31 Days to a More Effective Compliance Program: Recent Episodes

Thomas Fox

And this too?

View Details

The 2020 Update re-emphasized the need for both performing a root cause analysis but equally importantly using it to remediate your compliance program. It stated, “a hallmark of a compliance program that is working effectively in practice is the extent to which a company is able to conduct a thoughtful root cause analysis of misconduct and timely and appropriately remediate to address the root causes.” It went on to state, what additional steps the company has taken “that demonstrate recognition of the seriousness of the misconduct, acceptance of responsibility for it, and the implementation of measures to reduce the risk of repetition of such misconduct, including measures to identify future risk”).” The key is that after you have identified the causes of problems, consider the solutions that can be implemented by developing a logical approach, using data that already exists in the organization. Identify current and future needs for organizational improvement. Your solution should be a repeatable, step-by-step processes, in which one process can confirm the results of another. Focusing on the corrective measures of root causes is more effective than simply treating the symptoms of a problem or event and you will have a much more robust solution in place. This is because the solution(s) are more effective when accomplished through a systematic process with conclusions backed up by evidence. When you step back and consider what the DOJ was trying to accomplish with its 2020 Update, it becomes clear what the DOJ expects from the compliance professional. Consider the structure of your compliance program and how it inter-relates to your company’s risk profile. When you have a compliance failure, use the root cause analysis to think about how each of the structural elements of your compliance program could impact how you manage and deal with that risk. Three key takeaways:

The key is objectivity and independence.

The critical element is how did you use the information you developed in the root cause analysis?

The key is that after you have identified the causes of problems, consider the solutions that can be implemented by developing a logical approach, using data that already exists in the organization.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the biggest changes in the 2020 FCPA Resource Guide is the addition of a new Hallmark, entitled “Investigation, Analysis, and Remediation of Misconduct”, which reads in full: The truest measure of an effective compliance program is how it responds to misconduct. Accordingly, for a compliance program to be truly effective, it should have a well-functioning and appropriately funded mechanism for the timely and thorough investigations of any allegations or suspicions of misconduct by the company, its employees, or agents. An effective investigations structure will also have an established means of documenting the company’s response, including any disciplinary or remediation measures taken. In addition to having a mechanism for responding to the specific incident of misconduct, the company’s program should also integrate lessons learned from any misconduct into the company’s policies, training, and controls. To do so, a company will need to analyze the root causes of the misconduct to timely and appropriately remediate those causes to prevent future compliance breaches.  Ultimately, performing a root cause analysis is not simply a matter of sitting down and asking a multitude of questions. You need to have an operational understanding of how a business operates and how they have developed their customer base. Overlay the need to understand what makes an effective compliance program, with the skepticism an auditor should bring so that you do not simply accept an answer that is provided to you, as you might in an internal investigation. As Marks noted, “a root cause analysis is not something where you can just go ask the five whys. You need these trained professionals who really understand what they’re doing.” Three key takeaways:

A root cause analysis is now required if you have a reportable compliance failure.

There is no one process for performing a root cause analysis. You should select the one which works for you and follow it.

To properly perform a root cause analysis, you need trained professionals who really understand what they’re doing.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Your company has just made its largest acquisition ever and your CEO says they want you to have a compliance post-acquisition integration plan on their desk in one week. Where do you begin? A good place to start would be the 2020 FCPA Resource Guide language: Pre-acquisition due diligence, however, is normally only a portion of the compliance process for mergers and acquisitions. DOJ and SEC evaluate whether the acquiring company promptly incorporated the acquired company into all of its internal controls, including its compliance program. Companies should consider training new employees, reevaluating third parties under company standards, and, where appropriate, conducting audits on new business units. The bottom line is that you must train the newly acquired employees, reevaluate third parties under your company standards, and conduct compliance audits on new business units. This process should be based your pre-acquisition due diligence and risk assessment. Moreover, the DOJ and SEC clearly view both the pre- and post-acquisition phases of M&A as tied together in a unidimensional continuum. If pre-acquisition due diligence is not possible, you should review the requirements and time frames laid out in Opinion Release 08-02 or the 2020 FCPA Resource Guide, which noted, “pursuant to which companies can nevertheless be rewarded if they choose to conduct thorough post-acquisition FCPA due diligence.” Whatever compendium of steps you utilize for post-acquisition integration, they should be taken as soon as is practicable.  The earlier you can deploy these steps the better off your company will be at the end of the day. An acquisition that fails for compliance reasons is a preventable disaster of the first order. One need only consider the Latin Node Inc. FCPA enforcement actions where the acquiring company had to write off its entire investment because it had wholly failed to engage in appropriate pre-acquisition due diligence.  Three key takeaways:

Planning is critical in the post-acquisition phase.

Build upon what you learned in pre-acquisition due diligence.

You literally need to be ready to hit the ground running when a transaction closes.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A company that does not perform adequate due diligence prior to a merger or acquisition may face both legal and business risks. Perhaps most commonly, inadequate due diligence can allow a course of bribery to continue - with all the attendant harms to a business’s profitability and reputation, as well as potential civil and criminal liability. While most compliance practitioners have been long aware of the requirement in the post-acquisition context, the 2012 FCPA Guidance focused many compliance practitioners of the need to engage in robust pre-acquisition due diligence.  The 2020 Update made even more clear the need for a robust compliance presence in the pre-acquisition phase. It stated, “A well-designed compliance program should include comprehensive due diligence of any acquisition targets, as well as a process for timely and orderly integration of the acquired entity into existing compliance program structures and internal controls. Pre-M&A due diligence, where possible, enables the acquiring company to evaluate more accurately each target’s value and negotiate for the costs of any corruption or misconduct to be borne by the target. Flawed or incomplete pre- or post-acquisition due diligence and integration can allow misconduct to continue at the target company, causing resulting harm to a business’s profitability and reputation and risking civil and criminal liability.” There are multiple red flags which could be raised in this process, which might well warrant further investigation. They include if the target has ineffective compliance program elements in their compliance program or if there were frequent breach of policies and procedures. Obviously, a target which is in financial difficulty would bear closer scrutiny. Structurally, if the company did not have a formal ethics and compliance committee at the senior management or Board of Directors’ level, this could present issues. From the CCO perspective, if the position did not have Board or CEO access or if there were not regular reports to the Board, it could present an issue for compliance. Conversely, if there were frequent requests to waive policies, management over-ride of compliance controls or no consistent consequence management for violations; it could present clear red flags for further investigation. Three key takeaways: 

The results of your pre-acquisition due diligence will inform your post-acquisition integration and remediation going forward.

Periodically review your M&A due diligence protocol.

If red flags appear in pre-acquisition due diligence, they should be cleared.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas articulated in the 2020 Update was around payments and payroll. For the both the compliance professional and the corporate payroll function, there is a significant role to play in the operationalization of a corporate compliance program. The 2020 Update was replete with references to payment and its critical nature to any best practices compliance program. This includes references to payments to foreign officials, payments to third parties and hiding bribes in payments to distributors. The 2020 Update begins with an admonition to stop wasting time on low hanging fruit when there are much higher risks in your business operations. The role of payroll in compliance is not often considered in operationalizing your compliance program, yet the monies to fund bribes must come from somewhere. Unfortunately, one of those places is out of payroll. All CCOs need to sit down with his or her head of payroll, have them explain the role of payroll, then review the internal controls in place to see how they facilitate the goals of compliance. From that review, you can then determine how to use payroll to help to operationalize your compliance program. The DOJ has now provided its clearest statement on how it expects a company to actually do compliance going forward. Long gone are the days where the DOJ simply considered the inputs of a written program as sufficient to protect companies from compliance violations. Yet the mandate to operationalize a corporate compliance program drives home the concept that compliance is a business process, which should be administered by the appropriate business unit with the requisite SME. When it comes to following the money, payroll is the most well-suited corporate discipline to provide this first level of oversight and controls.  Three key takeaways:

Payroll can be a key prevent and detect control.

The 2020 Update specified the tying of the corporate compliance function to the corporate payroll function.

Offshore payments remain a key indicator for a red flag.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The role of the compliance professional and the compliance function in a corporation has steadily grown in stature and prestige over the years. When it came to the corporate compliance function, 2020 FCPA Resource Guide, under the Hallmarks of an Effective Compliance Program, simply noted the government would “consider whether the company devoted adequate staffing and resources to the compliance program given the size, structure, and risk profile of the business.” This Hallmark was significantly expanded in both the FCPA Corporate Enforcement Policy and 2020 Update. In the FCPA Corporate Enforcement Policy, the DOJ listed the following as factors relating to a corporate compliance function, that it would consider as indicia of an effective compliance and ethics program: 1) the resources the company has dedicated to compliance; 2) the quality and experience of the personnel involved in compliance, such that they can understand and identify the transactions and activities that pose a potential risk; 3) the authority and independence of the compliance function and the availability of compliance expertise to the board; 4) the compensation and promotion of the personnel involved in compliance, in view of their role, responsibilities, performance, and other appropriate factors; and 5) the reporting structure of any compliance personnel employed or contracted by the company. The 2020 Update and FCPA Corporate Enforcement Policy both demonstrate the continued evolution in the thinking of the DOJ around the corporate compliance function. Their articulated inquiries can only strengthen a corporate compliance function specifically; and the compliance profession more generally. The more the DOJ talks about the independence of the compliance function, coupled with resources being made available and authority concomitant with the corporate compliance function, the more corporations will see it is directly in their interest to provide the resources, authority and gravitas to compliance position in their organizations. Three key takeaways:

How is compliance treated in the budget process?

Has your compliance function had any decisions over-ridden by senior management?

Beware outsourcing of compliance as any such contractor must have access to company documents and personnel.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The role of the CCO has steadily grown in stature and prestige over the years. In the 2020 FCPA Resource Guide, under the Hallmarks of an Effective Compliance Program, it focused on the whether the CCO held senior management status and had a direct reporting line to the Board.  This Hallmark was significantly expanded in both the 2020 Update and the FCPA Corporate Enforcement Policy. And in so doing, the DOJ has increased the prestige, authority and role of both the CCO and corporate compliance function. The 2020 Update has five general areas of inquiry around the CCO and corporate compliance function. (1) How does the CCO salary and stature within the organization compare to other senior executives within the company. (2) What are the experience and stature of the CCO with an organization? Does the CCO have appropriate training for the role? (3) How much autonomy does the CCO have to report to the Board of Directors? How often do the CCO meet with directors? Are members of the senior management present for these meetings with the Board of Directors or of the Audit Committee? (4) What is your structure? Is the compliance function run by a designated chief compliance officer, or another executive within the company, and does that person have other roles within the company? (5) Is data in your organization so siloed that the CCO does not have access to it? If so, what are you doing about it? Once again for the compliance professional, the FCPA Corporate Enforcement Policy and 2020 Update make the importance of a best practices compliance program even more critical. The DOJ is focusing more on the role, expertise and how the compliance function is treated within an organization. Pay your CCO considerably less than your GC? You may now better be able to justify that discrepancy. If you have a legal department budget of $3 million and a compliance department budget of $500,000; you may be starting behind the eight-ball. Three key takeaways:

How can you show the CCO really has a seat at the senior executive table?

What are the professional qualifications of your CCO?

Does your CCO have true independence to report directly to the Board of Directors?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the critical elements found in the 2020 Update is the need to use the information you obtain, whether through risk assessment, root cause analysis, investigation, hotline report or any other manner to remediate the situation which allowed it to arise. Your company should establish a regular monitoring system to spot issues and address them. Effective monitoring means applying a consistent set of protocols, checks, and controls tailored to your company’s risks to detect and remediate compliance problems on an ongoing basis. To address this, your compliance team should be checking in routinely with local finance departments in your foreign offices to ask if they have noticed recent accounting irregularities. Regional directors should be required to keep tabs on potential improper activity in the countries in which they manage. These ongoing efforts demonstrate that your company is serious about compliance. It is a function of the CCO to reinforce the vision and goals of the compliance function, where assessment and updating are critical to an ongoing best practices compliance program. If you follow this protocol, you will put a mechanism in place to demonstrate your company’s commitment to compliance by following through on intentions as set forth in your strategic plan. What should you do with this information? Put a strategic plan in place ready to implement your findings of continuous improvement, by using the following:

Review the goals of the strategic plan. This requires that you arrange a time for the CCO and team to review the goals of the Strategic Plan, which the CCO should lead to determine how this goal in the Plan measures up to its implementation in your company.

Design an execution plan. The KISS method (Keep it Simple Sir) is the best to move forward. This would suggest that for each compliance goal, there should be a simple and straight forward plan to ensure that the goal in question is being addressed.

Put accountabilities in place. In any plan of execution, there must be accountabilities attached to them. This requires the CCO or other senior compliance department representatives to put these in place and then mandate a report requirement on how the task assigned is being achieved.

Schedule the next review of the plan. There should be a regular review of the process. It allows any problems which may arise to be detected and corrected more quickly than if meetings are held at a less frequent basis.

Continuous monitoring is a key step but it is only the first step. It is not simply that you tested your compliance program but that you did something with the information you obtained to improve your program. Three key takeaways:

Innovation can come through a new way to think about and use data going forward.

Have a plan in place to use the information garnered in your monitoring incorporated back into your compliance program.

Always remember that Document Document Document is critical if the regulators come knocking.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What happens when controls are continually overridden? Does that necessarily mean that companies are engaging in activities which violate the FCPA or some other law such as Sarbanes-Oxley (SOX). Cristina Revelo said she would start out with some basic questions such as “How often would something be manually approved? How often are controls skipped, what are the level of approvals that you have and what is your documentation? What are the reasons, and are you documenting how often a certain department is requiring those overrides?” While it could indicate a company lacks a culture of compliance or everything is an emergency, it might mean something else. It might mean that your internal controls need to be evaluated and then recalibrated. The Department of Justice calls this continuous monitoring leading to continuous improvement. Joe Oringel, co-founder of Visual Risk IQ, calls it continuous controls monitoring.  However, many compliance professionals, and particularly lawyers think once a control is in place, it’s set in stone, and it’s there forever. This derives from the unfortunate fact that once again many compliance professionals and most lawyers do not understand internal controls. Yet, internal controls, much like the rest of a compliance program can and should be continually monitored and continually improved based upon the information about such things as the number of overrides. Such a review can be evidence of a management problem or a culture of non-compliance at the organization. However, it could be that perhaps the controls need to be adjusted.  3 Key Takeaways 1. An internal control override is not necessarily a bad thing if proper procedure is followed. 2. Internal controls are not set in stone. 3. The key is to have a process for monitoring the controls, taking input, literally from each line of defense. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The call, email or tip comes into your office; an employee reports suspicious activity somewhere across the globe. That activity might well turn into a FCPA issue for your company. As the CCO, it will be up to you to begin the process which will determine, in many instances, how the company will respond going forward. This is more than simply maintaining hotlines. Companies have to make real efforts to listen to employees. You need to have managers who are trained on how to handle employee concerns; they must be incentivized to take on this compliance responsibility and you must devote communications resources to reinforcing the company’s culture and values to create an environment and expectation that managers will raise employee concerns. The reason is that a business’s own employees are a company’s best source of information about what is going on in the company. It is certainly a best practice for a company to listen to its own employees, particularly to help improve its processes and procedures. But more than listening to its employees, a company should provide a safe and secure route for employees to escalate their concerns. This is the underlying rationale behind an anonymous reporting system within any organization. Both the U.S. Sentencing Guidelines and the Organization of Economic Cooperation and Development (OECD) Good Practices list as one of their components an anonymous reporting mechanism by which employees can report compliance and ethics violations. Of course, the Dodd-Frank Whistleblower provisions also give heed to the implementation of a hotline. Given the number of ways that information about violations or potential violations can be communicated to the government regulators, having a robust triage system is an important way that a company can determine what resources to bring to bear on a compliance problem. Jonathan Marks has articulated a five-stage triage process which allows for not only an early assessment of any allegations but also a manner to think through your investigative approach. Marks cautions you must have an experienced investigator or other seasoned professional making these determinations, if not a more well-rounded group or committee. Next, consider what will be the types of evidence to review going forward. Finally, before selecting a triage solution, understand what tools are available, including both forensic and human, to complete the investigation.  Three key takeaways: 1. The DOJ and SEC put special emphasis on internal reporting lines. 2. Test your hotline on a regular basis to make sure it is working. 3. Every claim should be triaged before starting an investigation. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update was very clear about the need for continuous improvement in any compliance program. It stated quite succinctly, “One hallmark of an effective compliance program is its capacity to improve and evolve. The actual implementation of controls in practice will necessarily reveal areas of risk and potential adjustment. A company’s business changes over time, as do the environments in which it operates, the nature of its customers, the laws that govern its actions, and the applicable industry standards. Accordingly, prosecutors should consider whether the company has engaged in meaningful efforts to review its compliance program and ensure that it is not stale.”   Continuous improvement through continuous monitoring or other similar techniques will help keep your compliance program abreast of any changes in your business model’s compliance risks and allow growth based upon new and updated best practices specified by regulators. A compliance program is in many ways a continuously evolving organism, just as your company is. You need to build in a way to keep pace with both market and regulatory changes to have a truly effective anti-corruption compliance program.  Three key takeaways:

Your compliance program should be continually evolving.

Monitoring and auditing are different, yet complimentary tools for continuous improvement.

Culture assessment and monitoring are also now required as well.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There is nothing like an internal whistleblower report about a compliance violation, the finding of such an issue, or (even worse) a subpoena from the DOJ or notice letter from the SEC to trigger the Board of Directors and senior management attention to the compliance function and the company’s compliance program. Such an event can trigger much gnashing of teeth and expressions of outrage followed immediately by proclamations “We are an ethical company.” However, it may well be the time for a very serious reality check.  You may find yourself in the position that you will have to have some very frank discussions about what to expect in terms of costs and time outlays. While much of these discussions will focus on the investigative process and those costs, these discussions will allow you to initiate the talk about remediation going forward and begin to explain why money must be budgeted for the remediation process. One of the things rarely considered is how the investigation triggers the remediation process and what the relationship is between the two. When issues arise warranting an investigation that would rise to the Board of Directors level and potentially require disclosure to the government, there is usually a flurry of attention and activity. Everyone wants to know what is going on. In an interview with Russ Berland, CCO at Aventiv Technologies, he noted, “for that short moment in time, you have everyone’s full attention.” Yet it can still be “a tricky place, because you get your fifteen minutes to really get everyone’s full attention, and from then on, you’re fighting with everybody else for their attention, like the normal things in business life.” Three key takeaways:

A serious FCPA allegation gets the attention of the Board and senior management. Use this time to move the compliance program forward.

Be aware of how your investigation can impact and even inform your remediation efforts.

Be prepared to deal with the dreaded “where else” question.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

After the internal report comes in and you have properly triaged the matter, you need to scope out and investigate it, promptly, thoroughly and with competent personnel. In the 2020 Update, provided these series of questions about your internal investigations:   Properly Scoped Investigations by Qualified Personnel – How does the company determine which complaints or red flags merit further investigation? How does the company ensure that investigations are properly scoped? What steps does the company take to ensure investigations are independent, objective, appropriately conducted, and properly documented? How does the company determine who should conduct an investigation, and who makes that determination?  Investigation Response – Does the company apply timing metrics to ensure responsiveness? Does the company have a process for monitoring the outcome of investigations and ensuring accountability for the response to any findings or recommendations?  Resources and Tracking of Results – Are the reporting and investigating mechanisms sufficiently funded? How has the company collected, tracked, analyzed, and used information from its reporting mechanisms? Does the company periodically analyze the reports or investigation findings for patterns of misconduct or other red flags for compliance weaknesses? Does the company periodically test the effectiveness of the hotline, for example by tracking a report from start to finish? In a presentation Jay Martin, retired Chief Compliance Officer at Baker Hughes and now Senior Counsel at Willkie Farr & Gallagher LLP and Jacki Trevino, Senior Director, Advisory Services Group at SAI Global Limited, discussed the specifics of an investigation protocol. It consisted of 1) opening and categorizing the case; 2) planning the investigation; 3) executing the investigation plan; 4) determining appropriate follow-up; and 5) closing the case. If you follow this basic protocol, you should be able to work through most investigations, in a clear, concise and cost-effective manner. Furthermore, you should have a report at the end of the day which should stand up to later scrutiny if a regulator comes looking. Finally, you will be able to “Document, Document, and Document”, not only the steps you took but why and the outcome obtained. Three key takeaways:

A written protocol, created before an investigation, is a key starting point.

Create specific steps to follow so there will be full transparency and documentation going forward.

Consistency in approach is critical.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Due diligence is generally recognized in three levels: Level I, Level II and Level III. Each level is appropriate for a different level of corruption risk. The key is to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward.  The 2020 Update stated, “A well-designed compliance program should apply risk-based due diligence to its third- party relationships. Although the need for, and degree of, appropriate due diligence may vary based on the size and nature of the company, transaction, and third party, prosecutors should assess the extent to which the company has an understanding of the qualifications and associations of third-party partners, including the agents, consultants, and distributors that are commonly used to conceal misconduct, such as the payment of bribes to foreign officials in international business transactions.” The question becomes how you use the information you obtained in the business justification and the questionnaire to determine an appropriate level of due diligence for the next step in the five-step process of third-party management. A three-step approach of varying levels of due diligence is the appropriate analysis to take going forward. There are many different approaches to the specifics of due diligence. By laying out some of the approaches, you can craft the relevant portions into your program. The Level I, II and III trichotomy appears to have the greatest favor and one that you should be able to implement in a straightforward manner. But the key is that you must assess your company’s risk and then manage that risk. If you need to perform additional due diligence to answer questions or clear red flags you should do so. And do not forget to “Document, Document, and Document” all your due diligence.  Three key takeaways:

A Level I due diligence should only be used where there is a low risk of corruption.

A Level II due diligence is sufficient in a high-risk jurisdiction if there are no red flags to be cleared.

Level III due diligence is deep dive, boots on the ground investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance programs, the issue of third-party management becomes more important. It is also the one where the rubber meets the road of operationalizingcompliance. It is also an area the DOJ specifically articulated in the 2020 Update that companies need to consider. Managing your third-parties is where the rubber meets the road in your overall third-party risk manage program. You must execute on this task. Even if you successfully navigate the first four steps in your third-party risk management program, those are in reality the easy steps. Managing the relationship is where the real work begins. Three key takeaways:

Have a strategic approach to third-party risk management.

Rank third parties based upon a variety of factors including compliance and business performance, length of relationship, benchmarking metrics and KPIs for ongoing monitoring and auditing.

Managing the relationship is where the real work begins.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As every compliance practitioner is well aware, third parties still present the highest risk under the FCPA. The 2020 Update devotes an entire prong to third-party management. It begins with the following:  Prosecutors should also assess whether the company knows the business rationale for needing the third party in the transaction, and the risks posed by third-party partners, including the third-party partners’ reputations and relationships, if any, with foreign officials. For example, a prosecutor should analyze whether the company has ensured that contract terms with third parties specifically describe the services to be performed, that the third party is actually performing the work, and that its compensation is commensurate with the work being provided in that industry and geographical region.   Prosecutors should further assess whether the company engaged in ongoing monitoring of the third-party relationships, be it through updated due diligence, training, audits, and/or annual compliance certifications by the third party. This clearly specifies that the DOJ expects an integrated approach that is operationalized throughout the company. This means you must have a process for the full life cycle of third-party risk management. There are five steps in the life cycle of third-party risk management, which will fulfill the DOJ requirements as laid out in the 2020 FCPA Resource Guide and in the Hallmarks of an Effective Compliance Program. They five steps in the lifecycle of third-party management are: 

Business Justification by the Business Sponsor;

Questionnaire to Third-party;

Due Diligence on Third-party, including triage of results;

Compliance Terms and Conditions, including payment terms; and

Management and Oversight of Third Parties After Contract Signing.

Three key takeaways:

Use the full 5-step process for third party management.

Make sure you have business development involvement and buy-in.

Operationalize all steps going forward by including business unit representatives.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

After you complete your risk assessment, you must then translate it into a risk profile. If your estimate of where your bribery risk is greatest is wrong, it will be an effort to address it. As Ben Locwin explained in his  BioProcess International article, entitled “Quality Risk Assessment and Management Strategies for Biopharmaceutical Companies”: Once we have assessed risks and determined a process that includes options to resolve and manage those risks whenever appropriate, then we can decide the level of resources with which to prioritize them. There always will be latent risks: those that we understand are there but that we cannot chase forever. But we need to make sure we have classified them correctly. With a good understanding of each of these, we are in a better position to speak about the quality of our businesses. William C. Athanas, in his Industry Week article, “Rethinking FCPA Compliance Strategies in a New Era of Enforcement”, posited that companies assume that FCPA violations follow a bell curve in which most employees are responsible for most of the violations. However, Athanas believed that the distribution pattern more closely follows a hockey-stick distribution, where virtually all violations are committed by just a few people. Athanas concluded by noting that is this limited group of employees, or what he terms the “shaft of the hockey-stick,” to which a company should devote the majority of its compliance resources. With a proper risk assessment, a company can then focus its compliance efforts such as intensive training sessions or detailed analysis of key financial transactions involving those employees with the greatest means and motive to commit a violation. The most significant risks with the greatest likelihood of occurring are deemed to be the priority risks. These become the focus of your most significant risk management efforts, couple with audit and monitoring going forward. A variety of tools can be used to continuously monitoring risk going forward. Consider providing employees with substantive training to guard against the most significant risks coming to pass and to keep the key messages fresh and top of mind. It is important to create a risk control summary that succinctly documents the nature of the risk and the actions taken to mitigate it. Finally, let this risk assessment and evaluation inform your compliance program, rather than letting the compliance program inform the risk assessment. Three key takeaways:

Even after you complete your risk assessment, you must evaluate those risks for your company.

The DOJ and SEC are looking for a well-reasoned approach on how you evaluate your risk.

Create a risk matrix and rank your risks; then remediate and monitor as appropriate.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based upon a risk assessment, to understand your organization’s business from the commercial perspective, how your organization has identified, assessed, and defined its risk profile and, finally, the degree to which the program devotes appropriate scrutiny and resources to this range of risks. Yet the 2020 Update added a new emphasis that Risk Assessments should not be done not less than annually but in reality it should be done each time your risk change. Over the past couple of years, every company's risks changed in going from Work From Home to Return to the Office to Hybrid Work environments. Have you assessed each of these new paradigms for risks from the compliance perspective?   As far back as 1999, in the Metcalf & Eddy enforcement action, the DOJ has said that risk assessments that measure the likelihood and severity of possible FCPA violations should direct your resources to manage these risks. The 2012 FCPA Guidance stated it succinctly when it said, “Assessment of risk is fundamental to developing a strong compliance program and is another factor DOJ and SEC evaluate when assessing a company’s compliance program.” There are a number of ways you can slice and dice your basic inquiry. As with almost all FCPA compliance, it is important that your protocol be well thought out. If you use one, some or all of the above as your basic inquiries for your risk analysis, it should be acceptable for your starting point.  Three key takeaways:

Since at least 1999, the DOJ has pointed to the risk assessment as the start of an effective compliance program.

The DOJ will now consider both your risk assessment methodology for identifying risks and gathered evidence.

You should base your compliance program on your risk assessment.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Companies have finally come to realize that institutional justice and fairness are perhaps the most basic tenet of any successful workplace. If employees believe they will be treated fairly, it will engender a level of trust that can work to not simply motivate employees but lead to a more successful workplace and, at the end of the day, a more profitable company. This encompasses the entire lifecycle of the employment relationship, from hiring through separation. It works in areas as seeming disparate as compensation and incentives, discipline, promotion and internal reporting.  On this final point, Kyle Welch and Stephen Stubben, in their 2019 paper entitled “Evidence on the Use and Efficacy of Internal Whistleblowing Systems”, noted that a robust whistleblower reporting system speaks to a functioning and ethical corporate culture. Employees who can report issues, in a fair manner, without fear of retaliation are more empowered to make the company run more efficiently and more profitably. Yet an equally interesting finding was where there was robust internal reporting, employees were more likely to speak up to improve overall business processes, thereby making the company more profitable. An often-overlooked role of any CCO or compliance professional is to help provide employees with institutional justice. If your compliance function is seen to be fair in the way it treats employees, in areas as varied as financial incentives, to promotions, to appropriate and consistent discipline meted out across the globe; employees are more likely to inform the compliance department when something goes array. If employees believe they will be treated fairly, it will go a long way to more fully operationalizing your compliance program. Three key takeaways:

The DOJ and SEC have long called for appropriate and consistent application of both incentives and discipline.

The Fair Process Doctrine will help set institutional justice as the norm in your organization.

