John Phinney
February 13, 2020

Reducing your Chances of Being Victimized by Bad Behavior- Recognizing Red-Flags and Risk in an Asset Manager's Business

Convergence studied 100 SEC enforcement actions against investment advisers and found a multi-functional CCO in 67% of them. Its white paper also tracks 3,000 private fund managers from 2014 to 2019, comparing independent and multi-functional CCO models on trend and asset growth.

Post Summary

What is this white paper about?

It examines whether investors could have detected red flags in the businesses of investment advisers that were later subject to SEC enforcement actions, and focuses on one risk factor, the multi-functional chief compliance officer.

What is a multi-functional CCO?

A multi-functional CCO (MFCCO) is a chief compliance officer who also performs other senior duties, which the paper lists as CFO, COO, CRO, CIO, and CEO duties. The paper says this violates the basic principle of segregation of duties.

How often did a multi-functional CCO appear in the SEC enforcement actions Convergence studied?

In 67% of the 100 SEC enforcement actions modeled, with an independent CCO in the remaining 33%.

How did asset growth compare for managers with independent versus multi-functional CCOs?

The paper reports that, in all three size bands studied, managers with independent CCOs grew assets faster than managers with a multi-functional CCO.

How do institutional investors view managers with a multi-functional CCO?

The paper says institutional investors are increasingly passing on firms with the condition, and that its data shows them investing less often with those managers.

What does Convergence conclude?
That there are good business reasons for having an independent CCO, and that the share of managers with independent CCOs continues to increase.

Merrill Lynch recently admitted to misleading customers about how it handled their orders and agrees to pay a $42M penalty. Merrill Lynch admitted to a practice called "masking," when it tells customers that it executed millions of orders internally but had actually routed them for execution at other broker-dealers, including proprietary trading firms and wholesale market makers, according to the SEC order. Masking entails reprogramming Merrill's systems to falsely report execution venues, altering records and reports, and providing misleading responses to customers. By "masking" the broker-dealers who had executed customers' orders, Merrill Lynch made itself appear to be a more active trading center and reduced access fees it typically paid to exchanges," the SEC statement said. Even after Merrill stopped masking in May 2013, it took additional steps to hide its past practice, says the SEC.

Why do investors continue getting deceived by their financial intermediaries? Were these deceptions perpetrated by a rogue individual who cleverly found a crack in the manager's control armor or the result of a highly complex business environment that failed to establish and/or maintain the appropriate controls over high risk conditions? Convergence believes avoidance and prevention is a function of recognizing risk signals in a manager's business model and asking the right questions!

Seeing the Signals

Convergence studied 100 actions taken by the SEC against investment advisers for a variety of wrongdoings against institutional, high net worth and individual investors. Wrongdoing includes, and is not limited to, financial injury to investors caused by manager fraud, misrepresentation and/or disclosure failures. Our goal was to determine if investors could have detected red-flags, or risk signals, in the manager's business model that they might have considered before making their investment or identified during post investment ongoing due diligence.

The answer in both cases is "Yes." We saw high risk business conditions in the adviser's business model leading-up to and during the wrongdoing that if detected may have helped investors avoid or limit the financial and reputational harm they suffered.

Detecting Risk Signals

Convergence tracks 61 business conditions in a manager's business model that create non-investment risk. These business conditions fall into 4 risk categories, including operational, compliance, regulatory event and vendor. Our study concluded that most managers subject to the enforcement actions had several high-risk business conditions (HRBC) in their business that could be linked to what they did and that a high correlation existed with certain factors. Meaning, they existed in 67% of the SEC actions we studied. This paper focuses on one often-debated risk factor that we believe all investors should avoid.

The Challenging Role of Today's CCO

A quality compliance effort is a team, not spectator sport. Portfolio Managers, Traders, Operations, Accounting and investor relations staff all play a key role in supporting the CCO's effort to ensure regulatory filings are made on time and are accurate and complete. The Chief Compliance Officer in today's asset manager has a tougher job and faces more personal risk than at any time in recent memory. The CCO and the principles of the firm face civil and criminal penalties for making regulatory filings that contain material errors and omissions and misleading statements. At one time these filing required a "best efforts" basis. Thus, to fully limit personal and professional risk, they need to take greater efforts to understand and defend the data they use to complete their filings.

