From Casetext: Smarter Legal Research

Okla. Firefighters Pension & Ret. Sys. v. Corbat

COURT OF CHANCERY OF THE STATE OF DELAWARE
Dec 18, 2017
C.A. No. 12151-VCG (Del. Ch. Dec. 18, 2017)

Summary

explaining that bad faith inaction "must suggest, not merely inattention, but actual scienter" and "must imply that the directors are knowingly acting for reasons other than the best interest of the corporation"

Summary of this case from In re Chemed Corp.

Opinion

C.A. No. 12151-VCG

12-18-2017

OKLAHOMA FIREFIGHTERS PENSION & RETIREMENT SYSTEM, KEY WEST MUNICIPAL FIREFIGHTERS & POLICE OFFICERS' RETIREMENT TRUST FUND, JEFFREY DROWOS, FIREMAN'S RETIREMENT SYSTEM OF ST. LOUIS, and ESTHER KOGUS, Derivatively on Behalf of Nominal Defendant, Citigroup, Inc., Plaintiffs, v. MICHAEL L. CORBAT, DUNCAN P. HENNES, FRANZ B. HUMER, EUGENE M. MCQUADE, MICHAEL E. O'NEILL, GARY M. REINER, JUDITH RODIN, ANTHONY M. SANTOMERO, JOAN SPERO, DIANA L. TAYLOR, WILLIAM S. THOMPSON JR., JAMES S. TURLEY, ERNESTO ZEDILLO PONCE DE LEON, ROBERT L. JOSS, VIKRAM S. PANDIT, RICHARD D. PARSONS, LAWRENCE R. RICCIARDI, ROBERT L. RYAN, JOHN P. DAVIDSON III, BRADFORD HU, BRIAN LEACH, MANUEL MEDINA-MORA, and KEVIN L. THURM, Defendants, and CITIGROUP, INC., Nominal Defendant.

Stuart M. Grant, Nathan A. Cook, and Rebecca A. Musarra, of GRANT & EISENHOFER P.A., Wilmington, Delaware; OF COUNSEL: Mark Lebovitch, David L. Wales, and Alla Zayenchik, of BERNSTEIN LITOWITZ BERGER & GROSSMANN LLP, New York, New York; Brian J. Robbins, Felipe J. Arroyo, and Gina Stassi, of ROBBINS ARROYO LLP, San Diego, California, Attorneys for Plaintiffs. Donald J. Wolfe, Jr., T. Brad Davey, Tyler J. Leavengood, and Jay G. Stirling, of POTTER ANDERSON & CORROON LLP, Wilmington, Delaware; OF COUNSEL: Mary Eaton, of WILLKIE FARR & GALLAGHER LLP, New York, New York; Frank Scaduto, of WILLKIE FARR & GALLAGHER LLP, Washington, DC, Attorneys for Defendants Duncan P. Hennes, Franz B. Humer, Michael E. O'Neill, Gary M. Reiner, Judith Rodin, Anthony M. Santomero, Joan Spero, Diana L. Taylor, William S. Thompson, Jr., James S. Turley, Ernesto Zedillo Ponce de Leon, Robert L. Joss, Richard D. Parsons, Lawrence R. Ricciardi, and Robert L. Ryan, and Nominal Defendant Citigroup Inc. Stephen P. Lamb and Meghan M. Dougherty, of PAUL, WEISS, RIFKIND, WHARTON & GARRISON LLP, Wilmington, Delaware; OF COUNSEL: Brad S. Karp, Bruce Birenboim, and Susanna Buergel, of PAUL, WEISS, RIFKIND, WHARTON & GARRISON LLP, New York, New York; Jane B. O'Brien, of PAUL, WEISS, RIFKIND, WHARTON & GARRISON LLP, Washington, DC, Attorneys for Defendants Michael L. Corbat, Eugene M. McQuade, Vikram S. Pandit, John P. Davidson III, Manuel Medina-Mora, Bradford Hu, Kevin L. Thurm, and Brian Leach.


MEMORANDUM OPINION Stuart M. Grant, Nathan A. Cook, and Rebecca A. Musarra, of GRANT & EISENHOFER P.A., Wilmington, Delaware; OF COUNSEL: Mark Lebovitch, David L. Wales, and Alla Zayenchik, of BERNSTEIN LITOWITZ BERGER & GROSSMANN LLP, New York, New York; Brian J. Robbins, Felipe J. Arroyo, and Gina Stassi, of ROBBINS ARROYO LLP, San Diego, California, Attorneys for Plaintiffs. Donald J. Wolfe, Jr., T. Brad Davey, Tyler J. Leavengood, and Jay G. Stirling, of POTTER ANDERSON & CORROON LLP, Wilmington, Delaware; OF COUNSEL: Mary Eaton, of WILLKIE FARR & GALLAGHER LLP, New York, New York; Frank Scaduto, of WILLKIE FARR & GALLAGHER LLP, Washington, DC, Attorneys for Defendants Duncan P. Hennes, Franz B. Humer, Michael E. O'Neill, Gary M. Reiner, Judith Rodin, Anthony M. Santomero, Joan Spero, Diana L. Taylor, William S. Thompson, Jr., James S. Turley, Ernesto Zedillo Ponce de Leon, Robert L. Joss, Richard D. Parsons, Lawrence R. Ricciardi, and Robert L. Ryan, and Nominal Defendant Citigroup Inc. Stephen P. Lamb and Meghan M. Dougherty, of PAUL, WEISS, RIFKIND, WHARTON & GARRISON LLP, Wilmington, Delaware; OF COUNSEL: Brad S. Karp, Bruce Birenboim, and Susanna Buergel, of PAUL, WEISS, RIFKIND, WHARTON & GARRISON LLP, New York, New York; Jane B. O'Brien, of PAUL, WEISS, RIFKIND, WHARTON & GARRISON LLP, Washington, DC, Attorneys for Defendants Michael L. Corbat, Eugene M. McQuade, Vikram S. Pandit, John P. Davidson III, Manuel Medina-Mora, Bradford Hu, Kevin L. Thurm, and Brian Leach. GLASSCOCK, Vice Chancellor

In this matter, stockholders of Citigroup, Inc. seek damages, derivatively on the part of the company, against directors and officers. The Defendants have moved to dismiss. The burden is on the Plaintiffs to plead facts that, if true, raise a reasonable doubt that the director Defendants could exercise their business judgment to consider a demand, thus excusing demand under Court of Chancery Rule 23.1. The Plaintiffs seek to satisfy that burden by pointing to pleadings they allege demonstrate a substantial likelihood that the director Defendants are liable to Citigroup for failing to oversee company employees' compliance with law, under the rubric of In re Caremark International Inc. Derivative Litigation.

698 A.2d 959 (Del. Ch. 1996).

It is appropriate, I think, to discuss here the implications of a claim under Caremark. Corporate entities, acting through their employees, may violate laws or regulations. Such unlawful acts, in turn, can result in fines, penalties, third-party damages, and other losses on the part of the entity. The essence of a Caremark claim is an attempt by the owners of the company, its stockholders, to force the directors to personally make the company whole for these losses.

The circumstances under which a Caremark or oversight claim can be successful are limited. If the board directs employees to act unlawfully, the directors have breached the duty of loyalty and are liable; that, strictly speaking, is not an oversight claim. Caremark provides that if directors have failed to put in place any system whereby they may be made aware of and oversee corporate compliance with law, they may be liable. That situation is, manifestly, not the case here. Conversely, where the board has an oversight system in place, but nonetheless fails to act to promote compliance, the directors may be liable, but only where their failure to act represents a non-exculpated breach of duty.

It should be apparent that many failures of oversight by directors sufficient to constitute a breach of duty implicate the duty of care. Directors breach the duty of care where they act with gross negligence. In other words, where the directors are informed of potential unlawful acts in a way that puts them on notice of systematic wrongdoing, and nonetheless they act in a manner that demonstrates a reckless indifference toward the interests of the company, they may be liable for breach of the duty of care. Here, however, Citigroup's directors are exculpated from liability for such a breach. In that case, the path to director liability is straitened. In order to result in liability, the directors' inaction in the face of "red flags" putting them on notice of systematic wrongdoing must implicate the duty of loyalty. To imply director liability, the response of the directors must have been in bad faith. The inaction must suggest, not merely inattention, but actual scienter. In other words, the conduct must imply that the directors are knowingly acting for reasons other than the best interest of the corporation. That is the essence of a Caremark claim. The height of this bar, presumably, is what led to Chancellor Allen's famous observation that a Caremark claim is among the most difficult to prove in our corporate law.

Cf. City of Birmingham Ret. & Relief Sys. v. Good, 2017 WL 6397490, at *1 (Del. Dec. 15, 2017) ("We agree with the Court of Chancery that the plaintiffs did not sufficiently allege that the directors faced a substantial likelihood of personal liability for a Caremark violation. Instead, the directors at most faced the risk of an exculpated breach of the duty of care.").

Id. at *5.

In re Caremark Int'l Inc. Derivative Litig., 698 A.2d at 967.

Here, the Plaintiffs, with admirable effort and the aid of records obtained under Section 220, produced a ponderous omnibus of a complaint. It describes red flags placed before the directors, dating back to the financial crisis of a decade ago as well as more recently, in connection with activities of Citigroup and its subsidiaries that led to large fines levied against the bank. The Complaint makes it reasonably conceivable that the directors, despite these red flags, failed to take actions that may have avoided loss to the company. That is not the standard, however. To my mind, the allegations of the Complaint, if true, fail to demonstrate scienter. The Complaint does not make it reasonably conceivable that the directors acted in bad faith. Therefore, the Motion to Dismiss is granted.

My reasoning follows.

I. BACKGROUND

The facts, drawn from the Plaintiffs' Complaint and from documents incorporated by reference therein, are presumed true for purposes of evaluating the Defendants' Motion to Dismiss.

A. Parties and Relevant Non-Parties

Plaintiffs Oklahoma Firefighters Pension and Retirement System, Key West Municipal Firefighters and Police Officers' Retirement Trust Fund, Jeffrey Drowos, Fireman's Retirement System of St. Louis, and Esther Kogus are stockholders of nominal defendant Citigroup, Inc., and they held stock at all times relevant to this action.

Compl. ¶¶ 12-14.

Citigroup is a Delaware corporation headquartered in New York City. Citigroup maintains a complicated network of subsidiaries, but its business revolves around two primary segments: Citicorp and Citi Holdings. Citicorp contains a "regional customer banking and institutional clients group." "Citi Holdings consists of Citigroup's brokerage and asset management and local consumer lending businesses, and a special asset pool." Citibank N.A. is Citigroup's primary depository subsidiary.

Id. ¶ 15.

Id.

Id.

Id.

Id.

When the Plaintiffs filed their Complaint, Citigroup's board had sixteen directors, thirteen of whom are Defendants in this action. The thirteen directors named as Defendants are Michael L. Corbat, Duncan P. Hennes, Franz B. Humer, Eugene M. McQuade, Michael E. O'Neill, Gary M. Reiner, Judith Rodin, Anthony M. Santomero, Joan Spero, Diana L. Taylor, William S. Thompson, Jr., James S. Turley, and Ernesto Zedillo Ponce de Leon. These individuals began serving on the Citigroup board at different times, and some of them have been members of various board committees. Ten of them have also served on Citibank's board.

Id. ¶ 16.

Id.

Id. ¶¶ 17-29.

Id. ¶¶ 18-22, 24-26, 28-29.

The Defendants in this case also include former Citigroup directors. Defendant Robert L. Joss served on the Citigroup board from 2009 to April 2014, and he was a Citibank director from 2010 to 2014. Defendant Vikram S. Pandit was a member of the Citigroup board from December 2007 to October 2012, during which time he also served as Citigroup's CEO. Defendant Richard D. Parsons was a Citigroup director from 1996 to April 2012. Defendant Lawrence R. Ricciardi served on Citigroup's board from 2008 to April 2013, and he was a Citibank director from 2009 to 2013. Defendant Robert L. Ryan was a Citigroup director from 2007 to April 2015; he served on Citibank's board from 2009 to 2015.

Id. ¶ 31.

Id. ¶ 32.

Id. ¶ 33.

Id. ¶ 34.

Id. ¶ 35.

The final set of Defendants consists of Citigroup officers. Corbat has been Citigroup's CEO since October 2012, and from December 2011 to October 2012, he served as CEO of Citi Europe, Middle East, and Africa. From January 2009 to December 2011, Corbat was the CEO of Citi Holdings. Defendant John P. Davidson III has been Citigroup's Chief Compliance Officer since September 23, 2013. From April 2008 to September 2013, he headed Enterprise Risk Management at Citigroup, "a unit responsible for managing Citigroup's operational risk across businesses and geographies." Defendant Bradford Hu has been Citigroup's Chief Risk Officer since January 2013. Defendant Brian Leach was Citigroup's Chief Risk Officer from March 2008 to January 2013, and he worked as Citigroup's Head of Franchise Risk and Strategy from January 2013 to April 2015. Since June 2015, Defendant Manuel Medina-Mora has served as the non-executive chairman of the board of Grupo Financiero Banamex, S.A. de C.V. (the "Banamex Group"), a wholly owned, indirect Citigroup subsidiary. Before then, he held various high-level positions at Citigroup. Defendant Kevin L. Thurm was Citigroup's Chief Compliance Office from 2011 to September 2013, and, as noted above, Pandit was Citigroup's CEO from December 2007 to October 2012.

Id. ¶ 17.

Id.

Id. ¶ 38.

Id.

Id. ¶ 39.

Id. ¶ 40.

Id. ¶¶ 41, 50.

Id. ¶ 41.

Id. ¶¶ 32, 43.

B. Factual Overview

The Complaint contains a seventeen-page discussion of Citigroup's prior history of purported oversight failures. Id. ¶¶ 58-98. This history reveals what the Plaintiffs describe as "a larger pattern of compliance meltdowns[,] includ[ing, among other things]: hedge fund fraud; the improper disclosure of confidential client information in connection with equity research communications; inadequate insider trading oversight; misrepresentations concerning residential mortgage-backed securities and improper lending practices; [and] the failure to turnover trading records to the SEC over a period of fifteen years." Id. ¶ 72. The interested reader may turn to the Complaint for an elaboration of these incidents; I do not recount them here.