Inconsistent application of discipline will destroy your compliance program credibility.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas that many companies have not paid as much attention to in their compliance programs is compensation. However, the DOJ and SEC have long made clear that they view monetary structure for compensation, rewarding those employees who do business in compliance with their employer’s compliance program, as one of the ways to reinforce the compliance program and the message of compliance. As far back as 2004, then SEC Director of Enforcement Stephen M. Cutler noted that integrity, ethics and compliance needed to be part of promotion, compensation and evaluation processes: “At the end of the day, the most effective way to communicate that “doing the right thing” is a priority, is to reward it.”  The 2020 FCPA Resources Guide stated the “DOJ and SEC recognize that positive incentives can also drive compliant behavior. These incentives can take many forms such as personnel evaluations and promotions, rewards for improving and developing a company’s compliance program, and rewards for ethics and compliance leadership.” Obviously, the power of a compensation plan is to motivate employees to not only to sell more but to act in ways that support your company’s business model and overall culture and values. For the compliance practitioner, one of the biggest reasons is to first change a company’s culture to make compliance more important, and then integrate it into the DNA of your organization. But you must be able to evolve in your thinking and professionalism to recognize the opportunities to change and then adapt your incentive program to make the doing of compliance part of your company’s everyday business process.  Three key takeaways:

The DOJ and SEC have long advocated compensation as a way to motivate employees into ethical and compliant behaviors

Keep the compliance aspects of your compensation structure simple and easy for your employees to understand

Have full transparency in the framework of your compensation structure

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the key goals of any compliance program is to train employees in awareness and understanding of the FCPA; your specific company compliance program; and to create and foster a culture of compliance. While it seems axiomatic that compliance training is a mainstay of any best practices compliance program, the conversation around training has evolved over the years. Beginning in the fall of 2016, through the announcement of the FCPA Enforcement Pilot Program, the DOJ began to talk about whether you have determined the effectiveness of your training. This conversation continued with the 2017 Evaluation where it asked, “How has the company measured the effectiveness of the training?” This point has bedeviled many compliance professionals yet is now a key metric for the government in evaluating compliance training. It evolved further in the 2020 Update with the mandate that training must be “truly effective”. Finally, the training must be presented in a language in which the employees understand, which means in a local language, if the training is outside the US or other non-English-speaking countries. The 2017 Evaluation focused into whether your training was “tailored” for the audience. This added two requirements. The first was to assess your employees for risk to determine the type of training you might need to deliver by risk ranking your employees. Obviously, the sales force would be the highest risk but there may be others who are deserving of high-risk training as well. From this risk ranking, you were required to develop tailored training for the risks those employees will face. What are ‘espresso shots’ of training to help facilitate effective training? Tina Rampino, Associate Managing Director, at K2 Integrity suggests keeping your compliance training segments concise as “shorter, bite-size learning is a trend in training programs.” This means that instead of offering half-day and full-day sessions, break programs into shorter segments of 20 minutes or less, which are easier for participants to absorb - and schedule. Another example is that short cartoons or animated videos can be excellent quarterly reminders. Done properly, they do not feel like an assessment or certainly not a ‘check-the-box’ exercise. The bottom line is that with all training most employees must undergo now and even more so in the continued time of the Covid-19 Omicron Variant, espresso shots give people back a lot of time.  Three key takeaways:

How and why have you tailored your compliance training and how do you determine its effectiveness?

Try an espresso shot of training.

How is your training presented: both in languages and media?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the message of compliance inside of a corporation and how it is distributed? In a compliance program, the largest portion of your consumers/customers are your employees. Social media presents some excellent mechanisms to communicate the message of compliance going forward. Many of the applications that we use in our personal communications are free or available at very low cost. Why not take advantage of them and use those same communication tools in your internal compliance marketing efforts going forward?  Louis Sapirman, Vice President and Chief Ethics & Compliance Officer for Panasonic Corporation of North America – Panasonic USA, often talks about the integration of social media into compliance. You should start with the tech-savvy nature of the today’s workforce. It is not simply about having a younger workforce but a workforce whose primary tool for communication is social media. If your company is in the services business, it probably means your employee base is using technological tools to deliver business solutions. Finally, consider the data-driven nature of business today so using technological tools to deliver products and solutions is something your company most probably does now. Finally, never forget the social part of social media. Social media is a more holistic, multiple-sided communication. Not only are you setting out expectations but also these tools allow you to receive back communications from your employees. The D&B experience around the name change for its Code of Conduct is but one example. You can also see that if you have several concerns expressed it could alert you earlier to begin some detection and move towards prevention in your compliance program. Another approach is to use audio as a part of your compliance communications. Podcasts are a great way to tell a long form story about your compliance successes and challenges. Ronnie Feldman, founder of L&E Entertainment continually reminds us that the engagement of your compliance audience is through the entertainment of your compliance communications. But the key is the audio format can be a powerful tool for you and a way to reach your employee base that you are not taking advantage. It can be as simple as interviewing employees on the importance of culture and how they use culture to guide their decision-making process in their daily work. You are only limited by your imagination.  Three key takeaways: 1. Incorporation of social media into your compliance communications can pay big dividends. 2. Focus on the ‘social’ part of social media. 3. Consider incorporating podcasts and other audio clips into your compliance communications and training. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A 360-degree view of compliance is an effort to incorporate your compliance identity into a holistic approach so that compliance is in touch with and visible to your employees at all times. It is about creating a distinctive brand philosophy of compliance which is centered on your consumers. In other words, it helps a compliance practitioner to anticipate all the aspects of your employees needs around compliance. This is especially true when compliance is either perceived as something that comes out of the home office or is perceived as the “Land of No.” A 360-degree view of compliance gives you the opportunity to build a new brand image for your compliance program. This is important as the 2020 Update mandates that for a compliance program to be effective, it must be understood by a wide variety of stakeholders. Communications is often thought of as a two-way street, upward and downward, inbound and outbound, or side-to-side. However, it is better to think of it as a 360-degree effort. You simply can no longer effectively communicate in just two ways. You now communicate in a more holistic manner, and in multiple ways. If you are just thinking about communications in the classic form, you are missing something that is happening around you. 360-degrees of compliance communication is not just a classic form of communication but rather it is a communication in the concept of every interaction, whether they be planned or accidental. It is all a form of communication. This is particularly true if you are a compliance professional, practitioner or CCO. The things you do, the way you act, and the way people see you, you are always communicating. It is not simply communicating one to one as often you may be communicating to a group across siloed boundaries, to the constituencies you had not even planned to initially communicate with. It also allows you to see and hear new ideas, concepts or simply ways to create a more effective compliance regime for your front line BD folks and your first line of defense.  Three key takeaways: 1. Remember the definition of 360-degrees of communication. It is an effort that moves the compliance identity into a holistic approach so compliance is in touch and visible to your employees at all times 2. What is your objective? What are you trying to do with your 360-degrees of communications and how are you using that mechanism to deliver the objectives of your compliance program? 3. Evaluate. You need to evaluate three factors: 1) has the message been delivered; 2) has it been heard; and 3) is it being implemented? Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are internal controls? The best definition I have come across is from Jonathan Marks who defined internal controls as: An internal control is an action or process of interlocking activities designed to support the policies and procedures detailing the specific preventative, detective, corrective, directive and corroborative actions required to achieve the desired process outcomes or the objectives(s). This, along with continuous auditing, continuous monitoring and training reasonably assures: 

The achievement of the process objectives linked to the organization’s objectives;

Operational effectiveness and efficiency;

Reliable (complete and accurate) books and records (financial reporting);

Compliance with laws, regulations and policies; and 

The reduction of risk-fraud, waste and abuse, which,

Aids in the decline of process and policy variation, leading to more predictive outcomes. The DOJ and SEC, in the 2020 FCPA Resource Guide, stated: Internal controls over financial reporting are the processes used by compa­nies to provide reasonable assurances regarding the reliabil­ity of financial reporting and the preparation of financial statements. They include various components, such as: a control environment that covers the tone set by the organi­zation regarding integrity and ethics; risk assessments; con­trol activities that cover policies and procedures designed to ensure that management directives are carried out (e.g., approvals, authorizations, reconciliations, and segregation of duties); information and communication; and monitoring. … The design of a company’s internal controls must take into account the operational realities and risks attendant to the company’s business, such as: the nature of its products or services; how the products or services get to market; the nature of its work force; the degree of regulation; the extent of its government interaction; and the degree to which it has operations in countries with a high risk of corruption. This was supplemented in the 2020 Update, with a pair of pointed questions: whether a company has made significant investigation into its internal controls and have they been tested, then remediated based upon the testing? The bottom line is that internal controls are just good financial controls. The internal controls that detail requirements for third-party representatives in the compliance context will help to detect fraud, which could well lead to bribery and corruption. As an exercise, map your existing internal controls to the Ten Hallmarks of an Effective Compliance Program or some other well-known anti-corruption regime to see where gaps may exist. This will help you to determine whether adequate compliance internal controls are present in your company. From there you can move to see if they are working in practice. Three key takeaways:

Effective internal controls are required under the FCPA

Internal controls are a critical part of any best practices compliance program

There are four significant controls for the compliance practitioner to implement initially. (a) Delegation of authority (DOA); (b) Maintenance of the vendor master file; (c) Contracts with third parties; and (d) Movement of cash/currency.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There are numerous reasons to put some serious work into your compliance policies and procedures. They are certainly a first line of defense when the government comes knocking. The 2020 Update made clear that “Any well-designed compliance program entails policies and procedures that give both content and effect to ethical norms and that address and aim to reduce risks identified by the company as part of its risk assessment process.” This statement made clear that the regulators will take a strong view against a company that does not have well thought out and articulated policies and procedures against bribery and corruption; all of which are systematically reviewed and updated. Moreover, having policies written out and signed by employees provides what some consider the most vital layer of communication and acts as an internal control. Together with a signed acknowledgement, these documents can serve as evidentiary support if a future issue arises. In other words, the “Document, Document, and Document” mantra applies just as strongly to policies and procedures in anti-corruption compliance. The specific written policies and procedures required for a best practices compliance program are well known and long established. According to the 2020 FCPA Resources Guide, some of the risks companies should keep in mind include the nature and extent of transactions with foreign governments (including payments to foreign officials); use of third parties; gifts, travel, and entertainment expenses; charitable and political donations; and facilitating and expediting payments. Policies help form the basis of expectations for standards of conduct in your company. Procedures are the documents that implement these standards of conduct.  Three key takeaways: 1. Written compliance policies and procedures, together the Code of Conduct, with form the backbone of your compliance program. 2. The DOJ and SEC expect a well-thought out and articulated set of compliance policies and procedures and that they be adequately communicated throughout your organization. 3. Institutional fairness for the application of policies and procedures demands consistent application of your policies and procedures across the globe. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the value of having a Code of Conduct? In its early days, a Code of Conduct tended to be lawyer-written and lawyer-driven to wave in regulator’s face during an enforcement action as proof of ethical overall behavior. Is such a legalistic code effective? Is a Code of Conduct more than simply your company’s internal law? What should be the goal in the creation of your company’s Code of Conduct? How important is the Code of Conduct? Consider the 2016 SEC enforcement action involving United Airlines, Inc., which turned on violation of the company’s Code of Conduct. The breach of the Code of Conduct was determined to be a FCPA internal controls violation. It involved a clear quid pro quo benefit paid out by United to David Samson, the former Chairman of the Board of Directors of the Port Authority of New York and New Jersey, the public government entity which has authority over, among other things, United’s operations at the company’s huge east coast hub at Newark, NJ. The substance of your Code of Conduct should be tailored to your company’s culture, and to its industry and corporate identity. It should provide a mechanism by which employees who are trying to do the right thing in the compliance and business ethics arena can do so. The Code of Conduct can be used as a basis for employee review and evaluation. It should certainly be invoked if there is a violation. Your company’s disciplinary procedures must be stated in the Code. These would include all forms of disciplines, up to and including dismissal, for serious violations of the Code. Further, your company’s Code should emphasize it will comply with all applicable laws and regulations, wherever it does business. The code needs to be written in plain English and translated into other languages as necessary so that all applicable persons can understand it. Three key takeaways: 1. A Code of Conduct is a foundational document in any compliance regime.  2. The substance of your Code of Conduct should be tailored to the company’s culture, to its industry and corporate identity. 3. “Document, Document, and Document” your training and communication efforts regarding you Code of Conduct. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The most significant development for Boards and compliance in 2021 came from the Delaware courts, which have been expanding the civil law obligations of Boards through a series of court decisions involving the expansion of the Caremark Doctrine for a couple of years. These developments began with the Marchand decision which required Boards to manage the risks their organizations face. Next was the Clovis Oncology which required ongoing monitoring by the Board. The next case is Hughes which stands for the proposition that having the structures, policies and procedures in place is not enough. The Board must fully engage in oversight of a compliance program. Finally in 2021 came Boeing which stands for the continuing proposition that a Board cannot simply have the trappings of oversight, it must do the serious work required and have evidence of that work (Document, Document, and Document). The decision in Boeing is yet a further expansion of the Caremark Doctrine, once again beginning with Marchand. Boeing also stands for the proposition that a company must assess its risks and then manage those risks right up through the Board level. Finally a Board must be aggressive in their approach and not simply passively taking in what management has presented to them.  The DOJ has also made clear its thoughts on the role of the Board of Directors. The role of the Board is different than that of senior management. Both the 2020 Update  and DOJ Antitrust Division’s 2019 Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations was even more explicit in announcing their expectation for robust Board oversight of a corporate compliance function.  Name any of the most recent corporate scandals; Wells Fargo, Theranos, Volkswagen, Boeing, etc., and there was no compliance expertise on the Board. It is now enshrined as a best practice for companies to have a seasoned compliance professional on the Board. I would also add the DOJ may soon expect there be a Compliance Committee separate and apart from the Audit Committee. The DOJ continually speaks about the need for companies to operationalize their compliance programs. Businesses must work to integrate compliance into the DNA of their organization. Having a Board member with specific compliance expertise or heading a Compliance Committee can provide a level of oversight and commitment to achieving this goal. The DOJ enshrined this requirement in the FCPA Corporate Enforcement Policy. This means that when your company is evaluated by the DOJ, under the factors set out in the 2020 Update and FCPA Corporate Enforcement Policy, to retrospectively determine if your company had a best practices compliance program in place at the time of any violation, you need to have not only the structure of the Board-level Compliance Committee but also the specific subject matter expertise (SME) on the Board and on that committee. All of this means that every Board of Directors needs a true compliance expert. Almost every Board has a former Chief Financial Officer (CFO), former head of Internal Audit or persons with a similar background, and often times these are also the Audit Committee members of the Board. Such a background brings a level of sophistication, training and SME that can help all companies with their financial reporting and other finance-based issues. So why is there not such SME at the Board level from the compliance profession?

Comment Begins

Three key takeaways: 1. The 2020 Update required active Board of Director engagement and oversight around compliance. 2. Board communication on compliance is a two-way street; both inbound and outbound. 3. The Delaware courts have been expanding Boards roles through expansion of the Caremark Doctrine. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Mike Volkov has said, “Even when a company does all the right things at the senior management level, the real issue is whether or not that culture has embedded itself in middle and lower management. A company’s culture is reflected in the values and beliefs that exist throughout the company.” To fully operationalize your compliance program, you must articulate the message of ethical values and doing business in compliance and then drive that message from the top down, throughout your organization. What should the tone in the middle be? What should middle management’s role be in the company’s compliance program? This role is critical because the majority of company employees work most directly with middle, rather than top management and, consequently, they will take their cues from how middle management responds to a situation. Perhaps most importantly, middle management must listen to the concerns of employees. Even if middle management cannot affect a direct change, it is important that employees have an outlet to express their concerns. Your organization should train middle managers to enhance listening skills in the overall context of providing training for their “Manager’s Toolkit.” This can be particularly true if there is a compliance violation or other incident which requires some form of employee discipline. Most employees think it important that there be organizational justice so that people believe they will be treated fairly. For if there is organizational justice, it engenders perceived procedural fairness which makes it more likely an employee will be willing accept a decision that they may not like or disagree with the end result. Even with great “tone at the top” and positive “mood in the middle”, you cannot stop. One of the greatest challenges of a compliance practitioner is how to impact the most front-line employees or the “tone at the bottom”. One of the things you can do is assemble a compliance focus group to find out how business is done in the field and if it differs from what your company expects from an ethical and compliance perspective. Begin by assembling a group of employees who are familiar with the challenges of doing business in a compliant manner in certain geographic regions to discuss the challenges of doing business ethically and in compliance. Ask them questions about their understanding of your compliance regime. Then categorize the answers into the theory and practice of compliance in your company. Employees often look to their direct supervisor to determine what the tone of an organization is and will be going forward. Many employees of large, multi-national organizations may never have direct contact with the CEO or even senior management. By moving the values of compliance through an organization into the middle, you will be in a much better position to inculcate these values and operationalizing compliance with them.  Three key takeaways: 1. Tone at the top—direct supervisors become the most important influence on people in the company 2. Give your middle managers a Tool Kit around compliance so they can fully operationalize compliance 3. Organizational justice is an additional way to help operationalize compliance Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

DAG Lisa Monaco’s speech on FCPA enforcement and compliance laid out the very basics; that the key to every company is culture. She stated, “corporate culture matters. A corporate culture that fails to hold individuals accountable, or fails to invest in compliance — or worse, that thumbs its nose at compliance — leads to bad results.” From the enforcement perspective, the DOJ will be assessing companies for the ethical cultures. From the compliance perspective, the ethical tone of a company and accountability all starts at the top and, most specifically, senior management. This requirement is more than simply the ubiquitous “tone-at-the-top,” as it focuses on the conduct of senior management. The DOJ wants to see a company’s senior leadership actually doing compliance. The DOJ asks if company leadership has, through their words and concrete actions, brought the right message of doing business ethically and in compliance to the organization. How does senior management model its behavior on a company’s values and finally, how is such conduct monitored in an organization? I once had a Chief Executive Officer (CEO), observe the following, “You want me to be the ambassador for compliance.” I immediately said yes, that is exactly what I need you to do. A CEO, as an “Ambassador of Compliance”, can fully model the conduct that senior management engage in going forward. Another area a CEO can forcefully engage an entire company is through a powerful video message about doing business the right way and in compliance. A great example was a CenterPoint Energy video put out in 2015 after the Volkswagen (VW) emissions-testing scandal became public. The video featured Scott Prochazka, CenterPoint Energy President and CEO. He used the VW scandal to proactively address culture and values at the company and used the entire scenario as an opportunity to promote integrity in the workplace. But more than simply a one-time video, the company followed up with an additional resource, entitled, Manager’s Toolkit—What does Integrity mean to you? that managers used to facilitate discussions and ongoing communications with employees around the company’s ethics and compliance programs. Finally, the cost for the video was quite reasonable as it was produced internally.

Three key takeaways: 1. Senior management must actually do compliance; not simply talk-the-talk of compliance but also walk-the-walk. 2. Use your CEO to talk about current events and how those ethical failures are lessons to be learned for your organization. 3. Your CEO as Compliance Ambassador. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Continuous monitoring and continuous improvement are two of the most important phrases for any compliance program. These twin concepts were perhaps the biggest modifications in the 2020 Update to the Evaluation of Corporate Compliance Programs. In 2021, all companies’ risks changed as we moved from Working From Home to Return To Office and now a hybrid work model. These changes in our basic work location drove home perhaps the most prescient comment I heard during the pandemic year of 2020, which was by Jed Gardner, who said “We have moved from disaster recovery to business continuity to business as usual.” What this means is that risks will change in ways you may not see at speeds you not anticipate. Your compliance program must be ready to respond to whatever those risks might be going forward. 

In the 2020 Update, the DOJ it began to address this from the compliance program perspective with several questions. “Is the risk assessment current and subject to periodic review? Is the periodic review limited to a “snapshot” in time or based upon continuous access to operational data and information across functions? Has the periodic review led to updates in policies, procedures, and controls? Do these updates account for risks discovered through misconduct or other problems with the compliance program?” 

The next area for continuous monitoring and continuous improvement was in an area of compliance which is not normally associated with those concepts, Policies and Procedures. Here questions included “When was the last time your policies and procedures were updated? Perhaps more importantly under the 2020 Update what was your process for doing so? Was there any rigor around your process? Did that rigor include incorporating information and data collected through continuous monitoring, real-time monitoring or continuous access to operational data and information across functions?”

The final area in the 2020 Update for consideration is appropriate called Continuous Improvement, Periodic Testing and Review. Here the question included the following, “How often has the company updated its risk assessments and reviewed its compliance policies, procedures, and practices? Has the company undertaken a gap analysis to determine if particular areas of risk are not sufficiently addressed in its policies, controls, or training? What steps has the company taken to determine whether policies/procedures/practices make sense for particular business segments/subsidiaries? Does the company review and adapt its compliance program based upon lessons learned from its own misconduct and/or that of other companies facing similar risks?”

Three key takeaways:  1. How has your company’s risks changed over the past year? 2. What is your process for continuous monitoring and improvement? 3. What sources of information do you use come from outside your organization? Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days series in January 2021, I will post a key part a best practices compliance program each day. By the end of January, you will have enough information to create, design or enhancement a compliance program. Each podcast will be short, at 6-8 minutes with three key takeaways that you can implement at little or no cost to help update your compliance program. I hope you will plan to join each day in January for this exploration of best practices in compliance. 2021 was a very significant year for every compliance practitioner and compliance program. While there was a paucity of corporate FCPA enforcement actions, the three enforcement actions were significant with multiple lessons for the compliance professional. In Deutsche Bank, we learned about the costs of a corrupt culture and recidivism, in Amec Foster Wheeler, we saw happens to a company which pays bribes and then tries back out; the criminals they are dealing with have them in an untenable position that they must continue to pay the bribes and how catastrophic failure in pre- and post-acquisition due diligence can lead to massive FCPA violations. Finally, in WPP, we saw how accepted business incentives can become perverse, what happens when you ignore whistleblowers. However, there were two major policy announcements from the Biden Administration which every compliance professional needs to not simply be aware of but study and implement solutions based upon these announcements.  In late October, Deputy Attorney General Lisa O. Monaco key changes in the DOJ approach to FCPA enforcement.: (1) “today I am directing the department to restore prior guidance making clear that to be eligible for any cooperation credit, companies must provide the department with all non-privileged information about individuals involved in or responsible for the misconduct at issue. To be clear, a company must identify all individuals involved in the misconduct, regardless of their position, status or seniority.” This portends a return to the strictures of the Yates Memo. (2) “The second change I am announcing today deals with the issue of a company’s prior misconduct and how that affects our decisions about the appropriate corporate resolution. (3) The final change I am announcing today deals with the use of corporate monitors.” This final change is a rejection of the strictures laid out in the Benczkowski Memo regarding the DOJ use of corporate monitorships. In November, the Biden Administration released the United States Strategy on Countering Corruption (the “Strategy”); subtitled “Pursuant To The National Security Study Memorandum On Establishing The Fight Against Corruption as a Core United States National Security Interest”; in response to President Biden’s prior declaration of corruption as a national security issue of the United States. While obviously focused on the US government’s role in leading the fight against corruption, the entire document portends a major sea change in the approach of fighting bribery and corruption, literally on a worldwide basis. For this reason alone, it should be studied by all compliance professionals. Obviously, this more holistic approach is most welcomed. Corruption does more than simply steal money from the world economy.  Three key takeaways:

The Biden Administration released its Strategy on Countering Corruption.

Deputy Attorney General Lisa Monaco gave a speech refocusing the DOJ’s efforts on FCPA and other white-collar crime.

Even with a paucity of FCPA enforcement actions, there were multiple lessons for the compliance professional.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update re-emphasized the need for both performing a root cause analysis but equally importantly using it to remediate your compliance program. It stated, “a hallmark of a compliance program that is working effectively in practice is the extent to which a company is able to conduct a thoughtful root cause analysis of misconduct and timely and appropriately remediate to address the root causes.”  It went on to state, what additional steps the company has taken “that demonstrate recognition of the seriousness of the misconduct, acceptance of responsibility for it, and the implementation of measures to reduce the risk of repetition of such misconduct, including measures to identify future risk”).” The key is that after you have identified the causes of problems, consider the solutions that can be implemented by developing a logical approach, using data that already exists in the organization. Identify current and future needs for organizational improvement. Your solution should be a repeatable, step-by-step processes, in which one process can confirm the results of another. Focusing on the corrective measures of root causes is more effective than simply treating the symptoms of a problem or event and you will have a much more robust solution in place. This is because the solution(s) are more effective when accomplished through a systematic process with conclusions backed up by evidence. When you step back and consider what the DOJ was trying to accomplish with its 2020 Update, it becomes clear what the DOJ expects from the compliance professional. Consider the structure of your compliance program and how it inter-relates to your company’s risk profile. When you have a compliance failure, use the root cause analysis to think about how each of the structural elements of your compliance program could impact how you manage and deal with that risk. Three key takeaways:

The key is objectivity and independence.

The critical element is how did you use the information you developed in the root cause analysis?

The key is that after you have identified the causes of problems, consider the solutions that can be implemented by developing a logical approach, using data that already exists in the organization.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the biggest changes in the 2020 FCPA Resource Guide is the addition of a new Hallmark, entitled “Investigation, Analysis, and Remediation of Misconduct”, which reads in full: The truest measure of an effective compliance program is how it responds to misconduct. Accordingly, for a compliance program to be truly effective, it should have a well-functioning and appropriately funded mechanism for the timely and thorough investigations of any allegations or suspicions of misconduct by the company, its employees, or agents. An effective investigations structure will also have an established means of documenting the company’s response, including any disciplinary or remediation measures taken. In addition to having a mechanism for responding to the specific incident of misconduct, the company’s program should also integrate lessons learned from any misconduct into the company’s policies, training, and controls. To do so, a company will need to analyze the root causes of the misconduct to timely and appropriately remediate those causes to prevent future compliance breaches.  Ultimately, performing a root cause analysis is not simply a matter of sitting down and asking a multitude of questions. You need to have an operational understanding of how a business operates and how they have developed their customer base. Overlay the need to understand what makes an effective compliance program, with the skepticism an auditor should bring so that you do not simply accept an answer that is provided to you, as you might in an internal investigation. As Marks noted, “a root cause analysis is not something where you can just go ask the five whys. You need these trained professionals who really understand what they’re doing.” Three key takeaways:

A root cause analysis is now required if you have a reportable compliance failure.

There is no one process for performing a root cause analysis. You should select the one which works for you and follow it.

To properly perform a root cause analysis, you need trained professionals who really understand what they’re doing.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Your company has just made its largest acquisition ever and your CEO says they want you to have a compliance post-acquisition integration plan on their desk in one week. Where do you begin? A good place to start would be the 2020 FCPA Resource Guide language: Pre-acquisition due diligence, however, is normally only a portion of the compliance process for mergers and acquisitions. DOJ and SEC evaluate whether the acquiring company promptly incorporated the acquired company into all of its internal controls, including its compliance program. Companies should consider training new employees, reevaluating third parties under company standards, and, where appropriate, conducting audits on new business units. The bottom line is that you must train the newly acquired employees, reevaluate third parties under your company standards, and conduct compliance audits on new business units. This process should be based your pre-acquisition due diligence and risk assessment. Moreover, the DOJ and SEC clearly view both the pre- and post-acquisition phases of M&A as tied together in a unidimensional continuum. If pre-acquisition due diligence is not possible, you should review the requirements and time frames laid out in Opinion Release 08-02 or the 2020 FCPA Resource Guide, which noted, “pursuant to which companies can nevertheless be rewarded if they choose to conduct thorough post-acquisition FCPA due diligence.” Whatever compendium of steps you utilize for post-acquisition integration, they should be taken as soon as is practicable.  The earlier you can deploy these steps the better off your company will be at the end of the day. An acquisition that fails for compliance reasons is a preventable disaster of the first order. One need only consider the Latin Node Inc. FCPA enforcement actions where the acquiring company had to write off its entire investment because it had wholly failed to engage in appropriate pre-acquisition due diligence.  Three key takeaways:

Planning is critical in the post-acquisition phase.

Build upon what you learned in pre-acquisition due diligence.

You literally need to be ready to hit the ground running when a transaction closes.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A company that does not perform adequate due diligence prior to a merger or acquisition may face both legal and business risks. Perhaps most commonly, inadequate due diligence can allow a course of bribery to continue - with all the attendant harms to a business’s profitability and reputation, as well as potential civil and criminal liability. While most compliance practitioners have been long aware of the requirement in the post-acquisition context, the 2012 FCPA Guidance focused many compliance practitioners of the need to engage in robust pre-acquisition due diligence.  The 2020 Update made even more clear the need for a robust compliance presence in the pre-acquisition phase. It stated, “A well-designed compliance program should include comprehensive due diligence of any acquisition targets, as well as a process for timely and orderly integration of the acquired entity into existing compliance program structures and internal controls. Pre-M&A due diligence, where possible, enables the acquiring company to evaluate more accurately each target’s value and negotiate for the costs of any corruption or misconduct to be borne by the target. Flawed or incomplete pre- or post-acquisition due diligence and integration can allow misconduct to continue at the target company, causing resulting harm to a business’s profitability and reputation and risking civil and criminal liability.” There are multiple red flags which could be raised in this process, which might well warrant further investigation. They include if the target has ineffective compliance program elements in their compliance program or if there were frequent breach of policies and procedures. Obviously, a target which is in financial difficulty would bear closer scrutiny. Structurally, if the company did not have a formal ethics and compliance committee at the senior management or Board of Directors’ level, this could present issues. From the CCO perspective, if the position did not have Board or CEO access or if there were not regular reports to the Board, it could present an issue for compliance. Conversely, if there were frequent requests to waive policies, management over-ride of compliance controls or no consistent consequence management for violations; it could present clear red flags for further investigation. Three key takeaways: 

The results of your pre-acquisition due diligence will inform your post-acquisition integration and remediation going forward.

