To Disclose or Not to Disclose: Analyzing the Consequences of Voluntary Self-Disclosure for Financial Institutions

July 12, 2018

One of the most frequently discussed white collar issues of late has been the benefits of voluntarily self-disclosing to the U.S. Department of Justice (“DOJ”) allegations of misconduct involving a corporation.  This is the beginning of periodic analyses of white collar issues unique to financial institutions, and in this issue we examine whether and to what extent a financial institution can expect a benefit from DOJ for a voluntary self-disclosure (“VSD”), especially with regard to money laundering or Bank Secrecy Act violations.  Although the public discourse regarding VSDs tends to suggest that there are benefits to be gained, a close examination of the issue specifically with respect to financial institutions shows that the benefits that will confer in this area, if any, are neither easy to anticipate nor to quantify.  A full consideration of whether to make a VSD to DOJ should include a host of factors beyond the quantifiable benefit, ranging from the likelihood of independent enforcer discovery; to the severity, duration, and evidentiary support for a potential violation; and to the expectations of prudential regulators and any associated licensing or regulatory consequences, as well as other factors.

VSD decisions arise in many contexts, including in matters involving the Foreign Corrupt Practices Act (“FCPA”), sanctions enforcement, and the Bank Secrecy Act (“BSA”).  In certain situations, the benefits of voluntary self-disclosure prior to a criminal enforcement action can be substantial.  Prosecutors have at times responded to a VSD by reducing charges and penalties, offering deferred prosecution and non-prosecution agreements, and entering into more favorable consent decrees and settlements.[1]  However, as Deputy Attorney General Rod Rosenstein stated in recent remarks, enforcement policies meant to encourage corporate disclosures “do[] not provide a guarantee” that disclosures will yield a favorable result in all cases.[2]  The outcome of a prosecution following a VSD is situation-specific, and, as such, the process should not be entered into without careful consideration of the costs and benefits.

In the context of Bank Secrecy Act and anti-money laundering regulation (“BSA/AML”), VSDs present an uncertain set of tradeoffs.  The BSA and its implementing  regulations already require most U.S. financial institutions subject to the requirements of the BSA[3] to file suspicious activity reports (“SARs”) with the U.S. government when the institution knows, suspects or has reason to suspect that a transaction by, through or to it involves money laundering, BSA violations or other illegal activity.[4]  Guidance from DOJ encourages voluntary self-disclosure, and at least one recent non-prosecution agreement entered with the Department has listed self-disclosure as a consideration in setting the terms of a settlement agreement.[5]  Over the past three years, however, no BSA/AML criminal resolution has explicitly given an institution credit for voluntarily disclosing potential misconduct.  During this same period, DOJ began messaging an expanded focus on VSDs in the context of FCPA violations, announced the FCPA Pilot Project, and ultimately made permanent in the U.S. Attorney’s Manual the potential benefits of a VSD for FCPA violations.

This alert addresses some of the considerations that financial institutions weigh when deciding whether to voluntarily self-disclose potential BSA/AML violations to criminal enforcement authorities.  In discussing these considerations, we review guidance provided by DOJ and the regulatory enforcement agencies, and analyze recent BSA/AML criminal resolutions, as well as FCPA violations involving similar defendants.

Guidance from the Department of Justice – Conflicting Signals

DOJ guidance documents describe the Department’s general approach to VSDs, but, until recently, they left unanswered many questions dealing specifically with self-disclosure by financial institutions.  The Department’s high-level approach to general voluntary self-disclosure is outlined in the United States Attorney Manual (“USAM”).  Starting from the principle that “[c]ooperation is a mitigating factor” that can allow a corporation to avoid particularly harsh penalties, the USAM instructs prosecutors that they “may consider a corporation’s timely and voluntary disclosure” when deciding whether and how to pursue corporate liability.[6]

In the FCPA context, a self-disclosure is deemed to be voluntary—and thus potentially qualifying a company for mitigation credit—if (1) the company discloses the relevant evidence of misconduct prior to an imminent threat of disclosure or government investigation; (2) the company reports the conduct to DOJ and relevant regulatory agencies “within a reasonably prompt time after becoming aware of the offense”; and (3) the company discloses all relevant facts known to it, including all relevant facts about the individual wrongdoers involved.[7]

