CEO and CFO Liability in SEC Investigations.
The SEC typically initiates its investigations targeting companies (as well as their senior executives, outside directors, and individual employees) following referrals from other agencies, news reports, whistleblower complaints, or suspicious activity flagged by the SEC’s own ongoing compliance monitoring. When the SEC initiates a civil investigation, there is no presumption of individual executive liability. An investigation can, and often does, close without charges being filed against any individual executive.
Even when an individual is charged in an SEC enforcement action, this does not itself establish guilt or civil liability (and it does not establish criminal liability, either). While the SEC conducts civil enforcement proceedings, the Department of Justice (DOJ) is the sole agency that can pursue federal criminal charges. As a result, an SEC investigation can also trigger parallel DOJ scrutiny, exposing the CEO and CFO to additional risks including federal indictment, arrest, and jail time.
Senior executives’ risk of SEC liability often (but not always) depends on their specific role. For example, cybersecurity disclosures can create securities-enforcement exposure for any senior executive who fails to adequately disclose known cybersecurity risks, or who makes misleading public statements about cybersecurity compliance. In other types of securities litigation, such as those involving insider trading, FCPA, SPAC, and cryptocurrency conduct, CEO and CFO liability can depend on a variety of distinct statutory elements, procedural stages, evidence, and required strategic responses. If appropriate, the SEC can seek remedies such as:
- Civil monetary penalties
- Disgorgement of ill-gotten gains
- Officer-and-director bars (e.g., bars preventing an individual from serving as a senior executive at a publicly traded company)
- Permanent or temporary injunctive relief
- Additional remedies including temporary restraining orders (TROs), pre-judgment asset freezes, and receiverships
What Must the SEC Prove Against a CEO or CFO?
In some cases, SEC charges for individual CEOs and CFOs will be based on distinct statutory certifications requirements that do not apply to other executives. These certification requirements are part of the Sarbanes-Oxley Act of 2002 (SOX) and are codified at 18 U.S.C. § 1350 (SOX Section 906) and 15 U.S.C. § 7241, 7242, 7243, and 7244 (SOX Section 302). As a result, in cases involving insider trading, FCPA violations, and other statutory matters, some CEOs and CFOs may face additional liability risks not available in cases involving violations of other federal securities laws. These certification requirements are a significant part of the SEC’s enforcement toolset, and proving these violations has historically been an important priority for the SEC.
1. The Certification Requirements of Sarbanes-Oxley Sections 302 and 906
The certification requirements imposed by Sarbanes-Oxley Section 302 and 18 U.S.C. § 1350 (SOX Section 906) are separate, but overlapping. While SOX Section 302 imposes civil certification obligations under the Securities Exchange Act of 1934, SOX Section 906 imposes criminal certification obligations.
SOX Section 302 (15 U.S.C. § 7241) requires CEOs and CFOs to certify that:
- They have reviewed the issuer’s quarterly and annual reports filed pursuant to Section 13(a) or 15(d) of the Securities Exchange Act of 1934;
- Based on their review, the report does not contain any untrue statement of a material fact or omit to state a material fact necessary to make the statements made in the report not misleading;
- They have established and maintained disclosure controls and procedures; and,
- They have evaluated the effectiveness of the issuer’s disclosure controls and procedures.
Similar to SOX Section 302, SOX Section 906 (18 U.S.C. § 1350) imposes criminal certification requirements for corporate quarterly and annual reports. Under Section 906, corporate officers who knowingly certify fraudulent financial statements in violation of the Exchange Act can be held criminally liable. As we explain in more detail on our SOX Section 906 page:
- The filing of an erroneous report (even if it is material) does not, by itself, establish criminal Section 906 liability. To obtain a criminal conviction under Section 906, the government must prove that the issuer’s report was not accurate, that the CEO or CFO certified the report knowing it was not accurate, and that the CEO or CFO had the requisite intent to defraud investors.