The scope of the CCO role has expanded. They take an influential seat at the product development and fund-raising table. Think about the challenges the CCO has working with the aggressive personalities of today's alpha-male/female portfolio managers or traders. All driving toward more growth and improving returns. You might wonder why any asset manager, or its CCO for that matter, would underwrite the material risks that are clearly obvious when a CCO also performs CFO, COO, CRO, CIO and CEO duties? The condition violates the very basic segregation of duties principle and raises many questions.

Limited Partners in funds adviser expect CCO's to be independent and the ultimate steward of the firm's regulatory culture. While the culture of compliance starts with the "tone-from-the top", today's Compliance Officer stands at the intersection of a crowded and fast-moving investment highway.

The Multi-Functional CCO (MFCCO)-Does it Matter?

We considered the SEC's and other expert's comments on the MFCCO subject. While the SEC has commented publicly on the challenges it creates, they have essentially left the ultimate decision on whether it is "good/bad" to investors. Privately, investment consultants, audit firms and administrators we spoke with expressed concern. Unfortunately, large and small investors are not equipped to make the "good/bad" determination because little research exists to guide them on making the decision.

Most CEOs and CCOs interviewed by Convergence on the topic recognize the benefits of an independent CCO yet offered several practical challenges as to why it still exists. They fall into three categories, their founder's ability and willingness to pay for it, 2) their ability to effectively manage it and 3) the impact on the MFCCO compensation. While Convergence does not argue these points, we offer an alternative and data driven view on why separating the function makes good business sense.

We studied three business conditions to help us define "good/bad" for asset managers, service providers and investors; 1) the trend in independent and MFCCO, 2) the asset growth in managers with independent and MFCCO models and 3) SEC enforcement actions taken against managers for investor wrongdoing. We selected a sample of 3,000 asset managers who were 1) active during the 2014-2019 study period and 2) advised private funds. Private funds include Hedge, Private Equity, Venture Capital, Real Estate, Securitized Assets and Other Funds.

1. The MFCCO Trend and the Cumulative Asset Growth of Managers

  • In all three size bands listed below, the number of independent CCOs increased
  • Their assets grew faster than those with a Multi-Functional CCO model in place.
Table 1a: Advisers <$100MM AUM
Chart 2014 2015 2016 2017 2018 2019
Multi-Functional CCO Trend: Independent CCO41.7%45.9%46.3%45.2%44.0%44.7%
Multi-Functional CCO Trend: Multifunctional CCO58.3%54.1%53.7%54.8%56.0%55.3%
Multi-Functional CCO Asset Growth: Independent CCOn/a73%214%196%258%363%
Multi-Functional CCO Asset Growth: Multifunctional CCOn/a51%102%149%233%278%
Table 1b: Advisers >$500MM<$1BN
Chart 2014 2015 2016 2017 2018 2019
Multi-Function CCO Trend: Independent CCO54.2%56.4%56.7%57.7%57.4%56.7%
Multi-Function CCO Trend: Multifunctional CCO45.8%43.6%43.3%42.3%42.6%43.3%
Multi-Functional CCO Asset Growth: Independent CCOn/a19%36%56%157%171%
Multi-Functional CCO Asset Growth: Multifunctional CCOn/a17%28%22%43%45%
Table 1a: Advisers with $1BN<$5BN in AUA
Chart 2014 2015 2016 2017 2018 2019
Multi-Functional CCO Trend: Independent CCO61.2%64.6%64.6%66.3%65.8%66.3%
Multi-Functional CCO Trend: Multifunctional CCO38.8%35.4%35.4%33.7%34.2%33.7%
Multi-Functional CCO Asset Growth: Independent CCOn/a23%38%55%101%112%
Multi-Functional CCO Asset Growth: Multifunctional CCOn/a6%10%3%8%17%