DOJ has not yet offered specific instruction, however, on how prosecutors should treat voluntary self-disclosure in the BSA/AML context and, unlike other areas of enforcement, no formal self-disclosure program currently exists for financial institutions seeking to obtain mitigation credit in the money laundering context.  Indeed, the only guidance document to mention VSDs and financial institutions—issued by DOJ’s National Security Division in 2016[8]—specifically exempted financial institutions from the VSD benefits offered to other corporate actors in the export control and sanctions context, citing the “unique reporting obligations” imposed on financial institutions “under their applicable statutory and regulatory regimes.”[9]

Despite this lack of guidance, the recent adoption of DOJ’s FCPA Corporate Enforcement Policy may provide insight on how prosecutors could treat voluntary disclosures by financial institutions moving forward.  Enacted in the fall of 2017, the Corporate Enforcement Policy arose from DOJ’s 2016 FCPA Pilot Program, which was created to provide improved guidance and certainty to companies facing DOJ enforcement actions, while incentivizing self-disclosure, cooperation, and remediation.[10]  One year later, based on the success of the program, many of its aspects were codified in the USAM.[11]  Specifically, the new policy creates a presumption that entities that voluntarily disclose potential misconduct and fully cooperate with any subsequent government investigation will receive a declination, absent aggravating circumstances.[12]  In early 2018, Acting Assistant Attorney General John Cronan announced that the Corporate Enforcement Policy would serve as non-binding guidance for corporate investigations beyond the FCPA context.[13]

This expanded consideration of VSDs beyond the FCPA space was on display in March 2018, when, after an investigation by DOJ’s Securities and Financial Fraud Unit, the Department publicly announced that it had opted not to prosecute a financial institution in connection with the bank’s alleged front-running of certain foreign exchange transactions.[14]  DOJ’s Securities and Financial Fraud Unit specifically noted that DOJ’s decision to close its investigation without filing charges resulted, in part, from “timely, voluntary self-disclosure” of the alleged misconduct,[15] a sentiment echoed by Cronan in subsequent remarks at an American Bar Association white collar conference regarding the reasons for the declination.[16]  Cronan further commented that “[w]hen a company discovers misconduct, quickly raises its hand and tells us about it, that says something. . . . It shows the company is taking misconduct seriously . . . and we are rewarding those good decisions.”[17]

Other Agency Guidance

Guidance issued by other enforcement agencies similarly may offer clues as to how financial institutions can utilize VSDs to more successfully navigate a criminal enforcement action.

In the context of export and import control, companies that self-disclose to the U.S. Treasury Department’s Office of Foreign Asset Control (“OFAC”) can benefit in two primary ways.  First, OFAC may be less likely to initiate an enforcement proceeding following a VSD, as OFAC considers a party’s decision to cooperate when determining whether to initiate a civil enforcement proceeding.[18]  Second, if OFAC decides it is appropriate to bring an enforcement action, companies that self-disclose receive a fifty-percent reduction in the base penalty they face, as detailed in the below-base-penalty matrix published in OFAC guidance:[19]

Basic Penalty Matrix

As depicted by the chart, in the absence of a VSD, the base penalty for egregious violations[20] is the applicable statutory maximum penalty for the violation.[21]  In non-egregious cases, the base penalty is calculated based on the revenue derived from the violative transaction, capped at $295,141.[22]  When the apparent violation is voluntarily disclosed, however, OFAC has made clear that in non-egregious cases, the penalty will be one-half of the transaction value, capped at $147,571 per violation.[23]  This is applicable except in circumstances where the maximum penalty for the apparent violation is less than $295,141, in which case the base amount of the penalty shall be capped at one-half the statutory maximum penalty applicable to the violation.[24]  In an egregious case, if the apparent violation is self-disclosed, the base amount of the penalty will be one-half of the applicable statutory maximum penalty.[25]

Other agencies tasked with overseeing the enforcement of financial regulations also have issued guidance encouraging voluntary disclosures.  Although the Financial Crimes Enforcement Network (“FinCEN”) has not provided guidance on how it credits voluntary disclosures,[26] guidance issued by the Federal Financial Institutions Examination Council (“FFIEC”), consisting of the Office of the Comptroller of the Currency (“OCC”), the Federal Reserve, the Federal Deposit Insurance Corporation (“FDIC”), the Office of Thrift Supervision (“OTS”), and the National Credit Union Administration (“NCUA”), has made clear that, in determining the amount and appropriateness of a penalty to be assessed against a financial institution in connection with various types of violations, the agencies will consider “voluntary disclosure of the violation.”[27]

In 2016, the OCC published a revised Policies and Procedures Manual to ensure this and other factors are considered and to “enhance the consistency” of its enforcement decisions.[28]  That guidance includes a matrix with several factors, one of which is “concealment.”[29]  In the event that a financial institution self-discloses, they are not penalized for concealment.  Thus, while not directly reducing potential financial exposure, a VSD ensures that a financial institution is not further penalized for the potential violation.

