Europe · Investigations and protection of business

Role of the Board of Directors in Corporate Investigations

Erich Rath11 min read

The role of the board of directors in corporate investigations Practical guidance for companies doing business in the European Union

Mainstream

Corporate investigation in the European Union is not just a task for the legal department or external consultants. This is one of the key points when the actual effectiveness of the board of directors is tested.

The main risk for the board is not that the breach will be revealed. The main risk is that the board will learn about the problem but will not take adequate, timely and properly documented steps.

In EU jurisdictions, this is almost guaranteed to lead to personal liability of directors, reputational damage and claims from shareholders.

The Council’s effective role in the investigation is based on three key decisions:

  1. The right time to identify when an investigation goes from routine to compliance-critical.
  2. Ensure the independence and completeness of the investigation without impeding it.
  3. Define a strategy for disclosure and interaction with EU public authorities or national regulators.

If these three issues are not settled at the board level, the company risks not only fines, but also loss of market confidence and personal claims against directors.

When the role of the board of directors is particularly important

Interference of the Board of Directors in the course of the investigation is mandatory if:

  • The case involves top management (CEO, CFO, head of the region);
  • The investigation concerns systemic corruption or money laundering;
  • This is a violation of the EU sanctions legislation;
  • issues of financial statements and statements of the issuer are touched upon;
  • The company received a request from the European regulator (EPPO, NCA) or a signal from the whistleblower.
  • a decision on self-reporting (voluntary disclosure) should be made before the authorities;
  • Considering the dismissal of key persons or the suspension of business operations;
  • The incident threatens a license, bank guarantee or a substantial contract.
  • The disclosure of information in the stock market is required in accordance with the MAR (Market Abuse Regulation);
  • The potential damage from the investigation is comparable to the damage from the violation itself.

The mistake most directors make

Many board members believe their role is to be aware of and approve the budget.

That's the wrong approach.

Right position: Our role is to ensure that the investigation is conducted in a manner that minimizes the personal liability of the directors and the cumulative damage to the company.

Sometimes the best scenario is immediate notification and cooperation. Sometimes, the maximum preservation of attorneys’ confidentiality (legal professional privilege) until the scale of the problem is clarified. Sometimes, immediate isolation of the offender. Sometimes, it is necessary to create a special committee of the board of directors with the involvement of external lawyers to eliminate conflicts of interest.

The board’s role in corporate investigations is not passive surveillance, but active management of the legal defense of the company and its management.

Step 1. Understand their responsibilities in EU jurisdictions

The first thing that council members need to examine is not the details of the incident, but the nature of their responsibilities under the corporate and criminal law of the applicable EU countries.

Directors in Europe carry:

  • Duty of care (duty of loyalty)
  • duty to act in the interests of the company;
  • The obligation to ensure an effective internal control system;
  • Special obligations to prevent corruption, money laundering and violations of sanctions regimes;
  • In some countries (Germany, Netherlands, France) – direct responsibility for inaction in the detection of violations.

German civil and corporate law, French Sapin II, EU directives on whistleblowers protection and corporate reporting form a high standard: The director should not have simply not known, he should have taken reasonable steps to know.

Step 2. Assess the need for a Special Committee

In the event of a serious incident, the board of directors should immediately decide whether to establish an independent committee.

Such a committee is usually formed from:

  • Independent non-executive directors;
  • members of the audit committee;
  • persons not involved in operational activities and not associated with the persons involved in the investigation.

Committee:

  • monitor the progress of the investigation;
  • receive direct reports from external legal advisers and forensic specialists;
  • ensures the preservation of confidentiality;
  • decide on the scope of the inspection;
  • It provides recommendations to the Council on Human Resources and Reputational Solutions.

The presence of such a committee is one of the arguments for protection before European regulators. This demonstrates seriousness about the problem and compliance with duty of care.

Step 3. Ensure the correct legal design of the investigation

The most dangerous thing for the board is to mix internal control and legal protection.

Key mistakes:

  • to entrust the investigation to persons on whom it may potentially come out;
  • use the wrong form of interaction with lawyers, losing the privilege of attorney-client correspondence;
  • In EU countries where a limited version of legal privilege for corporate lawyers (in-house counsel) applies, rely on the confidentiality of internal correspondence.

The right design:

  • the involvement of an external legal adviser for an independent investigation;
  • clear distinction: lawyers give legal assessment and prepare defense, forensic accountants collect invoices;
  • Documentation of the fact that the work is carried out in the framework of the preparation of legal defense (especially important in Germany, France and at the risk of criminal prosecution).

Step 4. Decide on Disclosure of Information (Self-Reporting)

One of the most difficult decisions of the board is whether to report the results or progress of the investigation to the national regulator (NCA), the prosecutor's office or European authorities.