The Plaintiffs allege that the Defendants "consciously fail[ed] to develop, implement, and enforce effective internal controls throughout [Citigroup], including at its subsidiaries." The Plaintiffs seek relief for harm Citigroup has suffered as a result of four corporate traumas: "(1) pervasive violations of anti-money laundering rules; (2) substantial fraud at Banamex[, a wholly owned subsidiary of the Banamex Group]; (3) fraudulent manipulation of benchmark foreign exchange rates; and (4) deceptive credit card practices." I summarize the allegations relevant to each of these corporate traumas below.

Id. ¶ 58.

Id. ¶ 59.

1. Compliance with Anti-Money Laundering Laws

a. The Regulatory Environment

Citigroup and several of its subsidiaries are required to comply with an array of federal laws and regulations addressing the issue of money laundering. According to the Complaint, the most important of these anti-money laundering ("AML") laws are the Bank Secrecy Act of 1970 ("BSA") and various provisions of the USA Patriot Act. Several federal and state agencies are charged with administering these laws. At the federal level, the administering agencies include the Federal Reserve System ("FRB"), the Office of the Comptroller of the Currency ("OCC"), and the Federal Deposit Insurance Corporation ("FDIC"). At the state level, they include the California Department of Business Oversight ("CDBO").

Id. ¶ 106.

Id.

Id. ¶ 107.

Id.

Id.

The BSA imposes "mandatory reporting and record-keeping requirements to track currency transactions and detect and prevent money laundering." Likewise, under the USA Patriot Act, financial institutions must "establish AML and customer identification programs, and . . . conduct enhanced due diligence . . . for bank accounts held by non-U.S. persons." Banks must also compare their transactions and customers against sanctions lists kept by the Office of Foreign Asset Control ("OFAC"). Generally speaking, the federal AML laws require every bank to maintain a BSA/AML compliance program tailored to its risk profile.

Id. ¶ 108.

Id.

Id.

Id. ¶ 109.

The BSA's implementing regulations impose more specific requirements on financial institutions. Under those regulations, banks must maintain internal controls designed to ensure continuing compliance, perform independent testing of BSA/AML compliance, designate someone to serve as a BSA compliance officer, and train relevant personnel. A bank's internal BSA/AML controls must conform to a bevy of regulatory requirements. For example, banks must "[p]rovide sufficient controls and monitoring systems for timely detection and reporting of suspicious activity," "[i]dentify banking operations more vulnerable to abuse by money launderers and criminals," "[p]rovide for adequate supervision of employees that handle [activities covered by the BSA]," and "provide for timely updates in response to changes in regulations." Moreover, each bank must file a Suspicious Activity Report ("SAR") when it identifies "(i) certain known or suspected violations of federal law; (ii) suspicious transactions related to a money laundering activity; or (iii) a violation of the BSA/AML."

Id. ¶ 110.

Id. ¶ 112.

Id. ¶ 113.

The USA Patriot Act's implementing regulations require financial institutions to develop a Customer Identification Program ("CIP"). The CIP must enable the bank to verify the identities of its customers, and the program must be tailored to the bank's risk profile and size. The USA Patriot Act and its implementing regulations further require banks to conduct "special due diligence for accounts requested or maintained by, or on behalf of, foreign banks and non-U.S. persons." Finally, banks operating in the United States must comply with OFAC regulations, which "require that U.S. financial institutions ensure that their business operations and transactions do not violate U.S. economic and trade sanctions against entities such as targeted foreign countries, terrorists, international narcotics traffickers, and those engaged in activities related to the proliferation of weapons of mass destruction." Every bank must adopt an OFAC compliance program that fits its size and risk profile.

Id. ¶ 115.

Id. ¶¶ 115-16.

Id. ¶ 117.

Id. ¶ 120.

Id. ¶ 122.

b. The Alleged Compliance Failures

The Plaintiffs allege that Citigroup and its subsidiaries have continually failed to abide by BSA/AML laws and regulations. The compliance failures spanned several years and persisted in the face of multiple consent orders stemming from federal and state investigations into Citigroup's and its subsidiaries' BSA/AML practices. The end result, say the Plaintiffs, was that regulators were forced to fine Citigroup $140 million for its BSA/AML compliance failures.

Id. ¶ 125.

Id.

Id. ¶ 170.

The Complaint identifies a number of red flags that supposedly should have led the Defendants to improve Citigroup's BSA/AML controls. According to the Plaintiffs, if the Defendants had made the necessary improvements, Citigroup could have avoided paying the $140 million fine. I summarize the purported red flags and the responses to them from the Citigroup board and senior management.

See id. ¶¶ 408, 413 ("Indeed, Citigroup and its subsidiaries have already incurred tremendous reputational and financial penalties resulting from the Defendants' breaches including: i) $140 million in fines for failure to ensure compliance with applicable AML laws and regulations . . . .").

Citigroup and its subsidiaries face a high risk of AML violations for several reasons. First, Citigroup is a global corporation, and many of the countries it operates in pose a heightened risk of AML violations. For example, in January 2012, the Citigroup Compliance Committee learned from management that "50% of the countries in which Citigroup operates demonstrated a 'high' inherent geographic risk for AML violations." The Plaintiffs focus on Citigroup's operations in Mexico, in which "corrupt practices such as bribery and money laundering occur at a higher frequency . . . than in many of the other countries in which Citigroup operates." According to the Plaintiffs, Citigroup directors and senior management knew or should have known that the "corrupt practices" common in Mexico would pose a serious risk of money laundering at Citigroup subsidiaries operating in that country. Those subsidiaries included Banamex, which Citigroup acquired in 2001. As part of that acquisition, Citigroup also bought Banamex USA ("BUSA"), "which had numerous branches along the Mexican border and routinely engaged in cross-border transactions."

Id. ¶ 127.

Id. ¶ 131.

Id. ¶ 135.

Id. ¶ 132.

Id. ¶¶ 132, 134.

Second, Citigroup's "inorganic[]" growth led to the absorption of "disparate businesses with different and sometimes conflicting standards, systems, and controls." This potpourri of business lines created a heightened risk of AML violations. Senior management and directors appear to have recognized this. For example, in October 2009, management told the Audit and Risk Management Committees that Citigroup's AML compliance in North America "need[ed] improvement." And in January 2012, "management reported to the Citigroup Compliance Committee that the Company was rated 'medium high' in the categories of 'inherent AML risk,' 'quality of AML controls,' and 'residual AML risk.'" These AML issues were ascribed to, among other things, Citigroup's growing presence in emerging markets, its failure to create centralized AML systems, and its lack of consistent standards. Beginning in April 2012, Citigroup's Internal Audit ("IA") team continually informed Citigroup board members of these risks.

Id. ¶ 126.

Id.

Id. ¶ 127 (alteration in original).

Id.

Id.

Id. ¶ 128.

All of this is background to the primary allegations about Citigroup's BSA/AML compliance issues. The Plaintiffs' focus is the Citigroup board's purportedly inadequate response to a regulatory order and several consent orders issued by various government agencies. In July 2010, the OCC issued Citibank a Part 30 order as a result of "serious compliance deficiencies in the bank's operations." That order directed Citibank to improve its AML compliance in several of its business lines. In particular, Citibank was asked to improve "identification of high risk customers and of client relationships on a bank-wide basis; . . . expan[d] . . . periodic customer reviews; and . . . optimiz[e] . . . automated transaction monitoring systems." Two years later, the OCC found that these "[d]eficiencies were not properly and timely addressed."

A Part 30 order refers to an order issued under 12 C.F.R. § 30.2, which "establishes procedures for requiring submission of a compliance plan and issuing an enforceable order pursuant to" the law requiring the OCC "to establish safety and soundness standards."

Compl. ¶ 143.

Id.

Id.

Id. (alteration in original). The Plaintiffs refer to an April 17, 2012 board meeting at which the directors learned that "Citigroup's 2011 overall compliance risk rating was 'medium-high' and that its AML Risk Assessment was also 'medium-high.'" Id. ¶ 286. Yet they fail to mention that at the same meeting, the directors were also told that "28 of the 35 [Part 30] milestones were completed during 1Q 2012." Leavengood Aff. Ex. 3 at 11.

As a result of Citibank's failure to obey the Part 30 order, the OCC issued a consent order on April 5, 2012. The consent order "castigated Citibank for its AML program deficiencies," noting several "internal control weaknesses." The OCC identified weaknesses in Citibank's monitoring of client relationships, its customer due diligence processes, and the "scope and documentation of the validation and optimization process applied to the automated transaction monitoring system." Among other things, the consent order required Citibank to implement a "BSA/AML Action Plan" and to improve its customer due diligence practices. The OCC made clear that Citibank's board was ultimately responsible for ensuring the bank's compliance with the consent order.

Compl. ¶ 144.

Id. ¶¶ 144-45.

Id. ¶ 145.

Id. ¶ 146.

Id.

According to the Complaint, even after the April 2012 consent order was issued, "directors and senior management stood idly by with respect to AML compliance." In the months following entry of the consent order, Citigroup board members received several warnings about AML issues. For example, in July 2012, IA told the Compliance Committee that there was "[i]nadequate AML control, governance, and oversight" at Banamex and BUSA. That same month, the Audit Committee learned that AML risk was increasing. Documents incorporated by reference in the Complaint make clear, however, that the Citigroup board took action in response to the problems revealed by the first consent order. To take just one example, at an April 17, 2012 Citigroup board meeting, directors learned that "the Compliance Committees [had] received a presentation from the AML Monitoring Team, including efforts to improve the quality and integrity of the data feeding . . . Citibank's AML monitoring platforms." Directors were also told at this meeting that "the Compliance Committees directed [IA] to provide a country-by-country AML assessment."

Id. ¶ 151.

Id. ¶ 150 (alteration in original) (emphasis omitted).

Id.

Leavengood Aff. Ex. 3 at 12.

Id.

Despite these efforts, on August 2, 2012, BUSA entered into a consent order with the FDIC and the California Department of Financial Institutions ("CDFI"). The consent order required BUSA's board to "'develop, adopt, and implement an updated written compliance program' that would be designed to 'ensure and maintain compliance' with the BSA." BUSA was also ordered to hire a BSA compliance officer and enough staff to monitor compliance with the BSA. The Plaintiffs allege that "[t]he Citigroup Board was aware of the FDIC/CDFI Consent Order no later than October 2012, when Joss[, the chair of the Compliance Committee at the time,] discussed the consent order with the Citigroup, Citibank, and Citicorp boards."

Compl. ¶ 151.

Id. ¶ 152 (footnote omitted).

Id.

Id. ¶ 151.

The Plaintiffs allege that the entry of the second consent order failed to prompt action from the Defendants, "leav[ing] [Citigroup] and its subsidiaries vulnerable to AML violations." The Plaintiffs point out that in September and October 2012, IA found that "BUSA's control environment remained 'unsatisfactory.'" In October and November 2012, the FDIC and CDFI conducted an on-site visit of BUSA, and they concluded that since the entry of the August 2012 consent order, "BUSA had made inadequate progress on AML/BSA compliance." And in early 2013, the AML control environment "retained a 'limited assurance' rating, while the 'overall effectiveness of controls over affiliate transactions' at BUSA received an 'insufficient assurance' rating."

Id. ¶ 154.

Id. ¶¶ 155-56.

Id. ¶ 157.

Id. ¶ 158.

Again, however, documents incorporated by reference in the Complaint reveal that the Citigroup board took action in response to continuing AML issues. For instance, when the Citigroup board met on December 12, 2012, the directors learned that management had taken "proactive efforts concerning AML issues, [and] that management's current areas of focus include the Consumer North America high risk account re-remediation; expired customer due diligence documentation; migration programs in Mexico; . . . and broader structural issues." At the same meeting, the board also learned of "continued progress on OCC commitments and business priorities, including creating and implementing a global governance structure and framework and short-term tactical project execution."

Leavengood Aff. Ex. 4 at 7. The Complaint quotes from the minutes of this meeting. Compl. ¶ 287. Specifically, the Complaint notes that "'federal and state regulators . . . emphasized that they had expected more progress against the implementation of many of the enhanced or newly developed plans and programs' following the FDIC/CDFI Consent Order." Id. (alteration in original). The use of ellipses here is telling. The Complaint omits to mention that "federal and state regulators acknowledged BUSA's efforts." Leavengood Aff. Ex. 4 at 7 (emphasis added). The Complaint also fails to include the next part of that sentence, which reveals that "BUSA expects to submit a revised plan that aligns with the examiners' expectations." Id.

Leavengood Aff. Ex. 4 at 7.

Nevertheless, on March 21, 2013, yet another consent order was issued, this time by the FRB. Unlike the two consent orders discussed above, this one addressed Citigroup's role in ensuring that its subsidiaries achieved compliance. The FRB found that "Citigroup lacked effective systems of governance and internal controls to adequately oversee the activities of the Banks." Under the FRB consent order, Citigroup was required to ensure firmwide compliance, and to "implement a firmwide compliance risk management program." The consent order also required the Citigroup board itself to "review [Citigroup's] firmwide BSA/AML compliance program and, based on its findings, submit to the FRB a plan to 'strengthen the management and oversight' of the compliance program."

Compl. ¶ 159.

Id.

Id. (emphasis omitted). "Banks" refers to Citibank and BUSA. Id. ¶ 160 n.48.

Id. ¶ 159.

Id. ¶ 161.

The Complaint next focuses on the approximately two-year period between the entry of the FRB consent order and the imposition of the $140 million fine. The Plaintiffs allege that during this period, "Citigroup's Board failed to respond meaningfully and in good faith to the misconduct that attracted so much regulatory scrutiny, ultimately leading to the imposition of [the] fine." The Plaintiffs cite several reports from IA to the Citigroup board and its committees. In those reports, IA revealed that "BUSA's BSA/AML controls, risk management controls, and oversight procedures were deficient." A few examples illustrate the tenor of these reports. In an April 2013 report to the Audit and Compliance Committees, IA noted that "BUSA's AML control environment earned an 'insufficient assurance' rating, with increasing risk of violations 'due to poor risk management, failures in control design and execution, and inadequate management oversight.'" In July and August 2013, IA told the Audit Committee that BUSA was "'substantially non-compliant' with the FDIC Consent Order." And about nine months later, IA reported that "significant weaknesses continue to exist in AML." In sum, IA put out twenty-two reports in which "BUSA's AML programs were given an 'insufficient assurance' rating between February 2013 and April 2015."

Id. ¶ 162.

Id. ¶ 163.

Id.

Id.

Id.

Id.

Id. ¶ 302.

