The need to hold individuals accountable for securities violations has sparked a tremendous amount of dialogue in recent years, particularly in the wake of the financial crisis and the Enron-era accounting scandals. Regulators and prosecutors, legislators, and industry leaders have focused on the issue and the need to hold accountable those individuals who were involved in a company’s misconduct. For example, in September 2015, then-Deputy Attorney General Sally Yates issued a memorandum stating that “one of the most effective ways to combat corporate misconduct is by seeking accountability from the individuals who perpetrated the wrongdoing.”1 Our take on the Yates Memo is that it was an effort by the Department of Justice (DOJ) to broadly refocus attention on individual liability, although most DOJ employees were likely fully focused on this issue long before the memo’s release. Some members of Congress have gone even further, suggesting a potential expansion of individual liability. For example, during Jay Clayton’s confirmation hearing as Chairman of the U.S. Securities and Exchange Commission (SEC), one senator asked Clayton whether he would endorse a regime under which corporate executives would be subject to a strict liability standard for misconduct that takes place under their watch.2 Clayton stated that he had not given this issue much thought, but that “[s]trict liability without mens rea … [is] a big step.”3 Clayton’s views are consistent with the traditional view in U.S. jurisprudence that guilt should be personal.

Over the years, Congress has passed a number of laws and implemented different statutory regimes aimed at increasing individual accountability for senior executives. Several provisions passed into law under Sarbanes-Oxley, including the CEO and CFO certification requirements and clawback provisions, were intended to advance this purpose and yield valuable lessons about the effectiveness of such provisions in enhancing individual accountability. Given the upcoming 15-year anniversary of Sarbanes-Oxley, it is a good time to take stock of those lessons. In recent years, however, a different route to holding individuals accountable has been applied in a number of cases by companies that find themselves in regulatory and reputational crosshairs. In the aftermath, or in advance, of penalties imposed on them in connection with regulatory actions, some companies have taken steps to reduce the compensation of senior executives at the company, with respect to both salaries and bonus payments. While to some extent influenced by regulatory actions, this type of market-driven remedy can be an effective way of enhancing individual accountability, particularly since the new administration is unlikely to implement additional regulatory tools in this arena. This development is also responsive to those who have been calling for corporate penalties to be paid, in some way, by executives on whose watch the issues occurred, rather than by shareholders.


Attempts to increase senior executives’ accountability for corporate wrongdoing have appeared over time, usually reflecting public sentiment arising from industry scandals. The most recent and best examples of such attempts include two sections of the Sarbanes-Oxley Act (SOX or the Act), which was enacted as part of the legislative aftermath to the Enron and WorldCom accounting scandals: (1) Section 302, which imposes certain CEO and CFO certification requirements with respect to annual and quarterly reports, as well as related statutory provisions that criminalize false certifications; and (2) Section 304, which allows the SEC to bring an action to compel public companies’ CEOs and CFOs to disgorge bonus payments, other incentive- or equity-based compensation, and stock sales profits, following certain types of restatements of financial results. With the 15th anniversary of SOX fast approaching, the reliance on and ultimate utility of these statutory provisions yield valuable and relevant lessons for the attempts to increase individual executive liability.

Section 302 Requirements

Pursuant to §302, a public company’s CEO or CFO must certify in each annual or quarterly report filed or submitted that the report does not contain any untrue statement or omissions, and that the financial statements fairly present the company’s financials.4 False certifications under §302 can be pursued through SEC proceedings, as well as under §906 of SOX, pursuant to which company officers may be subject to criminal liability if they knowingly or willfully execute a false certification.5

At the time of their adoption, commentators speculated that the new certification provisions would lead to an increase in criminal prosecutions and SEC enforcement actions, reflecting a widespread view that new tools were needed in the wake of the accounting scandals that preceded their adoption.6 At the time, many believed that the preexisting statutes were insufficient to address the types of large-scale violations uncovered prior to SOX’s enactment, and that pursuing executive responsibility would be more likely under the new certification provisions incorporated into the Act.

Contrary to such contemporaneous predictions, however, the Act’s 15-year history has proven otherwise. To be sure, the DOJ and the SEC have brought false certification charges under §302. For the most part, however, those cases also involved charges for violations of statutes that predated SOX’s enactment,7 largely because the same proof of negligence, recklessness or intentionality is needed for the certification violation and that proof usually suffices to demonstrate other violations as well.

Nevertheless, the certification requirements have undoubtedly served an extremely critical purpose that has had a transformative impact on the quality of financial reporting. For example, the requirements generated a regime of sub-certifications, under which subordinates must certify that they are unaware of inaccuracies in the financial statements. In turn, the sub-certification regime led to the adoption of a number of practices and procedures for implementing controls and processes aimed at ensuring that financial statements are fully vetted before the CEO and CFO certify that they do not contain any material false statements or omissions. Perhaps unsurprisingly, requiring mid-level and lower-level managers to affix their own imprimatur regarding the accuracy of financial statements has promoted increased truthfulness in financial reporting. But such processes also serve as a significant defense for CEOs and CFOs facing potential liability where they were not directly involved in the underlying corporate misconduct. As a result, the relevant SOX provisions have not formed the basis of many SEC and DOJ actions brought against senior executives who were otherwise not liable for violations under the statutory framework that predated SOX, but have affected a sea change of enhanced quality in financial reporting.