- The certification requirements imposed by SOX Section 906 apply to both CEOs and CFOs. Some have mistakenly believed that CFOs are solely responsible for signing off on financial disclosures under SOX, but the federal certification statutes expressly impose these obligations on both top executives.
2. Control Person Liability (Exchange Act Section 20(a))
In addition to the potential for liability under the certification requirements of SOX Sections 302 and 906, some CEOs and CFOs may face liability (including civil and criminal liability) in cases involving insider trading, FCPA violations, and other statutory matters. This forms the basis for “control person liability” under Section 20(a) of the Exchange Act (15 U.S.C. § 78t). Under Section 20(a), the SEC must prove that (i) a “control person” had the ability to control the individual or entity that committed a primary violation of the Exchange Act; (ii) the individual or entity committed a primary violation; and, (iii) the control person is liable for the primary violation. The statute provides a single affirmative defense to Section 20(a) liability: the control person must show both that he or she acted in good faith and that he or she did not directly or indirectly induce the act or acts constituting the primary violation.
3. Scienter-Based SEC Enforcement (Exchange Act Section 10(b))
Exchange Act Section 10(b) and Rule 10b-5 (17 C.F.R. § 240.10b-5) prohibit fraud in the purchase or sale of securities. Under Section 10(b), the SEC can bring claims for various types of securities fraud, and these claims are broadly-applicable in nature. To establish liability under Section 10(b) and Rule 10b-5, the SEC must prove that:
- The defendant used a “manipulative or deceptive device” or engaged in fraud, deception, or other misleading conduct during the purchase or sale of a security, or engaged in a transaction or series of transactions to create a false or misleading appearance of active trading;
- The defendant acted with “scienter”, i.e., intent to deceive, manipulate, or defraud investors, or acted recklessly in order to violate the federal securities laws; and
- The conduct occurred in connection with the purchase or sale of a security; unlike a private plaintiff, the SEC need not prove reliance, loss causation, or that investors suffered losses.
4. Negligence-Based SEC Enforcement (Securities Act Section 17(a))
The SEC can also bring cases under Sections 17(a)(1), (2), and (3) of the Securities Act of 1933. Similar to Section 10(b), Section 17(a) authorizes SEC enforcement in the offering or sale of securities. However, Sections 17(a)(2) and 17(a)(3) permit the SEC to prove liability on a negligence-based theory. In cases involving Section 17(a)(2) or 17(a)(3), the SEC need only prove that a CEO or CFO acted negligently to establish liability. This significantly reduces the SEC’s burden of proof, and greatly increases the likelihood of success.
What Happens Before the SEC Files Charges Against an Executive?
In addition to the substantive requirements of the federal securities laws, SEC investigations are procedural in nature. While the SEC has issued well-known guidelines, there is no single set of “rules of the road” in SEC investigations. These investigations typically proceed in five steps, as discussed below.
At the earliest stage, SEC investigations generally involve an informal inquiry. During the informal inquiry stage, the SEC typically relies on voluntary requests for information from companies and executives rather than issued subpoenas. However, these inquiries are not bound by strict rules and the SEC’s staff have a variety of other options available during the informal inquiry stage as well.
2. Formal Order of Investigation (and Issuance of Subpoena)
If the SEC’s informal inquiry does not resolve the matter, the SEC will then request a formal order of investigation (which is then granted by the SEC Commissioners). Once the formal order of investigation is granted, the SEC designates specific staff members to oversee the investigation and designates staff who are authorized to issue subpoenas. Following issuance of the formal order of investigation, the SEC will often issue its first subpoenas targeting both the company and certain individuals at the company. With these subpoenas, the SEC can compel the production of documents and sworn testimony from a variety of sources including company management, individual employees, board members, and companies’ own accountants, lawyers, and other consultants.
