Auditen
action postmortem

Is a Subpoena Just a Suggestion?

The SEC has finally lost patience with Institutional Shareholder Services (ISS). For those who don't follow every filing, ISS is one of the giants of proxy advising, essentially telling the world how to vote at annual general meetings. The SEC wanted documents. They asked for them via subpoena. ISS decided that providing these documents was an optional exercise.

Now the SEC has filed an enforcement action to compel compliance.

It’s a fascinating study in corporate arrogance. We often see firms fail because their systems are too old or their staff are too tired. This is different. This is a failure of basic submission. ISS didn't miss a deadline because of a glitch; they simply refused to play ball.

The organisation likely believed that the "proprietary" nature of their advisory process acted as a shield. There is a common delusion in the C-suite that if a regulator's request feels intrusive or threatens a business model, one can simply ignore it or negotiate the scope until the regulator gets bored and moves on to an easier target.

The SEC does not get bored. It just builds a file.

From a control perspective, this is embarrassingly simple. Any firm subject to SEC oversight should have a regulatory response framework that separates the *receipt* of a legal mandate from the *evaluation* of its contents. The moment a subpoena lands on a desk, it should trigger an automatic legal hold and a production workflow.

The "proprietary data" argument is a red herring. If a firm believes a request is overbroad or threatens trade secrets, the correct procedure is to move for a protective order in court. You don't just stop answering the phone. By skipping the legal challenge and moving straight to non-compliance, ISS transitioned from a legal dispute to an enforcement action.

One might argue that the SEC is overreaching here, using a subpoena as a blunt instrument to intimidate proxy advisers. Perhaps the probe itself is a fishing expedition.

That may be true, but it's irrelevant to the compliance failure. Whether the regulator is right or wrong on the merits of the investigation, the rule remains: you produce the documents or you get a judge to tell you why you don't have to. You cannot simply decide the subpoena doesn't apply to you.

The cost here isn't just the inevitable legal fees—which will be north of several hundred thousand dollars by the time this settles—but the loss of "trusted partner" status.

This has a clear second-order effect on other proxy advisers. The SEC is essentially signalling that it will not tolerate a "black box" approach to how voting recommendations are generated. If ISS is the test case, every other firm in the sector should be scrubbing their document retention policies this afternoon. They'll be wondering if they are next on the list.

Even more precarious is the position of the external auditors who have been signing off on ISS’s internal governance. When an auditor confirms that a firm has effective controls for regulatory compliance, they are implicitly vouching for the fact that the firm knows how to respond to a government order without being sued into submission.

It's a messy look for everyone involved.

The real question is whether this will actually force transparency in proxy advising or if ISS will simply pay a fine and keep their secrets. Given the SEC's current appetite, I suspect they want the data more than the money.

I’ll be watching to see if the court grants the SEC’s request for a specific production date. If ISS misses that one, we move from a dispute over paperwork to a dispute over contempt.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Why the SEC Should Repeal Its Climate Disclosure Rule - The National Interest Compliance Week (Google News)
  2. CNIL Fines French Hospital €500K, 727K Records Hit [2026] - tech-insider.org Data Privacy (Google News)
  3. SEC Moves to Nix Rule on Investment Adviser, Political Donations - bloomberg.com Compliance Week (Google News)
  4. ISS Faces SEC Enforcement Action Over Document Refusal - coinfomania.com Compliance Week (Google News)
  5. Thailand’s SEC finalizes crypto Travel Rule, effective February 2027 - Bitget Compliance Week (Google News)
  6. Nutex Health Confirms Sensitive Data Stolen in August Cyberattack - The HIPAA Journal InfoSec Compliance (Google News)
  7. ICE plans for robodogs met with concern by privacy experts - FedScoop Data Privacy (Google News)
  8. SEC Moves to Scrap the Pay-to-Play Rule - thewealthadvisor.com Compliance Week (Google News)

How stories are selected and assessed