美股招股观察

Due Diligence Under US Securities Law: Liability Risks Every Issuer Must Manage

The Securities and Exchange Commission’s (SEC) fiscal year 2024 enforcement report, released in November 2024, recorded 583 total enforcement actions and USD 8.2 billion in financial remedies — the highest aggregate penalty figure in the agency’s history. Within this total, the Division of Enforcement filed 27 standalone actions against issuers for material misstatements or omissions in registration statements and periodic reports, a 17% increase from FY2023. For any issuer pursuing a listing on the NYSE or NASDAQ, these figures carry a direct, non-negotiable implication: the due diligence process is no longer a procedural checkbox for underwriters and auditors, but the primary legal defence against personal and corporate liability under the Securities Act of 1933. The landmark ruling in SEC v. Ripple Labs (2023) and the subsequent SEC Staff Accounting Bulletin No. 121 (SAB 121) guidance have further sharpened the focus on disclosure accuracy, particularly for issuers with digital asset exposures or complex cross-border structures. This article examines the specific liability provisions under Sections 11 and 12(a)(2) of the Securities Act, the evolving standards for a “reasonable investigation” defence, and the practical steps every issuer must embed into its pre-filing workflow to survive SEC scrutiny and shareholder litigation.

The Statutory Liability Framework: Sections 11 and 12(a)(2)

Section 11 of the Securities Act of 1933 imposes strict liability on every person who signs a registration statement — including the issuer, its directors, underwriters, and auditors — for any material misstatement or omission in the document at the time it becomes effective. Unlike common law fraud, Section 11 does not require the plaintiff to prove scienter, reliance, or loss causation in the traditional sense. The plaintiff need only demonstrate that the registration statement contained an untrue statement of a material fact or omitted a material fact required to make the statements not misleading. Once that threshold is met, liability shifts to the defendant, who must then prove they conducted a “reasonable investigation” and had “reasonable grounds to believe” the statements were true and complete.

Section 12(a)(2) extends similar liability to any person who offers or sells a security by means of a prospectus or oral communication that includes a material misstatement or omission. This provision applies not only to the issuer but also to underwriters, placement agents, and any selling shareholder who solicits investors. The key distinction from Section 11 is that Section 12(a)(2) requires the plaintiff to show the defendant offered or sold the security — meaning an actual transaction must have occurred — and that the plaintiff purchased the security in that offering. The defence, however, remains the same: the defendant must prove they “did not know, and in the exercise of reasonable care could not have known,” of the untruth or omission.

The Reasonable Investigation Standard: What the Courts Require

The Second Circuit’s decision in In re WorldCom, Inc. Securities Litigation (2005) established that the “reasonable investigation” standard under Section 11 is not a uniform checklist but a context-dependent inquiry. The court held that the standard varies based on the role of the defendant, the nature of the issuer’s business, the complexity of the transactions, and the availability of information. For the issuer itself, the standard is effectively strict: an issuer cannot assert a due diligence defence under Section 11 because it is presumed to know its own business. For directors who are not officers, the standard is lower but still requires active inquiry into areas of particular concern, such as revenue recognition policies or related-party transactions.

The SEC’s 2024 Enforcement Manual, Section 6.2.3, explicitly states that the staff will evaluate due diligence by examining whether the underwriter or auditor “(a) obtained and reviewed all material documents, (b) conducted independent verification of key representations, (c) identified and resolved red flags, and (d) documented the investigation process in a contemporaneous work paper.” The manual further notes that reliance on management representations alone, without independent verification, is “generally insufficient” to establish a reasonable investigation defence. For Hong Kong-based issuers listing in the US via a Cayman Islands or BVI holding company, this standard imposes a material burden: the underwriter’s counsel must independently verify the PRC operations of the operating entity, including its compliance with PRC foreign investment regulations and the validity of any variable interest entity (VIE) structures.

