the Court has previously emphasised waiver to be an “important factor” when considering whether or not it is in the interests of justice to resolve a case by means of a DPA.

The SFO also makes very clear that there are no guarantees of any particular outcome for a corporate who follows the Guidance, and that co-operation may look different from case to case. It will be interesting to see how the SFO responds to companies that adopt the practices identified in the Guidance, as well as its reaction to those that don’t.

For further analysis on the impact of the Guidance, see our article.

United Kingdom and the United States enter into Bilateral Data Access Agreement

On 3 October 2019, the United Kingdom and the United States entered into the world’s first-ever Bilateral Data Access Agreement, which aims to streamline the process by which either government can collect electronic evidence located in the other country. Under the agreement, designated authorities from the US and UK will be able to issue orders for the collection of electronic evidence during certain criminal investigations directly to communication service providers in the other country.

The agreement comes pursuant to the US Clarifying Overseas Use of Data (“CLOUD”) Act, which was enacted in March 2018. This is also the first agreement reached under the UK Crime (Overseas Production Orders) Act 2019, which authorises domestic law enforcement agencies, including the Serious Fraud Office, to apply for a court order with extraterritorial effect to obtain data stored electronically directly from communication service providers based outside the UK.

The agreement has been submitted to the US Congress and the UK Parliament. If approved by the US Congress and the House of Commons, the agreement will take effect in March 2020. Companies and individuals subject to investigation in either the US or the UK should be aware that law enforcement agencies in each country will have more ready and speedy access to electronic data abroad believed to be relevant to their enquiries. This may in turn impact those agencies' expectations when assessing a company's own cooperation and voluntary document production.

The FIU’s continued struggle with the growing volume of SARs

The UK Financial Intelligence Unit (FIU) has published its 2019 Annual Report on Suspicious Activity Reports (SARs). The volume of SARs continues to increase, putting further strain on the FIU’s capacity. 478,437 SARs were submitted between April 2018 to March 2019, up 3% on the previous year. The number of Defence Against Money Laundering (“DAML”) requests was particularly high, rising 53% on 2017/18 to 22,619.

It is the DAML requests that create the most work for the FIU. In this regard, it is notable that the FIU made a decision on 70% of DAML requests without referral to law enforcement for a recommendation (up from 58% in 2017/18), although the FIU defends this approach as reasonable in appropriate circumstances.

The FIU also appears to be making use of new powers introduced under the Criminal Finances Act 2017. It attributed significant growth in asset recoveries, which were 154% higher than 2017/18 at £131.7m, to the use of Account Freezing Orders and extensions to the moratorium period following a DAML request. The FIU is taking steps to grow its resources, including by adding staff and upgrading its IT. However, these improvements do not yet appear to be enough to keep up with the increase in reporting. For instance, average response times have increased to 5.12 days from 4.32 days in 2017/18. Further commentary is available here.

New Financial Conduct Authority guidance on regulation of crypto-asset business

UK crypto-asset business must comply with the requirements of the money laundering regulations (“MLR”) from 10 January 2020 (being the same date by which the EU’s 5th Money Laundering Directive (“5MLD”) must be implemented in the UK). The FCA will be the anti-money laundering (“AML”) and counter terrorist financing (“CTF”) supervisor of UK crypto-asset businesses under the MLR from that date. This deadline is fast approaching and, with this in mind, the FCA has published a new webpage setting out key information as to the applicability of AML and CTF rules to crypto-asset businesses. Key takeaways include:

  • The precise confines of the crypto-asset activities (“business activities”) that will fall within the MLR are yet to be determined (pending a response to the UK Government consultation on 5MLD) however they are expected to include:
    • crypto-asset exchange provider: the exchange of fiat currency or a crypto-asset for another crypto-asset, including the provision of such services by way of an ATM;
    • custodian wallet providers: businesses that hold a customer’s tokens or administer or transfer tokens for customers;
      • peer to peer providers: businesses providing online marketplaces to facilitate exchange; and
      • issuers of new crypto-assets: including initial coin offerings.
  • Any new crypto-asset business must be registered with the FCA before they can carry out any business activities.
  • Existing crypto-asset businesses may continue to carry out business activities as before but must be in compliance with the MLR from 10 January 2020. However, they have a one-year grace period before they must be registered with the FCA (no later than 10 January 2021).
  • The FCA will have three months to assess the applications for registration. In doing so they will consider, amongst other things, whether the applicant is fit and proper and the adequacy of their AML/CTF systems and controls. As such, existing businesses have a practical deadline of 10 October 2020 to submit their applications for registration.