2. MFCCO in SEC Wrongdoing Actions

  • The Multi-Functional CCO existed in 67% of 100 SEC Enforcement Actions Modeled
Table 2: Percentage of Advisers Cited in SEC Actions with a MFCCO
MULTI-FUNCTIONAL CCO, 100 SEC ENFORCEMENT ACTIONS Share
Multi Functional CCO67%
Independent CCO33%
MULTI-FUNCTIONAL CCO, 100 SEC ENFORCEMENT ACTIONS Share
Multi Functional CCO67%
Independent CCO33%

The MFCCO condition creates various conflicts of interest and additional work burdens because of the control roles and work required of the same person. Convergence studied 100 SEC enforcement actions involving wrongdoing, defined as actions that financially injured the investor. The MFCCO model existed in 67% of the cases during the time period leading up-to or during the period the wrongdoing action occurred. In these cases, the MFCCO was either a direct participant in the action or was unable to prevent the action from occurring.

We find this statistic compelling. Reading these cases is a sad yet eye-opening experience when you consider the financial and reputational losses that investors might have avoided had they 1) known about the condition and 2) if they knew about it and took action to ensure that additional checks and balances existed in the organization to avoid compensate for the condition.

And, yes, we expect MFCCOs to be outraged by this implication. We are not impugning their integrity as many are hard-working an honest. Yet we simply cannot ignore the facts. And while we hear the arguments that "I am a MFCCO, but I have outsourced work to an independent Compliance firm that serves as a check and balance and " I have someone working for me that is really the CCO", the reality is simply the risk is clear and the regulatory cases support the view. Yet, we respond to the first question by suggesting that "the nuances of how asset managers run their businesses and the dynamic nature of compliance renders third-party Compliance firms less effective in spotting day-to-day MFCCO conflicts. And to the second question we respond by suggesting that "unless your direct report has a reporting line to an independent third-party, their ability willingness to report potential issues without your knowledge is limited and in our opinion suspect. Many have said that they are less willing to report activities that may influence their status or compensation and more willing to try and work-out the situation.

Regulatory and Investor Sentiment on MFCCO1

The MFCCO has more work to do than their independent counterparty.

The paper's account of the SEC's position draws on an article by Todd Cipperman, managing principal of Cipperman Compliance Services, published in Financial Planning on April 30, 2019 (see footnote). The points below summarize that article. They are its reporting, not Convergence findings.

  • The article reports that the SEC pursues firms whose compliance programs are inadequate, whether or not any other rule was broken or any client was harmed, and that it regards executives who act as CCO alongside other duties as usually lacking the time or expertise to complete the required work.
  • It cites a 2017 Risk Alert from the SEC's Office of Compliance Inspections and Examinations that ranked weak compliance programs among the five most common deficiencies found, and says the SEC often attributes such weakness to the dual-hat structure.
  • It states that a dual-hatted CCO can be held personally liable, with fines and possible industry bars, and that where the CCO is also a firm principal, an action naming that person can end the business, particularly after an industry bar.
  • Cases it describes include a firm charged with underfunding its compliance program after a CCO's requests for resources went unmet, a general counsel serving as CCO who was censured, fined, and barred, and a firm sanctioned for failing to supervise a CEO/CCO who was later convicted of stealing from clients.
  • It describes the SEC's position that a CCO is a regulatory officer rather than an advocate for management, and notes that a general counsel serving as CCO faces a tension between legal advocacy and confidentiality obligations.
  • It concludes that a CCO needs significant independence from management and from the revenue-producing side of the firm.

Institutional Investors are increasingly passing on making investment in firms with the MFCCO condition in place. "It's just not worth the hassle of staying on top of the natural challenges this condition creates," cited one large state pension plan official. In fact, the data supports what we are hearing in the market. They are investing less often with managers with the MFCCO.

Solutions

The paper's Solutions section draws on the same article. According to it, firms should spend no less than 5 percent of revenue or 7 percent of operating budget on compliance, and most SEC-regulated entities spend between 7 and 20 percent of total operating costs. It adds that a simpler business may justify a lower figure, that emerging firms may spend 20 percent or more while building their programs, and that spending too little is a red flag to regulators.

The article describes two options for the CCO role: hire an in-house compliance officer or engage an outsourced compliance officer. It states that either route requires management to fund the program adequately and to keep the CCO independent of the revenue-producing team, and that the SEC examines whether a firm actually implements effective policies and procedures, not only whether policies exist and a CCO has been named. It adds that firms need a competent, dedicated CCO, whether a full-time employee or an established outsourcing provider.