Liability for Forward-Looking Statements and the PSLRA Safe Harbor

The Private Securities Litigation Reform Act of 1995 (PSLRA) provides a safe harbour for forward-looking statements — projections, forecasts, and plans — provided they are identified as forward-looking and accompanied by meaningful cautionary language that identifies the factors that could cause actual results to differ materially. The safe harbour does not apply to statements made in connection with an initial public offering (IPO) of securities, nor does it protect statements that were made with actual knowledge of their falsity.

The Ninth Circuit’s 2022 decision in In re Alphabet, Inc. Securities Litigation clarified that the safe harbour requires the cautionary language to be “meaningful” — not boilerplate. The court struck down Alphabet’s cautionary statements as “generic warnings that could apply to any company in any industry,” thereby denying the safe harbour defence. For issuers preparing registration statements on Form F-1 (for foreign private issuers), the practical implication is clear: the risk factors section must be issuer-specific, quantifying material risks where possible (e.g., “a 10% depreciation of the renminbi against the US dollar would reduce our reported revenue by approximately USD 15 million annually”).

The Due Diligence Process: From Pre-Filing to Effectiveness

A defensible due diligence process begins no later than the pre-filing stage, typically 12 to 18 months before the anticipated IPO date. The SEC’s Division of Corporation Finance, in its 2024 Disclosure Review Program Report, noted that 38% of comment letters issued on Form F-1 filings related to deficiencies in the description of the issuer’s business model, particularly for companies with VIE structures or operations in jurisdictions with capital controls, such as the PRC. The SEC’s 2021 statement on VIE disclosures (SEC Release No. 33-10975) explicitly requires issuers to disclose that the VIE structure may not provide the same investor protections as a direct equity ownership structure, and that the PRC government could intervene in the operations of the VIE at any time.

Financial Statement Due Diligence: PCAOB Standards and Auditor Independence

The Public Company Accounting Oversight Board (PCAOB) AS 6101, “The Auditor’s Consideration of an Entity’s Ability to Continue as a Going Concern,” requires the auditor to evaluate whether there is substantial doubt about the issuer’s ability to continue as a going concern for a reasonable period of time, not to exceed one year beyond the date of the financial statements. For issuers with negative operating cash flows or significant debt maturities within 12 months of the filing date, the auditor must assess management’s plans and disclose any material uncertainties in the audit report.

The SEC’s 2023 Enforcement Action against the audit firm of a PRC-based issuer (SEC Release No. 2023-112) highlighted a critical failure: the auditor did not independently confirm the existence of the issuer’s cash balances with the PRC banks, instead relying on management-provided bank statements. The SEC imposed a USD 1.5 million fine and a two-year suspension from practicing before the SEC. For Hong Kong-based sponsors and auditors, this case reinforces the requirement under HKICPA auditing standards (HKSAs) to obtain direct confirmations from financial institutions, and to document the confirmation process in the audit work papers.

For any issuer with PRC operations, legal due diligence must address three specific regulatory regimes: (1) the PRC Cybersecurity Law (2017), (2) the PRC Data Security Law (2021), and (3) the PRC Personal Information Protection Law (2021). The Cyberspace Administration of China’s (CAC) 2022 Measures for Cybersecurity Review require any issuer that possesses personal information of more than one million users to apply for a cybersecurity review before filing a registration statement with the SEC. The review can take 60 to 90 business days, and the CAC has the authority to order the issuer to cease data collection or to restructure its operations.

The SEC’s 2024 Staff Guidance on PRC-based Issuers (SEC Division of Corporation Finance, January 2024) explicitly states that the registration statement must disclose: (a) whether the issuer has obtained all necessary PRC regulatory approvals, (b) the risks associated with the CAC’s cybersecurity review, and (c) the legal basis for the VIE structure under PRC law. The guidance further requires the issuer to include a statement from PRC counsel opining on the enforceability of the VIE contracts under PRC law. For Hong Kong-based law firms acting as PRC counsel, this opinion must be based on a review of the actual VIE contracts, the corporate governance documents of the PRC operating entity, and a legal memo analysing the current PRC regulatory environment.

