CCCP Mergers & Acquisitions Compliance 5 — Questions and Answers
Question 1: Which agency administers the Committee on Foreign Investment in the United States (CFIUS) review process?
- Department of Justice (DOJ)
- U.S. Department of the Treasury (Correct answer)
- Federal Trade Commission (FTC)
- Department of Homeland Security (DHS)
Correct answer: U.S. Department of the Treasury
The U.S. Department of the Treasury chairs CFIUS, though the committee includes members from multiple agencies including DOD, DOJ, and DHS.
Question 2: What is a 'virtual data room' (VDR) used for in M&A due diligence from a compliance perspective?
- A secure, auditable platform for sharing confidential target company documents with authorized reviewers (Correct answer)
- A cloud server for storing post-merger integration plans
- A digital tool for filing HSR notifications with the FTC
- A compliance training portal for target company employees
Correct answer: A secure, auditable platform for sharing confidential target company documents with authorized reviewers
VDRs provide a controlled, tracked environment for sharing sensitive documents, creating an audit trail of who accessed what information during due diligence.
Question 3: Under the FCPA, which of the following actions by a newly acquired foreign subsidiary could expose the US acquirer to liability?
- Paying a government official a bribe to win a local contract before the acquisition closed (Correct answer)
- Signing a new sales contract with a government customer after closing
- Hiring a local compliance officer after the acquisition
- Filing required tax returns in the foreign jurisdiction
Correct answer: Paying a government official a bribe to win a local contract before the acquisition closed
Under successor liability, a US acquirer can face FCPA enforcement for pre-acquisition conduct of the target, especially if adequate pre-close due diligence was not conducted.
Question 4: What does a 'second request' from the DOJ or FTC during HSR review signify?
- A request to refile the HSR notification due to a procedural error
- A demand for additional documents and information, extending the waiting period (Correct answer)
- Approval of the transaction with minor conditions
- A notification that the transaction is cleared to close immediately
Correct answer: A demand for additional documents and information, extending the waiting period
A Second Request is a formal demand for extensive additional information, which extends the antitrust review period until the parties substantially comply.
Question 5: Which compliance risk is most commonly overlooked in private equity acquisitions of portfolio companies?
- Integration of IT systems
- Compliance program gaps in lower-revenue subsidiaries acquired as part of a platform strategy (Correct answer)
- Post-merger rebranding costs
- Real estate lease renegotiations
Correct answer: Compliance program gaps in lower-revenue subsidiaries acquired as part of a platform strategy
In platform-and-bolt-on strategies, smaller acquired subsidiaries often lack mature compliance programs, creating aggregate regulatory risk that is frequently underestimated.
Question 6: What is the role of the compliance officer during the letter of intent (LOI) phase of an M&A transaction?
- Negotiate final indemnification terms on behalf of the acquirer
- Identify key compliance risk areas and influence due diligence scope and focus (Correct answer)
- Draft the representations and warranties in the purchase agreement
- Obtain antitrust clearance from the FTC
Correct answer: Identify key compliance risk areas and influence due diligence scope and focus
At the LOI stage, the compliance officer should flag high-risk areas—such as sanctions exposure, regulatory investigations, or data privacy gaps—to shape the due diligence workplan.
Question 7: Which data privacy law creates the most significant compliance obligation when a US company acquires a European target that processes EU personal data?
- California Consumer Privacy Act (CCPA)
- Health Insurance Portability and Accountability Act (HIPAA)
- General Data Protection Regulation (GDPR) (Correct answer)
- Gramm-Leach-Bliley Act (GLBA)
Correct answer: General Data Protection Regulation (GDPR)
GDPR imposes strict obligations on any entity processing EU personal data, and the acquirer inherits these obligations upon taking control of the EU target.
Which agency administers the Committee on Foreign Investment in the United States (CFIUS) review process?