The picture painted in the Complaint is indeed one of a board that "sat like stones growing moss" in the face of clear warnings about persistent AML issues. But the documents incorporated by reference in the Complaint belie this narrative. For example, about one month after entry of the FRB consent order, the Citigroup board, along with the Citibank and Citicorp boards, learned that "management was preparing an action plan [in response to the FRB consent order] and will meet with the FRB's staff to better understand its expectations." The Citigroup board was also informed that "management reported progress on . . . de-risking, enhancing controls, strengthening governance and OCC commitments and business priorities." And, as to BUSA, the board was told that management planned to "de-risk the business, close money services businesses and close eight branches along the US-Mexican border." Later, in September 2013, the Citigroup, Citibank, and Citicorp boards learned that outside counsel had reviewed BUSA's operations and that "employee terminations" had been undertaken as part of the compliance effort. At this meeting, members of the three boards "directed questions to management about BUSA, including personnel changes and prior regulatory reviews."

Id. ¶ 9.

Leavengood Aff. Ex. 6 at 19.

Id.

Leavengood Aff. Ex. 6 at 24.

Leavengood Aff. Ex. 13 at 8.

Id.

The Citigroup board received additional updates about AML compliance in December 2013. Specifically, the board learned that the Citigroup and Citibank Compliance Committees were "focus[ed] on whether management is embracing AML controls." The board was told that "the AML surveillance process reviews 2.8 billion transactions per month, flags about 200,000 matters each month and that about 150,000 of these matters are subject to further review by analysts." About one year later, in January 2015, the Citigroup board was informed that, while the "aggregate risk rating for AML is High," "the aggregate risk trend is decreasing due to de-risking of certain high-risk client types, businesses, and geographies, in combination with ongoing improvements to the control environment." Moreover, the board learned that two products "identified as having inherently higher levels of AML risk" demonstrated "decreasing risk trends."

Leavengood Aff. Ex. 14 at 16.

Id.

Leavengood Aff. Ex. 11 at 5.

Id.

Citigroup's efforts were ultimately unavailing. On July 22, 2015, "the FDIC 'announced the assessment of a civil money penalty of $140 million against Banamex USA . . . for violations of the Bank Secrecy Act . . . and anti-money laundering . . . laws and regulations.'" The FDIC found that BUSA had

Compl. ¶ 164 (first alteration in original).

failed to implement an effective BSA/AML Compliance Program over an extended period of time. The institution failed to retain a qualified and knowledgeable BSA officer and sufficient staff, maintain adequate internal controls reasonably designed to detect and report illicit financial transactions and other suspicious activities, provide sufficient BSA training, and conduct effective independent testing.
For its part, the CDBO imposed a $40 million fine on BUSA, citing "new, substantial violations of the BSA and anti-money laundering mandates over an extended period of time." The FDIC fine was satisfied in part by the CDBO fine. On the same day that these fines were announced, Citigroup announced its decision to close BUSA. But BUSA "remains subject to a number of investigations, including a criminal investigation by the U.S. Department of Justice and an investigation by the Treasury Department's Financial Crimes Enforcement Network."

Id. ¶ 166.

Id. ¶ 165.

Id. ¶ 165 n.52.

Id. ¶ 167.

Id.

2. Accounts Receivable Fraud at Banamex

The Plaintiffs allege that lack of oversight and inadequate internal controls caused Banamex to become the victim of a massive accounts receivable fraud. Citigroup lost over $400 million as a result of the fraud, which took the following form. Oceanografia S.A. de C.V. ("OSA"), a Mexican oil services company, borrowed a total of approximately $585 million from Banamex. The loans were secured by accounts receivable submitted by OSA. OSA, in turn, was an important supplier to Pemex, a state-owned Mexican oil company. Many of Banamex's loans to OSA were secured by accounts receivable reflecting payments Pemex owed to OSA. The problem was that most of these accounts receivable were fraudulent. The fraud, which came to light in February 2014, wiped out 19% of Banamex's banking profits for 2013. And in October 2014, Mexico's banking regulator fined Banamex $2.5 million after determining that "the fraud resulted from weaknesses in Banamex's internal controls, errors in its loan origination and administration procedures, and deficiencies relating to risk administration and internal audits." I turn now to the purported red flags related to this fraud and the response to them.

Id. ¶ 171.

Id.

Id. ¶ 199.

Id.

Id. ¶ 200.

Id. ¶¶ 200, 206.

Id. ¶ 207.

Id. ¶¶ 207-08.

Id. ¶¶ 173, 217.

According to the Plaintiffs, Citigroup and its subsidiaries failed to implement adequate "maker/checker controls" or properly segregate duties. Maker/checker controls are designed to reduce the likelihood of misconduct "by preventing too much authority from being centralized in single individuals or positions." Segregation of duties is meant to achieve the same goal. The Defendants knew that maker/checker controls were not strong in Mexico, and in September 2013, management told the Audit Committees about "the failure to enforce the separation of duties in Mexico." Later, IA revealed in its 2013 year-end review that "a fraud within the treasury and trade business . . . 're-enforce[d] the need for attention to key maker-checker controls and oversight of manual processes.'" The Plaintiffs concede that Citigroup management developed "Project Andes," an initiative to improve segregation of duties and to address issues in the maker/checker process. But the Plaintiffs fault Citigroup for failing to consider "expanding Project Andes to retail banks until after the OSA fraud."

Id. ¶ 174.

Id.

Id.

Id. ¶ 175.

Id. (second alteration in original).

Id. ¶ 176.

Id. (emphasis omitted).

The Plaintiffs next point to a series of fraud-related incidents at Citigroup and its subsidiaries that supposedly should have warned the board of "significant issues concerning fraud detection and prevention." In one incident, "a Citigroup Treasury Finance employee fraudulently transferred $25 million to his own personal bank account." In a July 18, 2011 meeting, the Audit Committee learned that the fraud stemmed from "a 'poor control environment,' 'inadequate supervision and review,' and insufficient review of manual transactions." The next spring, the Audit Committee was told that "five Banamex employees had accepted at least 16 million Mexico pesos . . . in kickbacks as part of [a] scheme" with several Banamex vendors. Again, inadequate controls were to blame. In 2013, management discovered that a Banamex bond trader had fraudulently concealed trading losses by deferring loss recognition and manipulating trades. In March 2014, the Audit Committee learned that thirty-seven Banamex employees had been selling confidential credit card customer information. And in October 2014, Citigroup announced that a Banamex security unit had been engaging in several nefarious activities for almost fifteen years, including "recording phone calls without authorization; fraudulently misreporting gas expenses in order to increase the reimbursements [members of the unit] received from Banamex; developing shell companies to launder proceeds; and receiving kickbacks from vendors who overcharged Banamex."

Id. ¶ 181. The Plaintiffs suggest that these incidents were caused in part by "the failure to align subsidiaries' technology systems (including those of Banamex) with the rest of Citigroup." Id. ¶ 178.

Id. ¶ 182.

Id.

Id. ¶ 183.

Id.

Id. ¶ 184.

Id. ¶ 185.

Id. ¶ 186.

Banamex's brokerage unit, Accival, also fell victim to a fraud committed by one of its employees. In this scheme, an Accival operations manager "fraudulently transferred funds from an Accival account to a private customer account using foreign exchange . . . transactions." Accival lost approximately $6.9 million in the fraudulent transfers. IA later told the Audit Committee that the fraud stemmed from "[k]ey control weaknesses related to segregation of duties and maker/checker controls."

Id. ¶ 187.

Id.

Id.

Id. ¶ 189 (alteration in original) (emphasis omitted).

A more salient purported red flag was the Mexican homebuilders fraud, which involved fraudulent collateral. Banamex developed a product that resembled a revolving loan facility. Banamex extended credit to homebuilders who, in turn, transferred properties to a trust. Those properties served as collateral for the loan facility. When the homebuilders sold the homes they built, "they were required to deposit the proceeds of the sale into the trust, and the proceeds would be redistributed primarily to Banamex as repayment for the loan." Unfortunately, many of the homebuilders did not deposit the proceeds of their sales into the trust, and some "overstated the value of the collateral against which Banamex made its loans." Citigroup lost between $75 million and $85 million as a result of the fraud, which management attributed to "design and execution deficiencies in the management of collateral." Management also told the Citigroup board that it would conduct "a global, end-to-end assessment of Citi's management effectiveness with respect to secured lending and collateral management, as well as a review of Banamex's overall collateral framework, in order to identify potential gaps and the actions necessary to remediate control deficiencies."

Id. ¶ 190.

Id. ¶ 191.

Id.

Id.

Id.

Id. ¶ 193.

Id. ¶¶ 193-194 (emphasis omitted).

Leavengood Aff. Ex. 13 at 5.

According to the Plaintiffs, if the Defendants had heeded the warnings contained in the events just described, the OSA accounts receivable fraud could have been avoided. And, the Plaintiffs suggest, there were red flags about OSA itself. The Plaintiffs complain that Banamex decided to extend more credit to OSA under the receivables program even though "it had been apparent for several years that OSA was a troubled company." For example, in 2005, Mexican regulators learned that OSA had obtained a $27 million loan by submitting phony Pemex paperwork. And in 2009, Fitch, the ratings agency, highlighted OSA's "high leverage and poor cash flow." Fitch eventually refused to provide any rating for OSA because OSA failed to give Fitch enough information, which the Plaintiffs describe as "a telltale sign of potential wrongdoing."

Compl. ¶ 201.

Id. The Complaint does not say whether this information was ever conveyed to anyone at Citigroup.

Id. ¶ 202.

Id.

Despite the problems at OSA, Banamex extended so much credit to the "troubled company" that "by 2012, Banamex's loans to OSA constituted nearly half of OSA's revenue." Banamex loosened its lending procedures to make this happen. For example, at some point it ceased "contacting Pemex to verify the receipts submitted by OSA as the bases for its credit." Citigroup management later suggested that this was unusual among accounts receivable programs, in which invoices used as collateral are typically reconciled. These risky practices were possible because "Citi's Board had not implemented basic controls and legal compliance mechanisms." Moreover, while Banamex was being defrauded, IA failed to perform an audit to determine whether "the OSA/Pemex program 'was appropriately classified as a buyer centric or seller centric program.'" As noted above, Citigroup lost over $400 million in the accounts receivable fraud, and Mexico's banking regulator fined Banamex $2.5 million for allowing the fraud to occur. The Securities and Exchange Commission and the Mexican Attorney General later announced investigations into the fraud.

Id. ¶ 203.

Id. ¶ 204; see also id. ¶ 208 ("Although the funds loaned to OSA constituted the largest accounts receivable financing program at Banamex, no verification was performed regarding the quality of the receivables, and 'loans were made based on statements of individuals.'").

Id. ¶ 208.

Id. ¶ 205.

Id. ¶ 210. The Plaintiffs concede that "an internal audit was conducted in November 2013 of the supply finance program generally," but they note that "the OSA/Pemex relationship was completely excluded from the audit." Id.

Id. ¶¶ 173, 215, 217. Mexico's banking regulator also issued a corrective action plan, and Banamex was fined an unspecified amount in May 2015 for failing to comply with the terms of that plan. Id. ¶ 218.

Id. ¶ 219.

3. Foreign Exchange Rate Manipulation

The next corporate trauma for which the Plaintiffs seek relief involves foreign exchange ("FX") rate manipulation on the part of Citigroup traders. From at least 2007 to at least 2013, Citigroup FX traders colluded with traders at other firms to manipulate FX benchmark rates, triggered customer stop loss orders, and increased profits by sharing confidential client information with traders at other firms.

"A stop loss order is an instruction from a client to trade currency if the currency reaches a specified rate." Id. ¶ 228.

Id. ¶ 226.

These Citigroup traders manipulated two widely used FX benchmark rates—the 4:00 pm WM Reuters fix and the 1:15 European Central Bank fix—by "exchang[ing] details relating to their net currency orders and related future fixes with FX traders at other banks to coordinate trading strategies." The communications at issue occurred in "private electronic chat rooms." Citigroup FX traders also shared clients' instructions about stop loss orders with "traders at other firms to manipulate the FX spot rate and ultimately to set off clients' stop loss orders." Citigroup profited from this manipulation "because FX Traders could take advantage of the difference between the rate at which they purchased a particular currency and the rate at which they sold to a client pursuant to a stop loss order." And Citigroup FX traders revealed the identities of certain clients to traders at other firms in furtherance of their "collusive trading activity." Citigroup ultimately paid $2.2 billion in fines as a result of these activities, and Citicorp pleaded guilty to conspiracy to violate federal antitrust laws.

Id. ¶ 227.

Id.

Id. ¶ 228.

Id.

Id. ¶ 229. The Plaintiffs also allege that "Citigroup FX Traders and salespeople added 'sales markup, through the use of live hand signals or undisclosed prior internal arrangements or communications, to prices given to customers that communicated with sales staff on open phone lines.'" Id. ¶ 230.

Id. ¶¶ 222, 233.

The Plaintiffs point to several purported red flags that they say should have alerted the Defendants to the compliance threat posed by FX benchmark manipulation and collusive trading. In 2009, the Audit and Risk Management Committee learned that "the current 'market turbulence increases operational risk significantly.'" And in August 2011, "Citi became aware that a trader in its FX business outside London had inappropriately shared confidential client information in a chat room with a trader at another firm." This trader was fired, and "reminders were given to Citi employees about the need to maintain client confidentiality." Later, in April 2013, IA told the Audit Committee that "FX transaction execution maker/checker controls and post transaction reviews require improvement." The Plaintiffs omit the portion of this IA report that describes the remedial actions to be taken, including "[c]lear definition of FX execution mandates in terms of transaction size, products, tenors, currencies, and approvals."

Id. ¶ 247 (emphasis omitted). The report in which this remark appears does not specifically discuss FX-related issues, referring instead to "Madoff, large rogue trading losses at other firms," "mark manipulation, issuer/borrower fraud, [and] embezzlement." Leavengood Aff. Ex. 16 at CITI018447.

Compl. ¶ 248. The Complaint does not allege that this information was ever brought to the Citigroup board's attention. The same is true for the allegation that "several front office managers were aware of and/or involved in the FX misconduct as early as March 2010, but the misconduct persisted for years." Id. (footnote omitted).

Leavengood Aff. Ex. 15 at 15.

Compl. ¶ 249.

Leavengood Aff. Ex. 17 at CITI024853. The remedial action had a "final target completion date" of June 2013. Id.