Periodically review your M&A due diligence protocol.

If red flags appear in pre-acquisition due diligence, they should be cleared.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas articulated in the 2020 Update was around payments and payroll. For the both the compliance professional and the corporate payroll function, there is a significant role to play in the operationalization of a corporate compliance program. The 2020 Update was replete with references to payment and its critical nature to any best practices compliance program. This includes references to payments to foreign officials, payments to third parties and hiding bribes in payments to distributors. The 2020 Update begins with an admonition to stop wasting time on low hanging fruit when there are much higher risks in your business operations. The role of payroll in compliance is not often considered in operationalizing your compliance program, yet the monies to fund bribes must come from somewhere. Unfortunately, one of those places is out of payroll. All CCOs need to sit down with his or her head of payroll, have them explain the role of payroll, then review the internal controls in place to see how they facilitate the goals of compliance. From that review, you can then determine how to use payroll to help to operationalize your compliance program. The DOJ has now provided its clearest statement on how it expects a company to actually do compliance going forward. Long gone are the days where the DOJ simply considered the inputs of a written program as sufficient to protect companies from compliance violations. Yet the mandate to operationalize a corporate compliance program drives home the concept that compliance is a business process, which should be administered by the appropriate business unit with the requisite SME. When it comes to following the money, payroll is the most well-suited corporate discipline to provide this first level of oversight and controls.  Three key takeaways:

Payroll can be a key prevent and detect control.

The 2020 Update specified the tying of the corporate compliance function to the corporate payroll function.

Offshore payments remain a key indicator for a red flag.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The role of the compliance professional and the compliance function in a corporation has steadily grown in stature and prestige over the years. When it came to the corporate compliance function, 2020 FCPA Resource Guide, under the Hallmarks of an Effective Compliance Program, simply noted the government would “consider whether the company devoted adequate staffing and resources to the compliance program given the size, structure, and risk profile of the business.” This Hallmark was significantly expanded in both the FCPA Corporate Enforcement Policy and 2020 Update. In the FCPA Corporate Enforcement Policy, the DOJ listed the following as factors relating to a corporate compliance function, that it would consider as indicia of an effective compliance and ethics program: 1) the resources the company has dedicated to compliance; 2) the quality and experience of the personnel involved in compliance, such that they can understand and identify the transactions and activities that pose a potential risk; 3) the authority and independence of the compliance function and the availability of compliance expertise to the board; 4) the compensation and promotion of the personnel involved in compliance, in view of their role, responsibilities, performance, and other appropriate factors; and 5) the reporting structure of any compliance personnel employed or contracted by the company. The 2020 Update and FCPA Corporate Enforcement Policy both demonstrate the continued evolution in the thinking of the DOJ around the corporate compliance function. Their articulated inquiries can only strengthen a corporate compliance function specifically; and the compliance profession more generally. The more the DOJ talks about the independence of the compliance function, coupled with resources being made available and authority concomitant with the corporate compliance function, the more corporations will see it is directly in their interest to provide the resources, authority and gravitas to compliance position in their organizations. Three key takeaways:

How is compliance treated in the budget process?

Has your compliance function had any decisions over-ridden by senior management?

Beware outsourcing of compliance as any such contractor must have access to company documents and personnel.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The role of the CCO has steadily grown in stature and prestige over the years. In the 2020 FCPA Resource Guide, under the Hallmarks of an Effective Compliance Program, it focused on the whether the CCO held senior management status and had a direct reporting line to the Board.  This Hallmark was significantly expanded in both the 2020 Update and the FCPA Corporate Enforcement Policy. And in so doing, the DOJ has increased the prestige, authority and role of both the CCO and corporate compliance function. The 2020 Update has five general areas of inquiry around the CCO and corporate compliance function. (1) How does the CCO salary and stature within the organization compare to other senior executives within the company. (2) What are the experience and stature of the CCO with an organization? Does the CCO have appropriate training for the role? (3) How much autonomy does the CCO have to report to the Board of Directors? How often do the CCO meet with directors? Are members of the senior management present for these meetings with the Board of Directors or of the Audit Committee? (4) What is your structure? Is the compliance function run by a designated chief compliance officer, or another executive within the company, and does that person have other roles within the company? (5) Is data in your organization so siloed that the CCO does not have access to it? If so, what are you doing about it? Once again for the compliance professional, the FCPA Corporate Enforcement Policy and 2020 Update make the importance of a best practices compliance program even more critical. The DOJ is focusing more on the role, expertise and how the compliance function is treated within an organization. Pay your CCO considerably less than your GC? You may now better be able to justify that discrepancy. If you have a legal department budget of $3 million and a compliance department budget of $500,000; you may be starting behind the eight-ball. Three key takeaways:

How can you show the CCO really has a seat at the senior executive table?

What are the professional qualifications of your CCO?

Does your CCO have true independence to report directly to the Board of Directors?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the critical elements found in the 2020 Update is the need to use the information you obtain, whether through risk assessment, root cause analysis, investigation, hotline report or any other manner to remediate the situation which allowed it to arise. Your company should establish a regular monitoring system to spot issues and address them. Effective monitoring means applying a consistent set of protocols, checks, and controls tailored to your company’s risks to detect and remediate compliance problems on an ongoing basis. To address this, your compliance team should be checking in routinely with local finance departments in your foreign offices to ask if they have noticed recent accounting irregularities. Regional directors should be required to keep tabs on potential improper activity in the countries in which they manage. These ongoing efforts demonstrate that your company is serious about compliance. It is a function of the CCO to reinforce the vision and goals of the compliance function, where assessment and updating are critical to an ongoing best practices compliance program. If you follow this protocol, you will put a mechanism in place to demonstrate your company’s commitment to compliance by following through on intentions as set forth in your strategic plan. What should you do with this information? Put a strategic plan in place ready to implement your findings of continuous improvement, by using the following:

Review the goals of the strategic plan. This requires that you arrange a time for the CCO and team to review the goals of the Strategic Plan, which the CCO should lead to determine how this goal in the Plan measures up to its implementation in your company.

Design an execution plan. The KISS method (Keep it Simple Sir) is the best to move forward. This would suggest that for each compliance goal, there should be a simple and straight forward plan to ensure that the goal in question is being addressed.

Put accountabilities in place. In any plan of execution, there must be accountabilities attached to them. This requires the CCO or other senior compliance department representatives to put these in place and then mandate a report requirement on how the task assigned is being achieved.

Schedule the next review of the plan. There should be a regular review of the process. It allows any problems which may arise to be detected and corrected more quickly than if meetings are held at a less frequent basis.

Continuous monitoring is a key step but it is only the first step. It is not simply that you tested your compliance program but that you did something with the information you obtained to improve your program. Three key takeaways:

Innovation can come through a new way to think about and use data going forward.

Have a plan in place to use the information garnered in your monitoring incorporated back into your compliance program.

Always remember that Document Document Document is critical if the regulators come knocking.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the specific requirements laid out in the 2020 Update, is around internal controls and more specifically control testing. It stated: Control Testing – Has the company reviewed and audited its compliance program in the area relating to the misconduct? More generally, what testing of controls, collection and analysis of compliance data, and interviews of employees and third-parties does the company undertake? How are the results reported and action items tracked?    Fortunately, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) 2013 Internal Controls Framework considers assessing compliance internal controls. In “Internal Controls – Integrated Framework, Illustrative Tools for Assessing Effectiveness of a System of Internal Controls”, COSO laid out its views on assessing the effectiveness of internal controls. It noted that an effective system of internal controls provides “reasonable assurance of achievement of the entity’s objectives, relating to operations, reporting and compliance.” Moreover, there are two over-arching requirements that can only be met through such a structured protocol. First, each of the five components are present and functioning. Second, that the five components operate in an integrated fashion with each other. One of the most critical components of the COSO Framework is that it sets internal control standards against those which you can audit to assess the strength of your compliance internal controls.  Three key takeaways:

An effective system of internal controls provides reasonable assurance of achievement of the company’s objectives, relating to operations, reporting and compliance.

There are two over-arching requirements for effective internal controls. First, each of the five components are present and function. Second, are the five components operating together in an integrated approach.

For an anti-corruption compliance program, you can use the Hallmarks of an Effective Compliance Program as your guide to test against.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The call, email or tip comes into your office; an employee reports suspicious activity somewhere across the globe. That activity might well turn into a FCPA issue for your company. As the CCO, it will be up to you to begin the process which will determine, in many instances, how the company will respond going forward.  This scenario was driven home by the SEC in a 2015 FCPA enforcement action involving Mead Johnson Nutrition Company. In this enforcement action, the company performed two internal investigations into allegations that its Chinese business unit was engaged in conduct which violated the FCPA. Unfortunately, the first investigation, performed in 2011, did not turn up any evidence of FCPA violations. It was not until 2013, when the SEC made an inquiry to the company that it performed an adequate internal investigation which uncovered FCPA violations. Internal reporting. The 2020 FCPA Resource Guide has as clear and concise a statement about hotlines as any other requirement found in Hallmarks of an Effective Compliance Program. It states: "An effective compliance program should include a mechanism for an organization’s employees and others to report suspected or actual misconduct or violations of the company’s policies on a confidential basis and without fear of retaliation." Triaging claims. Given the number of ways that information about violations or potential violations can be communicated to the government regulators, having a robust triage system is an important way that a company can determine what resources to bring to bear on a compliance problem. Jonathan Marks has articulated a five-stage triage process which allows for not only an early assessment of any allegations but also a manner to think through your investigative approach. Marks cautions you must have an experienced investigator or other seasoned professional making these determinations, if not a more well-rounded group or committee. Next, consider what will be the types of evidence to review going forward. Finally, before selecting a triage solution, understand what tools are available, including both forensic and human, to complete the investigation. Finally, after you ascertain you have an effective reporting mechanism through your hotline and demonstrate you have a robust and properly scoped investigation protocol, you must use the information you receive to remediate any issues which may arise. It is not enough merely to show that a hotline exists, you must present the data it produces. Three key takeaways:

The DOJ and SEC put special emphasis on internal reporting lines.

Test your hotline on a regular basis to make sure it is working.

Have an investigation protocol in place before the call comes in so you will be ready to go and not required to scramble to create a protocol.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update was very clear about the need for continuous improvement in any compliance program. It stated quite succinctly, “One hallmark of an effective compliance program is its capacity to improve and evolve. The actual implementation of controls in practice will necessarily reveal areas of risk and potential adjustment. A company’s business changes over time, as do the environments in which it operates, the nature of its customers, the laws that govern its actions, and the applicable industry standards. Accordingly, prosecutors should consider whether the company has engaged in meaningful efforts to review its compliance program and ensure that it is not stale.”   Continuous improvement through continuous monitoring or other similar techniques will help keep your compliance program abreast of any changes in your business model’s compliance risks and allow growth based upon new and updated best practices specified by regulators. A compliance program is in many ways a continuously evolving organism, just as your company is. You need to build in a way to keep pace with both market and regulatory changes to have a truly effective anti-corruption compliance program.  Three key takeaways:

Your compliance program should be continually evolving.

Monitoring and auditing are different, yet complimentary tools for continuous improvement.

Culture assessment and monitoring are also now required as well.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There is nothing like an internal whistleblower report about a compliance violation, the finding of such an issue, or (even worse) a subpoena from the DOJ or notice letter from the SEC to trigger the Board of Directors and senior management attention to the compliance function and the company’s compliance program. Such an event can trigger much gnashing of teeth and expressions of outrage followed immediately by proclamations “We are an ethical company.” However, it may well be the time for a very serious reality check.  You may find yourself in the position that you will have to have some very frank discussions about what to expect in terms of costs and time outlays. While much of these discussions will focus on the investigative process and those costs, these discussions will allow you to initiate the talk about remediation going forward and begin to explain why money must be budgeted for the remediation process. One of the things rarely considered is how the investigation triggers the remediation process and what the relationship is between the two. When issues arise warranting an investigation that would rise to the Board of Directors level and potentially require disclosure to the government, there is usually a flurry of attention and activity. Everyone wants to know what is going on. In an interview with Russ Berland, CCO at Aventiv Technologies, he noted, “for that short moment in time, you have everyone’s full attention.” Yet it can still be “a tricky place, because you get your fifteen minutes to really get everyone’s full attention, and from then on, you’re fighting with everybody else for their attention, like the normal things in business life.” Three key takeaways:

A serious FCPA allegation gets the attention of the Board and senior management. Use this time to move the compliance program forward.

Be aware of how your investigation can impact and even inform your remediation efforts.

Be prepared to deal with the dreaded “where else” question.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

After the internal report comes in and you have properly triaged the matter, you need to scope out and investigate it, promptly, thoroughly and with competent personnel. In the 2020 Update, provided these series of questions about your internal investigations:   Properly Scoped Investigations by Qualified Personnel – How does the company determine which complaints or red flags merit further investigation? How does the company ensure that investigations are properly scoped? What steps does the company take to ensure investigations are independent, objective, appropriately conducted, and properly documented? How does the company determine who should conduct an investigation, and who makes that determination?  Investigation Response – Does the company apply timing metrics to ensure responsiveness? Does the company have a process for monitoring the outcome of investigations and ensuring accountability for the response to any findings or recommendations?  Resources and Tracking of Results – Are the reporting and investigating mechanisms sufficiently funded? How has the company collected, tracked, analyzed, and used information from its reporting mechanisms? Does the company periodically analyze the reports or investigation findings for patterns of misconduct or other red flags for compliance weaknesses? Does the company periodically test the effectiveness of the hotline, for example by tracking a report from start to finish? In a presentation Jay Martin, retired Chief Compliance Officer at Baker Hughes and now Senior Counsel at Willkie Farr & Gallagher LLP and Jacki Trevino, Senior Director, Advisory Services Group at SAI Global Limited, discussed the specifics of an investigation protocol. It consisted of 1) opening and categorizing the case; 2) planning the investigation; 3) executing the investigation plan; 4) determining appropriate follow-up; and 5) closing the case. If you follow this basic protocol, you should be able to work through most investigations, in a clear, concise and cost-effective manner. Furthermore, you should have a report at the end of the day which should stand up to later scrutiny if a regulator comes looking. Finally, you will be able to “Document, Document, and Document”, not only the steps you took but why and the outcome obtained. Three key takeaways:

A written protocol, created before an investigation, is a key starting point.

Create specific steps to follow so there will be full transparency and documentation going forward.

Consistency in approach is critical.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Due diligence is generally recognized in three levels: Level I, Level II and Level III. Each level is appropriate for a different level of corruption risk. The key is to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward.  The 2020 Update stated, “A well-designed compliance program should apply risk-based due diligence to its third- party relationships. Although the need for, and degree of, appropriate due diligence may vary based on the size and nature of the company, transaction, and third party, prosecutors should assess the extent to which the company has an understanding of the qualifications and associations of third-party partners, including the agents, consultants, and distributors that are commonly used to conceal misconduct, such as the payment of bribes to foreign officials in international business transactions.” The question becomes how you use the information you obtained in the business justification and the questionnaire to determine an appropriate level of due diligence for the next step in the five-step process of third-party management. A three-step approach of varying levels of due diligence is the appropriate analysis to take going forward. There are many different approaches to the specifics of due diligence. By laying out some of the approaches, you can craft the relevant portions into your program. The Level I, II and III trichotomy appears to have the greatest favor and one that you should be able to implement in a straightforward manner. But the key is that you must assess your company’s risk and then manage that risk. If you need to perform additional due diligence to answer questions or clear red flags you should do so. And do not forget to “Document, Document, and Document” all your due diligence.  Three key takeaways:

A Level I due diligence should only be used where there is a low risk of corruption.

A Level II due diligence is sufficient in a high-risk jurisdiction if there are no red flags to be cleared.

Level III due diligence is deep dive, boots on the ground investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance programs, the issue of third-party management becomes more important. It is also the one where the rubber meets the road of operationalizingcompliance. It is also an area the DOJ specifically articulated in the 2020 Update that companies need to consider. Managing your third-parties is where the rubber meets the road in your overall third-party risk manage program. You must execute on this task. Even if you successfully navigate the first four steps in your third-party risk management program, those are in reality the easy steps. Managing the relationship is where the real work begins. Three key takeaways:

Have a strategic approach to third-party risk management.

Rank third parties based upon a variety of factors including compliance and business performance, length of relationship, benchmarking metrics and KPIs for ongoing monitoring and auditing.

Managing the relationship is where the real work begins.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As every compliance practitioner is well aware, third parties still present the highest risk under the FCPA. The 2020 Update devotes an entire prong to third-party management. It begins with the following:  Prosecutors should also assess whether the company knows the business rationale for needing the third party in the transaction, and the risks posed by third-party partners, including the third-party partners’ reputations and relationships, if any, with foreign officials. For example, a prosecutor should analyze whether the company has ensured that contract terms with third parties specifically describe the services to be performed, that the third party is actually performing the work, and that its compensation is commensurate with the work being provided in that industry and geographical region.   Prosecutors should further assess whether the company engaged in ongoing monitoring of the third-party relationships, be it through updated due diligence, training, audits, and/or annual compliance certifications by the third party. This clearly specifies that the DOJ expects an integrated approach that is operationalized throughout the company. This means you must have a process for the full life cycle of third-party risk management. There are five steps in the life cycle of third-party risk management, which will fulfill the DOJ requirements as laid out in the 2020 FCPA Resource Guide and in the Hallmarks of an Effective Compliance Program. They five steps in the lifecycle of third-party management are: 

Business Justification by the Business Sponsor;

Questionnaire to Third-party;

Due Diligence on Third-party;

Compliance Terms and Conditions, including payment terms; and

Management and Oversight of Third Parties After Contract Signing.

Three key takeaways:

Use the full 5-step process for third party management.

Make sure you have business development involvement and buy-in.

Operationalize all steps going forward by including business unit representatives.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

After you complete your risk assessment, you must then translate it into a risk profile. If your estimate of where your bribery risk is greatest is wrong, it will be an effort to address it. As Ben Locwin explained in his  BioProcess International article, entitled “Quality Risk Assessment and Management Strategies for Biopharmaceutical Companies”:   Once we have assessed risks and determined a process that includes options to resolve and manage those risks whenever appropriate, then we can decide the level of resources with which to prioritize them. There always will be latent risks: those that we understand are there but that we cannot chase forever. But we need to make sure we have classified them correctly. With a good understanding of each of these, we are in a better position to speak about the quality of our businesses. William C. Athanas, in his Industry Week article, “Rethinking FCPA Compliance Strategies in a New Era of Enforcement”, posited that companies assume that FCPA violations follow a bell curve in which most employees are responsible for most of the violations. However, Athanas believed that the distribution pattern more closely follows a hockey-stick distribution, where virtually all violations are committed by just a few people. Athanas concluded by noting that is this limited group of employees, or what he terms the “shaft of the hockey-stick,” to which a company should devote the majority of its compliance resources. With a proper risk assessment, a company can then focus its compliance efforts such as intensive training sessions or detailed analysis of key financial transactions involving those employees with the greatest means and motive to commit a violation. The most significant risks with the greatest likelihood of occurring are deemed to be the priority risks. These become the focus of your most significant risk management efforts, couple with audit and monitoring going forward. A variety of tools can be used to continuously monitoring risk going forward. Consider providing employees with substantive training to guard against the most significant risks coming to pass and to keep the key messages fresh and top of mind. It is important to create a risk control summary that succinctly documents the nature of the risk and the actions taken to mitigate it. Finally, let this risk assessment and evaluation inform your compliance program, rather than letting the compliance program inform the risk assessment. Three key takeaways:

Even after you complete your risk assessment, you must evaluate those risks for your company.

The DOJ and SEC are looking for a well-reasoned approach on how you evaluate your risk.

Create a risk matrix and rank your risks; then remediate and monitor as appropriate.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based upon a risk assessment, to understand your organization’s business from the commercial perspective, how your organization has identified, assessed, and defined its risk profile and, finally, the degree to which the program devotes appropriate scrutiny and resources to this range of risks. Yet the 2020 Update added a new emphasis that Risk Assessments should not be done not less than annually.  As far back as 1999, in the Metcalf & Eddy enforcement action, the DOJ has said that risk assessments that measure the likelihood and severity of possible FCPA violations should direct your resources to manage these risks. The 2012 FCPA Guidance stated it succinctly when it said, “Assessment of risk is fundamental to developing a strong compliance program and is another factor DOJ and SEC evaluate when assessing a company’s compliance program.” There are a number of ways you can slice and dice your basic inquiry. As with almost all FCPA compliance, it is important that your protocol be well thought out. If you use one, some or all of the above as your basic inquiries for your risk analysis, it should be acceptable for your starting point.  Three key takeaways:

Since at least 1999, the DOJ has pointed to the risk assessment as the start of an effective compliance program.

The DOJ will now consider both your risk assessment methodology for identifying risks and gathered evidence.

You should base your compliance program on your risk assessment.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Companies have finally come to realize that institutional justice and fairness are perhaps the most basic tenet of any successful workplace. If employees believe they will be treated fairly, it will engender a level of trust that can work to not simply motivate employees but lead to a more successful workplace and, at the end of the day, a more profitable company. This encompasses the entire lifecycle of the employment relationship, from hiring through separation. It works in areas as seeming disparate as compensation and incentives, discipline, promotion and internal reporting.  On this final point, Kyle Welch and Stephen Stubben, in their 2019 paper entitled “Evidence on the Use and Efficacy of Internal Whistleblowing Systems”, noted that a robust whistleblower reporting system speaks to a functioning and ethical corporate culture. Employees who can report issues, in a fair manner, without fear of retaliation are more empowered to make the company run more efficiently and more profitably. Yet an equally interesting finding was where there was robust internal reporting, employees were more likely to speak up to improve overall business processes, thereby making the company more profitable. An often-overlooked role of any CCO or compliance professional is to help provide employees with institutional justice. If your compliance function is seen to be fair in the way it treats employees, in areas as varied as financial incentives, to promotions, to appropriate and consistent discipline meted out across the globe; employees are more likely to inform the compliance department when something goes array. If employees believe they will be treated fairly, it will go a long way to more fully operationalizing your compliance program. Three key takeaways:

The DOJ and SEC have long called for appropriate and consistent application of both incentives and discipline.

The Fair Process Doctrine will help set institutional justice as the norm in your organization.

Inconsistent application of discipline will destroy your compliance program credibility.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas that many companies have not paid as much attention to in their compliance programs is compensation. However, the DOJ and SEC have long made clear that they view monetary structure for compensation, rewarding those employees who do business in compliance with their employer’s compliance program, as one of the ways to reinforce the compliance program and the message of compliance. As far back as 2004, then SEC Director of Enforcement Stephen M. Cutler noted that integrity, ethics and compliance needed to be part of promotion, compensation and evaluation processes: “At the end of the day, the most effective way to communicate that “doing the right thing” is a priority, is to reward it.”  The 2020 FCPA Resources Guide stated the “DOJ and SEC recognize that positive incentives can also drive compliant behavior. These incentives can take many forms such as personnel evaluations and promotions, rewards for improving and developing a company’s compliance program, and rewards for ethics and compliance leadership.” Obviously, the power of a compensation plan is to motivate employees to not only to sell more but to act in ways that support your company’s business model and overall culture and values. For the compliance practitioner, one of the biggest reasons is to first change a company’s culture to make compliance more important, and then integrate it into the DNA of your organization. But you must be able to evolve in your thinking and professionalism to recognize the opportunities to change and then adapt your incentive program to make the doing of compliance part of your company’s everyday business process.  Three key takeaways:

The DOJ and SEC have long advocated compensation as a way to motivate employees into ethical and compliant behaviors

Keep the compliance aspects of your compensation structure simple and easy for your employees to understand

Have full transparency in the framework of your compensation structure

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the key goals of any compliance program is to train employees in awareness and understanding of the FCPA; your specific company compliance program; and to create and foster a culture of compliance. While it seems axiomatic that compliance training is a mainstay of any best practices compliance program, the conversation around training has evolved over the years.  The importance of determining effectiveness of your compliance program has been enshrined by the DOJ. The 2020 Update confirmed that the DOJ wants to see evidence of the effectiveness of your compliance program. This is something that many CCOs and compliance professionals still struggle to determine. Both the simple guidelines suggested herein, the more robust assessment and results provide you with a start to fulfill the precepts set out by the DOJ, as you will eventually need to demonstrate the effectiveness of your compliance training going forward. Three key takeaways:

How and why have you tailored your compliance training?

The DOJ has mandated demonstrating the effectiveness of compliance training

How is your training presented: both in languages and media?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the message of compliance inside of a corporation and how it is distributed? In a compliance program, the largest portion of your consumers/customers are your employees. Social media presents some excellent mechanisms to communicate the message of compliance going forward. Many of the applications that we use in our personal communications are free or available at very low cost. Why not take advantage of them and use those same communication tools in your internal compliance marketing efforts going forward?  Louis Sapirman, Vice President and Chief Ethics & Compliance Officer for Panasonic Corporation of North America – Panasonic USA, often talks about the integration of social media into compliance. You should start with the tech-savvy nature of the today’s workforce. It is not simply about having a younger workforce but a workforce whose primary tool for communication is social media. If your company is in the services business, it probably means your employee base is using technological tools to deliver business solutions. Finally, consider the data-driven nature of business today so using technological tools to deliver products and solutions is something your company most probably does now. Finally, never forget the social part of social media. Social media is a more holistic, multiple-sided communication. Not only are you setting out expectations but also these tools allow you to receive back communications from your employees. The D&B experience around the name change for its Code of Conduct is but one example. You can also see that if you have several concerns expressed it could alert you earlier to begin some detection and move towards prevention in your compliance program. Three key takeaways:

Incorporation of social media into your compliance communications can pay big dividends

Focus on the ‘social’ part of social media

Use internal corporate social media to facilitate a 360-degree conversation

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A 360-degree view of compliance is an effort to incorporate your compliance identity into a holistic approach so that compliance is in touch with and visible to your employees at all times. It is about creating a distinctive brand philosophy of compliance which is centered on your consumers. In other words, it helps a compliance practitioner to anticipate all the aspects of your employees needs around compliance. This is especially true when compliance is either perceived as something that comes out of the home office or is perceived as the “Land of No.” A 360-degree view of compliance gives you the opportunity to build a new brand image for your compliance program. This is important as the 2020 Update mandates that for a compliance program to be effective, it must be understood by a wide variety of stakeholders.  Communications is often thought of as a two-way street, upward and downward, inbound and outbound, or side-to-side. However, it is better to think of it as a 360-degree effort. You simply can no longer effectively communicate in just two ways. You now communicate in a more holistic manner, and in multiple ways. If you are just thinking about communications in the classic form, you are missing something that is happening around you. The best example I can provide to you is a story told to me by Louis Sapirman, Vice President and Chief Ethics and Compliance Officer at Panasonic Corporation of North America – Panasonic USA. This story happened to him in Argentina when he was the CCO at Dun & Bradstreet (D&B). Argentina has an interesting form of illegal conduct, which is an open black market for the changing of currency. Sapirman was with a colleague who was one of the leaders from the company’s South American operations and they went into a convenience store. The person who was going to sell him the product suggested that he go just around the corner and change money on the black market where he could get a much better exchange rate, almost a 100 percent difference in the exchange rate; he declined to do so. Sapirman paid and received the established bank rate in the small transaction. He had not considered role modeling that compliance. About six months later one of his team members was in Mexico speaking to the leader of the D&B operation there. The non-compliance function employee said that he was the person who had been with Sapirman. He recounted the story of doing the right thing, when literally no one was watching. That is the power of 360-degrees in communication.  Three key takeaways:

Remember the definition of 360-degrees of communication. It is an effort that moves the compliance identity into a holistic approach so compliance is in touch and visible to your employees at all times

What is your objective? What are you trying to do with your 360-degrees of communications and how are you using that mechanism to deliver the objectives of your compliance program?

