Season 2, Episode 9: Words and Action: A Fall Playbook of Speeches, Risk Alerts, and Rulemaking
In this episode of Asset Management Corner, Chris and Andrew discuss speeches from the heads of Examinations and Enforcement, an SEC “risk alert” on annual reviews, and the highly anticipated proposed rulemaking on pay to play. They are then joined by Joann Harris, a partner and CCO at TPG, and former SEC great, to discuss her transition to becoming a CCO, how to build and maintain an effective compliance function, and what everyone is looking forward to this fall season, including more college football talk.
Transcript
Andrew Dean: Hello and welcome back to Asset Management Corner. We are your hosts, Andrew Dean and Christopher Mulligan, partners at the law firm Weil. This is the podcast where we talk all things SEC regulatory and enforcement. Later in the episode, we are joined by Joann Harris, a Partner and Chief Compliance Officer at TPG and a former SEC Enforcement official. But first, Chris, we had David Woodcock on the podcast last time. He is a huge LSU fan, as we discussed, and right after we recorded that interview, LSU played Clemson.
Christopher Mulligan: And it was a little tense there at the beginning. I think it was tied in the first quarter, and we were wondering whether David was going to take some heat from us after talking up LSU on the podcast.
Andrew Dean: But LSU came around in a big way, so David is safe. We'll keep the college football talk going when Joann joins us later. First, though, David gave a speech this morning at the Government Enforcement Institute. Usually when something comes out right before we record, it does not work in our favor, but this one came out about an hour and a half before we started, so we have had a chance to pull out some highlights.
Andrew Dean: One of the first things he discussed was enforcement statistics. We are coming toward the end of the SEC's fiscal year, and I think everybody understands that the raw enforcement numbers are going to be down. David addressed that directly. He talked about the longest government shutdown in history and described this fiscal year as a period of recalibration for Enforcement. He also emphasized that the current Commission has high standards and has been thoughtful and deliberate about the cases it brings.
Christopher Mulligan: And he also talked about the review of the investigative docket that took place after the leadership transition. There were matters that did not fit the current Commission's priorities or where the costs of continuing the investigation were difficult to justify. His point was that closing those matters frees up staff to focus on cases that better fit the Commission's priorities.
Andrew Dean: Right. And I thought the broader point was important. He said he is not focused on judging the Enforcement program by case counts or dollar amounts. He wants Enforcement to be visible and effective. The market needs to understand that Enforcement is on the job and that people who violate the securities laws will suffer the consequences. That is the message he wants the market to take away, regardless of what the year-end statistics ultimately look like.
Christopher Mulligan: He also discussed the new Financial Reporting and Accounting Unit, which we talked about when David joined us. That unit is designed to bring dedicated expertise to financial reporting fraud, accounting misconduct and auditor cases.
Andrew Dean: Those can be some of the most challenging and time-consuming cases the Division handles. David's point was that bringing together people with specialized expertise should help Enforcement investigate those matters more efficiently and bring better cases more quickly.
Andrew Dean: He also spent a fair amount of time talking about speeding up investigations generally. That is one of the perennial challenges in Enforcement: how do you get matters done faster without sacrificing the quality of the investigation? He specifically encouraged the staff, where appropriate, to consider taking testimony before all of the document production is complete.
Christopher Mulligan: Which is interesting, because the traditional model can be document production first, testimony later.
Andrew Dean: Exactly. I actually encouraged teams to use that approach when I was at the SEC. Some of the best cases I worked on were matters where we got people locked into testimony or interviews relatively early. Then, as additional facts and documents developed, it became harder for somebody to change the story or explain away what they had already said. Obviously, it depends on the investigation, but it can be a very effective tool.
Christopher Mulligan: David also tied efficiency to cooperation. His message was that a company that self-reports, cooperates and remediates is not going to be treated the same as a company that conceals, delays or obstructs. And he made clear that the Division is not going to have much patience for unnecessary delays in productions or testimony.
Andrew Dean: The other process point that caught my attention involved meetings with the Front Office. David made clear that a meeting with a Deputy Director is a meeting with the Front Office. People should not assume that every Wells presentation or escalated issue means they are going to get a separate audience with the Director himself. The Deputy Directors are empowered to hear those arguments and exercise judgment.
Christopher Mulligan: So there is a lot in that speech for practitioners. It is worth reading.
Andrew Dean: Absolutely. Chris, let's move to rulemaking, because we have had a couple of significant proposals since we last recorded.
Christopher Mulligan: The first one is a big one for investment advisers. On September 3, the Commission proposed rescinding the pay-to-play rule, Rule 206(4)-5. This is the first major reconsideration of that rule since it was adopted about 16 years ago.