It is also worth noting that, unlike DOJ, these regulators do not appear to draw distinctions regarding the type of offense at issue (i.e., FCPA versus BSA versus sanctions violations).  Moreover, financial institutions contemplating not disclosing potential misconduct need to consider whether the nature of the potential misconduct at issue goes to the financial institution’s safety and soundness, adequacy of capital, or other issues of interest to prudential regulators such as the Federal Reserve, OCC, and FDIC.  To the extent such prudential concerns are implicated, a financial institution may be required to disclose the underlying evidence of misconduct and may face penalties for failing to do so.

The Securities and Exchange Commission (“SEC”) also has indicated that it will consider VSDs as a factor in its enforcement actions under the federal securities laws.  In a 2001 report (the “Seaboard Report”), the SEC confirmed that, as part of its evaluation of proper enforcement actions, it would consider whether “the company voluntarily disclose[d] information [its] staff did not directly request and otherwise might not have uncovered.”[30]  The SEC noted that self-policing could result in reduced penalties based on how much the SEC credited self-reporting—from “the extraordinary step of taking no enforcement action to bringing reduced charges, seeking lighter sanctions, or including mitigating language in documents . . . use[d] to announce and resolve enforcement actions.”[31]  In 2010, the SEC formalized its cooperation program, identifying self-policing, self-reporting, and remediation and cooperation as the primary factors it would consider in determining the appropriate disposition of an enforcement action.[32]  In 2015, the former Director of the SEC’s Division of Enforcement, reaffirmed the importance of self-reporting to the SEC’s enforcement decisions, stating that previous cases “should send the message loud and clear that the SEC will reward self-reporting and cooperation with significant benefits.”[33]  As of mid-2016, the SEC had signed over 103 cooperation agreements, six non-prosecution agreements, and deferred nine prosecutions since the inception of the cooperation program.[34]

Finally, like its federal counterparts, the New York Department of Financial Services (“NYDFS”) has previously signaled, at least in the context of export and import sanctions, that “[i]t is vital that companies continue to self-report violations,”[35] and warned that “those that do not [self-report] run the risk of even more severe consequences.”[36]  The NYDFS has not directly spoken to money laundering enforcement, but financial institutions considering disclosures to New York state authorities should keep this statement in mind.  Similar to the considerations an institution might face when dealing with federal regulators, to the extent DFS prudential concerns are implicated, a financial institution may be required to disclose the underlying evidence of misconduct and face penalties for failing to do so.

Recent BSA/AML and FCPA Resolutions

Even against this backdrop, over the last few years, voluntary self-disclosure has not appeared to play a significant role in the resolution of criminal enforcement proceedings arising from alleged BSA/AML violations.  Since 2015, DOJ, in conjunction with other enforcement agencies, has resolved BSA/AML charges against twelve financial institutions.[37]  In eleven of those cases, the final documentation of the resolution—the settlement agreements and press releases accompanying the settlement documents—make no mention of voluntary self-disclosure.  Even in the FCPA context, where DOJ has sought to provide greater certainty and transparency concerning the benefits of voluntary disclosure, there is a scant track record of financial institutions making voluntary disclosures in connection with FCPA resolutions.  Since 2015, DOJ has announced FCPA enforcement actions with six financial institutions.  The Justice Department did not credit any of them with voluntarily self-disclosing the conduct.[38]

Although recent resolutions have not granted credit for VSDs, financial entities facing enforcement actions should consider how such a disclosure might affect the nature of a potential investigation and the ultimate disposition of an enforcement action.  It is worth noting that in the one recent BSA/AML resolution with a financial institution in which voluntary self-disclosure was referenced—DOJ’s 2017 resolution with Banamex USA—it was in the course of explaining why the financial institution did not receive disclosure credit.  In other words, there is no example of a criminal enforcement action commending a financial institution for a VSD, or of an agency softening the enforcement measures as a result of a VSD.[39]  The fact that the Banamex USA resolution affirmatively explains why the defendant did not receive VSD credit may imply that this type of credit may be available to financial institution defendants when they do make adequate VSDs.

