Compliance refers to a category of internal control activities designed to induce, facilitate, recommend, or monitor compliance by a company and its officers and employees with laws and regulations, the articles of incorporation, and other internal ru...
Compliance refers to a category of internal control activities designed to induce, facilitate, recommend, or monitor compliance by a company and its officers and employees with laws and regulations, the articles of incorporation, and other internal rules. In principle, compliance functions are conducted at the level of an independent legal entity as compliance support or monitoring activities, and may therefore be perceived as matters confined to individual companies. Upon closer examination, however, it becomes apparent that substantial compliance-related interactions exist among affiliated companies within a corporate group. This article conceptualizes such interactions as corporate group compliance and examines their actual practices and patterns, legal characteristics, limitations, and possible supplementary measures.
Among the principal statutes that are commonly applicable to corporate group compliance across most corporate groups are the designation regime for large business groups under the Monopoly Regulation and Fair Trade Act, the prohibition of unfair support practices under the same Act, conflict-of-interest prevention provisions under the Commercial Act, and the offense of breach of trust under the Criminal Act. These legal rules may be classified into (i) structure- and procedure-oriented regulations with relatively clear interpretive contours, and (ii) substance-oriented regulations that require assessments based on indeterminate legal concepts. From an efficiency perspective, it is desirable to differentiate the allocation of compliance-related budgets and personnel, as well as the degree of cooperation among departments and affiliated companies, in accordance with this classification.
Corporate group compliance practices may be typologized into three categories. The first consists of cases in which an individual company conducts compliance activities independently, without collaboration with other affiliates, but where the applicable legal rules affect all or some of the affiliated companies within the corporate group. The second type involves situations in which a hub affiliate—such as a holding company or another core group entity—undertakes part or all of the compliance functions of other affiliated companies, typically on the basis of management advisory or management services agreements. The third type comprises cases in which major affiliates within a large business group jointly establish a compliance committee.
In practice, the role of the compliance hub affiliate is most often assumed by a holding company or a core affiliate with sufficient budgetary and human resources. This arrangement is commonly grounded in management advisory or management services agreements. In addition, as a matter of statutory interpretation, its legal basis may also be derived from the concept of a holding company or from the role of a representative company within a corporate group under the Fair Trade Act. The functions performed by such hub affiliates typically include compliance education, issuance of cautions or reminders, establishment of internal rules such as codes of ethics, handling or delegation of whistleblowing reports and investigations, provision of legal advice, and the review, coordination, and approval of contracts and agreements.
Representative examples of the compliance committee model include the Samsung Compliance Oversight Committee, the Kakao Compliance and Trust Committee and the Responsible Management Committee under the CA Council, the Lotte Compliance Committee, the Hanwha Compliance Committee, and the Information Security Committee under the SK SUPEX Council. These bodies generally present themselves as independent organizations external to individual affiliated companies, or in some cases as entities independent from the corporate group itself. Participation in such committees does not extend to all affiliated companies; rather, it is typically limited to a small number of core affiliates with substantial asset or revenue bases. Their principal activities include education, issuance of cautions, system building, whistleblowing management, cooperation with internal compliance organizations within affiliated companies, and supervision thereof.
An examination of the substance of corporate group compliance activities reveals that they are predominantly centered on recommendations, cooperation, and the presentation of opinions—such as education, advice, cautions, and monitoring—rather than on the exercise of coercive authority. As such, these activities more closely resemble non-authoritative actions that respect the discretion of the supported affiliates in determining whether and how to accept such support. In this respect, corporate group compliance should be distinguished from directive–subordinate relationships that have traditionally attracted attention in both domestic and comparative corporate group legislation and scholarship, and a differentiated analytical approach is therefore required. Nevertheless, because relationships of recommendation and cooperation may, depending on their development in practice, effectively transform into directive–subordinate relationships, it remains necessary to build upon and further develop the existing body of research in this field.
Corporate group compliance is not without limitations. In the course of compliance support being undertaken by a hub affiliate, several risks may arise, including (i) the regression or erosion of compliance management and execution capabilities within individual supported companies, (ii) the emergence of conflicts of interest or issues of dual representation, and (iii) concerns relating to the protection of trade secrets and personal data. Accordingly, supported affiliates must exercise particular care to ensure that their incentives to understand and actively engage in compliance are not diminished. Management advisory or services agreements should clearly and precisely specify the scope and limits of the entrusted tasks so as to prevent disputes arising from conflicts of interest. In addition, external independent bodies or consultative mechanisms outside the corporate group should be meaningfully utilized, and special attention should be paid to minimizing the sharing of trade secrets and personal data, as well as to appropriate ex post handling.
The establishment of compliance committees consisting solely of core affiliates also entails certain problems. These include (i) the risk of neglecting or exacerbating compliance blind spots among non-participating affiliates, (ii) the possibility that participating affiliates may waste time and resources due to substantial overlap between the committee’s functions and their existing internal compliance organizations, and (iii) the potential emergence of new issues—such as unfair support or undue managerial interference—during the selection of participating companies and the allocation of costs. Accordingly, institutional designs and supplementary measures are required to ensure that effective compliance control is extended to non-participating affiliates without exception. Care must also be taken to allocate responsibilities efficiently between compliance committees and internal compliance organizations within individual companies, and to establish rational criteria for participation and cost sharing that reflect the actual compliance needs of the affiliated companies.
Meanwhile, in directive–subordinate relationships within corporate groups, information and materials tend to be continuously and structurally centralized upward toward the directing entity. In such cases, where the liability of the directing entity for damages is at issue, it is desirable to adopt an interpretation that relaxes the burden of proof borne by the subordinate entity seeking compensation. By contrast, in relationships characterized by recommendation and cooperation, the ordinary principles governing the allocation of the burden of proof should suffice. Furthermore, because relationships of recommendation and cooperation within corporate groups are typically continuous and enduring, involve a broad scope of collaboration, and entail the sharing of highly sensitive information, it is reasonable to interpret that personnel engaged in such activities within a corporate group owe a heightened duty of care compared to situations in which similar activities are conducted with third parties outside the corporate group.
Finally, where a compliance hub affiliate issues unlawful instructions in the course of corporate group compliance activities and thereby causes damage to a supported affiliate, the hub affiliate should be deemed to bear liability for damages pursuant to Article 401-2 of the Commercial Act.