3. Issuance of the Wells Notice
If the SEC’s staff attorneys (the “staff”) believe that they have the evidence required to establish an enforceable violation of the federal securities laws, the SEC will then issue what is known as a Wells notice. As we explain on our Wells Notice Defense page, receiving a Wells notice is not equivalent to receiving formal charges. Rather, it is a notification by the SEC that the staff is planning to recommend charges against the notice’s recipient. Along with the Wells notice, the SEC will provide a summary of the alleged violations it believes are proven. Recipients of Wells notices may submit a series of “Wells arguments” to the SEC’s Commission for review before the Commission decides whether to authorize enforcement.
The Commission decides how to proceed in these cases, and if it chooses to proceed, the Commission will authorize the SEC staff to pursue enforcement action. Importantly, even if the Commission authorizes enforcement, this authorization does not itself establish liability for the company’s CEO, CFO, board members, or executives. Following Commission authorization, the SEC will then file (or threaten to file) charges.
4. SEC Enforcement Action (and DOJ Prosecution)
After the Commission authorizes an enforcement action, the SEC will then issue charges and potentially attempt to secure the civil remedies discussed above. Additionally, SEC investigations can also involve (i) interviews and proffers; (ii) grand jury testimony; and, (iii) negotiating resolutions with the SEC’s staff attorneys. If the DOJ pursues criminal charges in an SEC investigation, the potential for criminal liability will depend on whether the DOJ can establish the necessary intent-based and/or results-based criteria in order to justify criminal charges.
5. Criminal and Civil Prosecution
While the SEC’s staff members do not have a fixed deadline that requires them to close their investigations, the SEC has historically required its investigators to close their cases. Again, this only holds true in the context of non-criminal SEC enforcement actions. If an SEC investigation triggers a parallel DOJ investigation, the matter may trigger federal criminal charges regardless of how soon the SEC’s investigators close their cases.
If any of this describes your situation, it is worth talking it through with counsel. Spodek Law Group can be reached at 212-300-5196.
What Should I Do When SEC Investigators Contact Me?
When SEC investigators contact the CEO and CFO of a company (or company counsel), the SEC investigators will often encourage the individuals to work “hand in hand” with the SEC during its investigation. However, civil SEC enforcement and criminal DOJ proceedings can (and often do) operate in parallel, and an executive’s perceived cooperation in an SEC investigation can, under certain circumstances, lead to unnecessary criminal exposure in a parallel DOJ investigation. Senior executives, board members, and company counsel should keep the following factors in mind during the early stages of an SEC investigation:
While companies may often employ “joint” counsel for the investigation (meaning that the company’s counsel will also represent the CEO and CFO), many state-level rules prohibit joint representation. ABA Model Rule 1.7 (and corresponding state ethics rules) restrict attorneys from engaging in representation when the representation “involves a concurrent conflict of interest.” This includes when “the representation of one client will be directly adverse to another client,” and when “there is a significant risk that the representation of one or more clients will be materially limited by the lawyer’s responsibilities to another client (e.g., a former client, a government agency, or a third party).”
That said, while Model Rule 1.7 bars joint representation in some cases, joint representation is permitted in other circumstances. For example, pursuant to ABA Model Rule 1.7(b), if there is a conflict of interest, joint representation may still be permitted if:
- The lawyer reasonably believes that “the lawyer can provide competent and diligent representation to each affected client”;
- The representation is not prohibited by law;
- The representation does not involve the assertion of a claim by one client against another client represented by the lawyer in the same litigation or other proceeding before a tribunal; and,
- Each affected client gives informed consent, confirmed in writing.
Even in cases where joint representation is permitted, it is essential to understand what a conflict of interest is and when it may arise. CEOs, CFOs, and other senior executives should also be aware that joint representation may raise other ethical concerns as well.
If a company’s counsel engages in joint representation, he or she should promptly explain that the company (rather than the individual client or clients) controls the company’s internal-investigation privilege and that the company is entitled to a “privileged-communication exception” for interviews with current and former employees. This is among many considerations that executives and company counsel must consider carefully.