Self-reporting makes sense if:

  • It is impossible to cover up the incident;
  • the company seeks to conclude a plea bargain and reduce the fine;
  • regulators (e.g. SFO in the UK, PNF in France, OFAC/DOJ) encourage cooperation;
  • The consequences of self-disclosure are less than the risks of external detection.
  • Shareholders and the market will see the cover-up as a more serious breach.

The decision on self-reporting must be made at the level of a board or a special committee, as it determines the fate of the company for years to come.

Step 5. Ensure the safety of documents and data

On the day of the incident, the board of directors is obliged to initiate legal holding procedures through a legal adviser.

That means:

  • ban on deletion of any data (e-mails, chats, files, drafts);
  • sending notifications to information holders (custodians);
  • Suspension of automatic deletion policies;
  • Ensuring the safety of data on personal devices, if the BYOD policy has been used.

Failure to comply with this requirement may be qualified as obstruction of justice or breach of duty of care. In EU countries, this could lead to the conclusion that the directors were personally guilty of opposing the investigation.

Step 6. Separate communication from facts

The board often makes the mistake of trying to formulate a public position before the facts are established.

The right strategy:

  • facts are collected by a team of investigators;
  • The legal assessment is provided by an external consultant;
  • Communication with the market, employees and regulators is prepared by the Council with the participation of PR consultants, but after obtaining preliminary conclusions.

A false or premature statement, denied later, becomes a stand-alone basis for claims and accusations of misleading the market, especially under the MAR and the Transparency Directive.

Step 7. Managing the Risks of Parallel Processes

European corporate investigations almost always lead to parallel proceedings:

  • internal disciplinary proceedings;
  • civil claims from counterparties;
  • requests from auditors;
  • administrative investigation;
  • criminal investigation against a company or specific individuals.

The board should understand this multi-vector nature and not allow protection in one track (e.g., an employment dispute) to undermine protection in another (e.g., a criminal case or a transaction with a regulator).

Step 8. Assessing the personal risks of directors

In some EU jurisdictions, directors who are suspected of corruption, fraud or sanctions violations may be prosecuted not only in civil law but also for failure to act or connivance.

The Board shall take measures to minimize the personal risks of each Director:

  • document the fact of receiving information;
  • to ensure that the Council acted without delay;
  • to engage external legal advisers to protect the interests of directors if there is a conflict with the interests of the company;
  • Check the coverage of D&O insurance and make sure that the policy covers the costs of lawyers in criminal investigations in the relevant EU country.

Step 9. Make personnel decisions

Following the investigation, the board is obliged to decide the fate of the employees and managers involved.

Solutions may include:

  • suspension during the investigation;
  • dismissal;
  • Removal of bonuses (clawback provisions);
  • transfer of materials to law enforcement agencies for personal prosecution.

Inaction in personnel matters is considered in the EU as a tacit acceptance of violations and a violation of duty of oversight.

Step 10. Correct systemic causes and report to stakeholders

The investigation is not completed until the council is satisfied the cause of the incident has been eliminated.

This implies:

  • Changes in the internal control system;
  • Replacement of responsible persons;
  • Review of the KPI system and bonuses that incentivized violations;
  • introduction of new trainings;
  • Public reporting on measures taken (if applicable) in the framework of corporate governance and the sustainability report.

European investors, regulators and rating agencies assess the quality of the board’s response rather than the problem.

Internal committee vs. Full tip: what to control and who

CriteriaAd hoc committee of the councilFull composition of the board
Conflict of interestMinimal (Independent Directors)Could be high.
Speed of decisionsTall.Low (between meetings)
ConfidentialityEasy to controlMore difficult (more participants)
Leak protectionStrong.Weaker.
Completeness of information for the councilDepends on the rules.Maximum
Legal purityPreferablyIt could lead to the “infection” of witnesses.

The choice does not depend on general corporate practices, but on the specific incident, its scope, the individuals involved and the jurisdictional risks involved.

How to strengthen your position before an incident occurs

The best protection of the board of directors is not built after an incident, but at the stage of building a compliance system.

It is necessary to introduce:

  • Clear protocols for escalating information from the operational level to the board.
  • Regular compliance risk reports (at least once a quarter)
  • Policy of reporting whistleblower messages;
  • The right of compliance officer to have direct access to the board or audit committee;
  • the procedure for establishing a special committee;
  • Pre-approved budget for legal support in case of incidents;
  • a previously agreed external legal adviser for corporate investigations;
  • Regulations for interaction with regulators and PR-service in case of incidents.

Corporate governance in the EU is not a formality, but a working system that the regulator evaluates at a time of crisis.