Christopher Mulligan: As everybody in the advisory space knows, the current rule generally imposes a two-year timeout on receiving compensation for advisory services to a government entity after certain political contributions are made by an adviser or certain covered associates. It has created significant compliance burdens over the years, particularly because relatively small contributions or contributions made before someone joins a firm can create serious consequences.
Andrew Dean: And a lot of firms have responded to that complexity by going well beyond what the rule literally requires and effectively prohibiting political contributions altogether.
Christopher Mulligan: Right. That is part of the rationale behind the proposal. The Commission is proposing to eliminate the rule rather than simply modify the contribution limits or shorten the timeout. The proposal also would eliminate the related books-and-records requirements.
Christopher Mulligan: But it is important to emphasize that this is only a proposal. The current rule remains in effect unless and until the Commission adopts a final rule. Comments are due in November, so we will see what the record looks like and whether the Commission ultimately adopts the proposal as written.
Andrew Dean: And even if it is rescinded, that does not mean advisers suddenly have no obligations in this area.
Christopher Mulligan: Exactly. The proposing release goes out of its way to point out that the Advisers Act's antifraud provisions, fiduciary obligations, the Compliance Rule and the Code of Ethics Rule would all continue to apply. Advisers would still need to think about whether political contributions or related conduct create conflicts or other issues that their compliance programs need to address.
Christopher Mulligan: That creates an interesting question for compliance officers. If Rule 206(4)-5 ultimately disappears, what do you do with the detailed policies many firms already have? Some firms may decide to simplify them substantially. Others may retain controls because they are concerned about conflicts or other state and local requirements. And, of course, once you put policies in place, you need to follow them. We have seen plenty of SEC cases based on firms failing to comply with their own policies and procedures.
Andrew Dean: So rescission of the rule would not necessarily mean that everybody just deletes the political-contributions section of the compliance manual the next day.
Christopher Mulligan: Correct. That is going to require some thought.
Christopher Mulligan: The other very significant proposal came on September 16 and involves shareholder proposals. The Commission proposed rescinding Exchange Act Rule 14a-8, which is the federal framework that generally requires public companies, subject to various requirements and exclusions, to include qualifying shareholder proposals in their proxy materials.
Andrew Dean: That would be a major change.
Christopher Mulligan: A very major change. The Commission's rationale is both legal and policy-based. It takes the position that Rule 14a-8 improperly reaches into matters of corporate governance that traditionally belong to the states. Under the proposal, whether and how shareholders can submit proposals, and whether companies are required to include those proposals in their proxy materials, would depend much more heavily on state law and the company's governing documents.
Christopher Mulligan: There are also proposed amendments to Rule 14a-4 that would expand the circumstances in which companies can exercise discretionary voting authority over proposals presented at a shareholder meeting but not included in the company's proxy materials.
Andrew Dean: So instead of having one relatively uniform federal regime, you could end up looking much more closely at the law of the state where a company is incorporated and its particular governing documents.
Christopher Mulligan: That's right. Again, it is only a proposal, and there will be a comment process, but it is a significant potential shift.
Andrew Dean: Let's move to something that is much more immediately actionable for advisers: the new Risk Alert from the Division of Examinations.
Christopher Mulligan: Yes. This is one I would encourage compliance officers to read. Risk Alerts are some of the most useful materials the Division publishes because they give you a window into what examiners are actually seeing in the field. They are essentially taking observations from hundreds or thousands of examinations and deficiency letters, anonymizing them and telling the industry, "These are the problems we keep seeing."
Christopher Mulligan: This particular Risk Alert focuses on advisers' annual compliance reviews under Rule 206(4)-7. The issues are not exotic. In some cases, advisers simply were not conducting reviews annually. There were gaps between reviews, reviews covered periods longer than 12 months, or firms treated employee training or annual attestations as though those things themselves satisfied the annual-review requirement.
Andrew Dean: There were also issues with the actual procedures for conducting the review.
Christopher Mulligan: Exactly. Some policies said the firm would conduct testing and validation but did not explain what testing should be performed, what factors should be evaluated or what documentation should be created and retained. Other firms had topics scattered throughout their compliance manuals that were supposed to be reviewed annually but did not actually include those topics in their annual-review process.
Christopher Mulligan: Another category involved firms that did conduct a review but did not follow their own procedures. They used the wrong review period, did not complete required tests or workpapers, or evaluated outdated versions of policies that had already been superseded.
Andrew Dean: Which gets back to something we say all the time: having the policy is not enough. Your actual practices have to match the policy.