Section 304 Clawback Provision

Pursuant to §304 of SOX, the SEC may bring an action for reimbursement to the company of certain bonuses and stock sale profits if the financial statements of the company are subject to restatement as a result of misconduct.8 This provision has been deployed to mandate the clawback of compensation from executives directly involved in the misconduct.9 In addition, since at least 2010, the SEC has brought §304 claims to claw back compensation from executives who were not directly involved in the alleged corporate misconduct.10 Recently, the Ninth Circuit concluded that such clawbacks are constitutionally permissible under the statute, holding that “[Section] 304 allows the SEC to pursue a disgorgement remedy against CEOs and CFOs of issuers required to prepare an accounting restatement as a result of misconduct, even if the officers did not engage in the relevant misconduct themselves.”11

One question raised by the cases noted above is whether the purpose of such enforcement actions is punitive or remedial (i.e., intended only to prevent ill-gotten gains). Given the potentially broad scope of clawback liability, it is clear that these actions can be viewed as a form of “on your watch” liability against executives, intended to serve as a punitive deterrent. But in the majority of recent SEC actions that did not allege the executive’s personal or direct involvement in the misconduct, the company’s clawback recovery has been the difference between the bonus or stock sale profits received and what those payments would have been absent the misstatements, rather than the full amount of the bonuses or profits as allowed by the statute (the so-called “fraud delta”). Such actions are more remedial in nature, seeking only to recover for the company those funds that its senior executives would not have received in the first place had the financial reports been properly stated. Regardless of their ultimate purpose, it remains the case that §304 clawback liability is not determined by the amount that the company paid out as a result of the misconduct or by the financial impact that the enforcement action has had on the company. Rather, the magnitude of §304 clawbacks is set in reference to the compensation paid out to the executive, or the stock sales executed by the executive. Ultimately, then, §304 actions against executives not involved in the misconduct are best understood as remedial rather than punitive, limiting their utility as a form of individual accountability.

Post-SOX Developments

In the wake of the financial crisis of 2007-2008, Congress passed the Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank or Dodd-Frank Act). While Dodd-Frank expanded some bases for liability,12 and remedies available in administrative proceedings,13 it did not add significant substantive securities causes of action for senior executives or individuals.14 In the wake of continued corporate misconduct, some regulators, however, soon began to call for additional liability for senior executives for violations occurring on their watch. For example, William C. Dudley, president and CEO of the Federal Reserve Bank of New York, suggested that senior executive compensation should be deferred and pooled into funds or “performance bonds.”15 Under that proposed approach, in the event that a fine or penalty is later levied on that institution, it would be paid out of the performance bond, rather than by the shareholders.16 Proposals such as Dudley’s are an attempt to find ways for holding senior executives responsible for actions taken under their watch, without criminalizing them or providing a new civil cause of action. Others have suggested imposition of responsible corporate officer liability in the financial services context, which up to now has been limited to public health offenses.17

Some companies in recent years have themselves been proactive in imposing sanctions against senior executives with no statutory or regulatory compulsion to do so. Following a number of corporate scandals, several companies unilaterally have decided to reduce the compensation of executives who were either directly involved (or oversaw departments involved) in the scandal that resulted in significant penalties for the company. For example, Wells Fargo’s independent board of directors decided to claw back $28 million from its former CEO, in addition to $41 million that the CEO agreed to forfeit in connection with taking responsibility for improper sales practices.18 When this amount is added to the $66 million clawed back from another former senior manager, it approaches the total penalties paid by Wells Fargo of $185 million for the underlying conduct.19 Credit Suisse, Toshiba, and J.P. Morgan Chase have similarly reduced executive compensation in response to corporate scandals.20

This approach has several positive advantages over statutory changes. First, it is driven by market participants—not regulators—and, as such, can bypass the extended investigations period and burden of proof issues inherent in regulatory actions. Second, such company-levied sanctions often post-date the imposition of penalties on the corporate entity, thereby ensuring that the compensation clawed back from the executives better reflects the actual costs imposed on the institution. This outcome is consistent with the call from some regulators that executives, and not shareholders, bear the cost of sanctions imposed on the company. Third, because they are publicly disclosed, significant clawbacks or bonus reductions, and the concomitant public scrutiny, can have significant deterrent effects on individuals. Fourth, by imposing such sanctions prior to regulatory intervention, a company is better situated to demonstrate that it has identified misconduct by its own officers and has taken appropriate measures to address the inaccurate financial disclosures, and there is reduced regulatory risk of regulators feeling the need to act. This preemptive approach sends an important message to shareholders and the company as a whole about the importance that the institution places on appropriate corporate culture and truthful financial disclosures.


In the current de-regulatory climate, additional legislative and regulatory expansions of executive responsibility are unlikely, both because of the prevailing views of individual liability and because of the difficulty associated with passing such legislation. Nevertheless, companies have responsibly taken independent, discretionary actions to hold senior executives responsible for corporate misconduct through reductions and clawbacks of bonus payments and compensation. This trend has gained prominence in recent years and demonstrates that, when regulatory solutions are not forthcoming or not simple to adopt, market-based solutions can develop to fill a regulatory vacuum.

