CFIUS has the authority to negotiate, enter into or impose, and enforce any agreement, condition, or order with any party to mitigate any national security risk arising from a covered transaction.
CFIUS Mitigation Authorities
CFIUS may use its mitigation authority only after determining that:
- other provisions of law do not provide adequate authority to address the national security risk;
- mitigation measures will resolve the national security risk; and
- the mitigation measures are reasonably calculated to: be effective; allow for compliance in an appropriately verifiable way; and enable effective monitoring of compliance with, and enforcement of, such measures.
Examples of mitigation measures negotiated and adopted by CFIUS are available in the CFIUS Annual Report to Congress.
In cases involving completed transactions for which CFIUS is conducting a review or investigation, CFIUS has the authority to negotiate, enter into or impose, and enforce any agreement or condition to mitigate any interim national security risk that may arise as a result of the covered transaction until such time that CFIUS has completed its review or investigation or the President has taken action with respect to the transaction.
In cases where a party has voluntarily chosen to abandon a covered transaction, CFIUS also has the authority to negotiate, enter into or impose, and enforce any agreement or condition for purposes of effectuating such abandonment and mitigating any national security risk that arose as a result of the transaction.
CFIUS Monitoring Activities
Treasury, as the Chair of CFIUS, oversees and coordinates monitoring of compliance with CFIUS mitigation measures established with transaction parties to address national security risks arising from covered transactions. Treasury also designates at least one other CFIUS member agency with a substantive interest in the transaction to negotiate, monitor, and enforce each active mitigation agreement, condition, and order. This ensures that compliance with all mitigation measures is monitored by the agencies best equipped to do so, each with its own expertise and specialized resources.
Depending on the risks arising from a covered transaction and the terms of a mitigation agreement, condition, or order, the CFIUS Monitoring Agencies use a variety of tools to monitor and enforce compliance, including initial kick-off compliance meetings, conducting on-site compliance inspections, communicating with and reviewing regular and ad hoc reports from designated compliance personnel and third-party auditors and monitors, investigating potential violations, and overseeing remedial action, as appropriate. The work of these third-party providers is critical not only in facilitating compliance and identifying gaps in processes or procedures, but also in devising improvements and other measures to improve compliance by mitigated companies.
Designated Compliance Personnel
The Committee’s monitoring and compliance functions often leverage the skills and expertise of designated personnel of the transaction parties to ensure continuous and effective monitoring. For example, a mitigated entity will often be required to appoint a security officer to oversee implementation and compliance at the operational level. Mitigation agreements may also require the appointment of a security director or board observer. Certain mitigation agreements, conditions, and orders may also require that the foreign investor’s role in the U.S. business be completely passive. This may be effectuated through the appointment of a proxy holder or voting trustee to represent the foreign investor in the business’s governance.
While each mitigation agreement, condition, and order specifies the particular duties and responsibilities of security officers and directors, board observers, proxy holders, and voting trustees, as applicable, CFIUS expects that these designated compliance personnel:
- maintain frequent, substantive contact with the mitigated entity’s other designated compliance personnel and the CFIUS Monitoring Agencies regarding matters relevant to mitigation agreement compliance;
- be available to meet with the CFIUS Monitoring Agencies without other company representatives;
- act in the manner that they reasonably believe is in the national security interest of the United States;
- refrain from providing guidance, counsel, or advice to any mitigated entity in connection with any matter that could be inconsistent with their duties as described in the mitigation agreement or order; and
- promptly notify the CFIUS Monitoring Agencies if they believe a conflict arises between their duties as designated compliance personnel and other positions they may hold in the mitigated entity.
CFIUS may also supplement its monitoring efforts, where appropriate, by utilizing independent third-party providers as monitors, auditors, or consultants. These providers often possess technical or industry expertise and can rapidly deploy resources when and where needed.