Christopher Mulligan: Right. The staff also identified situations where annual reviews failed to recognize gaps between written policies and what the business was actually doing. That included issues involving fee calculations, proxy voting, custody, marketing policies, regulatory filings and other areas.
Christopher Mulligan: There were documentation issues as well. Firms sometimes did the testing or identified compliance issues but did not retain the supporting documentation. And there were situations where annual reviews recommended corrective action, but the firm did not actually follow through on the recommendation.
Andrew Dean: For advisers doing their annual reviews in the fall or winter, this is basically a checklist handed to you by the SEC. You can read the Risk Alert and ask, "Are we doing any of these things?"
Christopher Mulligan: Exactly. It is a very practical resource, and the timing is good because a lot of firms are either beginning or preparing for their annual-review process now.
Andrew Dean: There was also a speech from Keith Cassidy, the Director of the Division of Examinations.
Christopher Mulligan: Yes. He spoke at the ICI Compliance, Risk and Legal Conference, and the overarching theme was making EXAMS more accessible and integrated. He talked about trying to make the examination process less adversarial and more transparent.
Christopher Mulligan: Part of that is giving registrants more information before and during exams. The Division publishes annual priorities, conducts outreach and publishes Risk Alerts so firms have a better understanding of what examiners are looking at and what they expect.
Christopher Mulligan: He also specifically encouraged registrants to use the exit conference. If a firm believes an observation or potential deficiency is wrong, the exit conference is an opportunity to explain why, provide additional information and have that discussion with the examination team.
Andrew Dean: But he also made an important distinction about remediation.
Christopher Mulligan: Right. EXAMS can tell you what deficiency it identified, but it is generally not going to act as your consultant and write the remediation plan for you. Firms are expected to determine the appropriate corrective measures based on their obligations and their particular business.
Christopher Mulligan: Cassidy also talked about improving consistency across the Division and increasing integration between EXAMS and the policy divisions. That includes knowledge-sharing with Investment Management and Trading and Markets and staff rotations between EXAMS and policy groups.
Andrew Dean: Which is meaningful because EXAMS is enormous. People sometimes do not appreciate the size of the organization.
Christopher Mulligan: It is just under a thousand professionals. With an organization of that size operating across different offices and regions, consistency is always going to be a challenge. The Division is trying to put systems in place to reduce differences based simply on geography or which particular team is conducting the exam.
Christopher Mulligan: Cassidy also announced that the Division would publish a new and expanded replacement for the old EXAMS brochure. The idea is to give registrants a clearer, more practical guide to what to expect during an examination and what to do if issues arise.
Andrew Dean: One final SEC development before we bring Joann in. Since our last episode, the Commission filed a subpoena-enforcement action against Institutional Shareholder Services, or ISS.
Andrew Dean: ISS is a registered investment adviser, which is important because registered advisers are required to provide books and records to the SEC during examinations. According to the Commission's filing, EXAMS opened an examination and requested information relating to ISS's proxy recommendations and votes. There was a back-and-forth over the production, EXAMS did not get everything it believed it was entitled to, Enforcement became involved and ultimately an administrative subpoena was issued.
Christopher Mulligan: And when the requested material still was not produced, the SEC went to court.
Andrew Dean: Correct. When I was in Enforcement, if EXAMS was not getting information it was legally entitled to receive, Enforcement was often the hammer used to make sure the material got produced. Enforcement has subpoena authority, and if necessary it can seek an order from a federal court compelling compliance. That is essentially what happened here.
Christopher Mulligan: ISS has pushed back on the SEC's position, including arguments concerning its proxy-voting recommendations and the information the Commission is seeking.
Andrew Dean: So this one became contentious quickly. It is worth emphasizing that the SEC has said the investigation is continuing and that it has not concluded that ISS or anybody else violated the federal securities laws. At this point, the dispute is about obtaining information. We will be watching to see how it develops. These document disputes can sometimes get resolved, but this is an interesting one.
Andrew Dean: With that, let's get to our guest. We are very excited to welcome Joann Harris, a Partner and Chief Compliance Officer at TPG. Joann has been at TPG since 2015 and has helped lead the firm's compliance function through a period of tremendous growth and evolution.
Andrew Dean: Before joining TPG, Joann spent 12 years at the SEC, from 2003 to 2015. She served as an Assistant Director in the Division of Enforcement, where she supervised investigations across the Enforcement program, and she was a member of the SEC's Asset Management Unit, the national specialized unit focused on investment advisers, investment companies and private funds. Before the SEC, she was a corporate lawyer in private practice, and before law school she was a certified public accountant and auditor. She has a bachelor's degree in accounting from the University of Arkansas and a J.D. from SMU Dedman School of Law. Joann, it is such a privilege to have you on the show. Welcome.