Finally, companies must take the appropriate steps to issue an adequate litigation hold. This means that the litigation hold must cover all relevant materials, including:
- Relevant documents stored in hard copy, on the company’s internal networks, or with third parties (e.g., with the company’s outside accounting, IT, and cybersecurity firms);
- Company data on devices that are in the company’s possession or control, such as laptop computers, iPads, iPhones, and other mobile devices; and,
- Relevant communications on messaging applications (e.g., with respect to an company’s executives’ and employees’ use of iMessage, Slack, WhatsApp, and other encrypted messaging apps).
Crucially, by issuing a blanket preservation notice, companies can help ensure that they preserve all relevant communications regardless of where they are stored, and avoid the potential consequences of failing to preserve evidence.
Although there is a common misconception that invoking the Fifth Amendment effectively ends an SEC investigation, this is not necessarily true. While invoking the Fifth Amendment effectively terminates an executive’s obligation to provide testimony during the SEC’s investigations (as testified to during the Grand Jury process), it may not terminate the SEC’s ability to pursue civil charges. When an individual asserts the Fifth Amendment in a civil proceeding, the court may allow adverse inferences. That is, the jury may infer that the individual is not testifying because the truth would be unfavorable to the individual’s case.
This makes the decision to invoke the Fifth Amendment carefully calculated, and this decision must also consider whether the defendant has any viable non-Fifth Amendment defenses to the allegations at hand. As a result, senior executives will need to make informed decisions about whether to assert the Fifth Amendment in the context of both civil and criminal proceedings.
Along with the risk of the jury allowing adverse inferences, senior executives must also be careful not to volunteer potentially incriminating information to SEC investigators. As we discuss below, false statements made during SEC testimony can trigger additional criminal liability, and even innocent statements made to the government can potentially be used against defendants.
While the U.S. Supreme Court in the case of Bordello v. United States (2024) has yet to adopt the “favorable inference” rule, the prosecution is always at a disadvantage when senior executives rely on their constitutional privilege not to incriminate themselves. This rule also applies when executives testify during their company’s internal investigation. Senior executives can still inadvertently provide incriminating information, and the company’s internal investigation can trigger issues as well.
Ultimately, for CEOs, CFOs, and other senior executives, managing SEC investigations requires a well-informed decision about whether or not to cooperate with the SEC’s investigators. When assessing their executives’ willingness to cooperate, the SEC typically considers factors including:
- The executive’s self-reporting;
- The executive’s remediation efforts (e.g., remediation through internal audits and other methods);
- The executive’s assistance to investigators;
- The executive’s actions to correct past mistakes;
- The executive’s disclosures to the government about other executives’ and third parties’ fraudulent schemes;
- The executive’s diligence to prevent future non-compliance; and,
- The executive’s compliance with the SEC’s investigator’s requests.
Working with experienced defense counsel will allow CEO and CFO to make informed decisions about the legal issues involved in their SEC investigation.
Can Compensation Be Clawed Back Without Proving Personal Misconduct?
Yes, it is possible to recover compensation from individual executives in two contexts. Here is a discussion of these contexts in more detail.
1. Clawbacks Under SOX Section 304
The first context in which compensation can be recovered without establishing personal misconduct is in cases involving the enforcement of Sarbanes-Oxley Section 304. Under Section 304, an SEC enforcement action may result in the disgorgement of certain executive compensation received during the twelve-month period preceding the issuance of a company’s qualifying restatement. The key is that the clawback provision of SOX Section 304 is triggered upon a qualifying issuer restatement, and it is not triggered upon the CEO or CFO personally engaging in misconduct.
2. Clawbacks Under the Dodd-Frank Act
The second context in which executive compensation may be recovered without evidence of the executive personally engaging in misconduct is in cases involving the enforcement of the Dodd-Frank Act. The Dodd-Frank Act authorizes companies to recover (i) “incentive-based compensation” that would not have been “erroneously awarded,” (ii) the amount of “erroneously awarded” incentive-based compensation over the amount “required to be recovered,” and, (iii) any other forms of compensation that are directly tied to the issuance of a qualifying restatement.