The quality of your regulatory filings reflects directly on your compliance culture. Investors often ask about your commitment to maintaining a strong compliance culture. Sloppy regulatory filings may cost you more and are indicative of other weak internal processes. The quality of your regulatory data also impacts the cost of doing business. Filings that are wrong require amendments which costs the firm additional money. CEOs at the minimum should want to know what their quality scores look like and if they are weak, why?

The Market for Chief Compliance Officers

It is no surprise that competition for quality CCOs is fierce. There are over 35,000 SEC and State registered advisers offering advisory and other services to investors. Turnover in the CCO function has ranged from 3-6% over the study period.

Summary

Convergence believes there are good business reasons for having an independent CCO. More managers are listening to these reasons and our data shows that the percentage of asset managers with independent CCOs continues to increase. These managers understand that the independent CCO is good for their business. Their control environments are better, they growth their assets faster and the quality of their regulatory filings are better than their peers.

For additional research on this topic please contact George Gainer.

  1. Todd Cipperman, April 30, 2019, "5 reasons to just say no to having a part-time CCO" https://www.financial-planning.com/opinion/sec-intensifies-scrutiny-on-doubled-up-compliance-officers

Key Points

What question does the paper ask, and how did Convergence design its study?

  • Opens with an SEC enforcement case. Merrill Lynch agreed to pay a $42M penalty after admitting to "masking," telling customers their orders were executed internally when they were routed to other broker-dealers, according to the SEC order.
  • Asks why investors keep getting deceived. The paper questions whether the cause is a rogue individual who found a crack in the manager's controls, or a highly complex business environment that failed to establish and maintain controls over high-risk conditions.
  • States Convergence's belief. Avoidance and prevention depend on recognizing risk signals in a manager's business model and asking the right questions.
  • Studied 100 SEC actions. The actions were against investment advisers for wrongdoing against institutional, high net worth, and individual investors. The goal was to determine whether investors could have detected red flags before investing or during post-investment due diligence.
  • Sampled 3,000 asset managers. The managers were active during the 2014-2019 study period and advised private funds, including Hedge, Private Equity, Venture Capital, Real Estate, Securitized Assets, and Other Funds.
  • Examined three business conditions. These were the trend in independent and multi-functional CCO models, asset growth for each model, and SEC enforcement actions taken against managers for investor wrongdoing.

What did the study find about red flags and risk signals?

  • Investors could have detected red flags. The paper answers "Yes" both for before investing and during ongoing due diligence.
  • High-risk conditions preceded the wrongdoing. Convergence states it saw high-risk business conditions in the advisers' business models leading up to and during the wrongdoing that, if detected, may have helped investors avoid or limit financial and reputational harm.
  • 61 conditions tracked as of 2020. Convergence tracked 61 business conditions that create non-investment risk, in four risk categories including operational, compliance, regulatory event, and vendor.
  • Most managers had several high-risk conditions. Most managers subject to the enforcement actions had several high-risk business conditions (HRBC) that could be linked to what they did, and a high correlation existed with certain factors.
  • One risk factor is the focus. The paper centers on the multi-functional CCO, which it calls an often-debated risk factor that Convergence believes all investors should avoid.

How does the paper describe the CCO role and the multi-functional condition?

  • Compliance is a team effort. Portfolio managers, traders, operations, accounting, and investor relations staff all support the CCO's work to keep regulatory filings timely, accurate, and complete.
  • The CCO role has expanded. The CCO now holds an influential seat at the product development and fund-raising table.
  • Personal risk has increased. The CCO and the firm's principals face civil and criminal penalties for filings that contain material errors, omissions, or misleading statements, and the paper says the role carries more personal risk than at any time in recent memory.
  • The multi-functional condition is defined by added duties. It describes a CCO who also performs CFO, COO, CRO, CIO, and CEO duties, and states that this violates the basic principle of segregation of duties.
  • Limited partners expect independence. They expect CCOs to be independent and the ultimate steward of the firm's regulatory culture.
  • The SEC has left the judgment to investors. The paper reports the SEC has commented publicly on the challenges but essentially left the good-or-bad determination to investors. Investment consultants, audit firms, and administrators privately expressed concern, and little research exists to guide investors.
  • Interviewed executives cite three practical challenges. CEOs and CCOs recognize the benefits of an independent CCO but cite the founder's ability and willingness to pay for it, the ability to manage it effectively, and the effect on the multi-functional CCO's compensation.

