领衔动态|领衔律师在《商法》杂志专题刊文探讨“上市公司实控人履职刑事风险防控指引”话题

  近日,上海领衔律师事务所首席合伙人、法学博士蔡正华律师在知名法律杂志《商法》第17卷第3期专题刊文探讨《上市公司实控人履职刑事风险防控指引》话题。

1.jpg2.jpg

  中文版全文

      上市公司实控人履职刑事风险防控指引

  上市公司实际控制人作为企业经营决策的核心,其履职行为直接关系自身法律安全与企业稳健发展。他们既是企业发展的掌舵者,也是合规的第一责任人。当前资本市场“零容忍”执法已成常态,实控人在市值管理、涉税、商业贿赂、信息披露四大核心履职领域的刑事风险高发频发。

  有鉴于此,实控人需要清晰认知各领域风险的具体形式与危害,将合规防控融入日常经营决策的每一个环节,坚守法律底线、严格落实防控措施,这样才能有效规避各类刑事风险,既守护实控人履职安全,也为上市公司稳健发展保驾护航。

  本文结合实操场景,明确各领域刑事风险的具体形式与针对性应对方案,为实控人提供务实可落地的合规指引。

  市值管理

  实控人在市值管理履职中面临多重刑事风险。操纵证券、期货市场罪是高发罪名,多以“伪市值管理”的形式实施,通过违规操作拉抬、打压股价实现套利;内幕交易、泄露内幕信息罪则是利用自身掌握的未公开重大信息从事交易或泄露信息;违规披露、不披露重要信息罪源于为维持股价、配合减持等目的,授意公司虚假披露业绩或隐瞒重大事项;擅自挪用公司资金用于股价炒作还可能构成挪用资金罪。

  实控人的应对方案包括(1)明确合规边界,坚守合法市值管理原则,坚决摒弃“伪市值管理”思维,不触碰刑事红线;(2)严控账户与交易管理,主动报备证券账户,杜绝委托操盘、隐匿身份,减持严格遵守监管规定;(3)规范信息发布流程,严禁虚假披露、选择性披露,不与外部机构合谋炒作股价;(4)规范资金使用,严禁擅自挪用公司资金,合规使用需履行董事会、股东会审议程序;以及(5)建立常态化自查机制,每月排查风险隐患,及时整改并主动报备。

  涉税合规

  实控人在涉税领域可能触犯三类核心刑事犯罪:(1)虚开增值税专用发票罪,授意开具无真实业务支撑的发票用于抵扣或牟利;(2)逃税罪,通过“账外账”“阴阳合同”等方式隐瞒收入、虚列成本逃避缴税,经追缴仍不补缴,或五年内二次被处罚后再次逃税;(3)骗取出口退税罪,利用上市公司出口资质虚构业务、伪造单据骗取退税款。

  对此,实控人应当(1)严格管理发票,建立“合同—物流—资金—发票”四流合一审核机制,实行双人复核;(2)规范账务处理,严禁设置“账外账”,重大会计处理需经第三方审计,定期自查涉税隐患;(3)强化税务审核,每年聘请独立税务师事务所开展审计,结合最新政策调整筹划方案;(4)妥善应对税务稽查,主动配合调查,及时补缴税款、滞纳金和罚款,避免行政违法向刑事犯罪转化;以及(5)规范关联交易涉税管理,遵循独立交易原则,留存完整定价依据。

  商业贿赂

  商业往来中实控人面临三类行贿风险。以公司利益为目的安排资金向国家工作人员行贿,为公司谋取不正当利益的,构成单位行贿罪。为谋取个人不正当利益,以个人资金向国家工作人员或合作企业高管、采购人员行贿的,构成行贿罪或对非国家工作人员行贿罪。

  要注意的是,通过虚列“咨询费”“服务费”、赠送贵重礼品、安排高端旅游等方式输送利益的隐性贿赂同样构成犯罪。

  建议实控人(1)规范业务合作流程,确保招投标全程公开透明,建立合格合作方名录,开展反贿赂背景调查;(2)调整销售激励机制,减少与单一订单强绑定的“灰色激励”,转向合规的价格政策、返利规则等可审计机制;(3)严格费用支出管控,大额支出实行财务、法务、业务三重审核,实控人不直接干预审批;以及(4)加强人员管理与培训,定期开展反贿赂合规培训,建立匿名举报机制。

  信息披露

  信息披露领域的刑事风险与披露信息的真实性、准确性、完整性、及时性密切相关。授意虚假披露业绩,或隐瞒资金占用、违规担保等重大事项的,构成违规披露、不披露重要信息罪。在IPO或再融资中主导财务造假,隐瞒真实经营状况骗取发行注册的,构成欺诈发行证券罪。利用未公开重大信息本人或指使他人从事相关证券交易的,构成内幕交易罪。

  对此,实控人应当(1)严格保证信息披露真实、准确、完整、及时,杜绝虚假披露、误导性披露;(2)规范重大事项披露流程,明确披露标准与时限,先履行审议程序再对外披露;(3)建立全流程审核闭环,完善“业务提交—多部门审核—实控人确认”机制,实控人进行实质审核并留存痕迹;(4)强化财务造假防控,规范财务核算,定期自查,配合第三方审计并及时整改;及(5)做好风险应急处置,被立案调查后主动配合,及时聘请专业律师,争取从轻处理。

  英文版全文

  How actual controllers of listed companies ward off criminal risks

  Actual controllers are the heart of the listed companies’ decision-making systems. Their conduct directly affect not just their own personal legal security, but also the steady development of the corporation. They serve as the helmsmen of corporate growth; but in cases of non-compliance, they are also the first to be held accountable.