According to the Plaintiffs, another red flag appeared back in 2001, when Citigroup itself helped draft the industry standards governing good practices in FX trading. Those standards stated, among other things, that "[m]anipulative practices by banks with each other or with clients constitute unacceptable trading behavior." The Plaintiffs do not say, however, whether any of the Defendants played a role in formulating (or were even aware of) these standards. The same gap exists in the Plaintiffs' allegation that "Citigroup's oversight failures leading to the FX-related misconduct occurred in the midst of the LIBOR rate-fixing scandals that resulted in criminal investigations and monetary penalties against other firms."

Compl. ¶ 250.

Id. ¶ 250 (emphasis omitted).

Id. ¶ 252 (emphasis added). The Plaintiffs also allege that the Risk Management and Finance Committee learned in 2011 that "a trader at UBS had engaged in fraudulent trading, ultimately costing UBS $2 billion." Id. ¶ 252 n.110. And the Plaintiffs allege that "Citigroup was itself subject to an investigatory probe concerning LIBOR" when the FX-related misconduct took place. Id. ¶ 323.

Despite these supposed red flags, the FX manipulation scheme continued, eventually costing Citigroup billions of dollars in fines. On November 11, 2014, the Commodity Futures Trading Commission ("CFTC") sanctioned Citibank for violations of the Commodity Exchange Act and CFTC regulations. According to the CFTC, when the fraud took place, Citibank knew of "related attempts by banks 'to manipulate the London Interbank Offered Rate ["LIBOR"] and other interest rate benchmarks'; yet, the FX manipulation proceeded without detection because of 'internal control and supervisory failures' at Citibank." The CFTC imposed a $310 million fine and issued a consent order requiring the bank to improve its internal controls. That same day, the OCC issued its own consent order, in which it "identified 'deficiencies and unsafe or unsound practices related to [Citibank's] wholesale foreign exchange business.'" The OCC, for its part, fined Citibank $350 million. On the same day that these two consent orders were entered, the United Kingdom's Financial Conduct Authority ("FCA") issued a "Final Notice" finding that Citibank had "'fail[ed] to take reasonable care to organize and control its affairs responsibly and effectively with adequate risk management systems' in connection with FX trading manipulation." The FCA also found that Citibank knew of oversight issues at other firms related to LIBOR enforcement actions, and it levied a fine of approximately $358 million.

Id. ¶ 235.

Id.

Id.

Id. ¶ 236.

Id.

Id. ¶ 237.

Id.

Several months later, on May 20, 2015, Citicorp entered the guilty plea mentioned above. The plea agreement stated that Citicorp had participated in a "combination and conspiracy to fix, stabilize, maintain, increase or decrease the price of, and rig bids and offers for, the euro/U.S. dollar . . . currency pair exchanged in the foreign currency exchange spot market . . . in violation of the Sherman Antitrust Act." Citicorp paid a $925 million criminal fine, and it was put on probation for three years. And on the same day that Citicorp pleaded guilty to antitrust violations, Citigroup entered a consent order with the FRB, which fined Citigroup $342 million after determining that, "[a]s a result of deficient policies and procedures . . . Citigroup engaged in unsafe and unsound banking practices." There has also been "significant private litigation against Citigroup" stemming from its antitrust violations, and Citigroup is now being investigated by the Korea Fair Trade Commission in connection with FX manipulation.

Id. ¶ 233.

Id. (second alteration in original).

Id.

Id. ¶ 238 (alterations in original).

Id. ¶ 239.

As noted above, the regulators that investigated Citigroup's FX trading practices found that "Citigroup and its subsidiaries did not have sufficient measures in place to exercise satisfactory control over the FX spot trading business." To take just one example, the FRB noted that Citigroup

Id. ¶ 240.

lacked adequate firm-wide governance, risk management, compliance and audit policies and procedures to ensure that the firm's Covered FX Activities conducted at Citigroup complied with safe and sound banking practices, applicable U.S. laws and regulations, including policies and procedures to prevent potential violations of the U.S. commodities, antitrust and criminal fraud laws, and applicable internal policies.
The Plaintiffs conclude from these findings that the Defendants failed to exercise appropriate oversight and maintain effective controls.

Id. (emphasis omitted).

Id. ¶ 245.

4. Unlawful Credit Card Practices

The final corporate trauma for which the Plaintiffs seek relief relates to a variety of unlawful credit card practices engaged in by Citigroup subsidiaries from at least 2000 to at least 2013. The subsidiaries in question were Citibank, Citicorp Credit Services, Inc. ("CCSI"), and Department Stores National Bank ("DSNB"). Broadly speaking, these subsidiaries deceived millions of consumers into purchasing or keeping credit card "add-on products (i) relating to services that they did not receive, (ii) for which they did not give their informed and affirmative enrollment consent, (iii) that they did not know they could refuse, and/or (iv) that were not in their best financial interest." As a result of this unlawful conduct, on July 20, 2015, the Consumer Financial Protection Bureau ("CFPB") imposed a $35 million fine on Citibank and ordered it to pay $700 million in restitution to the victims of the deceptive practices. The OCC levied a separate fine of $35 million.

Id. ¶ 254. The unlawful practices stopped around February 2013. Leavengood Aff. Ex. 21 at 2-4.

Compl. ¶ 255.

Id. ¶ 254.

Id. ¶ 253.

Id. ¶¶ 253, 270-71.

The Complaint describes the unlawful credit card practices in some detail; I offer only a brief summary of their salient characteristics. One component of these practices was to misrepresent the terms of various optional additions to credit cards, which included "identity monitoring, debt protection, and identity theft reimbursement services." Another aspect of the unlawful practices was to bill customers for add-ons that they never received. And sometimes customer authorization was never secured for add-ons or "was obtained only after the[ Citigroup subsidiaries] began charging for the services." The Citigroup subsidiaries at issue also "engaged in improper consumer retention practices," for example by "misrepresent[ing] the benefits of various services or omit[ing] the terms or limitations thereof" when consumers sought to cancel the services. Finally, DSNB, which let customers "apply for credit cards via 'pin pad' offer screens at retail stores like Macy's," "deceptively made it appear that enrollment in . . . additional services was a condition to obtaining the credit card."

Id. ¶ 256.

Id.

Id. ¶ 257.

Id. ¶ 261.

Id. ¶ 262.

The Plaintiffs point to a variety of purported red flags related to these unlawful practices. In July 2011, IA informed the Audit Committee that the control environment for credit cards needed improvement. At the same meeting, the Audit Committee learned that "action will be taken through training and systems changes and the corrective action plans would be discussed and agreed with the OCC." The next month, the West Virginia Attorney General sued Citigroup for deceptive practices it employed in marketing credit card protection programs, alleging that those practices violated the state's Consumer Credit and Protection Act. Citigroup settled the charges about two years later for $1.95 million. Further red flags allegedly appeared in January 2012, when the Citibank and Citigroup Audit Committees received a memorandum describing the "'Retail Partners Cards Governance' controls . . . as medium-high risk." Later, in October 2012, the Audit Committees learned that "the CFPB and FDIC were taking action against competitors Discovery and American Express, requiring hundreds of millions of dollars in restitution and penalties relating to the sales of add-on products."

Id. ¶ 264.

Leavengood Aff. Ex. 24 at 3.

Compl. ¶ 265.

Id.

Id. ¶ 266.

Id.

Citigroup itself became the subject of investigation for unlawful credit card practices. The Citigroup and Citibank Audit Committees learned in April 2013 that the FCA had conducted an investigation and found that "add-on Payment Protection Insurance . . . products from U.K. insurance company Card Protection Plan Ltd. . . . , which were sold by a wholly owned subsidiary of Citigroup from 2000 to 2011, were 'fundamentally flawed' and 'missold.'" But the Complaint also alleges that in the wake of the FCA's investigation, "Citigroup . . . joined a customer remediation program involving 13 other financial institutions." A month earlier, in March 2013, IA had told the Citigroup and Citibank boards that Citigroup's consumer compliance rating was downgraded because of "'significant deficiencies in controls over third party vendors' relating to identify theft and other fee-based products." And, in October 2013, IA reported to the Audit Committees that there were "fifty-four control issues relating to the card services provided for the Macy's accounts[, which were handled by DSNB, the entity responsible for distributing credit cards for private account labels]." Three months later, IA was still telling the Audit Committee that there were several "ineffective controls in place to mitigate risks across Credit Granting, Customer Service, Fraud Management, Collections, and Technology."

Id. ¶ 267 (footnote omitted). The Plaintiffs also allege that "in 2009, the Australia Securities and Investments Commission . . . was engaged in an investigation concerning the sale of credit insurance for credit cards and the conduct of call center employees." Id. ¶ 333. The Audit and Risk Management Committees learned that a fine may be imposed for such conduct. Id.

Id. ¶ 339.

Id. ¶ 268.

Id. ¶ 269 (emphasis omitted). Not mentioned in the Complaint is that the Audit Committees also learned that "corrective actions [would] include awareness training and improved controls and procedures." Leavengood Aff. Ex. 28 at 5. Nor does the Complaint mention that those "Committees emphasized the seriousness of the findings and commended IA for the vigor of the review and the level of detail." Id.

Compl. ¶ 269.

As noted above, on July 20, 2015, the CFPB and the OCC issued consent orders against the offending Citigroup subsidiaries. As with the FX benchmark manipulation outlined above, the regulators found that these Citigroup subsidiaries "failed to enact adequate controls to ensure that their add-on credit businesses conformed to applicable consumer protection laws and regulations." The OCC and the CFPB stressed that the Citigroup board bore the ultimate responsibility for ensuring that its subsidiaries complied with consumer financial laws.

Id. ¶ 270.

Id. ¶ 272.

Id. ¶ 275.

C. Procedural History

Before the Plaintiffs initiated this litigation, they sought books and records from Citigroup under 8 Del. C. § 220. After facing resistance from Citigroup, the Plaintiffs pursued two separate Section 220 actions and obtained the documents that form the basis of the allegations in their Complaint.

Id. ¶ 7.

Id. ¶¶ 100-04.

The Plaintiffs filed their initial Complaint on March 30, 2016, and they filed a supplemental Complaint on April 14, 2016. After the Defendants moved to dismiss, the Plaintiffs amended their Complaint and filed the operative pleading in this case on August 15, 2016. The Complaint contains three counts. Count I is brought against both the current and former Citigroup directors who are named as Defendants in this case, and it alleges that they breached their fiduciary duties by failing to exercise appropriate oversight over Citigroup. Count II is asserted against the Citigroup officers named as Defendants in this action, and it similarly alleges that they breached their fiduciary duties by failing to adequately monitor and oversee Citigroup. Count III is a waste claim that the Plaintiffs have since voluntarily withdrawn.

Id. ¶¶ 404-09.

Id. ¶¶ 410-14. The parties have agreed to dismiss John P. Davidson III, Bradford Hu, and Kevin L. Thurm from this case.

Id. ¶¶ 415-422; Pls.' Answering Br. 27 n.102.

The Defendants moved to dismiss the Complaint on September 30, 2016. They argue primarily that the Complaint fails to adequately allege demand futility as to any of the four corporate traumas described above. I held oral argument on the Defendants' Motion on July 20, 2017, after which the parties submitted supplemental briefing on the red flags alleged in the Complaint and the Citigroup board's response to them.

II. ANALYSIS

As just noted, the Defendants seek dismissal of the Complaint under Court of Chancery Rule 23.1 for failure to make a demand. The demand requirement is an extension of the fundamental principle that "directors, rather than shareholders, manage the business and affairs of the corporation." Directors' control over a corporation embraces the disposition of its assets, including its choses in action. Thus, under Rule 23.1, a derivative plaintiff must "allege with particularity the efforts, if any, made by the plaintiff to obtain the action the plaintiff desires from the directors or comparable authority and the reasons for the plaintiff's failure to obtain the action or for not making the effort." Where, as here, the plaintiff has failed to make a pre-suit demand on the board, the Court must dismiss the complaint "unless it alleges particularized facts showing that demand would have been futile." The plaintiff's "pleadings must comply with stringent requirements of factual particularity that differ substantially from the permissive notice pleadings governed solely by Chancery Rule 8(a)." Under the heightened pleading requirements of Rule 23.1, conclusory "allegations of fact or law not supported by allegations of specific fact may not be taken as true."

The Defendants also moved to dismiss under Court of Chancery Rule 12(b)(6).

Aronson v. Lewis, 473 A.2d 805, 811 (Del. 1984) (citing 8 Del. C. § 141(a)), overruled on other grounds by Brehm v. Eisner, 746 A.2d 244 (Del. 2000).

Ct. Ch. R. 23.1(a).

Ryan v. Gursahaney, 2015 WL 1915911, at *5 (Del. Ch. Apr. 28, 2015), aff'd, 128 A.3d 991 (Table) (Del. 2015).

Brehm, 746 A.2d at 254.

Grobow v. Perot, 539 A.2d 180, 187 (Del. 1988), overruled on other grounds by Brehm, 746 A.2d 244.

Nevertheless, "[o]n a motion to dismiss pursuant to Rule 23.1, the Court considers the same documents, similarly accepts well-pled allegations as true, and makes reasonable inferences in favor of the plaintiff—all as it does in considering a motion to dismiss under Rule 12(b)(6)." And "where a complaint quotes or characterizes some parts of a document but omits other parts of the same document, the Court may apply the incorporation-by-reference doctrine to guard against the cherry-picking of words in the document out of context." Under the incorporation-by-reference doctrine, "a complaint may, despite allegations to the contrary, be dismissed where the unambiguous language of documents upon which the claims are based contradict[s] the complaint's allegations."

Beam ex rel. Martha Stewart Living Omnimedia, Inc. v. Stewart, 833 A.2d 961, 976 (Del. Ch. 2003), aff'd, 845 A.2d 1040 (Del. 2004).

Reiter ex rel. Capital One Fin. Corp. v. Fairbank, 2016 WL 6081823, at *5 (Del. Ch. Oct. 18, 2016); see also Amalgamated Bank v. Yahoo! Inc., 132 A.3d 752, 797 (Del. Ch. 2016) ("The incorporation-by-reference doctrine permits a court to review the actual document to ensure that the plaintiff has not misrepresented its contents and that any inference the plaintiff seeks to have drawn is a reasonable one. The doctrine limits the ability of the plaintiff to take language out of context, because the defendants can point the court to the entire document." (footnote omitted)).