Typical Board Mistakes in Corporate Investigations in the EU

1. The Council may be responsible for obtaining information and not recording it, even if it has not taken a formal decision.

2. In the EU, correspondence with internal lawyers is often not protected by privilege.

3. Delaying the decision to disclose Procrastination could be interpreted as an attempt at cover-up.

4. The Council shall not conduct interrogations but shall guarantee the quality of the procedure.

5. Investigative actions in one EU country may violate EU law or the national law of another Member State.

6. Forget about GDPR and employment law Illegal collection of employee data during an investigation will result in separate sanctions.

7. A public scandal often causes more harm than a fine.

Checklist of board member at start of investigation

Before you start, answer 15 questions:

  1. Have I received a written notice of the facts?
  2. Have I documented my reaction and actions?
  3. Are there conflicts of interest among the persons charged with the investigation?
  4. Has a special committee been established?
  5. Are external legal advisers involved?
  6. Is the contract with lawyers properly executed to preserve the privilege?
  7. Have you received a data retention notice (legal hold)?
  8. Is the need for immediate suspension of staff assessed?
  9. Has the obligation to disclose to the regulator been reviewed?
  10. Is the scope of potential criminal liability in the EU clear?
  11. Is the D&O policy and coverage reviewed?
  12. Is the communication project with the market ready?
  13. Is there a company reputation plan separate from the legal plan?
  14. Do I understand who is the main beneficiary of the protracted investigation?
  15. Which would be more devastating: Is it publicity or lack of it in the moment?

How a Strong Board Strategy Looks

The Council’s strong strategy in the EU corporate investigation consists of five levels:

1. Governance & Duty of Care Fixing duties, creating a committee, documenting steps, eliminating conflicts of interest.

2. Legal Professional Privilege & Procedure Proper investigation design through external lawyers, separation of facts and assessments, protection of materials.

3. Regulatory & Criminal Exposure Assessment of disclosure obligations, analysis of self-reporting prospects, interaction with the NCA, EPPO and other bodies.

4. Stakeholder & Market Communication Control of the information field, compliance of statements with facts, compliance with MAR.

5. Remedy & Future-proofing Demonstration of system deficiencies correction, management change, strengthening compliance, market reporting.

Without the first and fifth levels, the investigation would look like an attempt to wait out the storm, not as good faith risk management.

FAQ

Is the board required to investigate each signal? Each signal must be evaluated according to the criteria of materiality and risk. The decision not to open an investigation must be documented and motivated.

Is it possible to conduct an internal investigation without outside lawyers? Internal lawyers of the company do not always have the status of independent, and their correspondence can be claimed by the investigation without the protection of attorney-client privilege.

The exact moment depends on national legislation (Germany, France, the Netherlands have different regimes). But as a rule, immediately, as soon as the fact of the criminally relevant act is established, or when the board realized the inevitability of its detection.

Can the directors be personally involved? In EU jurisdictions, directors are regularly prosecuted civilly and criminally for inaction, particularly in cases of corruption, fraud and sanctions violations.

Immediately remove him from the decision chain, assign control to a special committee and appoint an external lawyer to protect the interests of the company separately from the CEO.

From the outset, engage an external qualified lawyer who will lead the factual collection of data and give a legal assessment. Distinguish communication on legal and business decisions.

It is necessary to evaluate the rules in all affected jurisdictions simultaneously, since disclosure of information in one country can provoke criminal prosecution in another, and vice versa.

Related services

  • Corporate Investigations, Regulatory Investigations & Business Integrity
  • International Regulatory Risk & Strategic Advisory
  • Sanctions, Export Controls & International Compliance
  • White-Collar Crime & Director’s Liability
  • Commercial Litigation & Cross-Border Disputes
  • EU Market Abuse Regulation (MAR) Advisory

Related material

  • How to Build an Effective Compliance System in an EU Holding
  • Responsibility of directors: Guide to protection in Germany, France and Benelux
  • What to do if the company receives a request from the European regulator
  • The EU policy of whistleblowing: guide
  • Self-reporting as a tool for reducing fines: EU experience
  • How to Protect Lawyers’ Privacy in Internal Investigation
  • D&O insurance in the EU: How not to lose coverage in an incident
  • Cross-border corporate investigations: 10 major mistakes

Conclusion

The role of the board in corporate investigations in the European Union is not ceremonial oversight, but the direct exercise of fiduciary duties and the management of personal risks.

The Council’s strong position is based on an immediate and documented response, independent legal design of the investigation, strict control over the preservation of privilege and a conscious strategic decision on interaction with the state and the market.

The company that wins the corporate crisis is not the one that has not had an incident. The one whose board made the right decisions in the first 72 hours after the problem was discovered.

Have a question about the topic of this article?

Write to us and we will respond within one business day.