  With China enforcing a "zero tolerance" enforcement policy in its capital markets, actual controllers face an unenviable share of criminal risks across four core functional areas: market value management, taxation, commercial bribery, and information disclosure.

  Therefore, it is crucial that actual controllers be familiar with the forms and dangers of risks in various fields. By integrating compliance and risk prevention into every aspect of daily operations, adhering to legal boundaries, and strictly implementing preventive measures, they can effectively avoid criminal risks, ensuring their own security in office and safeguarding the development of the listed company.

  This article outlines the specific forms of criminal risk and preventive measures in the abovementioned areas, which hopefully provides actual controllers with pragmatic and actionable compliance guidance.

  Market value management

  Actual controllers face multiple criminal risks in market value management. Manipulating the securities or futures markets is a frequent offense, often committed under the guise of market value management through illegal operations to inflate or deflate stock prices for arbitrage. The crimes of insider trading and leaking inside information involve trading or disclosing undisclosed material information. Illegal or non-disclosure of important information involves instructing the company to falsify performance or conceal major issues to maintain stock prices or facilitate divestment. Additionally, misappropriating corporate funds for stock speculation may also constitute a crime.

  Actual controllers may adopt the following preventive measures: (1) defining compliance boundaries by adhering to legal market value management, and rejecting pseudo-market value management; (2) strictly controlling accounts and trading by proactively filing securities accounts, prohibiting entrusted trading or concealed identities, and following divestment regulations; (3) standardising information disclosure to prohibit false or selective disclosure and avoid collusion with outside parties to hype stock prices; (4) standardising fund usage by strictly prohibiting misappropriation and ensuring usage follows board and shareholder approval; and (5) establishing routine self-inspections to conduct monthly risk assessments, ensure timely rectification, and proactively report findings.

  Taxation

  Actual controllers face three core criminal risks in the field of taxation: (1) falsely issuing special VAT invoices, involving instructions to issue invoices without genuine underlying transaction for deduction or profit; (2) tax evasion, involving concealing income or inflating costs via off-the-book accounts or dual contracts, and failing to pay after pursuit, or re-offending after two penalties within five years; and (3) cheating export tax rebates, involving fabricating business or forging documents using the listed company's export qualifications to claim rebates.

  Actual controllers should (1) strictly manage invoices by establishing aconsistent "contract, logistics, fund, invoice" procedure with dual-person review; (2) standardise accounting by prohibiting off-the-book accounts, requiring third-party audits for major accounting treatments, and conducting regular tax risk self-inspections; (3) strengthen tax audits by hiring independent tax firms annually and adjusting planning schemes based on latest policies; (4) properly handle tax inspections by co-operating and timely paying back taxes, late fees, and fines to prevent administrative violations from escalating into criminal charges; and (5) regularise the tax management of related-party transactions by following the arm's length principle and retaining complete pricing evidence.

  Commercial bribery

  Actual controllers face three types of bribery risks in business dealings. In particular, arranging funds to bribe state functionaries for corporate benefit to seek illegitimate gains constitutes the crime of offering bribes by a unit. Bribing state functionaries or executives and procurement personnel of partner enterprises with personal funds to seek illegitimate personal interests constitutes the crime of bribery or bribery of non-state functionaries.

  Notably, indirect bribery via transfer of interests in the form of inflated "consultancy" or "service" fees, expensive gifts, or luxury travel arrangements likewise constitutes a criminal offence.

  Actual controllers are advised to (1) standardise business collaboration by ensuring full transparency in bidding, establishing qualified partner lists, and conducting anti-bribery background checks; (2) adjust sales incentives by reducing "grey incentives" tied to single orders and shifting to auditable mechanisms like compliant pricing and rebate rules; (3) strictly control expenditures by implementing triple review (financial, legal and business) for large outlays, without direct interference from the controller; and (4) enhance personnel management and training by conducting regular anti-bribery compliance sessions and establishing anonymous whistleblowing mechanisms.

  Information disclosure

  Criminal risks in information disclosure are closely tied to the truthfulness, accuracy, completeness, and timeliness of the information itself. Instructing the false disclosure of performance, or concealing major matters such as fund misappropriation or illegal guarantees, constitutes the crime of illegal disclosure or non-disclosure of important information. Leading financial fraud during an IPO or refinancing to conceal actual operations and fraudulently obtain issuance registration constitutes the crime of fraudulent issuance of securities. Engaging in or instructing others to engage in securities trading using material non-public information constitutes insider trading.

  Actual controllers should (1) strictly ensure that information disclosure is truthful, accurate, complete, and timely, avoiding any false or misleading disclosures; (2) standardise disclosure procedures for major issues by defining standards and timelines, ensuring review before public release; (3) establish a closed-loop review process involving business team submission, multi-departmental review, and controller confirmation, with substantive audits and documented trails; (4) strengthen prevention of financial fraud by regularising accounting, conducting periodic self-inspections, and cooperating with third-party audits for timely rectification; and (5) manage risk emergencies by proactively cooperating with investigations and engaging professional counsel to seek leniency.