Evaluate. You need to evaluate three factors: 1) has the message been delivered; 2) has it been heard; and 3) is it being implemented?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are internal controls? The best definition I have come across is from Jonathan Marks who defined internal controls as:  An internal control is an action or process of interlocking activities designed to support the policies and procedures detailing the specific preventative, detective, corrective, directive and corroborative actions required to achieve the desired process outcomes or the objectives(s). This, along with continuous auditing, continuous monitoring and training reasonably assures: 

The achievement of the process objectives linked to the organization’s objectives;

Operational effectiveness and efficiency;

Reliable (complete and accurate) books and records (financial reporting);

Compliance with laws, regulations and policies; and 

The reduction of risk-fraud, waste and abuse, which,

Aids in the decline of process and policy variation, leading to more predictive outcomes. The DOJ and SEC, in the 2020 FCPA Resource Guide, stated: Internal controls over financial reporting are the processes used by compa­nies to provide reasonable assurances regarding the reliabil­ity of financial reporting and the preparation of financial statements. They include various components, such as: a control environment that covers the tone set by the organi­zation regarding integrity and ethics; risk assessments; con­trol activities that cover policies and procedures designed to ensure that management directives are carried out (e.g., approvals, authorizations, reconciliations, and segregation of duties); information and communication; and monitoring. … The design of a company’s internal controls must take into account the operational realities and risks attendant to the company’s business, such as: the nature of its products or services; how the products or services get to market; the nature of its work force; the degree of regulation; the extent of its government interaction; and the degree to which it has operations in countries with a high risk of corruption. This was supplemented in the 2020 Update, with a pair of pointed questions: whether a company has made significant investigation into its internal controls and have they been tested, then remediated based upon the testing? The bottom line is that internal controls are just good financial controls. The internal controls that detail requirements for third-party representatives in the compliance context will help to detect fraud, which could well lead to bribery and corruption. As an exercise, map your existing internal controls to the Ten Hallmarks of an Effective Compliance Program or some other well-known anti-corruption regime to see where gaps may exist. This will help you to determine whether adequate compliance internal controls are present in your company. From there you can move to see if they are working in practice. Three key takeaways:

Effective internal controls are required under the FCPA

Internal controls are a critical part of any best practices compliance program

There are four significant controls for the compliance practitioner to implement initially. (a) Delegation of authority (DOA); (b) Maintenance of the vendor master file; (c) Contracts with third parties; and (d) Movement of cash/currency.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There are numerous reasons to put some serious work into your compliance policies and procedures. They are certainly a first line of defense when the government comes knocking. The 2020 Update made clear that “Any well-designed compliance program entails policies and procedures that give both content and effect to ethical norms and that address and aim to reduce risks identified by the company as part of its risk assessment process.” This statement made clear that the regulators will take a strong view against a company that does not have well thought out and articulated policies and procedures against bribery and corruption; all of which are systematically reviewed and updated. Moreover, having policies written out and signed by employees provides what some consider the most vital layer of communication and acts as an internal control. Together with a signed acknowledgement, these documents can serve as evidentiary support if a future issue arises. In other words, the “Document, Document, and Document” mantra applies just as strongly to policies and procedures in anti-corruption compliance.  The specific written policies and procedures required for a best practices compliance program are well known and long established. According to the 2020 FCPA Resources Guide, some of the risks companies should keep in mind include the nature and extent of transactions with foreign governments (including payments to foreign officials); use of third parties; gifts, travel, and entertainment expenses; charitable and political donations; and facilitating and expediting payments. Policies help form the basis of expectations for standards of conduct in your company. Procedures are the documents that implement these standards of conduct. The 2020 FCPA Resource Guide ends its section on policies with the following, “Regardless of the specific policies and procedures implemented, these standards should apply to personnel at all levels of the company.” It is important that compliance policies and procedures are applied fairly and consistently across the organization. Institutional fairness demands that if compliance policies and procedures are not applied consistently, there is a greater chance that an employee dismissed for breaching a policy could successfully claim he or she was unfairly terminated. Moreover, inconsistent application of your policies and procedures will destroy the credibility of your compliance program. This last point cannot be over-emphasized. If an employee is going to be terminated for fudging their expense accounts in Brazil, you had best make sure that same conduct lands your top producer in the U.S. with the same quality of discipline. Three key takeaways:

Written compliance policies and procedures, together the Code of Conduct, form the backbone of your compliance program.

The DOJ and SEC expect a well-thought out and articulated set of compliance policies and procedures and that they be adequately communicated throughout your organization.

Institutional fairness for the application of policies and procedures demands consistent application across the globe.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the value of having a Code of Conduct? In its early days, a Code of Conduct tended to be lawyer-written and lawyer-driven to wave in regulator’s face during an enforcement action as proof of ethical overall behavior. Is such a legalistic code effective? Is a Code of Conduct more than simply your company’s internal law? What should be the goal in the creation of your company’s Code of Conduct?  The three most important things about your compliance program are “Document, Document, and Document.” The same is true in communicating your company’s Code of Conduct. You need to do more than simply put it on your website and tell folks it is there, available and that they should read it. You need to document that all employees, or anyone else that your Code of Conduct is applicable to, has received, read, and understands it. The DOJ expects each company to begin its compliance program with a very publicly announced, very robust Code of Conduct. If your company does not have one, you need to implement one forthwith. However, your Code of Conduct is not a static document to be put on a shelf and never reviewed again. For just as your compliance program is a living entity; it should be constantly evolving, the same is true for your Code of Conduct. If your company has not reviewed or assessed your Code of Conduct for five years, do so in short order, as much has changed in the compliance world. All of this has become much more clear in the age of Coronavirus. Some of the questions you should begin with include:

When was the last time your Code of Conduct was revised?

Have there been changes to your company’s business model since the last revision to the Code of Conduct?

Have there been changes to relevant laws relating to a topic covered in your company’s Code of Conduct?

Are any provisions of the Code of Conduct outdated?

What is the budget to revise your Code of Conduct?

Three key takeaways:

Every formulation of a best practices compliance program starts with a written Code of Conduct.

The substance of your Code of Conduct should be tailored to the company’s culture, and to its industry and corporate identity.

“Document, Document, and Document” your training and communication efforts.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In addition to a company’s senior management, there is a Board of Directors at the top. Yet the role of the Board is different than that of senior management. For the Board of Directors, the 2020 Update stated: Oversight – What compliance expertise has been available on the board of directors? Have the board of directors and/or external auditors held executive or private sessions with the compliance and control functions? What types of information have the board of directors and senior management examined in their exercise of oversight in the area in which the misconduct occurred? Having a Board member with specific compliance expertise or heading a Compliance Committee can provide a level of oversight and commitment to achieving this goal. The DOJ enshrined this requirement in the FCPA Corporate Enforcement Policy. This means that when your company is evaluated by the DOJ, under the factors set out in the 2020 Update and FCPA Corporate Enforcement Policy, to retrospectively determine if your company had a best practices compliance program in place at the time of any violation, you need to have not only the structure of the Board-level Compliance Committee but also the specific subject matter expertise (SME) on the Board and on that committee. Another arm of the US government has recognized the need for such expertise at the Board level. In 2015, the Office of Inspector General (OIG), in a publication entitled “Practical Guidance for Health Care Governing Boards”, called for greater compliance expertise at the Board level. The OIG said that a Board can raise its level of substantive expertise with respect to regulatory and compliance matters by adding to the Board a compliance member. The presence of a such a compliance professional with SME “on the board sends a strong message about the organization’s commitment to compliance, provides a valuable resource to other board members and helps the board better fulfill its oversight obligations.” All of this means that every Board of Directors needs a true compliance expert. Almost every Board has a former Chief Financial Officer (CFO), former head of Internal Audit or persons with a similar background, and often times these are also the Audit Committee members of the Board. Such a background brings a level of sophistication, training and SME that can help all companies with their financial reporting and other finance-based issues. So why is there not such SME at the Board level from the compliance profession?  Three key takeaways:

The 2020 Update requires active Board of Director engagement and oversight around compliance

Board communication on compliance is a two-way street; both inbound and outbound

Does the Board of Directors have a compliance expert?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Mike Volkov, in a blog post entitled “Mood in the Middle Versus Tone at the Top”, said, “Even when a company does all the right things at the senior management level, the real issue is whether or not that culture has embedded itself in middle and lower management. A company’s culture is reflected in the values and beliefs that exist throughout the company.” To fully operationalize your compliance program, you must articulate the message of ethical values and doing business in compliance and then drive that message from the top down, throughout your organization.  The 2020 Update made clear a company must have more than simply good ‘Tone-at-the-Top’; it must move down through the organization from senior management to middle management and into its lower ranks. It stated, “Beyond compliance structures, policies, and procedures, it is important for a company to create and foster a culture of ethics and compliance with the law at all levels of the company. The effectiveness of a compliance program requires a high-level commitment by company leadership to implement a culture of compliance from the middle and the top.” By engaging employees at this level, you can find out not only what the employees think about the company compliance program but use their collective experience to help design a better and more effective compliance program. Employees want to do business in an ethical manner. Giving employees the chance to engage in business the right way, as opposed to cheating, will win their hearts and minds almost all the time. By using this protocol, you can not only find out the effect of your compliance program on the employees at the bottom, but you can affect them as well. Employees often look to their direct supervisor to determine what the tone of an organization is and will be going forward. Many employees of large, multi-national organizations may never have direct contact with the CEO or even senior management. By moving the values of compliance through an organization into the middle, you will be in a much better position to inculcate these values and operationalizing compliance with them. Three key takeaways:

Tone at the top - direct supervisors become the most important influence on people in the company

Give your middle managers a Tool Kit around compliance so they can fully operationalize compliance

Organizational justice is an additional way to help operationalize compliance

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Obviously, in every compliance program, the ethical tone of a company and accountability all starts at the top and, most specifically, senior management. The 2020 Guidance stated, “Beyond compliance structures, policies, and procedures, it is important for a company to create and foster a culture of ethics and compliance with the law at all levels of the company. The effectiveness of a compliance program requires a high-level commitment by company leadership to implement a culture of compliance from the middle and the top.” This requirement is more than simply the ubiquitous “tone-at-the-top,” as it focuses on the conduct of senior management. The DOJ wants to see a company’s senior leadership actually doing compliance. The DOJ asks if company leadership has, through their words and concrete actions, brought the right message of doing business ethically and in compliance to the organization. How does senior management model its behavior on a company’s values and finally, how is such conduct monitored in an organization? Senior management must share these same values through operationalizing compliance going forward. Lynn Paine, in her seminal article “Managing for Organizational Integrity”, laid out five factors, which can be used as guideposts to not only to set the right tone from senior management on doing business ethically and in compliance, it can lay the groundwork for senior management to model appropriate behavior and then have it monitored by the company going forward.

The guiding values of a company must make sense and be clearly communicated by senior management in a variety of settings, to the entire company workforce.

The company’s leader must be personally committed and willing to take action on the values. This means that management must not simply ‘overlook’ the transgressions of top producers.

A company’s systems and structures must support its guiding principles and these internal systems and structures cannot be over-ridden by senior management without both justification and Board approval.

A company’s values must be integrated into normal channels of management decision-making and reflected in the company’s critical decisions. Sometimes a company must turn down business if there are too many red flags present or by engaging in such behavior the company’s value and ethics will be violated.

Managers must be empowered to make ethically sound decisions on a day-to-day basis. This means senior management must fully support and back-up such decisions.

I once had a Chief Executive Officer (CEO), observe the following, “You want me to be the ambassador for compliance.” I immediately said yes, that is exactly what I need you to do. A CEO, as an “Ambassador of Compliance”, can fully model the conduct that senior management engage in going forward. Another area a CEO can forcefully engage an entire company is through a powerful video message about doing business the right way and in compliance. A great example was a CenterPoint Energy video put out in 2015 after the Volkswagen (VW) emissions-testing scandal became public. The video featured Scott Prochazka, CenterPoint Energy President and CEO. He used the VW scandal to proactively address culture and values at the company and used the entire scenario as an opportunity to promote integrity in the workplace. But more than simply a one-time video, the company followed up with an additional resource, entitled “Manager’s Toolkit - What does Integrity mean to you?”, which managers used to facilitate discussions and ongoing communications with employees around the company’s ethics and compliance programs. Finally, the cost for the video was quite reasonable as it was produced internally. Three key takeaways:

Senior management must actually do compliance; walk-the-walk, not simply talk-the-talk.

Use your CEO to talk about current events and how those ethical failures are lessons to be learned for your organization.

CEO as Compliance Ambassador.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

I want to next focus specifically on the tactical steps of moving towards both continuous monitoring and continuous improvement of your compliance program. These twin concepts are perhaps the biggest modifications in the 2020 Update. The changes began in Section 1- Risk Assessments. The question-by-question analysis begins with “Is the periodic review limited to a “snapshot” in time or based upon continuous access to operational data and information across functions?” Do you have access to continuous and real time transactional data at your organization? How about across silos within your organization. Most likely the answer to both is “no”. This means you no longer have a best practices compliance program at this point in time. How can you garner such information?  While there is only one question in the Lessons Learned section, it is a compound question. It not only inquiries about data you may have obtained through your own work but also from other company’s in your industry operating in the same geo-region. Without commenting on the potential anti-trust aspects of this issue, if there is public source information available to you (and there always is), how are you using this information in your compliance regime. But this can be simply having your fully operationalized employee base keeping their eyes and ears open at trade show or any other gatherings of industry employee. The next area for continuous monitoring and continuous improvement was in an area of compliance which is not normally associated with those concepts, Policies and Procedures. The final area in the 2020 Update for consideration is appropriate called Continuous Improvement, Periodic Testing and Review and is found in the subsection monikered Evolving Updates. It reads: How often has the company updated its risk assessments and reviewed its compliance policies, procedures, and practices? Has the company undertaken a gap analysis to determine if particular areas of risk are not sufficiently addressed in its policies, controls, or training? What steps has the company taken to determine whether policies/procedures/practices make sense for particular business segments/subsidiaries? Does the company review and adapt its compliance program based upon lessons learned from its own misconduct and/or that of other companies facing similar risks? Similar to the language under Risk Assessment, this compound question considers the adaptation of a compliance program from your own lessons learned but also from other companies. The distinction now is that phrase is “other companies facing similar risks”? Think about how this language would apply to any company operating in China, West Africa or any other high-risk region in the globe. I would interpret this to mean every Chief Compliance Officer (CCO) and compliance practitioner needs to stay abreast of international anti-corruption enforcement actions where your company may be doing business. Three key takeaways:

What is your process for continuous monitoring?

What is your process for continuous Improvement?

What source of information do you use that are outside your organization?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

2020 was a very significant year for every compliance practitioner and compliance program. Not only was it the year with the single highest anti-bribery fine ever and highest annual amount of FCPA penalties. There were several significant enforcement actions, involving corporations coupled with a large number of individual prosecutions. Yet, perhaps most significantly, there were two noteworthy releases of information by the federal government which directly impacted compliance professionals. In June, the Department of Justice (DOJ) released its 2020 Update to the Evaluation of Corporate Compliance Programs - Guidance Document (2020 Evaluation) was released. It should be mandatory reading for every Chief Compliance Officer (CCO), compliance practitioner and professional or any other person interested in the latest thinking of the DOJ on what constitutes a best practices compliance program. The second release was the DOJ and Securities and Exchange Commission (SEC) released the updated A RESOURCE GUIDE TO THE U.S. FOREIGN CORRUPT PRACTICES ACT SECOND EDITION (2020 FCPA Resource Guide). This was a most welcomed update to the seminal and original FCPA Resource Guide, released in 2012 and widely recognized as the single best volume on the FCPA. Some of the key changes for the compliance professional include the following.  The first change to note is the expanded definition to the questions “Is it [a corporate compliance program] being applied in good faith” with the addition of the queries, “In other words, is the program adequately resourced and empowered to function effectively?” This language comes from the 2020 Update. This change clearly reflects the need for a company to do far more than have a paper compliance program in place which presaged many of the changes brought forward in the 2020 Update. However, the biggest change is the addition of a new Hallmark, entitled “Investigation, Analysis, and Remediation of Misconduct.  There are many interesting aspects to this new Hallmark, not the least that it begins with “The truest measure of an effective compliance program is how it responds to misconduct.”  The 2020 Resource Guide is a most welcomed document from the DOJ and SEC. It brings forward the top FCPA and compliance resource from the past decade into this decade. The 2020 Update continues the DOJ communication to the compliance community about its expectations for a best practices compliance program.  Three Key Takeaways

The 2020 Update brings business intelligence to compliance.

The key theme is continuous monitoring and continuous improvement.

The 2020 FCPA Resource Guide emphasized the importance of root cause analysis.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

If there is one truism from the practices of law which translates to the practice of compliance it is that you are only limited by your own imagination. This holds true in the 360-degree realm of communication in compliance, as communications obviously comes in many forms. Many compliance practitioners will well remember the 2012 Morgan Stanley declination. In this first declination made public, the DOJ recognized Morgan Stanley for emailing out 35 compliance reminders to Garth Peterson over seven years. Think about the power of 360-degrees of communications in the context of compliance reminders. Now imagine the power of short ethics and compliance video training clips going out over the same period of time and the effect it would have both on your employees and the regulators.  Marc Havener, founder and CEO of Resonate Pictures, Inc., created a series of video shorts for a consulting company on compliance and ethics. Rather than the traditional legal approach of telling employees about the corporate policy on compliance, they wanted to tell a story about compliance through the art of movie-based storytelling that wove messaging into characters to tell a story. I have urged compliance practitioners to bring more storytelling into their compliance messaging. If you put the employee in the shoes of the person they’re watching, they will remember it, because they will see how it applies to their lives. Havener noted the training experience will last “exponentially longer than if you just go over a written policy or show a PowerPoint”. He called it “expanding your classroom”. The next time they see George Clooney they’re going to remember the training, the next time they watch that movie that you showed a clip from they’re going to be reminded of the training and so it becomes a great drift method of training.” Three key takeaways:

Storytelling is another form of communication.

Movie clips in compliance training can provide useful touchstones that employees can relate to for compliance lessons.

The Morgan Stanley declination gave credit for annual compliance reminders.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Since at least 2017, the DOJ has emphasized the need for a determination of compliance training effectiveness. In the 2020 Update, it stated under the section entitled, “Form/Content/Effectiveness of Training” the following questions, How has the company measured the effectiveness of the training? Have employees been tested on what they have learned? How has the company addressed employees who fail all or a portion of the testing? Has the company evaluated the extent to which the training has an impact on employee behavior or operations? The importance of determining effectiveness of your compliance program was enshrined by the DOJ in its 2020 Evaluation. The 2020 Evaluation demonstrates the DOJ wants to see evidence of the effectiveness of your compliance program. This is something that many CCOs and compliance professionals still struggle to determine. Both the simple guidelines suggested herein, the more robust assessment and results provide you with a start to fulfill the precepts set out in the 2020 Evaluation, but you will eventually need to demonstrate the effectiveness of your compliance training going forward. Three key takeaways:

You must demonstrate you have measured the effectiveness of your compliance training.

The DOJ is clearly moving into requiring a demonstration of effectiveness of compliance training.

You should be moving towards a model of demonstrating compliance training ROI to validate full operationalization of your compliance training. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What should be your organization’s compliance training frequency? How does the amount of training can positively or negatively impact an overall training strategy? Unfortunately, these questions were not answered by the 2020 Update or the 2020 FCPA Resource Guide. Still every company should have a “well-designed compliance program is appropriately tailored training and communications.”  Often compliance professionals think that compliance training needs to be conducted very frequently, even if it means repeating the same training courses every year. However, Shawn Rogers analogizes compliance training to an automobile’s windshield wiper system in a discussion of how frequently compliance training should be administered. He went on to explain that “it would not make any sense to run your wipers constantly, even when it is not raining. First, it would be extremely annoying to the passengers. And second, eventually it would wear out both the wiper blades and the wiper motor. It would simply be nonsensical.” Requiring overly repetitive training is like running your windshield wipers in clear weather. The learners are going to be annoyed, the training will be viewed as a waste of time and energy and finally your employees will not take training as seriously when it is really needed to address a specific situation as the compliance training will be viewed literally and figuratively as a “check-the-box” exercise. While new employees should be required to take more detailed courses during their first year so that they are exposed to the key risks in detail, after that, full-length courses can be staggered in a three-year interval so you can keep the courses updated and to avoid over-training. In the interim, you can move towards a less frequent repetition of lengthy training courses and more frequent refresher or reminder training modules that keep the risk top-of-mind without assuming that lengthy courses need to be repeated every year. Once again this fits the 2020 Update prescription that “companies have invested in shorter, more targeted training sessions to enable employees to timely identify and raise issues to appropriate compliance, internal audit, or other risk management functions.” Rogers concluded “It is a very common sense and defensible approach to compliance training.”  Three key takeaways: 

Have a well-reasoned approach to training frequency.

Lengthier more full-bodied training can be given once every three years or so.

Shorter more frequent compliance refreshers or reminders can be used to keep the risk top-of-mind.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One issue not often considered by compliance professionals around compliance training is that of compliance training governance. Yet a multinational organization subject to the FCPA faces many legal and regulatory risks and often many of those risks are "owned" by organizations that are outside of the compliance function. How can your organization, create a comprehensive compliance training program that covers its complete risk profile?  In the age of Coronavirus, any multinational organization will have a broad risk portfolio which are typically owned across the organization. Consider compliance risk, fraud risk, reputational risk, financial accounting risk and discrimination risk. These are but a small sample of risk many of the risks will not be "owned" by the corporate compliance function. This presents a real challenge when you are trying to create a comprehensive compliance training program covering all of legal, regulatory, compliance and reputational risks faced by a company. Shawn Rogers suggests that one approach “is to establish a corporate Compliance Training Governance Committee that looks at the company's overall risk profile and builds a cross-functional and comprehensive multi-year training plan that effectively addresses all of the risks in a company's risk portfolio.”  A Compliance Training Governance Committee will allow your organization to effectively establish a multi-year training plan, help in the vendor selection and engage in course creation. Rogers said that “One of the biggest benefits has been the predictability that it brings to the compliance training program. Every stakeholder from a risk-owning organization knows exactly when their function will have their course deployed over the three-year calendar. They can plan resources, they have a long lead-time to develop the courses and during their off-years they can do communications campaigns and events to keep their risk top-of-mind.”  Three key takeaways: 

Why your organization should create a Compliance Training Governance Committee.

Who should be on the Compliance Training Governance Committee?

How should the Compliance Training Governance Committee work going forward?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Shawn Rogers, Senior Director, Global Training & Awareness, Walmart has developed ten design objectives for establishing your compliance program training design objectives. You should consider doing the same for your organization. It may well be that your organization may value other objectives. What the government has told us since the original FCPA Resource Guide back in 2012 is that it expects a well thoughout approach. If you consider your design objectives early in the planning phase, it will not only meet this requirement but also become a roadmap for your program implementation easier. Finally, in this new era, you will have the ability to pivot more quickly as new compliance risks emerge.  Three key takeaways: 

What are your design objectives?

They should be dynamic, not static.

You should use them as touchpoints going forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How can you begin to think through a best practices compliance training program? I put that question to Shawn Rogers, Senior Director, Global Training & Awareness, Walmart. Rogers advised that you ‘envision’ what your training would like as a first step. He stated, “A common mistake is jumping right to the question is which courses you want and how to deploy them. However, there are several things you need to think about before you start building the program.”  You should develop some principles on what your compliance training will look like. A key way to start is by reference to the Training and Communications section of the 2020 Update, which stated, “Prosecutors should assess the steps taken by the company to ensure that policies and procedures have been integrated into the organization, including through periodic training and certification for all directors, officers, relevant employees, and, where appropriate, agents and business partners. Prosecutors should also assess whether the company has relayed information in a manner tailored to the audience’s size, sophistication, or subject matter expertise. Some companies, for instance, give employees practical advice or case studies to address real-life scenarios, and/or guidance on how to obtain ethics advice on a case-by-case basis as needs arise.” Some of these principals include the following, What are the Guiding Principles of your compliance training? What are you trying to communicate? Is it a broad set of values you want to communicate to every employee about what your organization stands for? As noted in the 2020 Update, a company should “should examine whether the compliance program is being disseminated to, and understood by, employees in practice in order to decide whether the compliance program is “truly effective.”  Three key takeaways: 

The 2020 Update has a strong emphasis on compliance training.

Create a set of Principles for your compliance training programs.

You should always use the Principle of your compliance training program in making decisions going forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the ways that CCOs and compliance practitioners can better use 360-degrees of communication is through Twitter. In a  MIT Sloan Management Review article, entitled “How Twitter Users Can Generate Better Ideas”, authors Salvatore Parise, Eoin Whelan and Steve Todd found “employees with a diverse Twitter network – one that exposes them to people and ideas they don’t already know – tend to generate better ideas.” Their research led them to three interesting findings: 1) Employees who used Twitter had better ideas than those who did not do so; 2) There was a link between the amount of diversity in employees’ twitter networks and the quality of their ideas; and 3) Twitter users who combined idea scouting and idea connecting were the most innovative. Their research certainly confirms the experience of Louis Sapirman, during his time as CCO at Dun & Bradstreet.  The key concept for the compliance profession is the roles of Idea Scout and Idea Connector. An “idea scout is an employee who looks outside the organization to bring in new ideas. An idea connector, is someone who can assimilate the external ideas and find opportunities within the organization to implement these new concepts.” It is the ability to identify, assimilate and exploit new compliance ideas, which makes this concept so powerful. However, to improve your compliance innovation, “you need to maintain a diverse network while also developing your assimilation and exploitation skills.” Twitter can be powerful tool for the compliance practitioner. It is one of the only tools that can work both inbound for you to obtain information and insight and in an outbound manner as well; where you are able to communicate with your compliance customer base, your employees. You should work to incorporate one or more of the techniques to help you burn compliance into the DNA fabric of your organization. Three key takeaways:

Twitter can be powerful tool for the compliance practitioner.

Data mine twitter for not only best practices but see what the regulators may be saying.

Curiosity may have killed the cat, but it makes for a far better and more effective compliance practitioner.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Other than the skill of listening, asking questions is about as important to the compliance practitioner as any other that can be employed. Yet, equally critical is to ask the right question, which is an issue explored Brian Grazer and Charles Fishman in their book, entitled “A Curious Mind: The Secret to a Bigger Life”.  Grazer is a well-known and successful Hollywood director who has directed such movies as Splash, A Beautiful Mind and Cinderella Man. He believes that much of the success he has achieved is because he asks lots of questions and “Questions are a great management tool.” This is because “Asking questions elicits information” and it also “creates the space for people to raise issues they are worried about that a boss, or colleagues, may not know about.” By asking questions, you allow “people to tell a different story than the one you’re expecting.” Finally, and perhaps most significantly, “asking questions means people have to make their case for the way they want a decision to go.” You too can use this simple and straight-forward technique to improve not only your leadership qualities in the compliance function. The reason that asking questions is so much better than simply giving orders is that you have a vast talented workforce you can tap into it help you do business in compliance. But the how of doing a business process that is, or should be, burned into your company can be facilitated by possibilities that are out there in your employees’ minds. 360-degrees of communications allows you to create an atmosphere where nobody is afraid to ask a question. Perhaps equally importantly no one is afraid to answer a question. Three key takeaways:

Asking questions is a great technique to elicit information.

Asking questions creates the authority in people to come up with ideas, coupled with the responsibility for moving things forward.

Create an atmosphere where no employee is afraid to ask or answer a question.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A 360-degree approach to communications entails looking at all forms of interactions as a way to interconnect. This means both verbal and non-verbal and in clues and hints. This concept can be particularly helpful in relating to and with cultures outside the U.S. as one of the most critical issues to a compliance function is breaking through a company’s internal cultural boundaries. In a  Harvard Business Review article, entitled “Getting to Si, Ja, Oui, Hai and Da”, Erin Meyer explained that “managers often discover that perfectly rational deals fall apart when their [business] counterparts make what seem to be unreasonable demands or don’t respect their commitments.” She laid out a five-point solution that I have adapted for the CCO or compliance practitioner in communicating a compliance program across a multi-national organization. In its 2020 Update, the DOJ specified that when it comes to compliance training, a company must offer compliance training in the form and language appropriate for the audience. Initially look for as many cultural bridges as you can find as it will help you understand what your international audience is communicating to you, in both verbal and non-verbal formats, during a wide variety of activities familiar to any compliance professional such as training, investigations or simple meetings where the compliance perspective must be articulated in any business setting. If you fail to have an understanding or even a person who can navigate these signs for you, here are five steps to help you out: 1) Adapt the way you express disagreement; 2) Know when to bottle it up and let it all pour out; 3) Learn how the other culture builds trust; 4) Avoid yes or no questions; and 5) Be careful about putting it in writing. Three key takeaways:

Communications in compliance must be largely drawn around trust.

Look for as many cultural bridges as you can find as it will help you understand what your international audience is communicating to you.

One of the things most critical issues to a compliance function is breaking through a company’s internal cultural boundaries.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What if you could multiply the impact and effectiveness of your compliance program throughout your company? That would be a great boon to any compliance practitioner and compliance program. It is also something that is very possible by considering a 360-degree view of communications in compliance using multipliers.  Liz Wiseman is the co-author with Greg McKeown of “Multipliers: How the Best Leaders Make Everyone Smarter”, a book about the various types of leaders. They focus two different types of leaders, Diminishers and Multipliers. Multipliers are leaders who encourage growth and creativity from their workers, while Diminishers are those who hinder and otherwise keep their employees’ productivity at a minimum. Now imagine applying this leadership technique as you are trying to more fully operationalize your compliance program. If you take this approach of leading by asking questions, you not only guide the functional unit but you get greater buy-in to the entire concept and process as it becomes their process. The non-compliance team may design it and have ownership over it. Wiseman concluded by challenging each of us to multiply our influence to make those we work with and work even better. You can use these skills to more fully operationalize your compliance program. If you do so, you will not only fulfill the requirements of the DOJ, as laid out in the Evaluation, but you will integrate compliance into the DNA of your company by making it a part of the way you conduct your business. Three key takeaways:

Multipliers are leaders who encourage growth and creativity from their workers.

Diminishers are those who hinder and otherwise keep their employees’ productivity at a minimum.