Yahoo! Inc., 132 A.3d at 797 (quoting H-M Wexford LLC v. Encorp, Inc., 832 A.2d 129, 139 (Del. Ch. 2003)). For the first time in supplemental briefing, the Plaintiffs argue that the Court cannot consider documents attached to the Defendants' Motion to Dismiss. The Plaintiffs did not raise this argument in their opposition brief or at oral argument, and it is therefore waived. See Coughlan v. NXP B.V., 2011 WL 5299491, at *12 n.86 (Del. Ch. Nov. 4, 2011) (holding that, to the extent the plaintiff was attempting to assert a new argument in her post-oral argument supplemental brief, it was "unquestionably waived at this late stage"). The Plaintiffs now say that they did not waive this argument, but their opposition brief did not argue that it would be improper for the Court to consider the documents appended to the Defendants' Motion. Instead, the Plaintiffs challenged the inferences the Defendants drew from those documents. See Pls.' Answering Br. 56 ("Defendants now try to contort the meaning of the heavily redacted internal Company documents and ask this Court to make inferences in their favor. Defendants are not entitled to such inferences on a motion to dismiss."). In any event, in accordance with settled Delaware precedent on the incorporation-by-reference doctrine, I consider only those documents that the Complaint specifically quotes or references. See, e.g., Winshall v. Viacom Int'l, Inc., 76 A.3d 808, 818 (Del. 2013) ("[A] plaintiff may not reference certain documents outside the complaint and at the same time prevent the court from considering those documents' actual terms." (alteration in original) (quoting Fletcher Int'l, Ltd. v. ION Geophysical Corp., 2011 WL 1167088, at *3 n.17 (Del. Ch. Mar. 29, 2011))); see also Donald J. Wolfe, Jr. & Michael A. Pittenger, Corporate and Commercial Practice in the Delaware Court of Chancery § 4.06[b][2][i] (2016) ("If a plaintiff chooses to refer to a document in its complaint, the Court may consider the entire document, even those portions not specifically referenced in the complaint.").

The Plaintiffs in this case allege that the Defendants breached their fiduciary duties by consciously failing to exercise appropriate oversight over Citigroup. That failure, the Plaintiffs suggest, caused the four corporate traumas detailed above. Because the Plaintiffs allege that the Defendants violated their oversight duties, I must analyze demand futility under the Rales v. Blasband test. Under Rales, a court faced with allegations of director inaction must "examine whether the board that would be addressing the demand can impartially consider its merits without being influenced by improper considerations." More specifically, a court must decide whether the plaintiff has alleged particularized facts "creat[ing] a reasonable doubt that, as of the time the complaint is filed, the board of directors could have properly exercised its independent and disinterested business judgment in responding to a demand." A plaintiff may create such reasonable doubt by alleging particularized facts that "reveal board inaction of a nature that would expose [at least half of the directors] to 'a substantial likelihood' of personal liability." Thus, "[d]emand is not excused solely because the directors would be deciding to sue themselves," unless such a decision makes liability of at least half of the directors substantially likely.

Compl. ¶ 58.

634 A.2d 927 (Del. 1993).

See, e.g., Good, 2017 WL 6397490, at *5 ("For alleged violations of the board's oversight duties under Caremark, the test articulated in Rales v. Blasband applies to assess demand futility.").

Rales, 634 A.2d at 934.

Id.

Horman v. Abney, 2017 WL 242571, at *6 (Del. Ch. Jan. 19, 2017) (quoting Rales, 634 A.2d at 936).

In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d 106, 121 (Del. Ch. 2009)

Below, I examine alleged bad faith on the part of the directors with respect to inaction in light of corporate non-compliance with positive law. Some of the purported red flags date back more than a decade. In determining whether demand is futile, "it is important to remember that demand is made against the board of directors at the time of filing of the complaint," here, March 30, 2016. Thus, "whether demand is excused is typically analyzed with respect to the directors seated as of the date that the complaint was filed." And the Court usually conducts this analysis on a "director-by-director" basis. Here, because the Complaint's allegations fail to support a reasonable inference of bad faith on the part of the Citigroup board with respect to any particular failure to act, I need not undertake an analysis, with respect to any such alleged breach, of whether at least half of the directors seated on March 30, 2016, face a substantial likelihood of liability for that purported oversight violation.

E.g., Compl. ¶ 250.

In re INFOUSA, Inc. S'holders Litig., 953 A.2d 963, 985 (Del. Ch. 2007).

The composition of the Citigroup board did not change between the filing of the initial Complaint and the filing of the operative pleading in this case.

Park Emps.' & Ret. Bd. Emps.' Annuity & Benefit Fund of Chicago v. Smith, 2016 WL 3223395, at *9 (Del. Ch. May 31, 2016), aff'd, 2017 WL 5663591 (Del. Nov. 27, 2017).

Postorivo v. AG Paintball Holdings, Inc., 2008 WL 553205, at *6 (Del. Ch. Feb. 29, 2008).

A. Demand Is Not Excused as to the Caremark Claim

The Plaintiffs argue that demand is excused because at least half of the Citigroup board as of the filing of the Complaint faces a substantial likelihood of liability under Caremark. "A Caremark claim contends that the directors set in motion or 'allowed a situation to develop and continue which exposed the corporation to enormous legal liability and that in doing so they violated a duty to be active monitors of corporate performance.'" A Caremark claim typically rests on the assertion that the directors of a corporation failed "to properly monitor or oversee employee misconduct or violations of law."

South v. Baker, 62 A.3d 1, 14 (Del. Ch. 2012) (quoting In re Caremark Int'l Inc. Derivative Litig., 698 A.2d at 967).

In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d at 123.

Proof of such a claim is difficult. In Stone v. Ritter, our Supreme Court held that Caremark liability lies where "(a) the directors utterly failed to implement any reporting or information system or controls; or (b) having implemented such a system or controls, consciously failed to monitor or oversee its operations thus disabling themselves from being informed of risks or problems requiring their attention." Stone also made clear that "Caremark claims are breaches of the duty of loyalty, as opposed to care, preconditioned on a finding of bad faith." Thus, "imposition of liability requires a showing that the directors knew that they were not discharging their fiduciary obligations. Where directors fail to act in the face of a known duty to act, thereby demonstrating a conscious disregard for their responsibilities, they breach their duty of loyalty by failing to discharge that fiduciary obligation in good faith." Put differently, to state a Caremark claim, a plaintiff must allege facts "that allow a reasonable inference that the directors acted with scienter which, in turn, 'requires [not only] proof that a director acted inconsistently with his fiduciary duties,' but also 'most importantly, that the director knew he was so acting.'" As the Court in Stone stressed, "directors' good faith exercise of oversight responsibility may not invariably prevent employees from violating criminal laws, or from causing the corporation to incur significant financial liability, or both."

911 A.2d 362, 370 (Del. 2006).

Rich ex rel. Fuqi Int'l, Inc. v. Yu Kwai Chong, 66 A.3d 963, 981 (Del. Ch. 2013); accord Good, 2017 WL 6397490, at *5 ("[A] Caremark claim 'is rooted in concepts of bad faith; indeed, a showing of bad faith is a necessary condition to director oversight liability.'" (quoting In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d at 123)).

Stone, 911 A.2d at 370 (footnotes omitted).

Horman, 2017 WL 242571, at *7 (alteration in original) (quoting In re Massey Energy Co., 2011 WL 2176479, at *22 (Del Ch. May 31, 2011)).

Stone, 911 A.2d at 373.

The Plaintiffs do not argue that the Defendants are liable for "an utter failure to attempt to assure a reasonable information and reporting system exist[ed]" at Citigroup. Instead, they contend that the Defendants knew of red flags pointing to corporate misconduct and consciously chose to ignore them. "[A] plaintiff asserting a Caremark oversight claim must plead with particularity 'a sufficient connection between the corporate trauma and the board.'" One way to establish such a connection is to allege facts suggesting that "the board knew of evidence of corporate misconduct—the proverbial 'red flag'—yet acted in bad faith by consciously disregarding its duty to address that misconduct." For example, a claim that directors "had notice of serious misconduct," yet, so knowing, "failed to investigate[,] . . . would survive a motion to dismiss, even if the . . . board was well constituted and was otherwise functioning." Nevertheless, the corporate trauma in question "must be sufficiently similar to the misconduct implied by the 'red flags' such that the board's bad faith, 'conscious inaction' proximately caused that trauma."

In re Caremark Int'l Inc. Derivative Litig., 698 A.2d at 971.

See Pls.' Answering Br. 3 (arguing that "a legion of specific allegations demonstrat[e] that Defendants knew of red flags and yet consciously failed to take action in good faith to remedy the internal control deficiencies").

Fairbank, 2016 WL 6081823, at *8 (quoting La. Mun. Police Emps.' Ret. Sys. v. Pyott, 46 A.3d 313, 340 (Del. Ch. 2012), rev'd on other grounds, 74 A.3d 612 (Del. 2013)).

Id.

David B. Shaev Profit Sharing Account v. Armstrong, 2006 WL 391931, at *5 (Del. Ch. Feb. 13, 2006).

Melbourne Mun. Firefighters' Pension Trust Fund v. Jacobs, 2016 WL 4076369, at *8 (Del. Ch. Aug. 1, 2016) (footnote omitted), aff'd, 158 A.3d 449 (Del. 2017); see also, e.g., In re Dow Chem. Co. Derivative Litig., 2010 WL 66769, at *13 (Del. Ch. Jan. 11, 2010) ("Plaintiffs argue that because bribery may have occurred in the past (Dow paid a fine to the SEC in January 2007), by different members of management, in a different country (India), and for a different transaction (pesticide registrations), the board should have suspected similar conduct by different members of management, in a different country, in an unrelated transaction. This argument is simply too attenuated to support a Caremark claim." (footnote omitted)).

1. Demand Is Not Excused as to the Anti-Money Laundering Law Compliance Issues

The Plaintiffs argue that the Citigroup board was aware of several red flags pointing to BSA/AML compliance issues at Citigroup subsidiaries. The Plaintiffs focus on a regulatory order and a series of consent orders that Citigroup and Citibank entered into with various government agencies. First, in July 2010, the OCC issued Citibank a Part 30 order directing it to improve its AML compliance in various business segments. Then, on April 5, 2012, the OCC issued a consent order against Citibank, citing its failure to make the improvements outlined in the Part 30 order. The consent order criticized Citibank's AML controls, and it ordered Citibank to develop a "BSA/AML Action Plan." Several months later, on August 2, 2012, BUSA entered into a consent order with the FDIC and the CDFI. This consent order "required BUSA's Board of Directors to 'increase its oversight of the affairs of the Bank [and] assume full responsibility for . . . the oversight of all of the Bank's activities.'" A third consent order was issued on March 21, 2013, and it stated that "Citigroup lacked effective systems of governance and internal controls to adequately oversee the activities of [Citibank and BUSA]."

Compl. ¶ 143.

Id. ¶ 144.

Id. ¶¶ 144, 146.

Id. ¶ 151.

Id. ¶ 152 (alterations in original).

Id. ¶ 159 (emphasis omitted).

The red flags did not stop with the regulatory order and the three consent orders, however. After the April 2012 consent order was issued, the Citigroup board received a steady drumbeat of warnings about continuing AML compliance issues. In July 2012, for instance, IA informed the Compliance Committee that there was "[i]nadequate AML control, governance, and oversight" at Banamex and BUSA. The warnings continued after the entry of the August 2012 consent order. In September and October 2012, IA revealed that "BUSA's control environment remained 'unsatisfactory.'" And, several months later, the AML control environment "retained a 'limited assurance' rating, while the 'overall effectiveness of controls over affiliate transactions' at BUSA received an 'insufficient assurance' rating." The drumbeat continued after the third consent order was issued. As the Complaint points out, "[b]etween February 2013 and April 2015, IA issued 22 reports noting that BUSA was suffering from 'Insufficient Assurance' in its AML control environment."

Id. ¶ 150 (alteration in original) (emphasis omitted).

Id. ¶¶ 155-56.

Id. ¶ 158.

Id. ¶ 346 (emphasis omitted).

The Plaintiffs contend that despite receiving both internal and external warnings about serious AML compliance issues, the Citigroup board (in the Plaintiffs' memorable phrase) "sat like stones growing moss." Then, "after a full six years of inaction following the Part 30 Order, regulators were compelled to impose a $140 million fine on Citigroup." There is compelling evidence that the board was aware that Citigroup had serious problems with AML compliance. If the Complaint adequately alleged that the Citigroup board consciously did nothing in response to the red flags just described, and thereby acted consonant with the geologic metaphor just quoted, in my view that would state a Caremark claim. And, as I said above, the Complaint standing alone does give the impression of a board that sat on its hands in the face of clear warnings about potentially unlawful conduct. But the documents incorporated by reference in the Complaint make clear that the Plaintiffs' narrative is unsupported by the materials on which they relied in drafting their pleading. Those documents reveal that, far from doing nothing in response to red flags, the Citigroup board and its various committees oversaw significant efforts to comply with the consent orders and ensure that adequate AML controls were implemented.

Id. ¶ 9.

Id. ¶ 170 (emphasis omitted).

See Desimone v. Barrows, 924 A.2d 908, 940 (Del. Ch. 2007) ("[I]n order to state a viable Caremark claim, and to predicate a substantial likelihood of director liability on it, a plaintiff must plead the existence of facts suggesting that the board knew that internal controls were inadequate, that the inadequacies could leave room for illegal or materially harmful behavior, and that the board chose to do nothing about the control deficiencies that it knew existed.").

See Good, 2017 WL 6397490, at *6 (stating that a court is not "required to accept on a motion to dismiss" a plaintiff's "unfair[]" description of a board presentation cited in the complaint).

It is true that the first consent order came almost two years after the Part 30 order, and that the consent order resulted from "[t]he failure to obey the Part 30 Order." But, while the Complaint implies that no action was taken between the Part 30 order and the first consent order, the documents incorporated by reference tell a different story. For example, at an April 17, 2012 board meeting, directors learned that "28 of the 35 [Part 30] milestones were completed during 1Q 2012." While Citibank ultimately fell short in complying with the Part 30 order, that failure, of itself, does not suggest bad faith. Indeed, the fact that the majority of the Part 30 milestones were met suggests that a substantial effort was made to abide by the order's terms. As this Court has noted, "[s]imply alleging that a board incorrectly exercised its business judgment and made a 'wrong' decision in response to red flags . . . is insufficient to plead bad faith."

Compl. ¶ 144.

Leavengood Aff. Ex. 3 at 11.

Jacobs, 2016 WL 4076369, at *9.