1. Clawbacks Under SOX Section 304
The first context in which compensation can be recovered without establishing personal misconduct is in cases involving the enforcement of Sarbanes-Oxley Section 304. Under Section 304, an SEC enforcement action may result in the disgorgement of certain executive compensation received during the twelve-month period preceding the issuance of a company’s qualifying restatement. The key is that the clawback provision of SOX Section 304 is triggered upon a qualifying issuer restatement, and it is not triggered upon the CEO or CFO personally engaging in misconduct.
2. Clawbacks Under the Dodd-Frank Act
The second context in which executive compensation may be recovered without evidence of the executive personally engaging in misconduct is in cases involving the enforcement of the Dodd-Frank Act. The Dodd-Frank Act authorizes companies to recover (i) “incentive-based compensation” that would not have been “erroneously awarded,” (ii) the amount of “erroneously awarded” incentive-based compensation over the amount “required to be recovered,” and, (iii) any other forms of compensation that are directly tied to the issuance of a qualifying restatement. The law establishes an affirmative obligation for companies to recover this erroneously awarded incentive-based compensation from the executives who were deemed to have received the over-payment. While the clawback obligations under the Dodd-Frank Act generally reach three completed fiscal years, they are not limited to those specific years.
Under Exchange Act Section 10D (15 U.S.C. § 78j-1), a company is required to recover compensation from an executive “when the issuer is required to prepare a qualifying restatement.” This is among several different statutory clawback provisions and triggers available under federal law.
As the statute makes clear, a “qualifying restatement” (i.e., preparation of a restatement required under Exchange Act Section 10D(a)) will trigger the clawback obligation regardless of who is at fault, if at all. If any individual executive receives compensation that would not have been awarded without the issuance of the qualifying restatement, the issuer must seek recovery of the erroneously awarded incentive-based compensation.
Will D&O Insurance Cover My SEC Investigation Costs?
Whether D&O insurance will apply to cover the costs of an SEC investigation will depend on the specific language of the D&O insurance policies and the specific circumstances at hand. Generally speaking, D&O insurance policies may potentially cover:
- The CEO, CFO, and other senior executives’ defense costs;
- The costs of a civil settlement with the SEC; and,
- Certain penalties and disgorgement.
While the individual policies will dictate what specific types of coverage (if any) are available, this is an area in which D&O insurance coverage is broadly interpreted. This means that, in some cases, the payment of defense costs may not reduce the overall limit of the D&O insurance policy, and that payment of certain types of penalties and disgorgement will be permitted.
When D&O insurance applies, executives often have the right to advance costs to their defense counsel. Even when a company agrees to advance defense costs to executives, disputes may still arise over how much of these costs are covered under the D&O insurance policy. These disputes often center on whether executives’ and the company’s claims are combined in a manner that triggers the allocation of the D&O policy’s limits between covered and uncovered claims.
2. The “Final-Adjudication” Requirement
For D&O policies that trigger coverage based on a final adjudication, the applicability of the final-adjudication requirement is another important consideration. With the final-adjudication requirement in place, the insurer will generally only be required to reimburse (i) the company for any covered claims it pays on behalf of an executive, and (ii) executives’ defense costs and liabilities that are a result of a final adjudication of the executive’s covered misconduct (including, but not limited to, any court ruling or negotiated plea agreement).
3. Limitations on D&O Coverage
Finally, even in cases in which the company’s D&O insurance covers defense costs, there are some circumstances in which the policy may exclude coverage for the executives’ liability and civil penalties. These exclusions typically include coverage for adjudicated intentional misconduct or a violation of federal securities laws. In addition, many D&O policies may also exclude coverage for civil penalties and disgorgement in cases where applicable law prohibits indemnification for the penalty or disgorgement.
Get Advice on Your Situation
If you want someone to look at the specifics of your case, Spodek Law Group handles federal criminal defense nationwide from New York and Los Angeles. The firm has been practicing since 1976 and its motto is simple: we owe loyalty to only you. Call 212-300-5196.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196