OFSI imposes third financial sanctions penalty under civil enforcement regime

On 9 September, the Office for Financial Sanctions Implementation (“OFSI”) imposed a financial penalty of £146,341 against Telia Carrier UK Limited for breaches of the Syria financial sanctions. This is the third occasion on which OFSI has imposed a monetary penalty since the body was granted civil enforcement powers in April 2017. The amount of the penalty was actually reduced by approximately 50% following Ministerial review and additional information being made available on the nature of relevant transactions.

This matter is of particular interest since it involved the indirect provision of “economic resources”, rather than just funds, to a designated entity in breach of the Syria sanctions. Economic resources are assets of every kind, whether tangible or intangible, movable or immovable, which are not funds, but may be used to obtain funds, goods or services. In this case, Telia indirectly facilitated international telephone calls to SyriaTel. The matter therefore demonstrates how broadly the meaning of economic resources will be interpreted.

US v Connolly: “outsourcing” government investigations to the private sector

This case concerned the extent to which the US Government can outsource its investigations. In 2018, Matthew Connolly and Gavin Black were convicted of LIBOR-related misconduct. Before the trial, Mr Black’s lawyers attempted to suppress statements which he had made to his employer’s law firm, Paul Weiss, during the internal investigation, on the basis that the US Government had “outsourced substantial portions of the investigation to…Paul Weiss [and] supervised and directed Paul Weiss's investigative activities through, inter alia, periodic meetings and calls.”

The Court found that his employer’s actions were “fairly attributable” to the Government. The Government directed the employer “to conduct an investigation into a particular matter, to do so in a particular fashion, to interview particular people (including Black), to share its findings with the Government on a regular basis, and to carry out governmental investigative demands that were generated by its earlier efforts.”

The Court went on to say that “Paul Weiss did everything that the Government could, should, and would have done had the Government been doing its own work.”

Although Mr. Black’s statements were not eventually used at trial, the Court held that Mr Black’s rights had not be violated because even if his statements had been used, there was overwhelming evidence against him derived from independent sources. The upshot of this case is that enforcement agencies in the US must be careful to not outsource the conduct of their investigations which should be carried out directly by them and their agents or officers. This decision could, however, come into tension with the new SFO Cooperation Guidance outlined above and it remains to be seen how the difference in approaches will play out in matters that are jointly investigated by the DOJ and SFO.

A bank’s duty to spot misappropriation by a company director

The Supreme Court last week handed down an important judgment concerning the implied duties owed by banks to their customers when they detect suspicious payment instructions. Our analysis of the case is available here.

Under the so-called “Quincecare” duty (following a case of that name) a bank must refrain from executing a payment instruction if and for so long as the bank has reasonable grounds for believing that the instruction is an attempt to misappropriate funds. A breach can occur without actual knowledge that the order is dishonestly given – it is enough that the bank shuts its eyes to suspicious circumstances or acts recklessly in failing to make inquiries.

In Singularis v Daiwa, the Supreme Court ruled that a claim for breach of the Quincecare duty will not be defeated by arguments that seek to attribute the actions of dishonest individual(s) to the corporate entity to which the duty is owed. In that case, the instructions were given by the company’s Chairman, sole shareholder and “dominant influence”, yet the Court refused to attribute his actions to the company, saying that to do so would defeat the purpose of the duty (which is to protect the corporate entity).

The decision serves as a reminder of the practical and legal challenges for financial institutions in their dealings with corporate customers. It underscores the importance of a vigilant compliance culture, including amongst front office staff.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.