Multiply the influence of the compliance function both inside and outside the company in this manner.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Such small gestures can make a difference. I recently read a biography of Dale Carnegie by Steven Watts, entitled “Self-Help Messiah: Dale Carnegie and Success in Modern America”, penned by Ian Frazier. Carnegie is of course well known for his seminal work “How to Win Friends and Influence People” first published in 1936. I was somewhat surprised to learn that the text was largely drawn up as transcripts to lectures Carnegie was giving in New York City in the mid-1903s. Carnegie’s main thesis was to provide concrete steps on how ordinary people could help master the art of persuasion. While it has been some time since I read this book, what I recall is that to influence people, one has to listen to them. For me, the book was about how to become a better listener.  I cannot say enough about this skill for a CCO. If you hear any long-term CCO speak about their job, they will tell you it is largely about listening to people; whether those people are employees, senior management or the Chief Executive Officer (CEO) and Board members. By listening to others you not only hear, and hopefully will come to understand their concerns, but you allow them to come to decisions themselves and you are not in the position of telling them what to do. It is a skill that has served many CCOs very well for many years. Three key takeaways:

A little can mean a lot.

One of the primary keys to influencing people is to listen to them.

A CCO can enhance their communications by using the six principals of persuasion.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Our next lesson on compliance communications comes from best-selling authors James Patterson and David Baldacci and it about your brand. I had always thought of your brand as the image customers have of your business. It should be strategic and intentional. For a corporate compliance function, it might mean something along the lines of doing business ethically and in compliance. It could mean creating an effective compliance program that enhances business efficiency that drives greater profitability. It could mean driving an ethical culture to the very heart of your business.  However, Patterson and Baldacci discussed brand in a manner which was very different than the way I think about brand and branding. They said your brand is not an image but is about your relationship with your stakeholders. For an author, that means your readers. For these writers, it means that you deliver what your readers expect and if you are going to go in a different direction, it is important to let your readers know that you are doing something different so that if you pick up a Baldacci or a Patterson, the book will be something other than the thriller or murder mystery you are expecting. While there are other groups you may well have a relationship with as a compliance professional, looking at this from the perspective of Baldacci and Patterson you begin to see the corporate compliance brand and your own personal brand in a very different light. It is one which I think can help you to be both more effective as a compliance professional and lead to more professional opportunities for you as well. Three key takeaways:

How do you define your compliance brand?

What is your relationship with your stakeholders?

As a CCO or compliance professional you can draw lessons from a wide variety of disciplines.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How often have you thought about the role of communications in your entire hotline reporting system? I do not mean posters giving the hotline number, promising anonymity and non-retaliation. I mean using compliance communications to create a social environment where employees feel comfortable speaking up to ask questions and report concerns and they know the options for doing that.  Why do many compliance professionals find it so difficult to use compliance communications to help move the ball forward on driving a speak up culture? It begins because many conflate such communications with training. Training tends to be viewed as something that happens once per year or on a similar cadence. Yet even the DOJ has seen through the fallacy of this argument in its 2020 Update to the Evaluation of Corporate Compliance Programs when it stated, “companies have invested in shorter, more targeted training sessions to enable employees to timely identify and raise issues to appropriate compliance, internal audit, or other risk management functions.” The 2020 Update also leads to the following questions, what resources have been available to employees to provide guidance relating to raising an issue? And, has your company assessed whether its employees know when to seek advice and whether they would be willing to speak up? Can you answer these to satisfaction of the DOJ? If not, you may have a gap in your speak up communications program. The bottom line to all is that in compliance, you are only limited by your imagination. When you overlay creativity on your imagination, you can create something very special. And you can use compliance communications to drive a speak up culture.  Three key takeaways:

How can communications improve a speak up culture?

Use communications to foster trust.

A speak up culture only works when paired with a ‘listen-up’ culture.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 360-degree approach to compliance works with all the stakeholders in a compliance program, even the “Document, Document, and Document” stakeholders; i.e., the regulators. By using innovative techniques, one law firm came up with mechanism to present verifiable evidence to regulators, using the basic techniques of social media in operationalizing compliance as a solution to a difficult compliance issue around, of all things, honey. This example shows how creative thinking by a lawyer, in the field of import compliance, led to the development of a software application, using some of the concepts of social media. Once again demonstrating the maxim that compliance practitioners (and lawyers) are only limited by their imagination, the use of this software tool demonstrates the power of what a 360-degree view can bring to your compliance program. Three Key Takeaways

Use the tools of social media to help tell your story of compliance.

You are only limited by your imagination.

Converging text, pictures and data can be a powerful tool in compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the more difficult things to predict in the mergers and acquisition context is how the cultures of the two entities will merge. Further, while many mergers claim to be a ‘merger of equals’ the reality is far different as there is always one corporate winner that continues to exist and one corporate loser that simply ceases to exist. This is true across industries and countries; witness the debacle of DaimlerChrysler, the disaster of the HP acquisition of Autonomy or the slow downhill slide of United Airlines, Inc. after its merger with Continental Airlines.    In the compliance space this clash of cultures is often seen. One company may have a robust compliance program, with a commitment from top management to have a best practices compliance program. The other company may put profits before compliance. Whichever company comes out the winner in the merger, it can certainly mean not only conflict but if the winning entity is not seen as valuing compliance, it may mean investigations and possibly even violations going forward. Learning how your employees in other countries will approach decision-making and leadership will give you, as the CCO, insight into how they will approach compliance. It will require you to get out into the field to talk with folks. If your company grows organically or through M&A or the JV route, it will need to understand how your new employees will not only think through issues but how they will relate to instructions from the home office in America. Three key takeaways:

Culture clash through a merger can be extremely negative for a company.

What are the cultures of leadership in your organization?

Learning how your employees approach decision making can provide insight into how the will approach compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Why do people share information? The answer to that question has important implications for every compliance practitioner and compliance program. Sharing is a primary method to communicate and connect. In any far-flung international corporation, this is always a challenge, particularly for disciplines which can be viewed as home office overhead at best; the Land of No at worst. Work to hone your message through social media. Part of this is based on experimenting on what message to send and how to send it. Another aspect was based upon the Wave (of all things); its development and coming to fruition in the early 1980s. It took some time for it to become popular but once it was communicated to enough disparate communications, it took off, literally. “It’s the same thing with social media. On social media, we think something will go viral because the art is beautiful or the science is full of deep analytics, but at the end of the day it really takes time to build the community.”  This means that you will need to work to hone your message but also continue to plug away to send that message out. The Morgan Stanley declination will always be instructional as one of the stated reasons the DOJ did not prosecute the company as they sent out 35 compliance reminders to its workforce, over seven years. Social media can be used in the same cost-effective way, to not only get the message of compliance out but also to receive information and communications back from your customer base, the company employees.  Three key takeaways:

What makes your employees want to share information?

Facilitate mechanisms which allow sharing with the compliance function.

The Morgan Stanley declination still resonates.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

I am a huge fan of using social media in your compliance function. But how can you get your arms around how to structure such a program for your company? After acknowledging that social media focuses on the social aspects of the communication, the most important thing to remember is that communication in social media is two-way; both inbound and outbound. It helps to bring your employee base together in an efficient manner to create an environment conducive to compliance for your organization. It also has the benefit of continued engagement. It is more than putting on training or even a set of initiatives; you can continue the conversation and enthusiasm about compliance going forward throughout the year. The authors break this down further into three parts that emphasize 1) the need to listen to and learn from user-generated content; 2) the need to engage and facilitate dialogue with employee innovators; and 3) to find an audience of early adopters to create excitement and collect feedback. If your goal in the compliance function is to create awareness and publicize your compliance program and initiatives, social media can be a powerful tool. This is so paramount it should become a core activity of your compliance function. Using social media tools, your compliance function can not only tell the story of compliance but also communicate expectations and even train. Yet again it is simply more than a one-way tool. Just as employees are more apt to tell you about a concern immediately or soon after they have been trained on that issue; they may well communicate directly with you after having received a social media communication on subjects such as managing of third-party relationships. CCOs and compliance practitioners need to develop a dedicated compliance strategy around social media in the context of your corporate objectives. It allows you a 360-degree view of compliance, through which you can take the input from your employee base and create a compliance experience that your employees will embrace.  Three key takeaways:

Never forget that social media is a two-way communication.

Company employees are the customers of the compliance department.

As with all compliance issues, assess what works for your company and tailor your social media approach appropriately.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How does one company and one CCO actively use social media to make the company’s compliance culture more effective? The company was Dun & Bradstreet, Inc. (D&B) and its then CCO, Louis Sapirman, who discussed D&B’s integration of social media into compliance with me. These tools can go a long way towards enhancing your compliance program going forward. Recall the declination to prosecute that Morgan Stanley received from the DOJ, when one of its managing directors had engaged in FCPA violations. One of the reasons cited by the DOJ was 35 email compliance reminders sent over seven years, which served to bolster the annual FCPA training the recalcitrant managing director received. You can use your archived social media communications as evidence that you have continually communicated your company’s expectations around compliance. It is equally important that these expectations are documented. Finally, never forget the social part of social media. Social media is a two-way communication. Not only are you setting out expectations but also these tools allow you to receive back communications from your employees. The D&B experience around the name change for its Code of Conduct is but one example. You can also see that if you have several concerns expressed it could alert you earlier to begin some detection and move towards prevention in your compliance program. Three key takeaways:

How does 360 degrees of communication work in compliance?

Focus on the ‘social’ part of social media.

Use internal corporate social media to have a conversation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the message of compliance inside of a corporation and how it is distributed? In a compliance program, the largest portion of your consumers/customers are your employees. Social media presents some excellent mechanisms to communicate the message of compliance going forward. Many of the applications that we use in our personal communication are free or available at very low cost. So why not take advantage of them and use those same communication tools in your internal compliance marketing efforts going forward? There is much to be learned by the CCO and compliance practitioner from the disciplines of marketing and social media. These concepts are useful to companies in getting their sales pitches out and can be of great help to you in collaborating and marketing throughout your company. These are only some of the tools that you can incorporate into your compliance program going forward and are a different way to think about who your customers are and how you are reaching them with your message of doing compliance. Three key takeaways:

Let your employees know what you stand for.

Celebrate not only successes but even employees’ efforts.

Give employees a tool kit for compliance using social media.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In this month's offering of 31 Days to a More Effective Compliance Program, you will learn about training and communication techniques that the CCO can use to provide not only a well-rounded role as a CCO but also facilitate a much more holistic approach to compliance in your organization. Best of all the techniques, discussed are largely available to you at little to no cost. There are things that you can do both in your method of running the CCO positions and innovations that you can bring to the compliance function in your organization.  A 360-degree view of compliance is an effort to incorporate your compliance identity into a holistic approach so that compliance is in touch with, and visible to, your employees at all times. It is about creating a distinctive brand philosophy of compliance which is centered on the customers of your compliance program (i.e., your employees). It helps to anticipate all the aspects of your employees needs around compliance especially when compliance is either perceived as new, something that comes out of the home office or as the Land of No. It gives you the opportunity to build a new brand image for your compliance program. The objective is to build trust for the 360-degree process by determining if the goal was achieved. You can utilize surveys or focus groups to assess the impact on your target audience. Focusing on your customers of compliance allows you to identify gaps and improve the communication process for your compliance program. Three key takeaways:

Remember the definition of 360-degrees of compliance communications. It is an effort that moves the compliance identity into a holistic approach, so compliance is in touch and visible to your employees at all times.

What is your objective? What are you trying to do with your 360-degrees view of compliance communications and how are you using that mechanism to deliver the objective your compliance program desires?

You need to evaluate if the message has been delivered, has it been heard and is it being implemented?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update provided clear-cut criteria regarding effective compliance investigations. Sean Freidlin, host of the Compliance Book Club podcast believes that many compliance teams are failing to promptly substantiate a majority of the reports they investigate, due in part to their inability to quickly and easily find the evidence they need, especially in relation to harassment and misconduct cases. He stated, “This doesn’t just demonstrate a fundamental lack of effectiveness from the DOJ’s perspective, but a long-term organizational risk that goes well beyond any individual allegation of misconduct.” The reason is not simply legal but also operational. If there are substantive allegations that are indeed violations, they could continue, thereby exacerbating the problem(s) but also lengthening the time of legal liability. All of this is particularly significant in light of the industry research that shows many compliance investigations today are unsubstantiated and can take over 40 days from start to finish. The ability of AI to find and analyze data from the web and social media in this automated fashion will be able to overcome some of those challenges both in terms of length of time and overall scope of the investigation. Final always remember data preservation. One thing the regulators always want to know is if you have the documents and data tied down. This allows a company to have confidence their documents and, in turn, can make such representations to regulators and prosecutors that the documents are secure. In other words, Document, Document, and Document.  Three key takeaways:

AI is an appropriate tool for supplementing investigations.

AI can look at large bodies of social media data.

AI can help you decrease you investigation length.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update not only continued to emphasize the importance of monitoring and testing the effectiveness of a compliance program, but it spoke more about a Chief Compliance Officer (CCO) and compliance function utilizing data to engage in both continuous monitoring and continuous improvement. The DOJ for some time now has stressed the importance of leveraging data in order to have objective evidence around whether or not a compliance program is working effectively. Yet, as many CCOs are legally trained they are unsure about what some of the specific areas to be considered are in establishing quantifiable metrics to monitor for effectiveness. A methodical review of the 2020 Update to identify the different areas where a company could potentially establish and quantify metrics to assess effectiveness is the place to start. Many companies have what Edwards called “metrics on the basics” and noted they “have in place processes whereby their employees review the Code of Conduct and confirm they are in compliance with it either when they first onboard with the company and then periodically on an annual basis, companies are doing just fine at reporting.” But it is now the barest minimum of what compliance professionals must do. For instance, they could consider the lifecycles of Quote To Cash (QTC) or Procure To Pay (P2P). The key is to start with a documented process which can be audited and build out from there. Three key takeaways:

Create an inventory of compliance metrics.

Create your metrics based upon the 2020 Update.

Use these metrics for continuous monitoring and improvement.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update emphasized the need for the corporate compliance function to ensure both consistency and fairness not only in monitoring investigations but also in monitoring the resulting discipline. One of the ways the 2020 Update emphasized this was through tracking the investigations and the discipline that may come out of any investigation. One of the challenges companies have is facts and circumstances are always different in every investigation. This makes it sometimes difficult, but if companies treat employees of one country different in terms of discipline, it does create potential gaps in a compliance program. This can then give certain countries a feeling that they can do what they want, without the risk of punishment from corporate headquarters. This is why the DOJ re-emphasized monitoring the investigations and ensuring consistent application of discipline as a critical factor in ensuring an effective compliance program. The FCPA Resource Guide, 2nd edition, added a new hallmark to the previously titled 10 Hallmarks of an Effective Compliance Program (now it is simply the Hallmarks). The Hallmark added was one which has been around for some time and it is Root Cause Analysis (RCA). It is not new because it was subtly considered in the original FCPA Resource Guide and explicitly discussed since at least the original formulation of the Evaluation of Corporate Compliance Programs in February 2017. The focus on consistency is both insightful and instructive as a key element of a best practices compliance program. Consistency forms the basis of both institutional justice and institutional fairness. That in turns, facilitates a speak up culture, which is the role of the compliance department to foster. Three key takeaways:

Consistency is a key part of any compliance program.

Consistency forms the basis of both institutional justice and institutional fairness.

Consistency facilitates a speak up culture.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Going into the 2020s and beyond, a corporate compliance function needs to be an integral part of your corporate business strategy going forward. One of the key reasons is the ever-important debate of compliance as a cost center will become more critical going forward in this decade. Obviously if compliance programs are not effective, enforcement actions will continue to be extremely costly. Over last 10 years, there has been an increasing impact on the business where you not only must have compliance resources focused on remediation, but business resources as well. This has only grown greater with reputational risks amplified by social media. This is because as significant (and costly) as these regulatory fines and penalties have been, it is the intangible reputational damage which, in the long run, may be even more costly. With multiple stakeholders who might not desire to play out on the risk curve that might be higher risk or located in higher jurisdictions or operating in higher risk industries. Further, there are other consequential impacts if compliance does not have a seat at the table. If compliance has a seat at the table, there can be some leeway for compliance officers and for firms to figure out how best to roll out a compliance program that is commensurate with the organization’s risk and compliant with the regulations. If compliance is relegated to the back of the (corporate) bus there will be little chance to do so. Three key takeaways:

It will be even more important for compliance to have a seat at the table going forward.

Look for synergies with other types of compliance.

Such synergies can be a big cost savings.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Measuring the effectiveness of your compliance program will be one of the key criteria going forward. One of the mechanisms to do so is through Key Performance Indicators (KPIs). KPIs are a critical component in showing compliance program success or failure, if you have been working towards your stated goals and for reporting success. And while specific requirements for this kind of reporting have been hotly debated in the industry for some time, KPIs are a regulatory requirement. Your KPIs are going to be specific and unique to your company and what business it conducts along. Couple this with what goals you are trying to achieve as a whole as a compliance program and you will see there is no set list of these metrics. KPIs provide yet another mechanism for you to monitor and update your compliance program on an almost continuous basis. KPIs can be extremely low in cost and therefore something you can put in place without a lot of approval from higher ups in your organization that you might have to go to for budget approval. Finally, innovation can come in many ways. Obviously ComTech can be a huge jump forward. But sometimes innovation can occur at much less cost and a much more granular level. KPIs can be such a mechanism for you. Three key takeaways:

KPIs will be critical to assess a compliance program going forward.

Set your KPIs.

Decide on how to use KPIs and the blueprint for going forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Disconnectedness compliance comes from the fact there is not one system which connects the disparate strands of the compliance discipline. In the view of Thomas Sehested, GAN Integrity founder and its former Chief Executive Officer connected compliance “enables a CCO and all those people in the organization working with compliance, to have one central place, a one system of record for everything they do.” This can be their whistleblowing hotline, case management, training of their employees or training of their vendors policy. It is literally connecting them all so they are running from one central location and these disparate systems can be monitored from one central location. He put it as, “really like getting everything under one roof.” I was struck by that metaphor, “getting everything under one roof”, as one of the struggles many compliance officers have is that the information they need is literally siloed across different functions of the company. Information can be contained in the sales function, where there may be employee expense data, information on marketing expenses or charitable donations may be in the sales organization but it could be spread among other corporate functions as well. All of this is what the DOJ has articulated as operationalizing compliance. It first garnered attention in the February 2017 release of the original Evaluation of Corporate Compliance Programs. Since that time, compliance practitioners have steadily worked to move their compliance programs forward onto the front lines of their business units. Connected compliance is one way to do so but it clearly requires a human element to not only interpret data but to impart the appropriate or required compliance solution. Operationalizing compliance means that you cannot have an annual or even quarterly update on what’s going on in the program. It must be operationalized in such a way that you are sharing information not only with the regional business units of floating up to the corporate compliance folks, but also sharing information back and forth with the other business units, procurement, finance and reacting in real time. Three key takeaways:

Connected compliance moves you towards continuous monitoring.

Compliance under one roof.

Never forget the human element.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The DOJ and SEC have both made it clear that they expect companies to be more robust in their use of data analytics in compliance programs. This means using data to not only detect and prevent illegal conduct but also in the remediation prong of any best practices compliance program as well through continuous improvement. In 2019, former Deputy Assistant Attorney General Matthew Miner said in a speech that the DOJ will inquire whether compliance departments have access to internal data that could help them identify misconduct and whether compliance officers make adequate use of data analytics in their reviews of companies under investigation. Since at least 2016 in the FCPA enforcement action involving Key Energy Services, Inc., the SEC has been communicating to compliance professionals of the need for increased use of data and data analytics in any compliance program. The bottom line is that it is not if but when you begin to incorporate corporate information into your compliance program to make your compliance program more efficient and your business process run more effectively. My suggestion is that you begin now to identify the data you have access to and the data to which you currently do not have access. Find a way to bridge that gap. Three key takeaways:

DOJ pronouncements mandate CCO availability to and use of data.

Data can be an actionable solution across geographic and business lines.

Use data as a business strategy.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Yesterday we considered the compliance professional in the 2020s and beyond. Today we look at the Compliance Function. The Coronavirus pandemic has accelerated change in compliance that have been percolating for the last few years. Indeed, I believe that in as short a time as 5 years, 2020 will be seen as an inflection point in compliance; IE., the Year When Everything Changed. There are four major changes I would like to highlight. Compliance Convergence. In 2019 there were three significant releases of information by the federal government which directly impacted compliance professionals. Public/private partnership in anti-corruption fight. Over the past few years, the DOJ has gone far towards laying out real incentives for corporations to help in the fight against the international scourge against bribery and corruption. Data, Data, Data. The DOJ has made it clear that it expects companies to be more robust in their use of data analytics in compliance programs. Compliance as the Ethical Edge. We have known for many years that companies with more robust compliance programs were most generally better run companies. This academic research and other case studies demonstrate the effective compliance programs equates to more efficient business processes and leads to greater profitability. As senior business leaders come to understand this message, they will (properly) see compliance as a business process which can be analyzed and improved through continuous improvement to make companies run more efficiently and at the end of the day more profitably. These companies do not make money because they have a better heart, they are more profitable because they are better run. Finally, all of this ties back to a requirement from the DOJ for continuous improvement of your compliance program.  Three key takeaways:

It’s all about compliance now.

Compliance connectedness.

It’s all about the data.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What should compliance practitioners do to move themselves forward professionally in the 2020s and beyond? Ton consider this question, I drew inspiration from the Financial Times (FT) piece, entitled “Work in the 2020s: 5 essential skills to succeed”, by Lyndsey Jones. In this article Jones laid out five areas where workers need to have skills that will keep abreast of the ever-evolving marketplace. They are: (1) Adapt to thrive, (2) Be creative; (3) Develop emotional intelligence; (4) Become tech savvy; and (5) Build your personal brand. Being a compliance professional in the coming decade will be one of the most challenging, rewarding and exciting professions for anyone to engage in. You have the opportunity to help lead not only your organization but also your profession. To paraphrase Alyson Van Hooser, will you put your (compliance) stake in the ground and own it? For your sake and the sake of the compliance profession going forward, I hope you will do so. Three key takeaways:

Adapt to thrive as you are only limited by your imagination.

Build your brand and deliver.

Be creative.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Where is compliance training headed? In the 2020 Update, the DOJ stated, “companies have invested in shorter, more targeted training sessions to enable employees to timely identify and raise issues to appropriate compliance, internal audit, or other risk management functions.” While this tactical solution has proven useful, I wanted to consider the broader compliance training themes that compliance professionals have learned over the past few years to gain insight into where compliance training may be headed. I sat down with Shawn Rogers, Director Global Ethics and Compliance - Training and Awareness at Walmart, to provide some thoughts on the veiled land of the future of compliance training. Compliance training needs to get to the point where managers and leaders drive compliance training based on how they perceive the risks in their organizations. In other words, an awareness of risks can permeate the organization to such a degree that managers will be able to recognize when their employees need training and can call on the compliance function to provide custom training opportunities. Three key takeaways:

Business crisis almost always begin with a culture failure.

Focus your most detailed training on those employees who are truly high-risk.

This is the “just-in-time” training model provides training exactly when and where the employee needs the information.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The more you can operationalize compliance, the more it works to operationalize culture in your organization. It works for all levels of a company, literally from the Boardroom to the shop floor. The DOJ and SEC recognized this when they noted in their 2020 FCPA Resource Guide, “A compliance program should apply from the board room to the supply room - no one should be beyond its reach.” Yet culture can provide more than simply an ethical foundation, it is also a part of the business foundation of an entity. Using such an approach to communications, allows a CCO to “see around corners” and can be one of the greatest strengths of a best practices compliance program. The reason is listening. Listening is a key leadership component and there are certainly many ways to listen. You can sit in your office and wait for a call or report on the hotline or you can go out into the field and find out what challenges employees are facing. From this you can work with them to craft a solution that works for the company and holds to the company’s ethical and compliance values. Using social media tools, a CCO can move towards Thomas’ next key ingredient of a successful corporate culture; which is trust. Thomas said, “I’m obsessive about the culture that we create specifically around trust, and this is an adjustment for some people when they come here. If you join our team, there’s trust by default here. That means you trust in the competence of your teammates. You trust in their intentions and what they’re saying. At some companies, the culture is that trust is earned over time, but that means if everyone in the organization says you have to earn trust, the amount of energy that actually goes into the trust-earning process is a distraction from our mission.” Three key takeaways:

A company can fail if it does not get its culture right.

Using communications to “see around corners”.

Trust works as a business strategy.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

We are now at a place where there is sufficient data, academic research and actual use cases from corporations and businesses that demonstrate good ethics and compliance programs are not simply good for business but when properly used, they lead to greater profitability.  The data and information you collect, which might initially begin as a compliance solution or project can be used to improve business process efficiency. It can also be the case that the delivery of a compliance solution can improve an overall business process. When you start to consider the compliance data points in every organization, from the Quote To Cash (QTC) sales cycle to the Procure To Pay (P2P) procurement cycle you begin to see how compliance can be used to improve business efficiency and lead to greater profitability. Three key takeaways:

The World’s Most Ethical companies had 13.5% delta about the S&P 500 average in 2020.

Companies with robust compliance programs do better financially in countries prone to corruption than companies with less effective compliance programs.

What does the data tell you?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Through restructuring, senior leadership can signal that digital transformation in compliance is critical for the future of the organization. From this point the compliance function can work with an internal digital product design group. By doing so, the corporate compliance function can work with a team dedicated to supervising the development of the new compliance solution through product design, testing, and analysis, which will include customized generative design and analysis tools. Top management can signal the importance of the compliance digital transformation by using this dedicated team to spearhead the compliance function’s digital transformation development process. One of the great things about the compliance world is that we are only limited by our own imaginations. If you can imagine a better way for your company to fully do compliance, it is at your disposal to do so. Yet rarely do we think about the structure of how compliance activates as a way to more fully operationalize compliance. By identifying and bringing in the skills needed to move forward with compliance innovation, you can help kick-start the compliance operationalize process through a digital transformation of your compliance regime. By doing so, you may make all the difference between success and failure coming out of the Coronavirus health crisis as the world reopens for business. Three key takeaways:

Have you considered a generational team approach to a digital transformation in compliance?

Have non-compliance professionals aid in compliance program development.

In compliance you are only limited by your own imagination.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the lessons we have learned from various FCPA enforcement actions over the years is how complexity in business organizations can work to defeat compliance programs. Whether a corrupt employee is working to actively hide a pot of money, which can or will be used to pay a bribe, or an improper payment slips through the cracks; complexity can work to defeat a best practices compliance program. If a compliance function does not have visibility into a business unit, how it does business and where its payments are going; it may be due to design defect or inadvertent complexity. Compliance is now in an era of brisk innovation and evolution. It is prone to technological change and rapid obsolescence of the lawyer-driven, spreadsheets and word document-based compliance programs. Going forward the compliance professional needs to understand that a “package of resilience, adaptability, coordination, and inimitability becomes more attractive than the package of efficiency, understandability, manageability, and predictability.” The key is to learn how to harness complexity on a sustainable basis. Three key takeaways:

Not all complexity is bad.

If you cannot figure out how a foreign does business you have a problem.

Compliance is now properly seen as a business process.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Have you ever thought of compliance as an ecosystem? When you consider the concept, it becomes clear that this is one thing every company should strive towards. Obviously, every multi-national company must have a compliance program. But to have true effectiveness, your compliance program must be operationalized throughout the organization. One way to facilitate this is through the ecosystem concept. There is another way that this ecosystem approach can make your compliance program more effective. Think about the third parties your company has both on the sales and the supply chain side. If you could work to create a closer ecosystem with those stakeholders from the compliance perspective, it would not only make the business relationship stronger but also make the entire business process more efficient. 2020 has brought a paradigm shift to corporate compliance as a result of technological and digital innovation. CCOs who cannot interpret the data from their own systems will likely find themselves consigned to the dustbin of corporate luddites. Compliance will be moving into a new era of collaboration and connection to more fully operationalize compliance to make all business stakeholders more efficient and at the end of the day more profitable. Three key takeaways:

A compliance function’s customers are a variety of stakeholders.

Compliance can improve business processes.

A compliance ecosystem can help to operationalize compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Business ventures, whether JVs, partnerships, franchises, team agreements, strategic alliances or one of the myriad types of business relationships a U.S. company can form outside the U.S., are different than the usual risk presented by third-parties under compliance requirements such as those mandated by the FCPA. The problems for companies is that they tend to treat business venture risk the same as third-party risk. They are different and must be managed differently. The bottom line is that may compliance practitioners have not thought through the specific risks of business ventures such as JVs, franchises, strategic alliances, teaming partner or others as opposed to sales agents or representatives on the sales side of the business. I hope that this will help facilitate a discussion that maybe people will begin to think about more of the issues, more of the risk parameters and perhaps put a better risk management strategy in place. Three key takeaways: 

Business ventures bring different FCPA risks from third-parties.

JVs have both external compliance risks and corporate governance risks.