Citigroup continued to make an effort to address the AML control environment following entry of the April 2012 consent order. For example, on April 17, 2012, the Citigroup board learned that "the Compliance Committees [had] received a presentation from the AML Monitoring Team, including efforts to improve the quality and integrity of the data feeding . . . Citibank's AML monitoring platforms." The board was also told that "the Compliance Committees directed [IA] to provide a country-by-country AML assessment." Again, these efforts apparently proved unavailing, for in August 2012, another consent order was issued. But I cannot infer bad faith from that. The question is whether "the board chose to do nothing about the control deficiencies that it knew existed." That is simply not an accurate description of what the Citigroup board did. Moreover, there are no allegations from which I may infer that the reports of progress the board received were a sham, let alone that the directors so considered them. In any event, as the documents incorporated in the Complaint reveal, something was indeed done about the ongoing AML issues highlighted by the first consent order.

Leavengood Aff. Ex. 3 at 12.

Id.

Desimone, 924 A.2d at 940 (emphasis added).

The second consent order prompted more action from Citigroup. The Citigroup board met on December 12, 2012, and at that meeting, the directors were informed of "proactive efforts concerning AML issues, [and] that management's current areas of focus include the Consumer North America high risk account re-remediation; expired customer due diligence documentation; migration programs in Mexico; . . . and broader structural issues." And the directors learned of "continued progress on OCC commitments and business priorities, including creating and implementing a global governance structure and framework and short-term tactical project execution." These are not the minutes of a board that learned of red flags suggesting corporate misconduct and chose to do nothing about them. Instead, they reflect that steps were taken to improve the systems and controls related to AML compliance. Those efforts were not ultimately successful, and another consent order was issued in March 2013. But, to repeat, it is not enough to say that the board's response was ineffective. "Plaintiffs here simply seek to second-guess the . . . manner of the board's response to the red flags, which fails to state a Caremark claim."

Leavengood Aff. Ex. 4 at 7.

Id.

See Horman, 2017 WL 242571, at *14 ("The relevant inquiries under the second prong of Caremark are whether the Board was made aware of red flags and then whether the Board responded to address them. The documents incorporated by reference into Plaintiffs' Complaint demonstrate that when red flags were waved in front of the Audit Committee, the Board responded.").

In re Qualcomm Inc. FCPA S'holder Derivative Litig., 2017 WL 2608723, at *4 (Del. Ch. June 16, 2017).

A little over two years passed between the entry of the third consent order and the $140 million fine from the FDIC and the CDBO. Those agencies imposed the fine because of continued violations of BSA/AML laws at BUSA. The Plaintiffs argue that during this approximately two-year period, "the Board failed to act in the face of" the red flags outlined above. Bad faith could be imputed to a board that simply "failed to act" for over two years after the entry of a third consent order related to AML compliance issues. But the Plaintiffs' pleading, which includes the documents it incorporates by reference, paints a different picture.

Compl. ¶¶ 164-65.

Pls.' Answering Br. 44 (emphasis added).

The Citigroup board responded promptly to the third consent order. One month after its entry, the board learned that "management was preparing an action plan [in response to the FRB consent order] and will meet with the FRB's staff to better understand its expectations." And in September 2013, directors from Citigroup, Citibank, and Citicorp learned that outside counsel had undertaken a review of BUSA's operations and that several employees had been fired in furtherance of compliance efforts. At the same meeting, several directors posed "questions to management about BUSA, including personnel changes and prior regulatory reviews." And at the end of 2013, the Citigroup board was told that the Citigroup and Citibank Compliance Committees were "focus[ed] on whether management is embracing AML controls." About one year later, Citigroup had achieved progress in improving AML controls. Specifically, the board learned in January 2015 that, while the "aggregate risk rating for AML [wa]s High," "the aggregate risk trend [wa]s decreasing due to de-risking of certain high-risk client types, businesses, and geographies, in combination with ongoing improvements to the control environment."

Leavengood Aff. Ex. 6 at 19.

Leavengood Aff. Ex. 13 at 8.

Id.

Leavengood Aff. Ex. 14 at 16.

Leavengood Aff. Ex. 11 at 5.

Again, these measures did not secure the compliance sought by the regulators, and Citigroup ended up paying a hefty fine as a result. And it may be the case that, as the Plaintiffs put it, "Citigroup's Board failed . . . to adopt effective internal controls addressing the gaps in its compliance systems." But the question is not whether Citigroup's board adopted effective AML controls. As our Supreme Court has recognized, "directors' good faith exercise of oversight responsibility may not invariably prevent employees from violating criminal laws, or from causing the corporation to incur significant financial liability, or both." That is one reason why a Caremark claim requires a showing of "intentional dereliction of duty, [or] a conscious disregard for one's responsibilities," a standard that entails a greater degree of culpability than "simple inattention or failure to be informed of all facts material to the decision." At issue is the duty of loyalty; a board's efforts can be ineffective, its actions obtuse, its results harmful to the corporate weal, without implicating bad faith. Bad faith may be inferred where the directors knew or should have known that illegal conduct was taking place, yet "took no steps in a good faith effort to prevent or remedy that situation." Here, the facts the Plaintiffs have alleged imply that the Citigroup board could have done a better job addressing the issues highlighted by, among other sources, the consent orders. That is not enough to state a Caremark claim. Thus, the allegations relating to the AML compliance issues and the board's response to them do not raise a reasonable doubt that at least half of the Citigroup board as it existed when the Complaint was filed faces a substantial likelihood of personal liability for purported oversight failures. Demand is not excused as to these allegations.

Pls.' Answering Br. 10.

Stone, 911 A.2d at 373.

In re Walt Disney Co. Derivative Litig., 906 A.2d 27, 66 (Del. 2006) (emphasis added).

In re Caremark Int'l Inc. Derivative Litig., 698 A.2d at 971 (emphasis added).

See, e.g., Horman, 2017 WL 242571, at *14 ("Plaintiffs have not pled particularized facts that would allow the Court reasonably to infer that the Director Defendants face a substantial likelihood of liability based on having ignored red flags in a manner that demonstrates a conscious failure to monitor or oversee corporate operations. Demand on the Board cannot be excused as futile on the basis that the Board consciously ignored red flags.").

2. Demand Is Not Excused as to the Accounts Receivable Fraud Allegations

The Plaintiffs seek to hold the Defendants personally liable for losses Banamex suffered as a result of an accounts receivable fraud it fell victim to. According to the Plaintiffs, the Citigroup board knew for years of red flags related to problems in Banamex's "controls for detecting and preventing fraud." Despite receiving clear warnings about these control deficiencies, the Citigroup board "failed to take good faith action to implement controls to detect and prevent fraud." That failure caused Banamex to become the victim of a $400 million fraud by OSA, a Mexican oil services company. In the scheme, OSA took out loans from Banamex that were secured by fraudulent accounts receivable. The fraud led to an investigation by Mexico's banking regulator, which ultimately fined Banamex $2.5 million for "ineffective controls."

Pls.' Answering Br. 46.

Id. at 47.

Compl. ¶ 206.

Id. ¶ 173.

Before turning to the purported red flags related to the accounts receivable fraud, I pause to note the unusual nature of the Caremark claim that the Plaintiffs attempt to assert here. The primary injury for which the Plaintiffs seek to hold the Defendants personally liable is Banamex's loss of $400 million in a fraud that it fell victim to. The illegal conduct that caused this loss was committed largely by third parties, not by anyone at Banamex. That is unlike the typical Caremark claim, in which "plaintiffs argue that the defendants are liable for damages that arise from a failure to properly monitor or oversee employee misconduct or violations of law." In other words, Caremark claims involve a knowing failure to prevent or remedy illegality within the corporation. The Plaintiffs' theory appears to be that the Defendants' oversight failures caused Banamex to engage in a business venture that generated large losses because of fraud by the party on the other side. Put differently, Banamex made a risky business decision that turned out poorly for the company. That suggests a failure to monitor or properly limit business risk, a theory of director liability that this Court has never definitively accepted. Indeed, evaluation of risk is a core function of the exercise of business judgment.

In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d at 123 (emphasis added); see also In re Caremark Int'l Inc. Derivative Litig., 698 A.2d at 971 ("Generally where a claim of directorial liability for corporate loss is predicated upon ignorance of liability creating activities within the corporation . . . , in my opinion only a sustained or systematic failure of the board to exercise oversight—such as an utter failure to attempt to assure a reasonable information and reporting system exists—will establish the lack of good faith that is a necessary condition to liability." (emphasis added)).

See Guttman v. Huang, 823 A.2d 492, 506 (Del. Ch. 2003) (describing Caremark as addressing directors' oversight of "their corporations' compliance with legal standards" (emphasis added)).

See Asbestos Workers Local 42 Pension Fund v. Bammann, 2015 WL 2455469, at *14 (Del. Ch. May 22, 2015) ("It is not entirely clear under what circumstances a stockholder derivative plaintiff can prevail against the directors on a theory of oversight liability for failure to monitor business risk under Delaware law; the Plaintiff cites no examples where such an action has successfully been maintained."); In re Goldman Sachs Grp., Inc. S'holder Litig., 2011 WL 4826104, at *21 (Del. Ch. Oct. 12, 2011) ("As a preliminary matter, this Court has not definitively stated whether a board's Caremark duties include a duty to monitor business risk."); see also In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d at 131 ("There are significant differences between failing to oversee employee fraudulent or criminal conduct and failing to recognize the extent of a Company's business risk. Directors should, indeed must under Delaware law, ensure that reasonable information and reporting systems exist that would put them on notice of fraudulent or criminal conduct within the company. Such oversight programs allow directors to intervene and prevent frauds or other wrongdoing that could expose the company to risk of loss as a result of such conduct."); In re Lear Corp. S'holder Litig., 967 A.2d 640, 653 (Del. Ch. 2008) (describing the Caremark line of cases as "deal[ing] in large measure with what is arguably the hardest question in corporation law: what is the standard of liability to apply to independent directors with no motive to injure the corporation when they are accused of indolence in monitoring the corporation's compliance with its legal responsibilities?" (emphasis added)).

See In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d at 126 (noting that the obligation to "implement and monitor a system of oversight . . . does not eviscerate the core protections of the business judgment rule—protections designed to allow corporate managers and directors to pursue risky transactions without the specter of being held personally liable if those decisions turn out poorly").

On the other hand, the Plaintiffs do point to the $2.5 million fine handed down by Mexico's banking regulator "based on ineffective controls at Banamex." Specifically, this regulator found that "the [OSA] fraud resulted from weaknesses in Banamex's internal controls, errors in its loan origination and administration procedures, and deficiencies relating to risk administration and internal audits." If the Plaintiffs are seeking to recover the $2.5 million Banamex was fined as a result of these violations, they are pursuing a more traditional Caremark claim, one that involves a failure to prevent illegal conduct within the corporation. But the Complaint contains scant allegations about the Mexican laws or regulations that Banamex violated while it was being defrauded. Indeed, the Plaintiffs do not cite any Mexican law or regulation Banamex failed to comply with while it was falling victim to OSA's scheme. Instead, they simply allege that the fine was imposed because Banamex had ineffective controls. Moreover, the Complaint does not suggest that the Citigroup board ever had any inkling that Banamex could run afoul of Mexican laws or regulations governing the steps companies operating in Mexico must take in order to ensure that they do not become victims of fraud.

Compl. ¶ 173.

Id. ¶ 217.

Id. ¶¶ 173, 217.

Mexico's banking regulator imposed an additional fine on Banamex in May 2015 after it determined that Banamex had failed to comply with the corrective action plan issued in the wake of the accounts receivable fraud. Id. ¶ 218. The Complaint does not say whether any of the Defendants knew that Banamex was subject to the corrective action plan.

These problems aside, the allegations relating to the accounts receivable fraud fail to state a Caremark claim for an independent reason: the lack of red flags to put the Defendants on notice of what eventually happened. Moreover, any incidents that arguably served as red flags were met with responses that clearly fulfilled the Citigroup directors' obligation to act in good faith. The Plaintiffs primarily point to two types of alleged red flags related to the OSA fraud: fraud-related incidents that took place before the OSA fraud, and problems with Banamex's technology systems, segregation of duties, and maker/checker controls.

Another red flag, according to the Plaintiffs, was the Citigroup board's awareness that "Mexico businesses operated within a culture that largely viewed informal compliance (such as trust and prestige) as sufficient." Pls.' Answering Br. 46. That does not constitute a red flag, however, because there is nothing "illegal or wrongful per se" about doing business in Mexico, and "[l]egal, if risky, actions that are within management's discretion to pursue are not 'red flags' that would put a board on notice of unlawful conduct." In re Goldman Sachs Grp., Inc. S'holder Litig., 2011 WL 4826104, at *20.

The first set of purported red flags involves a series of fraud-related incidents that occurred primarily at Banamex over a period of several years. One incident involved "a Citigroup Treasury Finance employee fraudulently transferr[ing] $25 million to his own personal bank account." In a separate incident, "five Banamex employees . . . accepted at least 16 million Mexico pesos . . . in kickbacks as part of [a] scheme" with several Banamex vendors. Another fraud affecting Banamex involved a bond trader who hid trading losses by delaying loss recognition and manipulating trades, and in a separate scheme, dozens of Banamex employees sold confidential credit card customer information. It later emerged that a Banamex security unit was "recording phone calls without authorization; fraudulently misreporting gas expenses in order to increase the reimbursements [members of the unit] received from Banamex; developing shell companies to launder proceeds; and receiving kickbacks from vendors who overcharged Banamex." The Plaintiffs also point to fraud committed by an operations manager at Accival, Banamex's brokerage unit; this employee "fraudulently transferred funds from an Accival account to a private customer account using foreign exchange . . . transactions." Finally, the Complaint discusses the Mexican homebuilders fraud, in which Banamex developed a revolving credit facility for homebuilders. The homebuilders put up their properties as collateral, and when they sold the homes they built, they were supposed to pay off the loans with the sale proceeds. Many of them failed to do so, however, and some "overstated the value of the collateral against which Banamex made its loans."

Compl. ¶ 182.

Id. ¶ 183.

Id. ¶¶ 184-85.

Id. ¶ 186.

Id. ¶ 187.

Id. ¶ 191.

Id.

Id. ¶ 193.

Even assuming that these fraud-related incidents were brought to the attention of the Defendants before the OSA fraud, they could not have served as red flags. As discussed above, a corporate trauma "must be sufficiently similar to the misconduct implied by the 'red flags' such that the board's bad faith, 'conscious inaction' proximately caused that trauma." The corporate trauma here involved a particular kind of fraud: phony accounts receivable submitted by a large borrower. None of the incidents just recounted bear a material resemblance to the accounts receivable fraud. For example, there is no meaningful connection between the embezzlement committed by the Citigroup Treasury Finance employee and the OSA fraud. The same goes for the kickbacks received by Banamex employees, the concealment of losses by the Banamex bond trader, and the nefarious activities of the Banamex security unit. These incidents were simply too far removed from the OSA fraud to have served as red flags for that corporate trauma.