Joann Harris: Thank you. I'm really happy to be here.
Andrew Dean: You have had a fascinating career. You started in accounting, became a lawyer, spent more than a decade at the SEC and ultimately became the CCO of one of the world's largest multi-platform asset managers. Walk us through that journey. How did you get from where you started to where you are today?
Joann Harris: I started as an accounting major in college, and I became a CPA and an auditor. I think that background has been incredibly valuable throughout my career. As an auditor, you learn to understand the business, understand the numbers and look across transactions and processes rather than just at one isolated issue.
Joann Harris: I ultimately decided that I wanted to go to law school. After law school, I practiced as a corporate lawyer, and then in 2003 I joined the SEC. I spent about 12 years there. I worked as an Enforcement attorney, became an Assistant Director and also spent time in the Asset Management Unit.
Joann Harris: I loved my time at the SEC. You are exposed to an incredible range of issues and businesses, and you learn how to investigate complicated facts. You also learn how important judgment is. Every matter is different, and you have to figure out which facts really matter and what the securities laws require in that particular situation.
Joann Harris: When I moved to TPG in 2015, I knew the securities laws and I knew Enforcement, but I was surprised by how much I still had to learn. Being the compliance officer inside an organization is a completely different perspective. Suddenly you are not looking backward at one set of facts after something may have happened. You are helping the business operate every day across a very broad range of activities.
Christopher Mulligan: What did that transition look like? You go from being the regulator looking at other people's compliance programs to actually being responsible for one.
Joann Harris: There was definitely a learning curve. When you are at the SEC, you can become very focused on the securities laws and the issues that come through the Enforcement program. When you move in-house, you realize how broad the world is. There are business issues, operational issues and regulatory regimes across many jurisdictions, and the compliance function has to understand how all of those things fit together.
Joann Harris: Today, I think about the CCO's job as helping the firm conduct its business with integrity. To do that, I need to understand how the business operates globally and then understand whether we are doing those things within the regulatory frameworks that apply to us in the United States, Europe, Asia and everywhere else we operate.
Joann Harris: One thing you learn very quickly at a global firm is that the United States is not the only jurisdiction with sophisticated regulation. Different places may focus on different risks. Privacy, for example, may receive a different level of emphasis in other jurisdictions. You have to understand those differences and build a program that works across the organization.
Andrew Dean: That is an enormous amount of regulation to keep track of.
Joann Harris: It is. There is an overwhelming amount of regulation that touches virtually everything a firm does. I cannot personally be the expert on every rule in every jurisdiction. The job is to make sure we have the right people, the right expertise and the right systems, and that we understand enough about the business to recognize when something needs deeper attention.
Christopher Mulligan: What distinguishes a genuinely effective compliance program from something that just looks good on paper?
Joann Harris: To me, an effective compliance program cannot just be a binder of policies that you pull off the shelf when a regulator arrives. It has to be part of how the organization actually operates. You need policies, testing and training, of course, but you also need compliance to have influence, credibility and access to leadership.
Joann Harris: A good compliance function is a resource for the business, not simply an obstacle. If the business thinks compliance exists only to say no, people are going to stop calling you. And if they stop calling you, you are going to start getting surprised. That is one of the worst things that can happen to a compliance officer.
Joann Harris: I want people to reach out when they have a question, even if the issue is not fully formed. I would much rather hear about something early and help the team work through it than learn about it after the fact because somebody was afraid compliance would automatically shut it down.
Joann Harris: That means the compliance team has to understand the business. You have to ask questions. Sometimes the most valuable thing you can say is, "I don't understand what you mean. Explain the transaction to me." You do not build credibility by pretending to know everything. You build credibility by doing your homework, asking intelligent questions and being willing to learn.
Andrew Dean: That is an important point. People sometimes think the compliance officer is supposed to walk into every conversation already knowing the answer.
Joann Harris: Exactly, and that is not realistic. You need to know the rules and you need to know your organization, but businesses are complex. There are going to be new products, new strategies and new situations. You have to be comfortable saying, "Help me understand this," and then asking the right questions.
Joann Harris: That is also how you build trust. If the business knows that you understand what they are trying to accomplish, and that you are approaching the question thoughtfully rather than reflexively, they are much more likely to involve you early the next time.
Christopher Mulligan: And presumably the relationship with senior leadership is part of that as well.
Joann Harris: Absolutely. Compliance has to have the ability to raise issues and be heard. Senior leadership needs to understand the compliance risks facing the organization and needs to support the compliance function. But it is equally important for compliance to spend time throughout the organization. You cannot do the job entirely from your office.