Use your full compliance tool kit for business ventures in managing the FCPA risk for franchises.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Three enforcement actions which made clear that there were no distinctions between agents and distributors. They were the Smith & Nephew, Inc., Oracle and Eli Lilly and Company. Each of these enforcement actions had different FCPA violations and they each revealed separate steps which a company should take to both prevent and detect FCPA violations in their company.  These three separate bribery schemes call for three different but overlapping responses. The Lilly enforcement action also makes clear the need for internal audit to follow up with ongoing monitoring and auditing. Internal audit can be used to help determine the reasonableness of a commission rate outside the accepted corporate norm. The Oracle enforcement action demonstrates that Oracle needed to institute the proper controls to prevent its employees at Oracle India from creating and misusing the parked funds in the distributor’s account. The Company needed to audit and compare the distributor’s margin against the end user price to ensure excess margins were not being built into the pricing structure. Smith & Nephew did not perform sufficient due diligence on these distributors nor did they document any. Further, the distributor was domiciled in a location separate and apart, the UK, from the sole location it was designed to deliver products or services into, Greece. This clearly demonstrated that the entities were used for a purpose that the company wished to hide from Greek authorities. While it is true that a distributor might sell products into a country different than its domicile, if the products are going into a single country, this should have raised several Red Flags. Three Key Takeaways

Use auditing and monitoring.

Distributors will be treated the same as other business ventures. 

Robust due diligence must be performed. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Polycom came to FCPA grief in China, as have many other US companies. The bribery scheme was long running, occurring from 2006-2014. They included the creation of an off-the books accounting and recordation system for corrupt payments made by or on behalf of Polycom China. The money to fund these bribes came through variations of the basic bribery scheme. There would be a discount between the price reported to Polycom and that paid by the buyer. These discounts were not passed on to the end customer, but instead were intended to cover the cost of the payments the distributors made to the Chinese government officials. In other words, this discount would form the basis of the pot of money to pay the bribe.  The Chinese business unit was equally creative with the reasons for the discounts, which were listed in the CRM. Polycom China usually cited competition with one or more vendors was required to give discounts on pricing. They also claimed that some end-using customers refused to pay full price. However these were all false excuses entered into the CRM to hide the truth from auditors and others charged with reviewing and approving the discounts. Three Key Takeaways

Channel your inner Woodward and Bernstein and follow the money.

Simply because some type of compliance oversight is difficult or requires extra effort, it is no excuse not to monitor.

Channel you inner Ronnie Reagan as well and ‘trust but verify.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Most franchisors have thorough financial vetting requirements before allowing any person or business to become a franchisee. However, how many of these same businesses perform compliance due diligence on their prospective overseas franchises? How many U.S. franchisors have compliance training programs? How many evaluate, on an ongoing basis, the compliance program of their overseas franchisees? How many U.S. franchisors have a compliance hotline or other reporting mechanism for any compliance violations made against their franchisees?  Some issues include health and wage compliance officials who may appear during routine health inspections or local wage and hour compliance determinations; intellectual property officials, as maintaining intellectual property rights is critical for any franchise model; utility officials as every franchise operation needs power maintained; and government procurement officials if the franchise is selling to a foreign government or state owned enterprise. How would all of this play out for a franchisor? As a franchisor moves into foreign markets there could well be the temptation to “grease the skids” and make payments or offer gifts to government officials, or their family members, to get the permits or permissions necessary to open and operate. In many countries, bribery is a common way of getting business done, and there can be tremendous pressure from local agents or franchisee candidates to follow regional customs and use bribes to become or remain competitive. Even if it is not the U.S. franchisor’s own employees that engage in the FCPA violations, the U.S. franchisor will still face the risk of an enforcement action if the franchisee’s employees engage in such conduct. Three key takeaways: 

Franchises can bring an unexpected level of FCPA exposure.

Franchisors must have more than financial vetting for potential franchisees.

Use your compliance tool kit for business ventures in managing the FCPA risk for franchises.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There remains a question about franchisor liability under the FCPA. Franchising has been a successful model in the U.S. and now many corporations are looking at overseas expansion opportunities. Franchise law has become well developed across the U.S., with many states developing laws to protect the rights and obligations of both parties in a franchise agreement.  There are no reported FCPA enforcement actions regarding franchisors. However, the factors in a franchise relationship would appear to lead to clear FCPA responsibility of the franchisor for its overseas franchisee’s actions. Additionally, court interpretation of the FCPA has held that it is applicable where conduct is used “to obtain or retain business or secure an improper business advantage” which can cover almost any kind of advantage, including indirect monetary advantage even as nebulous as reputational advantage. As everyone knows, the FCPA prohibits payments to foreign officials to obtain or retain business or secure an improper business advantage. Nevertheless, many U.S. companies view franchisees as different from other types of more direct sales representatives, such as company sales representatives, agents, resellers or even JV partners, for the purposes of FCPA liability. The Master Franchise model is typically the most used model in international franchise expansion. It generally revolves around a Master Franchise agreement between the U.S. based franchisor and a franchisee in a specific geographic territory. This franchisee then contracts with third-party sub-franchisees within the specified territory. Typically, the U.S.-based franchisor will have no contractual relationship with the international sub-franchisees. The master franchisee acts as the franchisor in the local market and recruits, trains, and provides other support in the local area on behalf of the U.S. franchisor. Here the FCPA exposure is both direct and indirect. While some believe that a franchisor may not have direct involvement in conduct prohibited by the FCPA, as there may not be the requisite corrupt intent required under the statute. However, unless a franchisor has an adequate compliance program in place, a franchisor may well find itself in the shoes of Frederic Bourke and sustain a finding of conscious indifference. Three key takeaways: 

Consider the different types of international franchise agreements to help assess your compliance risk. 

There are no reported FCPA enforcement actions involving international franchisors, yet.

Franchisors must conduct thorough research in both the foreign market they hope to enter and on their potential franchisees.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Many compliance practitioners generally view distributors as a part of their third-party risk management program, with most of their attention on the pre-contract phase of the risk management process. Typically, most of the efforts are spent on due diligence with less on managing the relationship after the contract is signed. However, many facets of a corporate relationship with a distributor are closer to those of other business venture partners.  One of the issues in any compliance program is the compensation paid to a business venture partner as FCPA exposure arises when companies pay money - either directly or indirectly - to fund bribe payments. In the traditional intermediary scenario, the company funnels money to a business venture partner, who then passes on some or all of it to the bribe recipient. Often, the payment is disguised. Rethinking approaches to evaluating distributor activities is but one of the ways that the increased number of enforcement actions, 2020 FCPA Resource Guide, 2nd edition and DOJ’s 2020 Update to the Evaluation of Corporate Compliance Programs, have provided insight into how the government interprets and enforces the FCPA. This information, in turn, allows companies to get smarter about FCPA compliance. With a manageable amount of forethought, companies who rely on distributors can create, install and maintain systems which allow them to spend fewer resources to more effectively prevent violations. Moreover, these systems generate tangible proof of a company’s genuine commitment to FCPA compliance, by more fully operationalizing this aspect of their compliance program. Many companies have been involved in FCPA enforcement actions because of distributors. This sales side channel does not receive the focus equal to that of commissioned sales agents. Yet it can present an equally large compliance risk. By using this DAR approach, you will have created a well-thought out process which will operationalize your compliance program around distributor compensation, in a manner which documents your decision-making calculus. Three key takeaways: 

The creation of well-thought out process which operationalizes your compliance program around distributor compensation, in a manner which documents your decision-making calculus is key.

Require multiple levels of approval for an out of range distributor discount.

Tracking distributor discounts globally makes your company more efficient.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One area not usually considered around your business ventures is the financial health of JV partner, teaming partner, strategic partner or any other type of business partner or relationship which might occur in a business venture. It turns out such an oversight may have some significant ramifications for an accurate picture of a business venture partner. The financial health of a business venture partner as not only a key metric but also a key tool which allows a more robust assessment prior to contract signing and in managing the relationship after the contract has been signed.  A business venture partner which is in a weakened financial position can come back to damage your business in a variety of ways. Obviously, a company which is under financial strain is more susceptible to cutting corners to obtain business. You can almost begin to see the fraud triangle forming at this point and a rationalization for committing a FCPA violation forming in the mind of a business venture partner. Continuous improvement through monitoring of ongoing financial health is a tool where technological solutions can have an impact. Understanding the financial viability of third-parties can help the compliance practitioner meet the DOJ requirement to more fully operationalize a compliance program. It can also lead to more and better operational stability and with that ever-sought increase in corporate profitability. As compliance moves into the business process, this type of review should become part of your compliance toolkit going forward. Three key takeaways: 

What is the financial health of your business venture partners? Do you even know?

Poor financial results can open a business venture partner to engaging in risky behavior.

Financial health monitoring is key for monitoring business venture partners.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One area not often considered by the CCO as a key part of any compliance regime is the Corporate Controller. The Controller generally has the responsibility to accurately record and report the financial transactions of the company, to design, implement and execute the financial processes and controls of the company to be both effective and efficient, and to safeguard the financial assets of the company. Some of the compliance responsibilities of the Controller include: 1) Designing and implementing internal controls that impact ethics and compliance risks; 2) Accurately recording the financial transactions of the company; and 3) Preventing and detecting fraudulent activity. All of this means, in practical terms the Controller is both being the keeper of the books and records and the implementer of internal controls. Moreover, while many of these internal controls would most probably be viewed financial internal controls, there are additional internal controls which are not financial in nature.  Russ Berland, Chief Integrity & Risk Officer at Aventiv Technologies, has noted, “Those guys live really in the battle zone. They are constantly looking at financial transactions. They’re evaluating them. They’re figuring out where things go within the books and records. They are implementing the processes that should be keeping fraud from happening; keeping bribery and corruption from happening.” These benefits are not a one-way street for compliance as a Controller benefits from a closer relationship with the corporate compliance function as well. They can leverage compliance resources. The compliance function can bring its observations and insights from investigations and emerging risks to the Controller. A closer collaboration will broaden awareness of compliance risks which relate to the company’s financial processes. By more fully integrating compliance into the Controller function a more robust picture of enterprise risk emerges, one which encompasses legal, compliance, ethics, internal controls, financial, business and governance risks. Three key takeaways: 

CCOs need to integrate the function of the Controller into their compliance regime.

Offshore payments must be flagged for further investigations.

The Controller is both the keeper of the books and records and the implementer of internal controls.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Do FCPA considerations come into play for customers? How should you think about your obligations under the FCPA for a group not traditionally associated with FCPA liability or even FCPA risk? These questions and perhaps others are raised by the 2015 FCPA investigation into certain transactions in Venezuela by Derwick Associates (Derwick) and a U.S. company ProEnergy Services (ProEnergy). ProEnergy supplied turbines that Derwick resold to the Venezuelan government and then installed in that country. This investigation demonstrates why businesses need to be more concerned with not only who they do business with but how their customers might be doing business. In banking and financial services parlance, you now need to ramp up your organization’s Know Your Customer (KYC) information to continue throughout a seller-purchaser relationship, in the context of the FCPA. There does not have to be a direct bribe or other corrupt payment made by a U.S. company to have liability under the FCPA. FCPA enforcement is littered with companies that have paid bribes through third-parties. However, as the Fifth Circuit said in US v. Kay, “[W]e hold that Congress intended for the FCPA to apply broadly to payments intended to assist the payor, either directly or indirectly,” [emphasis mine]. While at first blush, ProEnergy may appear to be at the edge of potential FCPA liability; if it knew, had reason to know, or should have taken steps to know about some nefarious conduct by its customer, it does not take too many steps to get to some FCPA exposure. The FinCEN rules on customer due diligence for financial institutions are a good starting point for other commercial entities to base their compliance program for customers around. Three key takeaways: 

Non-banking and non-financial service entities need to consider their KYC obligations in the context of FCPA risk.

FinCEN rules on customer due diligence are a good starting point for the non-financial institution.

Ongoing monitoring should be used and the information incorporated into your customer risk profile going forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

I want to emphasize again the risks JVs pose under the FCPA. Mike Volkov has stated, “A joint venture requires the integration of disparate company cultures. It can be successful and is usually one of the significant reason for the joint venture itself.” Both parties should assess each other and decide that the JV is a good fit, meaning that each side will benefit. Too much time is spent on looking at the JV partner’s compliance toolbox (i.e., policies, procedures, and controls), and not enough time is spent on identifying compliance strengths and weaknesses. You must bring it all together with one format. Indeed the 2020 Update to the Evaluation of Corporate Compliance Programs posed the following questions under the category, “Process Connecting Due Diligence to Implementation” What has been the company’s process for tracking and remediating misconduct or misconduct risks identified during the due diligence process? What has been the company’s process for implementing compliance policies and procedures, and conducting post- acquisition audits, at newly acquired entities? Remember a “newly acquired entity” can be a joint venture. Three key takeaways: 

It all starts with a Relationship Manager.

Have company oversight of all JVs. Couple this with a COC for a second set of eyes.

Audit, monitor, and remediate (as appropriate) your JVs on an ongoing basis.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Your company has just made its largest acquisition ever and your CEO says that he wants you to have a compliance post-acquisition integration plan on his desk in one week. Where do you begin? Of course, you think about the 2020 FCPA Resource Guide, 2nd edition but you also remember that the established time frames in the enforcement actions involving Johnson & Johnson (J&J), Pfizer Inc. and DS&S and the Halliburton Opinion Release.  While there are time frames listed in these DPAs, they are a guide of timeframes, not a ‘how to’ guide and many compliance professionals struggle with how to perform these post-acquisition compliance integrations. The 2020 Update to the Evaluation of Corporate Compliance Programs asked the following questions, What has been the company’s process for tracking and remediating misconduct or misconduct risks identified during the due diligence process? What has been the company’s process for implementing compliance policies and procedures, and conducting post- acquisition audits, at newly acquired entities? Whatever compendium of steps you utilize for post-acquisition integration, they should be taken as soon as practicable. Three key takeaways: 

Planning is critical in the post-acquisition phase.

Build upon what you learned in pre-acquisition due diligence.

You need to be ready to hit the ground running when a transaction closes.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The compliance component of your M&A regime should begin with a preliminary pre-acquisition assessment of risk. Such an early assessment will inform the transaction research and evaluation phases. This could include an objective view of the risks faced and the level of risk exposure, such as best/worst case scenarios. A pre-acquisition risk assessment could also be used as a “lens through which to view the feasibility of the business strategy” and help to value the potential target.  I suggest a four-step process to plan and execute a strategy to perform pre-acquisition due diligence in the M&A context.

Establish a point of contact.

Collect relevant documents. 

Review the compliance and ethics mission and goals. 

Review the elements of an effective compliance program.

There are multiple red flags which could be raised in this process, which might well warrant further investigation. They include if the target has ineffective compliance program elements in their compliance program or if there were frequent breach of policies and procedures. Obviously, a target which is in financial difficulty would bear closer scrutiny. Structurally, if the company did not have a formal ethics and compliance committee at the senior management or Board of Directors’ level, this could present issues. From the CCO perspective, if the position did not have Board or CEO access or if there were not regular reports to the Board, it could present an issue for compliance. Conversely, if there were frequent requests to waive policies, management over-ride of compliance controls or no consistent consequence management for violations; it could present clear red flags for further investigation. Three key takeaways: 

The results of your pre-acquisition due diligence will inform your post-acquisition integration and remediation going forward.

Periodically review your M&A due diligence protocol.

If red flags appear in pre-acquisition due diligence, they should be cleared.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the clearest themes from the original, 2012 FCPA Resource Guide was around the importance of your pre-acquisition work in any M&A on a target company. In the section on Declinations, the 2012 FCPA Resource Guide provided an example of a company which had received a declination in large part because of its pre-acquisition work, which then served as a basis of its post-acquisition remediation. I find it appropriate to think of the process as a straight line, directly from the pre-acquisition phase through to closing and then to remediation, integration and self-reporting in the post-acquisition phase. These same concepts were brought forward in the 2020 FCPA Resource Guide, 2nd edition.  It should all begin with a preliminary pre-acquisition assessment of risk. Such an early assessment will inform the transaction research and evaluation phases. This could include an objective view of the risks faced and the level of risk exposure, such as best/worst case scenarios. A pre-acquisition risk assessment could also be used as a mechanism through which to view the feasibility of the business strategy and help to value the potential target. The first step is to develop the risk assessment as a base document. From this document, you should be able to prepare a focused series of queries and requests to be obtained from the target company. Thereafter, company management can use this pre-acquisition risk assessment to attain what might be required in the way of integration, in the post-acquisition phase. It would also help to inform how the corporate and business functions may be affected. It should also assist in planning for timing and anticipation of the overall expenses involved in post-acquisition integration. These costs are not insignificant and they should be thoroughly evaluated in the decision-making calculus. The pre-acquisition risk assessment can be a critical element in any M&A work for compliance. Use this opportunity to see where the target might stand on compliance. Your risk assessment can evolve as you obtain greater information. Finally, use this pre-acquisition risk assessment as a base document to plan, resource and budget for your post-acquisition remediation, integration and reporting. Three key takeaways: 

One never has enough time to engage in all of the pre-acquisition review you might want to do, so optimize your time and resources.

Consider what you can review to put together a preliminary risk assessment on the target.

As with most compliance initiatives, you are only limited by your imagination, so if you are limited in time and scope, try something new and different.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Why should a company engage in pre-acquisition due diligence in the M&A context? Certainly, compliance with anti-corruption laws such as the FCPA or U.K. Bribery Act is a good starting point. A Transparency International white paper, entitled “Anti-Bribery Due Diligence for Transactions”, suggested that there are greater forces driving compliance than simply compliance with anti-corruption and anti-bribery laws. A company engaging in an international acquisition should also strive to avoid the potential financial and reputational damage that may arise from investing in or purchasing a company associated with bribery or corruption. Financial, legal, or reputational risk can have a significant impact the valuation or a transaction or its desirability. Factors such as current or historical bribery/corruption discovered at any point in the acquiring company provide the compliance practitioner with strong ammunition when confronted with a management that fails to understand the need for a robust due diligence in a M&A transaction. By not focusing on the regulatory aspects of M&A transactions, but more on the market reasons for engaging in the appropriate due diligence, you can emphasize the business reasons for compliance. Three key takeaways: 

There are numerous legal and business reason to engage in anti-corruption due diligence in the M&A space.

ESG can present significant corruption risks in emerging markets.

Present your analysis in high, medium and low risk formats.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

White collar defense practitioners have long called for a specific safe harbor for companies in the mergers and acquisition context where they meet the criteria set out by the DOJ. This clarion call was answered in the summer, 2018 when in July 2018, the DOJ announced a revision to the FCPA Corporation Enforcement Policy, specifically around mergers and acquisitions. The new language read:  M&A Due Diligence and Remediation: The Department recognizes the potential benefits of corporate mergers and acquisitions, particularly when the acquiring entity has a robust compliance program in place and implements that program as quickly as practicable at the merged or acquired entity. Accordingly, where a company undertakes a merger or acquisition, uncovers misconduct through thorough and timely due diligence or, in appropriate instances, through post-acquisition audits or compliance integration efforts, and voluntarily self-discloses the misconduct and otherwise takes action consistent with this Policy (including, among other requirements, the timely implementation of an effective compliance program at the merged or acquired entity), there will be a presumption of a declination in accordance with and subject to the other requirements of this Policy. In announcing the change, then Deputy Assistant Attorney General Matthew Miner, that while the 2012 FCPA Resource Guide did provide some guidance on what may constitute a safe harbor; that word ‘may’ was a “sticking point for corporate management when deciding whether and how to proceed with a potential merger or acquisition. There is a big difference between a theoretical outcome and one that is concrete and presumptively available.” Three Key Takeaways

The FCPA Corporate Enforcement Policy was amended in 2018 to provide a safe harbor in the M&A context.

Pre and post-acquisition compliance work must be equally robust.

If you find misconduct, report and remediate.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

JVs provide many FCPA risks that other types of business relationships do not bring. For instance, the JV may interact with foreign government officials or employees of a state-owned enterprise; then leverage those relationships for an improper benefit relating to contracts, regulatory licenses, permits or customs approvals. It is difficult to regulate a JVs interaction with foreign government officials when your partner is a state-owned enterprise, or where your company is relying on the local company for its local contacts and expertise for business development and/or regulatory knowledge and experience.  The risks are compounded when the U.S. company does not exercise control of the JV. This is further compounded by the fact there is no minimum threshold for a FCPA enforcement action against a U.S. company for the actions of a JV in which it holds an interest. If a company holds something less than majority rights, it must to urge, beg and plead for the majority partner to adhere to anti-corruption compliance standards and controls. Often, these requirements are established in the JV agreement but the success in securing such contract protections depends on the importance of the global company to the JV itself. Another set of issues comes from the JV when it seeks to retain third-party agents and/or distributors. Depending on the amount of control, the U.S. company usually can impose its set of standards for conducting due diligence of third-party agents and distributors. These risks become more difficult when the JV partner brings a proposed third-party agent or distributor and vouches for the agent or distributor. If the JV partner is a state-owned enterprise, the issues become even more complicated as such a referral creates an obvious red flag for a government-sponsored referral. Now add on the fact that the JV partner may not be proficient in English as a first language. The U.S. company may not have financial personnel with requisite language skills in the foreign country. Some companies have a policy that English will be used throughout the world in its business dealings. However, even with such an English only policy in place, the risks represented by such lack of effective oversight by the multinational extend not only to potential FCPA violations, but to other corrupt acts, including kickbacks, fraud and theft. Three key takeaways: 

JVs present unique FCPA risks and must be managed accordingly.

Your final report needs to consider the final viewer of the document, potentially the DOJ or SEC.

Be sure to follow up on any red flags raised but not cleared and action items for remediation or additional scrutiny. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Numerous U.S. companies have come to FCPA grief for their overseas JVs and this continues to be a bane for many companies under the FCPA. There are some basic compliance terms and conditions which should be considered for any foreign JV agreement to help U.S. companies manage these compliance risks.  As a starting point, it is important to have compliance terms and conditions, these reasons can include some of the following: 1) to set expectations between the parties; 2) to demonstrate the seriousness of the issue to the non-U.S. party; and 3) to provide a financial incentive to do business in compliant manner. This all must be spelled out for them, so you should have language regarding the following:

Prohibition of all forms of bribery and corruption. 

Right to cancel, and recoupment rights.

Duties in JV Governance.

Audit rights.

Prohibited Parties.

Certifications.

After the contract is signed your company will have to work just as hard to keep the compliance program for any JV robust and meaningful. However, with these terms and conditions in place, you will have a chance to maintain your FCPA obligations and to manage the risk that is involved when working jointly with non-U.S. companies. Three key takeaways: 

Failure to secure appropriate compliance terms and conditions in a JV agreement can cause great FCPA risk for a U.S. company.

Certifications are important requirements to obtain.

Audit rights must be secured and equally importantly, exercised. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

When you bring two entities together to operate jointly, there are several difficult issues to analyze. For the U.S. company operating under the FCPA, there must be an adequate business justification for a JV with a specific partner, all in writing and approved by an appropriate level of the organization. This is where the due diligence process comes into play. The due diligence process should be built on principles similar to those involving third-parties. The procedure should be robust, documented and address all potential risks involved. A company should use its due diligence review of the JV partner to properly assess and uncover any corruption risk. Using this due diligence and its evaluation, you can then move to contractual clauses, certifications, representations and warranties from a JV partner or insist on other remedial measures to minimize its risk exposure. In addition to asking for all of this information, you must take care to document the entire process that your company goes through in the investigation and creating a foreign JV. (“Document, Document, and Document”) It is equally important to remember that obtaining this information is only one step. A company must evaluate the information and follow up if responses to such inquiries warrant such action. A paper program is simply not good enough and can lead to serious consequences if red flags are not reviewed and cleared. This evaluation should also be documented so that if a regulator ever comes knocking you can demonstrate what you asked for, why, the response, your follow up and the details of your evaluation. Finally, never forget the human factor. It is important to perform an in-person interview of your proposed JV partner. It is important that you meet them, see their facilities and assess them up close and personal. A U.S. business looking to engage a JV partner must consider the people who make up its JV partner. As you will have to mesh what may be two very different cultures and understandings of compliance, it is important to assess how your potential JV partner will take these obligations before, rather than after you ink the JV agreement. Three key takeaways: 

JV due diligence must focus on the unique risks.

Ask for a detailed list of information from your potential JV partner.

Be sure to do onsite investigation of your potential JV partner.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Just as the FCPA enforcement field is covered with actions centering around M&A, there are multiple actions involving JVs. JVs continue to plague many U.S. companies up to this day. In many ways, JVs present more difficult issues for the compliance practitioner than M&A because of the control issues present in JVs with foreign governments or state-owned enterprises ownership. There are other risks that a company must seek to avoid. These include the transfer of things of value to a state-owned enterprise for benefits of someone outside the JV. A company must avoid payments for which there is no legitimate business purpose to the state-owned enterprise in the JV itself; as they will be deemed to be illegal benefits to the state-owned enterprise outside the JV. In this case, the JV becomes a vehicle by which to disguise bribery payments for benefits to those outside the JV. Any company which operates a JV with foreign governments or state-owned enterprises holds the same FCPA risk as the JV partner itself; the risks become apparent relating to the operation of the JV itself. This means that if the JV interacts with foreign government officials or employee of a state-owned enterprise and leverages its state-owned enterprise relationships for an improper benefit either contracts and/or regulatory licenses, permits or customs approvals; it could well be subject to FCPA scrutiny. Unfortunately, it is often difficult to regulate JV interactions with foreign government officials, particularly when your partner is a state-owned enterprise, or where your company is relying on the local company for its local contacts and expertise for business development and/or regulatory knowledge and experience in the country where the JV operates. The bottom line is JVs present a unique set of FCPA risks for the compliance practitioner. You will need to incorporate risk management techniques in all phases of the JV relations; pre-formation, the JV agreement and in operations after the JV has begun operation. The compliance obligations and compliance process are ongoing. Three key takeaways: 

JVs present unique FCPA risks.

Control is only one issue a compliance practitioner must consider in evaluating JV risks.

Companies continue to have significant FCPA risks from JVs.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of my favorite words in the context of FCPA enforcement is dis-link. It a useful adjective in explaining how certain conduct by a company must be separated from the winning of business and more broadly it works on many different levels when discussing the FCPA. The concept of dis-linking was most prominently laid out in Opinion Release 14-02. It provided one of the most concrete statements from the DOJ on the unidimensional nature of compliance in the M&A context; both in the pre-acquisition and post-acquisition phases. Opinion Release 14-02, taken together with the steps laid out in the 2020 FCPA Resource Guide, 2nd edition, has provided the post-acquisition actions a compliance professional needs to take after the transaction is closed. If you cannot perform any or even an adequate pre-acquisition due diligence, the time frames you put in place after the acquisition closes will need to be compressed to make sure that you are not continuing any nefarious FCPA conduct going forward. But it all goes back to dis-linking. If a Target is engaging in conduct that violates the FCPA but the Target itself is not subject to the jurisdiction of the FCPA, you simply cannot afford to allow that conduct to continue. If you do allow such conduct to continue your company will be actively engaging and participating in an ongoing FCPA violation. That is the final takeaway from this Opinion Release; it is allowing corruption and bribery to continue which brings companies into FCPA grief. Opinion Release 14-02 provides a roadmap of the steps you can take to prevent such exposure. Three key takeaways: 

In the M&A context, the key is to dis-link any illegal conduct going forward.

Opinion Release 14-02 provides the clearest roadmap for pre- and post-acquisition compliance actions in the M&A context.

Never forget the Opinion Release procedure. It has been used successfully in two important M&A matters (08-02 and 14-02).

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are some of the key FCPA enforcement actions involving M&A? These enforcement actions, FCPA Resource Guide and the Evaluation of Corporate Compliance Program (and Update) have all made clear that the DOJ and SEC will vigorously prosecute companies which allow bribery and corruption to continue after a merger or purchase occurs. The key point to remember is that if a company was engaging in bribery and corruption before it was acquired and continues to do so after the transaction is completed, it is now you who is engaging in bribery and corruption, not them.   Three key takeaways: 

FCPA enforcement in the M&A space is one of the most well settled areas of enforcement.

Failure to perform pre-acquisition due diligence can significantly devalue a purchased asset.

Always remember that if bribery continues after an acquisition it is no longer them engaging in bribery and corruption but you who are engaging in bribery and corruption. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

We next consider how to create a more effective compliance program involving business ventures. This will include the role of compliance in M&A, JV agreements, distributorships, teaming agreements and franchises as well as other forms of business relationships.  The FCPA Resource Guide, 2nd edition made clear that one of the Hallmarks of An Effective Compliance Program is around M&A, in both the pre- and post-acquisition context. A company that does not perform adequate due diligence prior to a merger or acquisition it may face both legal and business risks. Perhaps, most commonly, inadequate due diligence can allow a course of bribery to continue - with all the attendant harms to a business’s profitability and reputation, as well as potential civil and criminal liability. In contrast, companies that conduct effective due diligence on their acquisition targets can evaluate more accurately each target’s value and negotiate for the costs of the bribery to be borne by the target. Equally important is that if a company engages in the suggested actions, they will go a long way towards insulating, or at least lessening, the risk of FCPA liability going forward. The 2020 Update went on to say that to “The extent to which a company subjects its acquisition targets to appropriate scrutiny is indicative of whether its compliance program is, as implemented, able to effectively enforce its internal controls and remediate misconduct at all levels of the organization” and posed the following queries. One of the key themes in this chapter is the integrated nature of compliance and business ventures. Whether the compliance work is seen in the M&A context, JV context or one of the myriad of other business relationships of the current business world, there is an approach that a CCO or compliance professional should take to assess the risk, monitor the risk and then manage the risk with continued monitoring with a feedback of data and information into your risk management strategy. Three key takeaways: 

Consider the role of compliance in a wide variety of business relationships, including M&A, JV agreements, distributorships and franchises as well as other forms of business relationships.