Furthermore, over the same time period, prosecutors have credited financial institutions for other forms of cooperation.  For example, in 2015, the Department of Justice deferred prosecution of CommerceWest Bank officials for a BSA charge arising from their willful failure to file a SAR, in part because of the bank’s “willingness to acknowledge and accept responsibility for its actions” and “extensive cooperation with [DOJ’s] investigation.”[40]  Similarly, a 2015 non-prosecution agreement with Ripple Labs Inc. credited the financial institution with, among other factors, “extensive cooperation with the Government.”[41]  These favorable dispositions signal that the government is willing to grant mitigation credit for cooperation, even when financial institutions are not credited with making VSDs.

Other Relevant Considerations Relating to VSDs

As discussed above, the government’s position regarding the value of VSDs and their effect on the ultimate resolution of a case vary based on the agency and the legal and regulatory regime(s) involved.  Given the lack of clear guidance from FinCEN about how it credits VSDs and the fact that BSA/AML resolutions tend not to explicitly reference a company’s decision to disclose as a relevant consideration, navigating the decision of whether to self-report to DOJ is itself a fraught one.  Beyond the threshold question of whether or not to self-disclose to DOJ, financial institutions faced with potential BSA/AML liability should be mindful of a number of other considerations, always with an eye on avoiding the specter of a full-blown criminal investigation and trying to minimize institutional liability to the extent possible.

  • Likelihood of Discovery:  A financial institution deciding whether to self-disclose to DOJ must contemplate the possibility that the government will be tipped off by other means, including by the prudential regulators, and will investigate the potential misconduct anyway, without the financial institution gaining the benefits available for bringing a case to the government’s attention and potentially before the financial institution has had the opportunity to develop a remediation plan.  Financial institutions that plan to forego self-disclosure of possible misconduct will have to guard against both whistleblower disclosures and the possibility that other institutions aware of the potential misconduct will file a Suspicious Activity Report implicating the financial institution.
  • Timing of Disclosure:  Even after a financial institution has decided to self-report to DOJ, it will have to think through the implications of when a disclosure is made.  A financial institution could decide to promptly disclose to maximize cooperation credit, but risks reporting without developing the understanding of the underlying facts that an internal investigation would provide.  Additionally, a prompt disclosure to DOJ may be met with a deconfliction request, in which the government asks that the company refrain from interviewing its employees until the government has had a chance to do so.  This may slow down the company’s investigation and impede its ability to take prompt and decisive remedial actions, including those related to personnel decisions.  On the other hand, waiting until after the internal investigation has concluded (or at least reached an advanced stage) presents the risk of the government finding out first in the interim.  The financial institution also will have to decide whether to wait longer to report to the government having already designed and begun to implement a remediation plan or to disclose while the remediation plan is still being developed.
  • Selective or Sequential Disclosures:  Given the number of agencies with jurisdiction over the financial industry and the overlaps between their respective spheres of authority, financial institutions contemplating self-disclosure will often have to decide how much to disclose, whether to both prudential regulators and DOJ, and in what order.  In some cases, a financial institution potentially facing both regulatory and criminal liability may be well-advised to engage civil regulators first in the hope that, if DOJ does get involved, they will stand down and piggy-back on a global resolution with other regulators rather than seeking more serious penalties.  Indeed, DOJ prosecutors are required to consider the adequacy of non-criminal alternatives – such as civil or regulatory enforcement actions – in determining whether to initiate a criminal enforcement action.[42]  For example, the non-prosecution agreement DOJ entered in May 2017 with Banamex recognized that Citigroup, Banamex’s parent, was already in the process of winding down Banamex USA’s banking operations pursuant to a 2015 resolution with the California Department of Business Oversight and FDIC and was operating under ongoing consent orders with the Federal Reserve and OCC relating to BSA/AML compliance; consequently, DOJ sought only forfeiture rather than an additional monetary penalty.[43]  Of course, any decision to selectively disclose must be balanced carefully against the practical reality that banking regulators will, in certain instances, notify DOJ of potential criminal violations whether self-disclosed or identified in the examination process.  Whether that communication will occur often is influenced by factors such as the history of cooperation between the institutions or the relationships of those involved.  Nevertheless, the timing and nature of any referral by a regulator to DOJ might nullify any benefit from a selective or sequential disclosure.


In this inaugural Developments in the Defense of Financial Institutions Client Alert, we addressed whether and to what extent a financial institution should anticipate receiving a benefit when approaching the pivotal decision of whether to voluntarily self-disclose potential BSA/AML violations to DOJ.  We hope this publication serves as a helpful primer on this issue, and look forward to addressing other topics that raise unique issues for financial institutions in this rapidly-evolving area in future editions.