Joann Harris: I spend a lot of time talking to people. I want to understand what different teams are working on and what they are worried about. When I visit an office, I want people to know who I am and feel comfortable coming to me or to someone on my team. Those relationships take time to build, but they are incredibly important.
Andrew Dean: When you think about the issues that demand your attention today, what is at the top of the list?
Joann Harris: It is a broad list. We obviously pay close attention to the issues regulators are focused on, and there is no mystery about many of those. For a firm in our industry, that includes things like conflicts, fees and expenses, disclosures and making sure that our actual practices line up with what we have told investors and what our policies require.
Joann Harris: But one of the biggest things I think about is judgment. We have a large compliance organization working across businesses and geographies. I need people to exercise good judgment and to know when an issue needs to be escalated. You cannot write a policy for every possible situation.
Joann Harris: So a lot of the work is training, communicating and calibrating. If similar issues arise in different parts of the organization, we want people approaching them consistently. You need mechanisms for sharing information so the left hand knows what the right hand is seeing.
Christopher Mulligan: You have been at TPG for more than a decade now. How has the CCO role itself changed during that time?
Joann Harris: I think compliance generally has become more strategic, more visible and more integrated into the business. The expectations are higher. Compliance officers are participating in senior leadership discussions, board and committee meetings and strategic conversations in ways that perhaps were less common in the past.
Joann Harris: At the same time, the technical work has become more complex. There is more regulation, the businesses are more complex and firms operate in more jurisdictions. You are designing policies, conducting testing, reviewing data and trying to make sure the program keeps pace with the organization. None of that happens in a vacuum.
Andrew Dean: We cannot have a conversation about how the job is changing without talking about technology and AI. How are you thinking about AI from a compliance perspective?
Joann Harris: It is something we spend a lot of time thinking about. AI is not solely a compliance issue. You need Legal, Information Security, Privacy and other functions involved, particularly when you are thinking about what tools employees can use, what data can go into those tools, what vendors are doing with that data and what controls are necessary.
Joann Harris: There is clearly risk, but there is also enormous opportunity. I am excited about what these tools may eventually allow compliance teams to do. We have a lot of work that involves reviewing information, researching issues, comparing documents, identifying patterns and performing other tasks that can be time-consuming.
Joann Harris: If AI can help with some of that more mechanical work, it gives compliance professionals more time to exercise judgment and focus on the difficult questions where human experience really matters. That is potentially very valuable.
Joann Harris: We are still in the early stages, and I do not think anybody should pretend that these tools eliminate the need for review or judgment. But I think there is a tremendous amount of potential, and the younger people on our teams are often the ones showing the rest of us new ways to use the technology.
Christopher Mulligan: That knowledge-sharing piece is interesting too. Compliance organizations accumulate enormous amounts of institutional knowledge. If technology can help people find and use that knowledge more efficiently, that could be incredibly powerful.
Joann Harris: Exactly. There are a lot of possibilities, and I am excited to see where it goes.
Andrew Dean: All right, Joann, we are heading into fall, and we always end with something a little more fun. What are you looking forward to this fall?
Joann Harris: College football. That is probably the thing I associate most with fall. There is something about a Saturday morning when the weather starts getting a little cooler, taking the dog for a walk, coming back and having games on all day. I went to the University of Arkansas, so college football has always been a big part of fall for me.
Christopher Mulligan: We knew we could get some more college football into this episode.
Joann Harris: Absolutely. When the kids were younger, fall weekends also meant all of the family traditions - going places, apple picking, all of those things. They are older now, so some of those traditions change. The upside is that I can actually sit down and watch a little more football.
Andrew Dean: That is a very reasonable trade-off.
Christopher Mulligan: I agree.
Andrew Dean: Joann, thank you so much for joining us. This was incredibly insightful, and I think you gave listeners a really useful picture of what it is like to be the CCO of one of the world's largest multi-platform asset managers and what it takes to build an effective compliance function.
Joann Harris: Thank you. I really enjoyed it. It was great to be here.
Christopher Mulligan: Thanks, Joann.
Andrew Dean: And thanks to everybody for joining us today. We will see you next time on Asset Management Corner.
Disclaimer: The information contained in this podcast is provided for informational purposes only and does not constitute legal advice. Listening to this podcast does not create an attorney-client relationship. You should consult a qualified legal professional with any questions. This podcast may be considered attorney advertising under the laws of certain jurisdictions.
View more about Weil's White Collar, SEC Examinations, Private Funds and Securities Litigation practices.