Compliance for M&A should be seen as a unidimensional continuum.

The Evaluationfocuses on what data did your risk monitoring system turn up and how did you utilize it going forward?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

To conclude this month's series on Internal Controls, I am joined by Vin DiCianni, Founder and CEO of AMI. We discuss how corporate culture is a foundational internal control. It is a fascinating topic that is not discussed enough by compliance professionals.   3 Key Takeaways.

It must start at the top.

Hiring is critical to creating and sustaining an ethical culture. 

Creative internal controls around culture. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A gap analysis is a method of assessing the differences in performance between a business’ internal controls to determine whether business requirements are being met and, if not, what steps should be taken to ensure they are met successfully. Moreover, it is a determination of the degree of conformance of your organization to the requirements of an internal controls standard. A gap analysis is mainly a document review or a “show me the evidence” type activity, evidence which usually will come in the form of a record or document. During a gap analysis, there is some auditing accomplished, through key stakeholders providing the evidence they may have - or not - for each of the requirements set forth in the relevant internal controls standard. In this episode, I am joined by AMI's Eric Feldman to explore this topic.   3 Key Takeaways

Now is the time for a gap analysis. 

Add a Fraud Risk Assessment to your gap analysis.

Culture is a foundational internal control. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next, consider what COSO says about assessing compliance internal controls. In its Illustrative Guide, COSO laid out its views on “how to assess the effectiveness of its internal controls.” It went on to note, “An effective system of internal controls provides reasonable assurance of achievement of the entity’s objectives, relating to operations, reporting and compliance.” Moreover, there are two over-arching requirements that can only be met through such a structured post. First, each of the five components are present and functioning. Second, are the five components “operating together in an integrated approach.” One of the most critical components of the COSO 2013 Internal Controls Framework is that it sets internal control standards against those which you can audit to assess the strength of your compliance internal controls. Under a compliance regime, you may be faced with known or relevant criteria to classify any deficiency. For example, if written policies do not have at a minimum the categories of policies laid out in the 2020 FCPA Resource Guide, which states “the nature and extent of transactions with foreign governments, including payments to foreign officials; use of third parties; gifts, travel, and entertainment expenses; charitable and political donations; and facilitating and expediting payments”, also formulated in the Illustrative Guide, such a finding would preclude management from “concluding that the entity has met the requirements for effective internal controls in accordance with the Framework.” Three key takeaways:

A new revenue recognition standard has become effective. What have you done from the compliance perspective?

This new revenue recognition standard is much more judgment based and when a standard is more judgment based, there can be more room for manipulation.

Compliance internal controls now can also be used to gather the information which will be presented to auditors under the new rev rec standard.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The fifth and final Objective is Monitoring Activities and as with all other components of the COSO Cube, Monitoring Activities are part of an inter-related whole and cannot be taken singularly. For the CCO or compliance practitioner, Monitoring Activities has been growing in importance over the past few years and will continue to do so in the future as is reinforced in the COSO 2013 Internal Controls Framework.  The Monitoring Activities objective consists of two principles: 1) The organization selects, develops and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning; and 2) the organization evaluates and communicates internal control deficiencies timely to those parties responsible for taking corrective action, including senior management and the Board of Directors, as appropriate. Principle 16: Ongoing evaluation. Principle 17: Evaluation and communication of deficiencies. Discussion. Monitoring Activities should bring together your entire compliance program and give you a sense of whether it is running properly. Both ongoing monitoring and auditing are tools the CCO and compliance practitioner should use in support of this objective. The most important item to note is that all the controls need to be sustainable. You cannot just build one-off controls and not have a process in place to help you monitor all the controls that you need to cover. Controls cannot just be a one and done. Many companies are going to find that their initial approach to all of this is one and done. There must also be a mechanism in place for the communication of controls which do not work or can readily be over-ridden. From there, you must be able to remediate your controls going forward. This will align with the compliance professional’s requirement to prevent, detect and remediate going forward. Three key takeaways:

Monitoring activities is inter-related with all other Principles and cannot be taken singularly.

Monitoring activities helps to ensure that all controls are present and functioning.

Monitoring Activities should bring together your entire compliance program and give you a sense of whether it is running properly.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As with the other components of the COSO Cube, the objective of Information and Communication is not to be taken in a vacuum. Indeed, one of the more interesting aspects of this objective is that it runs not only vertically but also horizontally.  Principle 13: Use of relevant and quality information. Principle 14: Communicate internally. Principle 15: Communicate externally. Discussion. Obviously, there must be communications up and down from the Board but also within an organization for dissemination of the appropriate compliance related information. For this principle, the CCO or compliance practitioner should also evaluate the communication lines to third parties. This communication can flow both ways, as noted, with compliance obligations to third parties but also information in the form of compliance issues back from third parties. Joe Howell noted “communication internally is how you establish the communications with your sales organization, with your sales operations. How do you establish communications with the legal organization? How do you establish information with the post-sales organizations? Even with the auditors, and your internal auditors and your external auditors and the board, to give the Audit Committee of the Board comfort that the company has put in place the right levels of controls.” Three key takeaways:

Consider the use of relevant and quality information.

You need to document your internal communications so auditors can review the audit trail.

This objective relates to your third-party compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In its Framework Volume, COSO Control Activities “are the actions established through policies and procedures that help ensure that management’s directives to mitigate risks to the achievement of objectives are carried out.” They should be performed at all levels in an organization’s process cycle.  Principle 10: Selects and develops controls activities. Principle 11: Selects and develops general controls over technology. Principle 12: Control activities established through policies and procedures. Discussion. While the objective of Control Activities should be the most familiar to the CCO or compliance practitioner, this objective demonstrates the inter-relatedness of all the five COSO Objectives and the corporate functions in your organization. It is your control environment and then risk assessment that should lead you to this point. It is the Control Activities objective that lays the groundwork for a living, breathing compliance program going forward. This objective requires that you have new ways of capturing, gathering, confirming the accuracy and completeness of the information and the controls reporting it. The Control Activities regarding the policies and procedures needed is certainly an important consideration going forward. Three key takeaways:

Think of a “second set of eyes” as a primary control activity.

SODs must always be employed.

Control Activities should be performed at all levels in the business process cycle and this speaks directly to the operationalization of your compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Objective II is designed to provide a company with a dynamic and iterative process for identifying and assessing risks. For the compliance practitioner, none of this will sound new or even insightful, However the Framework requires a component of management input and oversight that was perhaps not as well understood.  The objective of Risk Assessment consists of four principles. Principle 6: Suitable objectives. Principle 7: Identifies and analyzes risk. Principle 8: Fraud risk. Principle 9: Identifies and analyzes significant change. Discussion. The SEC has made it clear that companies should be expanding their view of risk in implementing the COSO 2013 Internal Controls Framework. Obviously, risk assessments are a cornerstone of a best practices compliance program as laid out in the 2012 FCPA Guidance and in the DOJ’s Evaluation. The regulators are telling companies specifically that they should be seeing new risks that they need address because of the changes brought about by the new standard. Three key takeaways:

Risk assessments are required under the COSO 2013 Internal Controls Framework, the 2012 FCPA Guidance and almost all other best practices compliance programs.

Look at your risks across your organization and not in a siloed manner.

Risks, both determination and management of, changes over time so be cognizant of changes in business practices on the ground.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The first of the five objectives is control environment and it sets the tone for the implementation and operation of all other components of internal control. It begins with the ethical commitment of senior management, oversight by those in governance, and a commitment to competent employees. The five principles of the control environment object are as follows:  Principle 1: Commitment to integrity and ethical values. Principle 2: Board independence and oversight. Principle 3: Structures, reporting lines, authority and responsibility. Principle 4: Attracting, developing and retaining competent individuals. Principle 5: individuals held accountable. Discussion. Both Board of Directors’ independence and Compliance Committee (or other applicable committee) oversight are essential to this objective because the committee needs to be actively engaged to be comfortable that the company has implemented the internal controls under SOX 404(a); as required under Principles 1 and 2. Under Principle 3, structures in reporting lines, authority and responsibility are essential to the recognition of revenue. Under Principle 4, a business must attract and develop, then retaining competent talent. This ties into Principle 5, which mandates individuals being held responsible. This requires someone to document that they have made a judgment based upon the evidence that they have been able to accumulate, that the company has analyzed that evidence and has gone through the process of comparing this to the COSO 2013 Internal Controls Framework and to the spirit of the standard.  Three key takeaways:

What controls do you have in place to measure conduct at the top?

Reporting lines must be clear and functioning.

You must provide the right personnel with the right resources.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

COSO was adopted in 1992 as a framework for basis to design and then test the effectiveness of internal controls. In 2010, it was deemed necessary to update this more than 20-year old COSO Framework, to provide a more supportable approach when adversarial third parties challenged whether a company has effective internal controls (such as the SEC). While the COSO 2013 Internal Controls Framework is designed for financial controls, I believe that the SEC will use this to review a company’s compliance internal controls. This means that you need to understand what is required under the COSO 2013 Internal Controls Framework and can show adherence to it or justify an exception if you receive a letter from the SEC asking for evidence of your company’s compliance with the internal controls provisions of the FCPA. COSO has produced three volumes detailing the COSO 2013 Internal Controls Framework. The first lays out the Framework and is entitled “Internal Control – Integrated Framework”, herein “the Framework volume.” The second is an illustrative guide, entitled “Internal Controls – Integrated Framework, Illustrative Tools for Assessing Effectiveness of a System of Internal Controls”, herein “the Illustrative Guide”, which discusses how best to assess your internal control regime and provides forms and work sheets to use. The third volume is the “Executive Summary of the first volume, herein “Executive Summary”. All three works form an excellent starting point for exploration of the COSO 2013 Internal Controls Framework and how you might use it for your best practices anti-corruption compliance program. In the COSO 2013 Internal Controls Framework update the basic framework was retained with substantial support from user companies, and 3 specific objectives were added: I) Operations Objectives – effectiveness and efficiency of operations, including safeguarding assets against loss; II) Reporting Objectives – internal and external financial reporting; and III) Compliance Objectives – adherence to laws and regulations to which the entity is subject. According to the guidance in the 2013 update, the system of internal controls can be considered effective only if it provides reasonable assurance the organization, among other things, complies with applicable laws, rules, regulations and external standards. With the addition of those specific objectives, the COSO 2013 Internal Controls Framework now specifically includes the need for controls to address compliance with laws and regulations. The COSO 2013 Internal Controls Framework defines internal controls, from bottom to top, with the following Objectives: a) Control Environment, b) Risk Assessment, c) Control Activities, d) Information and Communication, and e) Monitoring. From these five Objectives come 17 Principles which we explore in more detail. Three key takeaways:

You must use the 2013 Internal Controls Framework or a similar source for your internal controls structure.

The 2013 Internal Controls Framework identifies the following areas: a) Control Environment, b) Risk Assessment, c) Control Activities, d) Information and Communication, and e) Monitoring.

Your internal controls must be sustainable.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In 2016, one of the most interesting non-international focused FCPA enforcement actions was announced by the SEC. It involved a clear quid pro quo benefit paid out by United Airlines, Inc. to David Samson, the former chairman of the Board of Directors of the Port Authority of New York and New Jersey, the public government entity which has authority over, among other things, United’s operations at the company’s huge east coast hub at Newark, New Jersey. The reason that it is so interesting from an enforcement prospective is that it is not foreign corruption but domestic corruption, therefore not subject to the foreign government official requirement of the FCPA. However, the actions of United’s former CEO, Jeff Smisek, in personally approving the benefit granted to favor Samson violated the company’s internal controls around gifts to government officials. That sounds suspiciously like a books and records violation of the FCPA. The $2.4 million civil penalty levied on United was in addition to its NPA settlement with the DOJ, which resulted in a penalty of $2.25 million. Former Chairman Samson also pled guilty for putting pressure on United to reinstitute a flight service which was near his weekend residence. At the time, United’s Code of Conduct prohibited “United employees from directly or indirectly making bribes, kickbacks or other improper payments to government officials, civil servants or anyone else to influence their acts or decisions” and that “[n]o gift may be offered or accepted if it will create a feeling of obligation, compromise judgment or appear to improperly influence the recipient.” Only the United Board of Director’s could grant a waiver to the code and none was sought or obtained by Smisek. The Order concluded, “The [Chairman’s] Route was initiated in violation of United’s policies.” Three key takeaways:

It is very unusual for the FCPA to form the basis of a domestic bribery violation.

A Code of Conduct can be an internal control.

Even a CEO must follow internal controls.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Is a Board of Directors a compliance internal control? The clear answer is yes. In the 2020 FCPA Resource Guide, Hallmarks of an Effective Compliance Program, there are two specific references to the obligations of a Board in a best practices compliance program. One states, “Within a business organization, compliance begins with the Board of Directors and senior executives setting the proper tone for the rest of the company.” The second is found under the Hallmark entitled “Oversight, Autonomy and Resources,” which says the CCO should have “direct access to an organization’s governing authority, such as the Board of Directors and committees of the Board of Directors (e.g., the audit committee).” Further, under the U.S. Sentencing Guidelines, the Board must exercise reasonable oversight on the effectiveness of a company’s compliance program. The DOJ Prosecution Standards posed the following queries: Do the directors exercise independent review of a company’s compliance program, and are directors provided information sufficient to enable the exercise of independent judgment? The DOJ’s remarks drove home to me the absolute requirement for Board participation in any best practices or even effective anti-corruption compliance program. Three key takeaways:

Board oversight over the compliance function is a separate internal control so document it and use it.

Board must perform oversight over your company’s internal controls.

Does your Board use the five principles for involvement in compliance internal controls?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

It is reasonable to expect that internal controls over gifts, travel and entertainment be designed to ensure that they satisfy the criteria as defined in company policies. These are narrow, including a definition of the dollar limit, which must not be exceeded for gifts to be permissible, coupled with some subjective criteria such as the legality of the gifts for the recipient and whether the practice is customary within the country where the gift is delivered. The question I focus on is how to enforce the policies so that employees are not free to disregard them at will?  The key analysis is whether there are controls in place to enforce the policies and whether those controls are documented. There are four issues to evaluate:

Is the correct level of person approving the payment/reimbursement for the gift?

Are there specific controls, including signoffs, to demonstrate that the gift had a proper business purpose?

Are the controls regarding gifts sufficiently preventative, rather than relying on detect controls?

If controls are not followed, is that failure detected by other internal controls or the compliance protocols?

Internal controls around gifts can be used in a variety of ways in your best practices compliance program. They can certainly be used to detect an issue and perhaps even prevent an issue from becoming a full-blown FCPA violation, however, by using some of the techniques you can move your compliance program to a proscriptive phase where you not only stop an issue from becoming a violation but through identification, you can move towards remediation as a part of your ongoing compliance efforts. The bottom line is good internal controls make for good business processes; if you can move your compliance program’s internal controls forward, you can help make them a part of your financial controls and thereby have a better run company.  Three key takeaways:

Gifts, travel and entertainment compliance internal controls are low hanging fruit, pick them.

Compliance internal controls can be both detect and prevent controls.

Good compliance internal controls are good for business.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the questions GSK faced during the bribery and corruption investigation of its Chinese operations was how an allegedly massive bribery and corruption scheme occurred? Where were the appropriate internal controls? You might think that a company as large as GSK and one that had gone through the ringer of a prior DOJ investigation resulting in charges for off-label marketing and an attendant Corporate Integrity Agreement (CIA) might have such controls in place. It would be reasonable to expect that internal controls over gifts would be designed to ensure that all gifts satisfy the required criteria, as defined and interpreted in company policies. It should fall to compliance to finalize and approve a definition of permissible and non-permissible gifts, travel and entertainment and internal controls will follow from such definition or criteria set by the company. These criteria would include the amount of the spend, localized down into increased risk such the higher risk recognized in China. Within this context, there are four general internal controls to consider. 1) Is the correct level of person approving the payment/reimbursement?; 2) Are there specific controls (and signoffs) that the gift had proper business purpose?; 3) Are the controls regarding gifts sufficiently preventative, rather than relying on detect controls?; and 4) If controls are not followed, is that failure detected? Obviously, the use of third parties can be a powerful and effective way for a business to achieve its strategic goals. This may be one of the key reasons why third parties are still one of the leading indicia of bribery and corruption. Every compliance program should regularly review its third-party service providers and evaluate internal policies and procedures to ensure compliance. Three key takeaways:

GSK continues to be an example of the lack of internal controls for third-parties in an effective compliance program.

General areas of review for compliance internal controls.

Third parties are still the highest risk of corruption related issues.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next, I consider some ways in which a compliance professional can work to implement internal controls in a multi-national organization. The first step is to convert your company’s compliance risks into internal control objectives. The internal control objectives are then given to each business unit with instructions to develop controls, which meet the objectives. This process should allow more of a fine-tuning approach within existing systems than the development of specific controls by corporate which all business units must adopt and will give the business unit a sense of buy-in and participation in the process.  Good compliance internal controls are not some standalone protective measure. They can help to make a company run more efficiently as the internal controls that prevent FCPA violations are the same ones that prevent fraud in the workplace. The presence of good internal controls saves money by preventing fraud. It is a business best practice to prevent fraud, which includes preventing corruption. One need only consider Ethisphere and its annual survey of the world’s most ethical companies because they exceed the Standard & Poor’s index of average profits and growth by a factor of 4X. A key reason such companies have better than average profitability is that they have better internal controls. Three key takeaways:

Convert your compliance risks into internal control objectives.

As with many components of a best practices compliance program, tone at the top is critical.

If you receive pushback from the business folks, always remember, good internal controls make for a better, more efficient and more profitable business.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As they made clear with several FCPA enforcement actions in 2020, the SEC has continued to emphasize the accounting provisions of the FCPA, specifically the internal controls provisions. Charles Cain, the Chief, FCPA Unit; Division of Enforcement of the SEC, reiterated that the SEC is committed to protecting investors in U.S. public companies and those which list other securities in the U.S., through enforcement of the accounting provisions, including internal controls provisions of the FCPA. The reason is straightforward; a company with rigorous internal compliance controls is better able to prevent, detect and remedy any FCPA violations that may occur. What can you do around the FCPA’s requirements for internal controls and continued SEC enforcement emphasis? I would suggest that you begin with an exercise where you map the internal controls your company has in place to the indicia of the Ten Hallmarks of an Effective Compliance Program, as set out in the 2012 FCPA Guidance. While most compliance practitioners are familiar with the Hallmarks, you may not be as familiar with standards for internal controls. I would suggest that you begin with the COSO 2013 Internal Controls Framework as your starting point. As a CCO or compliance practitioner, this is an exercise that you can engage in at no cost. You simply investigate and note what internal controls you have in place and how they may be a part of your anti-corruption efforts going forward. Compliance is a straightforward exercise; this does not mean that it is easy, you do have to work at it so that you will simply not have a paper, “check the box”, program. But using the excuse that you have limited resources is simply an excuse and a rather poor one at that. While the clear lesson from the BHP enforcement action is that you are required to have effective internal controls in place, by engaging in this mapping exercise you can then figure out what you have and, more importantly, what internal compliance controls that you do not have and need to institute. Three key takeaways:

Learn the internal controls your company currently has in place.

Map your compliance internal controls to the COSO 2013 Internal Controls Framework.

Use your gap analysis as a basis for remediation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next, I will review how to use the risk assessment you have performed as a tool to provide a structured approach to establishing effective internal controls. After preparation of the risk assessment, the next step is to prioritize the listing of the risks and which locations they are common. This begins by mapping existing internal controls to risks and then assessing whether the internal controls are sufficient to mitigate the risks.  One of the biggest risks under the FCPA is where sales are conducted through third parties. If your company is moving to new geographic markets or new products and does not plan to use an internal sales team to facilitate these new efforts it presents a high compliance risk. The compliance function should understand the corporate or business unit controls over the international business in addition to the necessary controls over agents. Some of the questions you might consider are the following: Is there a U.S. based international sales manager who is responsible for growing the business? What is the incentive compensation plan? How good are the SODs? In other words, can the international sales manager unilaterally make high-risk decisions, or must a senior officer of the business unit or the corporate home office be part of the approval process? Finally, and in a point not to be forgotten or dismissed, how are these internal controls documented? What about a situation in opposite to the above scenario, where your company’s primary sales channel uses a U.S. based sales force which only travels to locations outside the U.S. for temporary visits of generally short duration. This situation minimizes, retains and shifts some compliance risks. The minimized compliance risks come from the lessening on the reliance of third parties so that a company, at least in theory, would have more control over its own work force than those employed outside the company. The retained risks are the risks associated with gifts, travel and entertainment; approval of credit terms to customers; product pricing; special arrangements with customers such as providing product samples; knowing who the ultimate customer is and where the goods are ultimately shipped; and use of freight forwarders and customs agents. Shifted risks are created if there is no physical location outside the U.S. because the accounting must be done in the U.S. This means that compliance risks regarding the accounting function simply shift to the U.S. accounting department where transactions are processed and recorded and where the financial statements are prepared.  These identified risks need to be subject to appropriate internal controls because it is well established that the issuance of a Code of Conduct and/or compliance policy and training of said policy’s requirements is a good practice, but it does not provide reasonable assurance that employees will comply with the policies. What is needed are written procedures and work instructions, in the native language of the respective employees, that defines exactly what the procedures to be performed are and how they will be evidenced. As difficult as it is for U.S. employees to translate, by themselves, what it means to comply with policies, it may be significantly more difficult for employees outside the U.S., not only due to language but also due to traditional local business practices, cultures and customs. Three key takeaways:

Third party risks are still your highest risks under the FCPA so use your internal controls appropriately to help prevent this risk from becoming a violation. 

Use mapping and a gap analysis to collate risks to existing controls. 

Always consider the regional and geographic variances. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How should you assess your internal controls regime for international operations? It is incumbent that you need to review as much information as you can to understand the financial and operational structure of an entity and how it is integrated with the corporate headquarters, or the U.S. business unit’s financial and operation structure, if the foreign operation is part of a U.S. business unit.  You could begin with the TI-CPI to garner a sense of the reputation of the country in which your business unit is located, as well as the CPI for all other countries in which the location either markets business or has current customers. Another area for inquiry or review is the scope of your foreign operations. This means you will need to consider your sales model, whether employee based or primarily using third party representatives. You will also need to consider if such third-party representatives are coming into a commercial relationship with your company through your supply chain. Other areas of inquiry should include whether your company’s finance and accounting staff produce financial statements that are integrated into the parent’s financial statements; whether your international business locations utilize a local bank account for local sales receipts as well as funds transfers from the U.S. and whether the account has local check signers and whether dual signatures are required on the checks. You may also want to consider the extent to which disbursements are made in the local currency and, of course, is there a local petty cash fund. Three key takeaways:

You must understand the financial and operational structure of your company and how that structure outside the U.S. is integrated with the corporate headquarters.

Are your financial statements and reporting systems integrated?

Always consider the fraud triangle. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next, I want to consider some of the issues around internal controls outside the U.S. and why your company’s internal controls might require changes for different countries across the globe. However, this provides an opportunity to further operationalize your compliance program through internal controls more narrowly tailored to mirror your business practices. Every CCO should consider entity-wide internal controls for a company. Under the FCPA accounting provisions, issuers can be held liable for the conduct of their foreign subsidiaries, even though the improper conduct occurred outside of the U.S. The scope of liability is based on the issuer’s incorporation of the subsidiary’s financial statements in its own records and SEC filings. So, as with the use of third-party distributors to sell product, FCPA enforcement looks past the structure of the transaction and makes enforcement decisions based upon the substance. While a CCO should expect (or at least hope) that internal controls at locations outside the U.S. are of the same effectiveness as internal controls within U.S. business units and at the U.S. corporate office; unfortunately, that might not always be the case. It is often the case that corporate level internal controls are stronger than those in foreign business units. There may well be several reasons for this. First, the CFO may be paying closer attention to the corporate level internal controls, with the idea that the corporate level internal controls are the final “filter” to detect issues. This follows partly from the focus in most companies on the controls over financial reporting, which does not include all controls needed for compliance. A second reason is that many companies were built through acquisitions, resulting in many business units (both in and outside the U.S.) having completely different accounting, ERP and internal control systems than the corporate office. There is often a tendency to leave acquired companies in the state in which they were acquired, rather than trying to integrate their controls and conform them to those of current business units. After all, the reason for the acquisition was the profitability of the acquired company and nobody wants to be accused of negatively impacting profitability. Three key takeaways:

Modifying your internal controls can work to more fully operationalize your compliance program.

Check the effectiveness of your internal controls for your international locations.

Revisit your internal controls when a country or region experience large growth or other disruption.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There are four significant controls that I would suggest the compliance practitioner implement initially. They are: 1) DOA; 2) maintenance of the vendor master file; 3) contracts with third parties; and 4) movement of cash/currency. Your DOA should reflect the impact of compliance risk including both transactions and geographic location so that a higher level of approval for matters involving third parties, for fund transfers and invoice payments to countries outside the U.S. would be required inside your company. The vendor master file, can be one of the most powerful preventativecontrol tools largely because payments to fictitious vendors are one of the most common occupational frauds. Near and dear to my heart as a lawyer are contracts with third parties. These can be a very effective internal control which works to prevent nefarious conduct rather than simply as a detect control. The Hewlett-Packard (HP) FCPA enforcement action was an excellent example of the lack of internal control over the disbursements of funds and movement of currency because you had the country manager delivering bags of cash to a Polish government official to obtain or retain business. All situations where funds can be sent outside the U.S., including such methods accounts payable computer checks, manual checks, wire transfers, replenishment of petty cash, loans or advances, should all be reviewed from the compliance risk standpoint. This means you need to identify the ways in which a country manager or a sales manager could cause funds to be transferred to their control and to conceal the true nature of the use of the funds within the accounting system. To prevent these types of activities internal controls, need to be in place. This means all wire transfers outside the U.S. should have defined approvals in the DOA, and the persons who execute the wire transfers should be required to evidence agreement of the approvals to the DOA and wire transfer requests going out of the U.S. should always require dual approvals. Lastly, wire transfer requests going outside the U.S. should be required to include a description of proper business purpose. The bottom line is that internal controls are just good financial controls. The internal controls that detail requirements for third party representatives in the compliance context will help to detect fraud, which could well lead to bribery and corruption.  Three key takeaways:

Remember the top four internal controls for an effective compliance program.

Effective internal controls should do more than protect but also prevent internal program violations.

Effective internal compliance controls are good financial controls.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

New York Times columnist David Brooks’ thoughts on building and maintaining order inform the discussion on rigor in your internal controls. In internal controls, I believe it is incumbent to consider not only the most obvious risk areas for your internal controls but also the universe of potential transactions within the operations of a company. There is a clear need for rigor in your internal controls protocols and adherence to that rigor can increase operationalization around the internal controls a company should consider including gifts, travel and entertainment expenses. Brooks said, “Building and maintaining order…requires toughness of mind and rigid discipline to properly serve your own work.” By having the rigor to institute and enforce the types of internal controls Howell has identified, you can go a long way towards detecting and, more importantly, preventing a FCPA violation from occurring. Three key takeaways:

You must maintain rigor around your internal controls.

Controls against fraud can also help to prevent corruption.

Building and maintaining good internal controls requires rigor.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What specifically are internal controls in a compliance program? Internal controls are not only the foundation of a company but are also the foundation of any effective anti-corruption compliance program. Internal controls expert Joe Howell, former Executive Vice President (EVP) at Workiva, Inc., has said that internal controls are systematic measures, such as reviews, checks and balances, methods and procedures, instituted by an organization that performs several different functions. These functions include allowing a company to conduct its business in an orderly and efficient manner; to safeguard its assets and resources, to detect and deter errors, fraud, and theft; to assist an organization ensuring the accuracy and completeness of its accounting data; to enable a business to produce reliable and timely financial and management information; and to help an entity to ensure there is adherence to its policies and plans by its employees, applicable third parties and others. Howell adds that internal controls are entity wide; that is, they are not just limited to the accountants and auditors. Howell also notes that for compliance purposes, controls are those measures specifically to provide reasonable assurance any assets or resources of a company cannot be used to pay a bribe. This definition includes diversion of company assets, such as by unauthorized sales discounts or receivables write-offs as well as the distribution of assets. Three key takeaways:

Effective internal controls are required under the FCPA.

Internal controls are a critical part of any best practices compliance program.

There are multiple FCPA enforcement actions that demonstrate the enforcement spotlight on internal controls.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In an area of inquiry entitled Oversight, the 2020 Update asks three basic questions which we have explored throughout this chapter: 

What compliance expertise has been available on the Board of Directors?