Jacobs, 2016 WL 4076369, at *8 (footnote omitted).

See South, 62 A.3d at 17 ("Although the complaint asserts that the directors knew of and ignored the 2011 safety incidents, the complaint nowhere alleges anything that the directors were told about the incidents, what the Board's response was, or even that the incidents were connected in any way." (emphasis added)); In re Dow Chem. Co. Derivative Litig., 2010 WL 66769, at *13 ("Plaintiffs argue that because bribery may have occurred in the past (Dow paid a fine to the SEC in January 2007), by different members of management, in a different country (India), and for a different transaction (pesticide registrations), the board should have suspected similar conduct by different members of management, in a different country, in an unrelated transaction. This argument is simply too attenuated to support a Caremark claim." (footnote omitted)).

The homebuilders fraud is similarly remote from the corporate trauma at issue. Part of the fraud involved homebuilders overstating the value of the properties they used as collateral for the loans they received from Banamex. Like the homebuilders fraud, the OSA fraud involved misrepresentations about collateral. But the collateral at issue was different in the two frauds: accounts receivable in the OSA scheme, properties in the homebuilders scheme. The Plaintiffs have not explained how the processes for verifying one type of collateral resemble the methods used to detect fraud in the other type of collateral. Thus, I doubt that the homebuilders fraud could have served as a red flag for the accounts receivable fraud. And even if the homebuilders fraud could have provided the requisite notice, the Citigroup board took action in response to the issues it highlighted. Soon after the fraud came to light, the Citigroup board learned that management would perform "a global, end-to-end assessment of Citi's management effectiveness with respect to secured lending and collateral management, as well as a review of Banamex's overall collateral framework." That is sufficient to show that, following the homebuilders fraud, the board did not decide "to do nothing about the control deficiencies that it knew existed."

See In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d at 129 ("[T]he use of [structured investment vehicles ("SIVs")] in the Enron related conduct would not serve to put the director defendants on any type of heightened notice to the unrelated use of SIVs in structuring transactions involving subprime securities.").

Leavengood Aff. Ex. 13 at 5.

Desimone, 924 A.2d at 940.

The second set of purported red flags involves defects in Banamex's technology systems, the failure to properly segregate duties, and inadequate maker/checker controls. As the Plaintiffs admit, however, Citigroup management attempted to address the latter two issues via "'Project Andes,' which was purportedly to focus on the effective segregation of duties and to eliminate weaknesses in dual controls and the maker/checker process." The Plaintiffs criticize Project Andes for "focus[ing] solely on corporate clients and Citibank cash accounts" and not addressing Citibank branches. But, as I stated above, a plaintiff cannot plead bad faith "[s]imply [by] alleging that a board incorrectly exercised its business judgment and made a 'wrong' decision in response to red flags." As for the allegations about problems with Banamex's technology systems, the Plaintiffs fail to explain how those issues allowed the OSA fraud to occur. Indeed, Mexico's banking regulator attributed the fraud to "weaknesses in Banamex's internal controls, errors in its loan origination and administration procedures, and deficiencies relating to risk administration and internal audits." It did not identify any technological issues as contributing to the accounts receivable fraud. Thus, these issues could not have served as red flags for the Defendants. Because the Plaintiffs have failed to adequately allege that the Citigroup board faces a substantial likelihood of liability as to the OSA fraud allegations, demand is not excused as to those allegations.

Compl. ¶ 176.

Id.

Jacobs, 2016 WL 4076369, at *9.

Compl. ¶ 217.

3. Demand Is Not Excused as to the Foreign Exchange Rate Manipulation Allegations

The Plaintiffs also seek to hold the Defendants personally liable for alleged oversight failures related to FX rate manipulation by Citigroup traders over a period of about six years. From at least 2007 to at least 2013, Citigroup FX traders, working with traders at other firms, manipulated FX benchmark rates, set off customer stop loss orders, and shared confidential client information. As a result, Citigroup paid $2.2 billion in fines, and Citicorp pleaded guilty to conspiracy to violate federal antitrust laws. These allegations fail to state a Caremark claim.

Id. ¶ 226.

Id. ¶¶ 222, 233.

First, the purported red flags the Plaintiffs point to either were not red flags at all or were met with good-faith responses from Citigroup. The Plaintiffs point out that in 2009, the Audit and Risk Management Committee was told that "the current 'market turbulence increases operational risk significantly.'" The Complaint fails to mention that this line appears in a report that does not specifically discuss FX-related misconduct. Instead, the report discusses, among other things, the Madoff fraud, "mark manipulation, issuer/borrower fraud, [and] embezzlement." Two years later, it emerged that "a trader in [Citi's] FX business outside London had inappropriately shared confidential client information in a chat room with a trader at another firm." This incident bears some resemblance to the corporate trauma at issue, which involved the sharing of confidential client information. But Citigroup took action in response to this misconduct: the trader was terminated, and employees received reminders "about the need to maintain client confidentiality." Two years after this incident, the Audit Committee learned that "FX transaction execution maker/checker controls and post transaction reviews require improvement." Even if this were a red flag of FX-related issues at Citigroup, the company set out to address the issues it highlighted by providing "[c]lear definition of FX execution mandates in terms of transaction size, products, tenors, currencies, and approvals." These efforts did not prevent the corporate trauma in question from taking place. And one might legitimately criticize the adequacy of the board's response to FX-related issues. But I cannot infer that "the defendants consciously allowed [Citigroup] to violate the law so as to sustain a finding they acted in bad faith."

Id. ¶ 247 (emphasis omitted).

Leavengood Aff. Ex. 16 at CITI018447.

Id.

Compl. ¶ 248.

Leavengood Aff. Ex. 15 at 15.

Compl. ¶ 249.

Leavengood Aff. Ex. 17 at CITI024853.

Reiter, 2016 WL 6081823, at *14.

The second problem with the Plaintiffs' purported red flags is that some of them were not waved in front of the Defendants. For example, the Plaintiffs allege that in 2001, Citigroup helped draft the industry standards for good practices among FX traders. Those standards decried "[m]anipulative practices by banks with each other or with clients." Even given the dubious proposition that the drafters of such standards were aware that Citigroup's controls in these areas were deficient, the Plaintiffs do not allege that any of the Defendants played a role in developing (or even knew about) these standards, which were drafted years before the misconduct at issue began. Similarly, the Plaintiffs argue that "the Board allowed the FX-related misconduct to occur in the midst of the LIBOR rate-fixing scandals," and they stress that Citigroup was itself investigated for LIBOR rate-fixing when the misconduct at issue was taking place. But, even assuming that LIBOR-related infractions in the industry implicated inadequate FX controls at Citigroup, the Complaint does not say whether these issues were brought to the Defendants' attention. That prevents them from serving as red flags. Thus, because the allegations relating to FX benchmark rate manipulation fail to create a reasonable doubt that the Citigroup board faces a substantial likelihood of liability, demand is not excused as to those allegations.

Compl. ¶ 250.

Id. (emphasis omitted).

Id. ¶ 323.

See In re Citigroup Inc. S'holders Litig., 2003 WL 21384599, at *2 (Del. Ch. June 5, 2003) ("There is nothing in the Amended Complaint to suggest or to permit the court to infer that any of these [purported red flags] ever came to the attention of the board of directors or any committee of the board. How, exactly, a member of the Citigroup board of directors was supposed to be put on inquiry notice by something he or she never saw or heard of is not explained. The answer to the question is obvious. 'Red flags' are only useful when they are either waived in one's face or displayed so that they are visible to the careful observer.").

To the extent that the Plaintiffs rely on regulators' findings about inadequate FX-related controls at Citigroup, those findings alone fail to demonstrate bad faith. See, e.g., Desimone, 924 A.2d at 940 ("Delaware courts routinely reject the conclusory allegation that because illegal behavior occurred, internal controls must have been deficient, and the board must have known so."); see also In re Qualcomm Inc. FCPA S'holder Derivative Litig., 2017 WL 2608723, at *4 ("Plaintiffs also argue that the FCPA establishes a statutory floor for adequate internal controls, and because the Qualcomm cease-and-desist order describes internal control violations of the FCPA, the Complaint necessarily states a claim. But that argument is misplaced here. A corporation's violation of the FCPA alone is not enough for director liability under Caremark." (footnote omitted)). And while the CFTC and the FCA found that Citibank knew of LIBOR-related issues at other firms, that does not suggest the Citigroup board knew of similar issues at Citigroup or its subsidiaries.

4. Demand Is Not Excused as to the Unlawful Credit Card Practices Allegations

The final corporate trauma for which the Plaintiffs seek recovery from the Defendants involves deceptive credit card practices engaged in by several Citigroup subsidiaries for over a decade. These subsidiaries misled consumers into buying "add-on products (i) relating to services that they did not receive, (ii) for which they did not give their informed and affirmative enrollment consent, (iii) that they did not know they could refuse, and/or (iv) that were not in their best financial interest." On July 20, 2015, the CFPB and the OCC fined Citibank $35 million, and the CFPB ordered it to pay $700 million in restitution to consumers who fell victim to the unlawful practices. The Plaintiffs' allegations about this corporate trauma fail to state a Caremark claim for several reasons.

Compl. ¶ 254.

Id. ¶¶ 253, 270.

At the outset, one of the Plaintiffs' purported red flags involves conduct that did not even take place at Citigroup or any of its subsidiaries. According to the Complaint, the Citigroup and Citibank Audit Committees were told in 2012 that "the CFPB and FDIC were taking action against competitors Discovery and American Express, requiring hundreds of millions of dollars in restitution and penalties relating to the sales of add-on products." But directors' failure to act in the face of warnings about misconduct at other businesses does not imply bad faith with respect to the entity to which the directors owe fiduciary duties.

Id. ¶ 266.

Cf. In re Dow Chem. Co. Derivative Litig., 2010 WL 66769, at *13 ("Plaintiffs argue that because bribery may have occurred in the past (Dow paid a fine to the SEC in January 2007), by different members of management, in a different country (India), and for a different transaction (pesticide registrations), the board should have suspected similar conduct by different members of management, in a different country, in an unrelated transaction. This argument is simply too attenuated to support a Caremark claim." (footnote omitted)); In re Citigroup Inc. S'holder Derivative Litig., 964 A.2d at 129 ("Plaintiffs have not shown how involvement with the Enron related scandals should have in any way put the director defendants on a heightened alert to problems in the subprime mortgage market.").

Another red flag allegedly appeared when the Audit Committee was told in July 2011 that control systems related to credit cards needed improvement. But it also learned at the same meeting that "action will be taken through training and systems changes and the corrective action plans would be discussed and agreed with the OCC." Thus, Citigroup dealt with this red flag in a manner that cannot be said to reflect bad faith. The Plaintiffs also point to the West Virginia Attorney General's lawsuit against Citigroup for deceptive practices in the marketing of credit card protection programs, a case that Citigroup settled for $1.95 million in September 2013, two years after the litigation began. However, the Complaint fails to allege that the West Virginia lawsuit was ever brought to the attention of at least half of the directors serving on the Citigroup board when the Complaint was filed. Even if I infer knowledge on the part of the entire board, moreover, board action regarding credit card sales controls was taken contemporaneously, as detailed below.

Compl. ¶ 264.

Leavengood Aff. Ex. 24 at 3.

Compl. ¶ 265.

See In re Citigroup Inc. S'holders Litig., 2003 WL 21384599, at *2 ("'Red flags' are only useful when they are either waived in one's face or displayed so that they are visible to the careful observer."). According to the Plaintiffs, "[t]he lawsuit was reported to the Nomination and Corporate Governance Committee in September 2011," Compl. ¶ 331, but the Complaint does not say who was serving on that committee in September 2011. And there is no merit to the Plaintiffs' suggestion that I can presume the entire Citigroup board learned of something simply because a board committee with reporting obligations had the relevant information. See Horman, 2017 WL 242571, at *13 ("Delaware courts have consistently rejected . . . the inference that directors must have known about a problem because someone was supposed to tell them about it." (alteration in original) (quoting Cottrell ex rel. Wal-Mart Stores, Inc. v. Duke, 829 F.3d 983, 995 (8th Cir. 2016)).

The other red flags alleged in the Complaint were not simply brushed aside; they were met with action by Citigroup. For example, in April 2013, the Citigroup and Citibank Audit Committees were told that the FCA had done an investigation and determined that "add-on Payment Protection Insurance . . . products from U.K. insurance company Card Protection Plan Ltd. . . . , which were sold by a wholly owned subsidiary of Citigroup from 2000 to 2011, were 'fundamentally flawed' and 'missold.'" Yet the Complaint itself says that following the investigation, "Citigroup . . . joined a customer remediation program involving 13 other financial institutions." Later, in October 2013, the Audit Committees were informed of "fifty-four control issues relating to the card services provided for the Macy's accounts[, which were handled by DSNB, the Citigroup subsidiary tasked with distributing credit cards for private account labels]." At the same meeting, however, the Audit Committees also learned that "corrective actions [would] include awareness training and improved controls and procedures," and those "Committees emphasized the seriousness of the findings and commended IA for the vigor of the review and the level of detail." These are not the actions of a board that has decided to do nothing about potential corporate misconduct. Thus, demand is not excused as to the allegations about deceptive credit card practices.

Compl. ¶ 267 (footnote omitted).

Id. ¶ 339.

Id. ¶ 269 (emphasis omitted).

Leavengood Aff. Ex. 28 at 5.

See Guttman, 823 A.2d at 502 (noting that a plaintiff could state a Caremark claim by alleging that "the audit committee had clear notice of serious accounting irregularities and simply chose to ignore them"). The Complaint alleges that "in 2009, the Australia Securities and Investments Commission . . . was engaged in an investigation concerning the sale of credit insurance for credit cards and the conduct of call center employees." Compl. ¶ 333. But only Defendants Corbat and Ricciardi attended the meeting where this information was revealed to the Audit and Risk Management Committees, id. ¶ 333 n.156, and there is no allegation that they relayed this information to the full Citigroup board.