The Underwriter’s Role and the “Global Coordinator” Defence

The underwriter bears the heaviest due diligence burden of any non-issuer defendant. The Second Circuit in In re Morgan Stanley Information Fund Securities Litigation (2010) held that the lead underwriter is expected to conduct a “thorough investigation” of the issuer’s business, financial condition, and management, and to verify the accuracy of all material representations in the registration statement. The underwriter cannot delegate this duty to the issuer’s counsel or to the auditor; it must independently review the issuer’s contracts, financial records, and regulatory filings.

The Due Diligence Meeting and the “Red Flag” Analysis

The due diligence meeting, typically held 6 to 8 weeks before the filing date, is the underwriter’s primary opportunity to identify red flags. The meeting should include the issuer’s CEO, CFO, general counsel, heads of business units, and the external auditor. The underwriter’s counsel should prepare a due diligence memorandum that lists each material representation in the registration statement and identifies the source of verification for each representation. Common red flags include: (1) revenue recognition policies that deviate from industry norms, (2) significant related-party transactions, (3) high customer concentration (more than 20% of revenue from a single customer), (4) material litigation or regulatory proceedings, and (5) inconsistencies between the issuer’s financial statements and the auditor’s management letter.

The SEC’s 2023 Enforcement Action against a lead underwriter (SEC Release No. 2023-189) illustrates the consequences of ignoring red flags. The underwriter failed to follow up on a whistleblower complaint that the issuer’s revenue recognition policy was inconsistent with ASC 606 (Revenue from Contracts with Customers). The SEC imposed a USD 5 million penalty and a one-year bar from acting as a lead underwriter on any IPO. For Hong Kong-based investment banks acting as bookrunners on US listings, this case underscores the necessity of having a dedicated in-house due diligence team that works independently of the deal team.

The Underwriter’s Reliance on Experts: The “Expertised Portions” Defence

Section 11 provides a limited defence for underwriters with respect to “expertised portions” of the registration statement — those portions that are prepared by or on the authority of an expert, such as the audited financial statements. The underwriter is not required to verify the accuracy of the expertised portions, provided it had no reasonable grounds to believe they were false or misleading. However, the defence does not extend to the “non-expertised portions” — the business description, risk factors, management discussion and analysis (MD&A), and legal opinions.

The Supreme Court’s decision in Omnicare, Inc. v. Laborers District Council Construction Industry Pension Fund (2015) clarified that a statement of opinion in a registration statement can be actionable if the issuer or underwriter did not actually hold the opinion, or if the opinion was not supported by a reasonable basis in fact. For underwriters, this means they must independently verify the factual basis for any opinion statements in the prospectus, particularly those relating to market size, competitive positioning, or regulatory outlook.

Practical Takeaways for Issuers and Their Advisors

  1. Start due diligence 12 to 18 months before the anticipated filing date, with a dedicated due diligence team that includes the issuer’s CFO, general counsel, external auditor, and PRC legal counsel, and document every step of the process in contemporaneous work papers to survive SEC or plaintiff scrutiny.
  2. For any issuer with PRC operations, obtain a written legal opinion from PRC counsel addressing the enforceability of the VIE structure, the status of CAC cybersecurity review (if applicable), and the issuer’s compliance with the PRC Data Security Law, and disclose the opinion in the registration statement.
  3. Ensure that the risk factors section of the prospectus is issuer-specific and quantified, avoiding generic boilerplate language, and include a meaningful cautionary statement for any forward-looking projections that identifies the specific factors that could cause actual results to differ materially.
  4. Require the lead underwriter to conduct an independent verification of all material representations in the registration statement, including direct confirmation of cash balances with financial institutions and independent review of the issuer’s top 10 customer contracts.
  5. Retain all due diligence work papers, including meeting minutes, email correspondence, and verification checklists, for a minimum of seven years after the effective date of the registration statement, consistent with the SEC’s document retention requirements under Rule 17a-4 of the Securities Exchange Act of 1934.