How did managers with independent CCOs compare with managers with multi-functional CCOs on trend and asset growth?

  • Convergence's stated finding. In all three size bands studied, the number of independent CCOs increased and their assets grew faster than those with a multi-functional CCO model.
  • Independent share rose in every band. It went from 41.7% in 2014 to 44.7% in 2019 for advisers under $100MM in AUM, from 54.2% to 56.7% for advisers between $500MM and $1BN, and from 61.2% to 66.3% for advisers with $1BN to $5BN in AUA.
  • Under $100MM: 363% versus 278%. These are the cumulative asset growth figures by 2019 for independent versus multi-functional CCO managers.
  • $500MM to $1BN: 171% versus 45%. The same comparison, by 2019, in the middle size band.
  • $1BN to $5BN: 112% versus 17%. The same comparison, by 2019, in the largest size band.
  • The larger group varied by size. In the under-$100MM band, multi-functional CCOs were the larger group in every year charted (58.3% in 2014, 55.3% in 2019). In the two larger bands, independent CCOs were the larger group in every year charted.

What did the paper find about multi-functional CCOs in SEC enforcement actions, and how does Convergence respond to objections?

  • 67% of actions involved the multi-functional model. It existed in 67% of the 100 SEC enforcement actions modeled, and an independent CCO was present in the other 33%.
  • Wrongdoing is defined by investor injury. The paper defines it as actions that financially injured the investor.
  • Timing and role are stated. The model existed during the period leading up to or during the wrongdoing, and the paper states the multi-functional CCO "was either a direct participant in the action or was unable to prevent the action from occurring."
  • Convergence addresses the likely reaction. It says it expects multi-functional CCOs to be outraged by the implication and states it is not impugning their integrity.
  • Response to the outsourced-firm argument. To the claim that work has been outsourced to an independent compliance firm as a check and balance, the paper says third-party firms are less effective at spotting day-to-day conflicts, given how asset managers run their businesses and the dynamic nature of compliance.
  • Response to the "someone else is the real CCO" argument. The paper says that unless that person reports to an independent third party, their willingness to report issues without the multi-functional CCO's knowledge is limited and, in Convergence's opinion, suspect.
  • Institutional investors are passing. The paper quotes one large state pension plan official calling the condition "just not worth the hassle," and states its data shows investors investing less often with these managers.

What does the paper conclude, and what does it relay about SEC positions and compliance resourcing?

  • Convergence's conclusion. There are good business reasons for an independent CCO, and the share of managers with independent CCOs continues to increase.
  • Convergence's stated advantages. It states that these managers have better control environments, grow assets faster, and have better regulatory filing quality than their peers.
  • Filing quality reflects compliance culture. The paper says wrong filings require amendments that cost additional money and that CEOs should want to know their quality scores.
  • Market context. The paper reports more than 35,000 SEC and state registered advisers and CCO turnover of 3-6% over the study period, and describes competition for quality CCOs as fierce.
  • SEC positions relayed from a cited article. Drawing on a Todd Cipperman article in Financial Planning (April 30, 2019), the paper relays that the SEC pursues firms with inadequate compliance programs even without other violations or client harm, that a 2017 SEC Risk Alert ranked weak compliance programs among the five most common deficiencies, and that dual-hatted CCOs can face personal liability including fines and industry bars. These points are the article's reporting, not Convergence findings.
  • Spending benchmark relayed from the same article. The benchmark is no less than 5% of revenue or 7% of operating budget, with most SEC-regulated entities spending 7% to 20% of operating costs.
  • Staffing options relayed from the same article. The options are an in-house or an outsourced compliance officer, either with adequate funding and independence from the revenue-producing team.

More Insights from Convergence

Let's Connect

See three live signals against your book. Request a 30-minute demo
with the Convergence team today.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
A Lite Studio Production