B. The Cases on Which the Plaintiffs Rely Support Dismissal

The Plaintiffs point to several Caremark cases that purportedly support demand futility here. In fact, none of those cases suggests that demand should be excused as to any of the corporate traumas described in the Plaintiffs' Complaint. One of the cases the Plaintiffs rely on is Massey, in which then-Vice Chancellor Strine found that the plaintiffs had likely stated a Caremark claim "center[ed] on the allegation that directors and officers of Massey breached their fiduciary duties by failing to make a good faith effort to ensure that Massey complied with applicable laws designed to protect the safety of miners." The facts in Massey were extreme. The Massey board was "dominated by [Don] Blankenship," Massey's CEO. Blankenship believed that "governmental safety regulators were overly nit-picking when it came to inspecting non-union mines like Massey's," and he "took a combative approach with the key federal agency charged with enforcing United States mining operations' compliance with federal safety regulations." Indeed, the plaintiffs alleged that "Blankenship knowingly flouted applicable miner safety laws, believing he knew better about how to run mines safely than the [Mine Safety and Health Administration], and more blatantly, made the conscious choice to put miners at risk in order to cut cost-corners and up mining profits." "Even after Massey had already pled guilty to criminal charges for willful violations of mining safety laws and falsification of evidence, settled a claim with the Environmental Protection Agency for a record sum, and suffered a punitive damages award for firing a whistleblower," Blankenship continued to publicly voice his view that government regulators could not possibly know more about mine safety than he did.

In re Massey Energy Co., 2011 WL 2176479, at *19.

Id. at *5, *19.

Id. at *5.

Id. at *19 (emphasis added).

Id.

Even though they were aware of "the management culture at Massey[, which] allegedly put profits ahead of safety," the independent directors failed to "make a good faith effort to ensure that Massey complied with its legal obligations." Instead, "the Board allowed itself to continue to be dominated by Blankenship." The Court found that while the independent directors took some steps toward compliance, a plausible inference was that they were simply "go[ing] through the motions." As the Court put it:

Id.

Id.

Id.

Notably, the plaintiffs point to evidence that in the wake of pleading guilty to criminal charges and suffering liability for numerous violations of federal and state safety regulations, Massey mines continued to experience a troubling pattern of major safety violations. But, instead of using their supervisory authority over management to make sure that Massey genuinely changed its culture and made mine safety a genuine priority, the independent directors are alleged to have done nothing of actual substance to change the direction of the company's real policy.

Id. (footnote omitted).

The facts in Massey are a far cry from the allegations in the Plaintiffs' Complaint. Massey was run by a CEO who publicly expressed his contempt for the law, at least as it applied to his company. That contempt found expression in "an attitude of law-flouting" that continued to pervade the company even after it had repeatedly been punished for breaking the law. The Court faulted Massey for "embrac[ing] the idea that its regulators are wrongheaded and . . . view[ing] itself as simply a victim of a governmental conspiracy." It was this defiant and adversarial relationship to the law—and the independent directors' failure to do anything of substance about it—that gave rise to an inference of bad faith on the defendants' part. Here, by contrast, there are no allegations suggesting that any of Citigroup's officers or directors viewed themselves (or Citigroup) as above the law. Instead, the picture that emerges is of a massive, poorly integrated company that made efforts to comply with the wide range of laws and regulations governing large financial institutions. Those efforts failed in many instances, but that is not enough to support a plausible inference of bad faith. Bad results alone do not imply bad faith.

Id. at *20.

Id. at *21.

See In re Gen. Motors Co. Derivative Litig., 2015 WL 3958724, at *17 (Del. Ch. June 26, 2015) ("Pleadings, even specific pleadings, indicating that directors did a poor job of overseeing risk in a poorly-managed corporation do not imply director bad faith."), aff'd, 133 A.3d 971 (Del. 2016).

The Plaintiffs also rely on Pyott, in which Allergan's board allegedly approved a business plan premised on violations of the law prohibiting drug manufacturers from marketing off-label uses of their products. While physicians may prescribe drugs for off-label uses, drug manufacturers are forbidden to market drugs for off-label uses. Nevertheless, "the Board discussed and approved a series of annual strategic plans that contemplated expanding Botox sales dramatically within geographic areas that encompassed the United States." Under these plans, Allergan would attempt to push Botox into markets "that involved applications that were off-label uses in the United States." The expansion envisioned by these plans was so large that "it necessarily contemplated marketing and promoting off-label uses within the United States." Crucially, the board continued to approve this expansion even after Allergan's general counsel warned the board that the company might be violating the prohibition on off-label marketing. Vice Chancellor Laster found the plaintiffs' allegations sufficient to "support a reasonable inference that the Board knew Allergan personnel were engaging in or turning a blind-eye towards illegal off-label marketing and promotion and that the Board nevertheless decided to continue Allergan's existing business practices in pursuit of greater sales."

Id. at 317-18.

Id. at 352.

Id.

Id.

Id. at 320.

Id. at 355.

The facts in Pyott are unlike what has been alleged here. "[T]he board's alleged bad faith in Pyott was not based on its conscious disregard for its duty to prevent the company from engaging in illegal conduct. Instead, it was based on the board's alleged decision to cause the company to engage in illegal conduct." That kind of conduct constitutes a breach of fiduciary duty because "'Delaware law does not charter law breakers,' and 'a fiduciary of a Delaware corporation cannot be loyal to a Delaware corporation by knowingly causing it to seek profit by violating the law.'" The Complaint in this case contains no allegations supporting an inference that any of the Defendants decided to cause Citigroup to break the law in pursuit of profits. To the contrary, the crux of this action is that the "incidents of corporate malfeasance" described in the Complaint "occurred because Defendants—who were aware of significant internal control weaknesses throughout the enterprise—consciously and knowingly failed to take action." Thus, Pyott is of no help to the Plaintiffs here.

Jacobs, 2016 WL 4076369, at *12.

In re Qualcomm Inc. FCPA S'holder Derivative Litig., 2017 WL 2608723, at *3 (quoting Jacobs, 2016 WL 4076369, at *9).

Compl. ¶ 1 (emphasis added).

The Plaintiffs also rely on Rosenbloom v. Pyott, 765 F.3d 1137 (9th Cir. 2014), which involved a complaint that was essentially identical to the one in Pyott. Id. at 1151. It is therefore inapposite for the reasons just discussed. It bears mentioning as well that this Court has been careful to limit Massey and Pyott to their facts. See In re Qualcomm Inc. FCPA S'holder Derivative Litig., 2017 WL 260872, at *4 (distinguishing Massey and Pyott from the case at hand); Reiter, 2016 WL 6081823, at *13-14 (same); Jacobs, 2016 WL 4076369, at *12 (same).

Finally, the Plaintiffs argue that the Seventh Circuit's decision in Westmoreland is "instructive." There, the plaintiff alleged that Baxter International's "directors and officers breached their fiduciary duties by 'consciously disregard[ing] their responsibility to bring Baxter into compliance with [a 2006] Consent Decree and related health and safety laws.'" From 2006 to 2008, "Baxter devoted significant attention and resources to the task of" complying with the consent decree, under which Baxter was required to, among other things, "stop manufacturing and distributing all models of the [Colleague Infusion] Pump within the United States." Yet, according to the plaintiff, the directors "made a conscious decision to halt these efforts in late 2008, despite clear and specific guidance from the [Food and Drug Administration ("FDA")] that additional action from Baxter was needed to bring the company into compliance with FDA regulations and the terms of the Consent Decree." The plaintiff's allegations supported a reasonable inference that "the directors diverted critical resources to speed the development of the new Sigma pump, cynically gambling that this next-generation device could establish a market foothold, and that Colleague Infusion Pumps already in use would become obsolete before the FDA spotted Baxter's abandonment of its earlier efforts." In light of these allegations and the reasonable inferences they supported, the Seventh Circuit, applying Delaware law, concluded that the plaintiff had successfully alleged demand futility.

Westmoreland Cty. Emp. Ret. Sys. v. Parkinson, 727 F.3d 719 (7th Cir. 2013).

Pls.' Answering Br. 31.

Westmoreland, 727 F.3d at 721 (alterations in original).

Id. at 722.

Id. at 728.

Id. at 729.

Id.

Westmoreland resembles Pyott in that the allegations in both cases supported a reasonable inference that the defendants knowingly decided to flout the law. In Westmoreland, the Seventh Circuit inferred bad faith "during th[e] later period" when the directors allegedly chose to stop trying to comply with the FDA's consent decree. Here, however, the Complaint does not raise a reasonable inference that any of the Defendants decided to simply give up on efforts to comply with the law. The Plaintiffs try to create such an inference by challenging the effectiveness of the Citigroup board's response to various purported red flags. But that is not enough to state a Caremark claim, because an ineffective response does not, without more, indicate bad faith. As our Supreme Court has stated, "there is a vast difference between an inadequate or flawed effort to carry out fiduciary duties and a conscious disregard for those duties."

Id. 728.

See In re Goldman Sachs Grp., Inc. S'holder Litig., 2011 WL 4826104, at *23 ("Good faith, not a good result, is what is required of the board.").

Lyondell Chemical Co. v. Ryan, 970 A.2d 235, 243 (Del. 2009).

C. The Plaintiffs' Holistic Approach to Demand Futility

The Plaintiffs urge me to evaluate their demand futility allegations "holistically, not in isolation." They suggest that the Defendants have "resort[ed] to a 'divide and conquer' approach by isolating and selectively attacking Plaintiffs' allegations piecemeal, as if each well-pleaded allegation exists alone in a vacuum." In support of this holistic approach to demand futility, the Plaintiffs cite Delaware County Employees Retirement Fund v. Sanchez. In Sanchez, our Supreme Court employed an aggregate examination of all factors bearing on a director's independence with respect to a particular transaction; Sanchez is not pertinent to my analysis of the Plaintiffs' Caremark claim here. In this matter, I must examine whether demand on the board is excused because, with respect to the board action that would otherwise have been demanded, a majority of the directors would have been unable to act in the face of a credible threat of liability. Such an analysis requires a separate examination of whether liability may attach with respect to each discrete corporate trauma alleged. Thus, I have evaluated the red flags offered by the Plaintiffs and determined (a) whether they in fact constitute red flags and (b) if they do, whether the board's response (or lack of response) to them supports a reasonable inference of bad faith. That is how this Court has traditionally analyzed Caremark claims in the context of evaluating whether demand is excused.

Pls.' Answering Br. 27.

Id.

124 A.3d 1017 (Del. 2015).

Id. at 1022-24.

Cf. Seinfeld v. Slager, 2012 WL 2501105, at *3 (Del. Ch. June 29, 2012) ("In a derivative suit, this Court analyzes each of the challenged transactions individually to determine demand futility.").

See, e.g., Horman, 2017 WL 242571, at *11-14 (analyzing a Caremark claim in the manner just described); Reiter, 2016 WL 6081823, at *8-14 (same).

The Plaintiffs are correct, however, that a series of actions or inactions of the board may have utility in determining whether board performance with respect to a discrete trauma involved scienter. In that regard, I have considered the actions and inactions of the directors in all the instances pled by the Plaintiffs. What emerges is a picture of directors of a very large, inorganically grown set of financial institutions, beset by control problems as it struggled to integrate. Those directors may be faulted for lack of energy, or for accepting incremental efforts of management advanced at a testudinal cadence, when decisive action was called for instead. I may infer from the facts pled that the board's actions in response to the notices of compliance problems brought to its attention involved directorial negligence. If so, that is a problem that exercise of the stockholder franchise may remedy. If, however, directors of a large and diverse entity such as Citigroup could be liable for negligence, or even gross negligence, it would be difficult to encourage capable individuals to serve, and more difficult to encourage them to bring business judgment to bear on decisions involving risk (such as, for instance, whether to acquire Banamex). Such, at least, was the understanding of our General Assembly, when it extended the right to Delaware corporations to exculpate liability for breaches of the duty of care. Nothing in the facts pled, considered individually or together, implies scienter on the part of the director Defendants. The bad results the Plaintiffs point to, in my view, do not imply bad faith. No substantial likelihood of liability for any of the director Defendants exists under the facts in the Complaint and as gleaned from the documents cited therein, and, therefore, demand is not excused.

See Good, 2017 WL 6397490, at *15-16 (compiling a list of several allegations that collectively supported "a fair inference that the board was all too aware that [Duke Energy's] business strategy involved flouting important laws, while employing a strategy of political influence-seeking and cajolement to reduce the risk that the company would be called to fair account" (Strine, C.J., dissenting)).

8 Del. C. § 102(b)(7); see also Prod. Res. Grp., L.L.C. v. NCT Grp., Inc., 863 A.2d 772, 793 (Del. Ch. 2004) ("Section 102(b)(7) authorizes corporate charter provisions that insulate directors from personal liability to the corporation for breaches of the duty of care. This is an important public policy statement by the General Assembly, which has the intended purpose of encouraging capable persons to serve as directors of corporations by providing them with the freedom to make risky, good faith business decisions without fear of personal liability."). As noted above, Citigroup, in its charter, availed itself of this exculpation provision. --------

III. CONCLUSION

For the foregoing reasons, the Defendants' Motion to Dismiss is GRANTED. An appropriate order is attached. ORDER

AND NOW, this 18th day of December, 2017,

The Court having considered the Defendants' Motion to Dismiss, and for the reasons set forth in the Memorandum Opinion dated December 18, 2017, IT IS HEREBY ORDERED that the Motion to Dismiss is GRANTED. SO ORDERED:

/s/ Sam Glasscock III

Vice Chancellor


Summaries of

Okla. Firefighters Pension & Ret. Sys. v. Corbat

COURT OF CHANCERY OF THE STATE OF DELAWARE
Dec 18, 2017
C.A. No. 12151-VCG (Del. Ch. Dec. 18, 2017)

explaining that bad faith inaction "must suggest, not merely inattention, but actual scienter" and "must imply that the directors are knowingly acting for reasons other than the best interest of the corporation"

Summary of this case from In re Chemed Corp.
Case details for

Okla. Firefighters Pension & Ret. Sys. v. Corbat

Case Details

Full title:OKLAHOMA FIREFIGHTERS PENSION & RETIREMENT SYSTEM, KEY WEST MUNICIPAL…

Court:COURT OF CHANCERY OF THE STATE OF DELAWARE

Date published: Dec 18, 2017

Citations

C.A. No. 12151-VCG (Del. Ch. Dec. 18, 2017)

Citing Cases

Teamsters Local 443 Health Servs. & Ins. Plan v. Chou

To plead a substantial risk of liability, a plaintiff need not "demonstrate a reasonable probability of…

W. R. Berkley Corp. v. Dunai

Showing bad faith is hard. The Committee might have been “ineffective, its actions obtuse, its results…