Have the Board of Directors held executive or private sessions with the compliance function?

What types of information has the Board of Directors examined in their exercise of oversight in the area in which the misconduct occurred?

To facilitate the answers to these questions, consider this list of 20 questions to reflect the oversight role of directors. These are questions the Board should ask of both senior management and the Board should ask itself. The questions are not intended to be an exact checklist, but rather a way to provide insight and stimulate discussion on the topic of compliance. The questions provide directors with a basis for critically assessing the answers they get and digging deeper as necessary. Although the questions apply to most medium to large organizations, the answers will vary according to the size, complexity and sophistication of each individual organization. Three key takeaways:

The DOJ Evaluation requires active Board of Director engagement around compliance.

Board communication on compliance is a two-way street; both inbound and outbound.

Has the Board built an effective Compliance Committee for itself?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There are three core areas upon which directors should focus their attention regarding to help establish and maintain an effective compliance program: structure, culture, and risk management. Structural questions. This area consists of questions which will aid in determining the fundamental sense of a company’s overall compliance program. The questions should begin with the basics of the program through to how the program operates in action. Cultural questions. This area of inquiry should focus on the culture of the organization regarding compliance. Board members should understand what message is being communicated not only from senior management but also middle management. Equally important, the Board needs to understand what message is being heard at the lowest levels within the company. Risk management questions. Board members need to understand the company’s process being used to identify emerging risks, their evaluation and management. Such risk analysis would be broader than simply a compliance risk assessment and should be tied to other broader corporate matters. Three key takeaways:

A Board of Directors should inquire into the structural component of the compliance program as it will aid in determining the fundamental sense of a company’s overall compliance program.

Cultural questions should be asked to garner an understanding of what message is being communicated not only from senior management but also middle management.

Risk management questions should be asked to understand the company’s process being used to identify emerging risks, their evaluation and management.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Where does “tone at the top” start? With any public and most private U.S. companies, it is at the Board of Directors. But what is the role of a company’s Board in compliance? We start with several general statements about the role of a Board in U.S. companies. First, a Board should not engage in management but should engage in oversight of a CEO and senior management. The Board does this through asking hard questions, risk assessment and identification.  A white paper by Deloitte & Touche LLP, entitled “Risk Intelligence Governance - A Practical Guide for Boards”, laid out six general principles to help guide Boards in the area of risk governance. These six areas can be summarized as follows:

Define the Board’s role. There must be a mutual understanding between the Board, CEO and senior management of the Board’s responsibilities.

Foster a culture of risk management. All stakeholders should understand the risks involved and manage such risks accordingly.

Incorporate risk management directly into a strategy. Oversee the design and implementation of risk evaluation and analysis.

Help define the company’s appetite for risk. All stakeholders need to understand the company’s appetite or lack thereof for risk.

How to execute the risk management process. Maintain an approach that is continually monitored and has continuing accountability.

How to benchmark and evaluate the process. Systems need to be installed which allow for evaluation and modifying the risk management process as more information becomes available or facts or assumptions change.

All of these factors can be easily adapted to compliance and ethics risk management oversight. Initially it must be important that the Board receive direct access to such information on a company’s policies on this issue. Three key takeaways:

The Board’s role is to keep really bad things from happening to a company.

There are six general areas the point can inquire into and lead from.

A Board should have direct access to information on the company’s compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How can a Board work to incorporate the compliance function into a long-term business strategy of the organization? A Board can do so by engaging with the CCO and compliance function through having a strong Board which is committed to doing business ethically and incompliance with anti-corruption laws and engaging actively with the CCO and compliance function. The questions have become even more important after the release of the 2020 Update. Under the topic, Seniority and Stature, are the following question What role has compliance played in the company’s strategic and operational decisions? The starting point for a Board of Directors is to develop a framework for incorporating compliance into your long-term strategy. To set up the framework for evaluation of the compliance into your Board’s long-term strategy is a three-step process, which you can use to determine how comprehensive the Board’s role in your compliance program is as a starting point. The Board should work to communicate the influence of compliance factors on overall corporate strategy by demonstrating how compliance was integrated into the business. Not only is this good from a business perspective and shareholder expectation but it is also, as the 2020 Update makes clear, what the government expects is the operationalization of compliance going forward. Three key takeaways:

Having a long-term strategy is critical.

What is the Board’s framework for assessing compliance?

Create KPIs to measure senior management’s actions around compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update mandated a Board of Directors ensure “the sufficiency of the personnel and resources within the compliance function, in particular, whether those responsible for compliance have: (1) sufficient seniority within the organization; (2) sufficient resources, namely, staff to effectively undertake the requisite auditing, documentation, and analysis; and (3) sufficient autonomy from management, such as direct access to the board of directors or the board’s audit committee.” Here are six steps to utilize.  Examine the key corporate documents. This includes Board review of all relevant corporate governance documents, including guidelines, the Charter for Board Governance, the director nomination policy and any relevant policies setting out the appropriate protocols and procedures. Use an assessment framework. 1) the current strengths and weaknesses of the CCO; 2) the short­ and long-term skills needs of a CCO; 3) evaluating how the Board’s assessment changes regarding departing CCOs; and 4) shifting the Board’s approach to oned based on criteria such as organization needs and director performance. Conduct due diligence. Conduct an executive level due diligence background investigation, not simply a background check. Maintain a pipeline. Every Board should maintain a pipeline of qualified candidates. Conditions may arise, such as health or other personal emergencies, that call for rapid director succession. It’s crucial that there are potential qualified candidates on hand to fill the gap quickly. Assess Board policies. Just as a company should periodically assess and reassess its policies and procedures, the Board assess their policies in this area. Disclose your succession strategy. Both a large number of institutional investors and good corporate governance advocates suggest that companies disclose their succession strategies. It provides greater transparency to stakeholders. Benchmark your succession strategy. Every Board should benchmark its succession strategy with industry peers around the use of the steps outlined and stay aligned with the evolving policies and positions of large institutional shareholders and good corporate governance advocates. Three key takeaways:

Refreshment is a hot topic in corporate governance.

Review your Board policies to understand what your company will need going forward.

Transparency in succession planning.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the role of a Board of Directors in hiring senior executives, CCOs and even other board members? I explored this issue with Candice Tal, who began by noting, that bad senior executive hires can cost a company much more than simply dollars. She related, the “financial costs in day-to-day operations easily can quadruple that of a regular employee, but it can also impact the company’s corporate governance and board of directors if that executive hire was found to be involved with unethical and illegal activities. Not even a signed contract can protect a company if an executive hire’s unethical actions come to the attention of the national media. Fiduciary risk and exposure for the board of directors cannot be overlooked.” She pointed to the example of Yahoo! and its hire of Scott Thompson. It turned out that Thompson had incorrect information on his online biography regarding his academic credentials. The “implications went beyond the activist shareholder accusations to reflect on the Board of Directors for not vetting his background more carefully. The company may have been exposed to claims of providing false information to the SEC and potential stockholder law suits. Thompson’s 120-day tenure at Yahoo! cost the company over $7 million and seriously tarnished the company’s reputation in the business community.” The key is that a company engages in an executive due diligence investigation rather than simply a routine or even executive-level background investigation. Tal explained that an executive background search, is “typically limited to a five-component review of: criminal records, employment verification, degree or education verification, social security validation, address verification and sometimes credit history.” Such searches are “very limited searches.” Conversely, executive due diligence, “looks in-depth at all available public records sources: criminal history, civil litigation issues, financial and legal issues, relationships with other companies and board advisory positions, reputation, misrepresented education and overstated work history, behavioral history (for example litigiousness), and, in particular, undisclosed or adverse issues.” While it is generally “more costly than executive background checks and takes more time, the information gathered is extremely valuable and can save a company substantially more. A high quality due diligence review can find important information which would not be returned in a routine executive background check.” Infortal has found that up to 20% of executive search candidates fail a deep-level due diligence investigation. Now consider how many senior executive slots your company has and add to that Board of Directors seats and you can quickly see the risk of failure to consider an executive due diligence search when promoting or hiring. Moreover, you need an executive level due diligence in other business situations as well, including the senior management of new business acquisitions brought into your organization through a merger or other acquisition, selecting new Board members, screening corporate Board of Directors and of course, for third party business partners and other agents in the sales and supply chain channels.  Three key takeaways:

The costs of a bad executive hire can far exceed the dollar loss.

Do not forget the differences between an executive background check and executive level due diligence.

20% of all senior executives fail an executive level due diligence check.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The Trump Administration’s trade war with China has highlighted the risks of both doing business in China and investing the Chinese companies which come to America to raise capital. Yet this has been a long-known and outstanding problem in the anti-corruption enforcement world. The 2014 bribery and corruption case of GlaxoSmithKline PLC (GSK), which resulted in a $490 million fine for the firm, resonated across the corporate globe. While many questions are still unanswered, one that seems to be at the forefront of the inquiry was where was the GSK Board of Directors? This matter demonstrates that the role of a Board of Directors is becoming more important and more of a critical part of any effective compliance program. In a NACD Directorship article, entitled “Corruption in China and Elsewhere Demands Board Oversight”, Eric V. Zwisler and Dean A. Yoost note, “Boards are ultimately responsible for risk oversight” any Board of a company with operations in China “needs to have a clear understanding of its duties and responsibilities under the FCPA and other international laws, such as the U.K. Bribery Act”. Why should China be on the radar of Boards? From 2010-2019, over 25% of all FCPA enforcement actions derived from China, that’s why.  FCPA enforcement actions have made clear that numerous Chinese businesses have proven adept at appearing compliant while hiding unacceptable business practices. A Board should be aware that a well-crafted compliance program must be complemented with a thorough understanding of frontline business practices and constant auditing of actual practices, not just a paper compliance program. This means that both monitoring and auditing should be visible to the Board. Three key takeaways:

China presents the highest FCPA risk and after GSK, domestic law corruption risk as well.

Chinese companies have been adept at hiding corrupt business practices from their western owners.

A Board must be cognizant of these risks and enhance their risk management process in China and other high-risk jurisdictions. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next, consider a couple of landmark failures at the Board level around bribery and corruption. VimpelCom Ltd. In 2015 (now Veon Ltd.), the DOJ alleged that Dutch telecom VimpelCom sought to enter the telecom market through the acquisition of a local player, Unitel, as an entrée into the Uzbekistan market. Unitel made clear to VimpelCom that to have access to, obtain and retain business in the Uzbeki telecom space, VimpelCom would have to, according to the DPA, “regularly pay Foreign Officials millions of dollars” to Gulnara Karimova, the daughter of the then President of the country. VimpelCom also acquired another entity Butzel, that was at least partially owned by an Uzbeki government official, who hid their interest through a shell company, which was known to VimpelCom. VimpelCom did not articulate a legitimate business reason for the deal and paid $60 million for Buztel. Ultimately, VimpelCom agreed to pay approximately $800 million in fines for these activities in 2016.  BizJet. Another FCPA enforcement action involved the Tulsa-based company BizJet International Sales and Support Inc. (BizJet), which had four senior executives convicted for their participation in a bribery scheme. But this case also involved the Board of Directions. In the Criminal Information it stated that in November 2005: …at a Board of Directors meeting of the BizJet Board, Executive A and Executive B discussed with the Board that the decision of where an aircraft is sent for maintenance work is generally made by the potential customer’s director of maintenance or chief pilot, that these individuals are demanding $30,000 to $40,000 in commissions, and that BizJet would pay referral fees in order to gain market share. In both cases, this is where the rubber hits the road. If a company is willing to commit bribery and engage in corruption to secure business, no amount of doing compliance is going to help. If senior management is ready, willing and able to lie, cheat and steal, the Board is the final backstop to prevent such conduct. Both the VimpelCom and BizJet Boards sorely failed in their compliance duties. Three key takeaways:

Board liability will be severe based upon similar conduct going forward.

Board members must critically challenge management on its conduct.

The Board is the ultimate backstop against bribery and corruption.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are metrics for a Board of Directors around compliance? Former Assistant Attorney General Leslie Caldwell laid out some that the Department of Justice (DOJ) would consider in a review of compliance programs. These metrics are:

Does the institution ensure that its directors and senior managers provide strong, explicit and visible support for its corporate compliance policies?

Does the Board maintain a material role in overseeing a company’s overall compliance framework?

These requirements move beyond simply having the correct tone at the top, which every Board should articulate. The 2020 Update to the Evaluation of Corporate Compliance Programs added the following, under Oversight by posing the following questions: What compliance expertise has been available on the board of directors? Have the board of directors and/or external auditors held executive or private sessions with the compliance and control functions? What types of information have the board of directors and senior management examined in their exercise of oversight in the area in which the misconduct occurred? Based on the foregoing, when determining the Board’s role, begin with two questions. First, does the Board of Directors exercise independent review of a company’s compliance program? Second, is the Board of Directors provided information sufficient to enable the exercise of independent judgment? Three key takeaways:

The DOJ expects active engagement by a Board around compliance.

Does the Board exercise independent review of the compliance program?

The convergence of the Yates Memo, Caldwell’s metrics, the Evaluation and FCPA Corporate Enforcement Policy mandate Board metrics around compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Once again, referencing the article, “Successful Board Investigations”, David Bayless and Tammy Albarrán, offered seven considerations to facilitate a successful Board investigation. 

Consider whether you need independent outside counsel. 

Consider hiring an experienced investigator to lead the internal investigation. 

Consider the need to retain outside experts. 

Analyze potential conflicts of interest at the outset and during the investigation. 

Carefully evaluate whistleblower allegations. 

Request regular updates from outside counsel, without limiting the investigation. 

Consider whether an oral report at the conclusion of the investigation is sufficient. 

The authors conclude their piece by stating, “By keeping in mind the issues addressed above, the Board will be better prepared for the investigation and readily able to exercise good judgment throughout the review. A well-conducted investigation by the Board may spare the company further disruption and costs associated with follow-on investigations by the regulators, or at the very least minimize the company’s exposure.” Three key takeaways:

Retain the right counsel. Consider conflicts and appearance.

Carefully evaluate all whistleblower allegations and reject retaliation.

Consider receiving oral reports on an ongoing basis and one lengthy oral report at the end of the investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Many companies have an investigation protocol in place when a potential Foreign Corruption Practices Act (FCPA) or other legal issue arises? However, many Boards of Directors do not have the same rigor when it comes to an investigation, which should be conducted or led by the Board itself. The consequences of this lack of foresight can be problematic, because if a Board of Directors does not get an investigation which it handles right, the consequences to the company, its reputation and value can all be quite severe. In an article in the Corporate Board magazine, entitled “Successful Board Investigations”; David Bayless and Tammy Albarrán, wrote about five key goals that any investigation led by a Board of Directors must meet. They are:

Thoroughness - The authors believe that one of the key, and most critical, questions that any regulator might pose is just how thorough is an investigation; to test whether they can rely on the facts discovered without hav­ing to repeat the investigation themselves. Regulators tend to be skeptical of investigations where limits are placed (expressly or otherwise) on the investigators, in terms of what is investigated, or how the investigation is conducted.

Objectivity - Here the authors write that any “investigation must follow the facts wherever they lead, regardless of the conse­quences. This includes how the findings may impact senior management or other company employees. An investigation seen as lacking objectivity will be viewed by outsiders as inadequate or deficient.”

Accuracy - As in any part of a best practices anti-corruption compliance program, the three most important things are Document, Document and Document. This means that the factual findings of an investiga­tion must be well supported. For if the developed facts are not well supported, the authors believe that the investigation is “open to collateral attack by skeptical prosecutors and regulators. If that happens, the time and money spent on the internal investigation will have been wasted, because the government will end up conducting its own investigation of the same issues.”

Timeliness - This has become even more necessary with the tight deadlines set under the Dodd-Frank Act Whistleblower provisions. But there are other considerations for a public company such as an impending Securities and Exchange Commission (SEC) quarterly or annual report that may need to be deferred absent as a timely resolution of the matter. Lastly, the Department of Justice (DOJ) or SEC may view delaying an investigation as simply a part of document spoliation. So timeliness is crucial.

Credibility - One of the realities of any FCPA investigation is that a Board of Directors led investigation is reviewed after the fact by not only skeptical third parties but also sometimes years after the initial events and investigation. So not only is there the opportunity for Monday-Morning Quarterbacking but quite a bit of post event analysis. So the authors believe that any Board of Directors led investigation “must be (and must be perceived as) credible as to what was done, how it was done, and who did it. Otherwise, the board’s work will have been for naught.”

Three Key Takeaways

The Board should have a written protocol for investigations prepared in advance.

This gives cover to a Board when regulators come knocking or other third parties seek review.

Remember the 5 goals of any Board led investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the ongoing questions from members of Board of Directors is how to resolve the tension between oversight and managing. I recently had the opportunity to visit with Joe Howell, the Executive Vice President (EVP) of Workiva, Inc. on this subject. Howell has worked on and with Boards of Directors at various companies and I wanted to garner his understanding of the role of a Board and both senior management and a Chief Compliance Officer (CCO). Howell had a short response which I thought was an excellent starting point to understand the role; put sand in the shoes of management. The key to such a metaphor succeeding is that a Board of Directors, “by continuing to challenge management on these scenarios that management has considered and the stories management is telling itself about what could go wrong”, can “help get management out of its comfort zone by and large executive teams begin to believe themselves when they talk about how well they’re doing. The independent challenge that the board can offer putting the little bit of sand in the shoe to make sure that you’re thinking about things carefully can cause you to step back and really focus your resources where they're needed.” Howell noted the role of the Board is not management but oversight, focusing on governance. To do so, an effective Board should challenge senior management not only on what they have planned for but what they may not have considered or may not even know about. He said, “one very good example is the whole, the reputation of those stakeholders involved in the company and that can be the management team itself, the employees, and the board members themselves.” This is because reputational damage hurts everyone. Howell went on to state, “it’s very important as we go through some of the ways the board can help management in that role. I think the things that really make a difference to management is when the board is able to be an effective devil’s advocate. Not managing management but helping them in their governing role by helping management to step back and think critically of their own underlying assumptions and biases.” A Board is not simply there to be a rubber stamp for senior management. It must exercise independent judgment, action and oversight. Further, it is the Board’s role to ask hard, difficult and probing questions to make sure management is not only doing its job but has considered other risk possibilities. Three Key Takeaways

Boards should force management to open up the company to itself.

Boards should be a grain of sand in the shoe of management.

Boards should make sure senior management is aware of and planning for both known and unknown risks.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

James Doty, former Commissioner of the Public Company Accounting Oversight Board (PCAOB) was once asked if the Board or its sub-committee which handles audits was a part of a company’s internal financial controls. He answered that yes, he believed that was one of the roles of an Audit Committee or full Board. I had never thought of the Board as an internal control but the more I thought about it, the more I realized it was an important insight for any Chief Compliance Officer or compliance practitioner as it also applies as a compliance internal control. In the FCPA Resource Guide, 2nd edition, in the Hallmarks of an Effective Compliance Program, there are two specific references to the obligations of a Board. The first in Hallmark No. 1 , which states, “Within a business organization, compliance begins with the board of directors and senior executives setting the proper tone for the rest of the company.” The second is found under Hallmark No. 3, entitled “Oversight, Autonomy and Resources”, where it discusses that the CCO should have “direct access to an organization’s governing authority, such as the board of directors and committees of the board of directors (e.g., the audit committee).” Further, under the US Sentencing Guidelines, the Board must exercise reasonable oversight on the effectiveness of a company’s compliance program. The Department of Justice’s (DOJ) Prosecution Standards posed the following queries: (1) Do the Directors exercise independent review of a company’s compliance program? and (2) Are Directors provided information sufficient to enable the exercise of independent judgment? Doty’s remarks drove home to me the absolute requirement for Board participation in any best practices or even effective anti-corruption compliance program. A Board’s oversight is part of effective compliance controls, then the failure to do so may result in something far worse than bad governance. Such inattention could directly lead to a FCPA violation and could even form the basis of an independent SOX violation as to the Board. Three Key Takeaways

A Board must engage in active oversight.

A Board should review the design of internal controls on a regular basis.

Failure to do so could form the basis for an independent legal violation under SOX.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The basic framework for internal controls is derived from the COSO Model developed by the Committee of Sponsoring Organizations of the Treadway Commission in 1992 (COSO). This model has become the standard for an internal control framework and provides a structure to ensure companies address the key elements that should result in an effective system of internal controls. Using the COSO Model, as modified in 2013, provides a very supportable approach when regulators challenge whether a company has effective internal controls. The COSO Model defines internal controls in a pyramid, from bottom to top, as follows: (a) Control environment, (b) Risk assessment, (c) Control activities, (d) Information and communication, and (e) Monitoring. Internal controls for a Board or Board Compliance Committee should be broken down into five concepts:

Risk Assessment – A Board should assess the compliance risks associated with its business.

Corporate Compliance Policy and Code of Conduct – A Board should have an overall governance document which will inform the company, its employees, stakeholders and third parties of the conduct the company expects from an employee. If the company is global/multi-national, this document should be translated into the relevant languages as appropriate.

Implementing Procedures – A Board should determine if the company has a written set of procedures in place that instructs employees on the details of how to comply with the company’s compliance policy.

Training – There are two levels of Board training. The first should be that the Board has a general understanding of what the FCPA is and it should also understand its role in an effective compliance program.

Monitor Compliance – A Board should independently test, assess and audit to determine if its compliance policies and procedures are a ‘living and breathing program’ and not just a paper tiger.

Three Key Takeaways

Has your company implemented COSO 2013?

What was the Board’s involvement?

What is your documentation?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Where does “tone at the top” start? With any public and most private U.S. companies, it is at the Board of Directors. But what is the role of a company’s Board in compliance? First a Board should not engage in management but should engage in oversight of a CEO and senior management. The Board does this through asking hard questions, risk assessment and identification. Initially it must be important that the Board receive direct access to such information on a company’s policies on this issue. The Board must have quarterly or semi-annual reports from a company’s CCO to either the Audit Committee or the Compliance Committee. Every Board should create a Compliance Committee to deal with compliance issues, as an Audit Committee may more appropriately deal with financial audit issues. A Board Compliance Committee can devote itself exclusively to non-financial compliance. The Board’s oversight role should be to receive such regular reports on the structure of the company’s compliance program, its actions and self-evaluations. From this information the Board can give oversight to any modifications to managing FCPA risk that should be implemented. CCO reporting to the Compliance Committee must be structured carefully to promote ethics and compliance. Three key takeaways:

A Board Compliance Committee should provide oversight not management.

A CCO should use multiple reports to communicate with the Board Compliance Committee.

Board Compliance Committee oversight makes companies more efficient and at the end of the day more profitable.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The OIG white paper “Practical Guidance for Health Care Governing Boards on Compliance Oversight” (OIG Guidance), provides an excellent road map for thinking about how to structure a Compliance Committee for your Board and a Board’s obligations. As an introduction, the OIG Guidance states that a Board must act in good faith around its obligations regarding compliance. This means that there must be both a corporation information and reporting system and that such reporting mechanisms provide appropriate information to a Board. It states: The existence of a corporate reporting system is a key compliance program element, which not only keeps the Board informed of the activities of the organization, but also enables an organization to evaluate and respond to issues of potentially illegal or otherwise inappropriate activity. The OIG Guidance sets out four areas of Board oversight and review of a compliance function:

Roles of, and relationships between, the organization’s audit, compliance, and legal departments;

Mechanism and process for issue-reporting within an organization;

Approach to identifying regulatory risk; and

Methods of encouraging enterprise-wide accountability for achievement of compliance goals and objectives.

The OIG Guidance is an excellent review for not only compliance professionals and others in the healthcare industry but a good primer for Boards around their own duties under a best practices compliance program. The U.S. Sentencing Guidelines, the Hallmarks of an Effective Compliance Program, the OIG Guidance, and OIG Corporate Integrity Agreements can be used as baseline assessment tools for Boards and management in determining what specific functions may be necessary to meet the requirements of an effective compliance program. Three key takeaways:

Information flow up to the Board is critical.

Compliance should be institutionalized in your company as a way of life.

A Board needs to consider all risks.

This month's sponsor is Affiliated Monitors, Inc.  Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Every Board of Directors need a true compliance expert sitting at the table. Almost every Board has a former CFO, former head of Internal Audit or persons with a similar background and often times these are also the Audit Committee members of the Board. Such a background brings a level of sophistication, training and SME that can help all companies with their financial reporting and other finance-based issues. So why is there not such compliance SME at the Board level? This requirement was set out in 2017 in the FCPA Corporate Enforcement Policy, where one of the criteria to be evaluated in compliance program is “the availability of compliance expertise to the board;”. Finally, in the 2020 Update to the Evaluation of Corporate Compliance Programs, under the section entitled Oversight, it posed the following questions What compliance expertise has been available on the board of directors? The DOJ and Securities and Exchange Commission brought this concept forward into the FCPA Resource Guide, 2ndedition. This means that when your company is evaluated by the DOJ, under the factors set out in the 2020 Update and the FCPA Corporate Enforcement Policy, to retrospectively determine if your company had a best practices compliance program in place at the time of any violation, you need to have not only the structure of the Board-level Compliance Committee but also the specific SME on the Board and on that committee. Three key takeaways:

Boards must have compliance expertise.

Government regulators and shareholder groups have both called for greater compliance expertise at the Board.

Compliance expertise at the Board works up and down as such expertise can be a resource to both the CCO and Compliance Department.

This month's sponsor is Affiliated Monitors, Inc.  Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Under the U.S. Sentencing Guidelines, the Board must exercise reasonable oversight on the effectiveness of a company’s compliance program. The DOJ Prosecution Standards posed the following queries: 1) Do the directors exercise independent review of a company’s compliance program? and 2) Are directors provided information sufficient to enable the exercise of independent judgment? Moreover, the FCPA Resource Guide, 2nd edition required a CCO to have direct access to the Board or an appropriate sub-committee and requires a tangible commitment from the top levels of an organization, starting with the Board of Directors, that the company creates an ethical culture. This requirement was brought forward in 2017 in the FCPA Corporate Enforcement Policy. Finally, nn the 2020 Update to the Evaluation of Corporate Compliance Programs, under the section entitled Oversight, it posed the following questions What compliance expertise has been available on the board of directors? Have the board of directors and/or external auditors held executive or private sessions with the compliance and control functions? Today’s regulatory climate and hyper-transparency in social media make a Board Compliance Committee’s task seem Herculean. But more than simply the regulatory climate, shareholders are taking a much more active role in asserting their rights against Boards of Directors. It is incumbent that Boards seek out and obtain sufficient information to fulfill their legal obligations and keep their company off the front page of the New York Times, Wall Street Journal or Financial Times, just to name a few, to prevent serious reputational damage. A Board Compliance Committee is a good place to start. Three key takeaways:

The Board Compliance Committee exists to provide oversight and assist the CCO, not to substitute its judgment for that of the CCO.

The Board Compliance Committee should work to hold the CCO accountable to hit appropriate metrics.

The Board Compliance Committee is ideal for leading the efforts around strategic planning.

This month's sponsor is Affiliated Monitors, Inc.  Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are the obligations of a Board member regarding the FCPA? Are the obligations of the Compliance Committee under the FCPA at odds with a director’s “prudent discharge of duties to shareholders”? Do the words prudent discharge even appear anywhere in the FCPA? In the the case of Stone v. Ritter is found the proposition that “a duty to attempt in good faith to assure that a corporate information and reporting system, which the board concludes is adequate exists.” From the case of In re Walt Disney Company Derivative Litigation, she drew the principle that directors should follow the best practices in the area of ethics and compliance. The Board has the role of monitoring the performance of the compliance function, including monitoring the performance of it using customary economic metrics, and by overseeing compliance with applicable laws and regulations. While the Board is not responsible for auditing or ferreting out compliance problems, it is responsible for determining that the company has an appropriate system of internal controls. The Board should also monitor company policies and practices that address compliance and matters affecting the public perception and reputation of the company. Every company should ensure that it conducts appropriate compliance training for employees and conducts regular compliance assessments. Finally, the Board must take appropriate action if and when it becomes aware of a material problem that it believes management is not properly handling. There is no reference to prudent discharge in the FCPA itself. However, a Board member might well think more than twice about the prudent discharge of duties to the shareholders as both the DOJ and SEC now might well wish to look into a Board’s prudent discharge of duties under the FCPA. Three key takeaways:

What is prudent discharge?

What is your process for doing compliance at the Board level?

A Board must have active rather than passive engagement around compliance.

This month's sponsor is Affiliated Monitors, Inc.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Welcome to this month's offer of 31 Days to a More Effective Compliance Program. This month I will focus on the Board of Directors and its role in an effective compliance program. At the end of August, you will not only have a good summary of the basics of a best practices compliance program for a Board of Directors but information that you can incorporate into your compliance regime. Case law. As to the specific role of best practices in the area of general compliance and ethics, one can look to Delaware corporate law for guidance. The case of In Re Caremark International Inc., 698 A.2d 959, (Del. SCt. 1996) was the first case to hold that a Board’s obligation “includes a duty to attempt in good faith to assure that a corporate information and reporting system, which the board concludes is adequate, exists, and that failure to do so under some circumstances may, in theory at least, render a director liable for losses caused by non-compliance with applicable legal standards.” 2020 FCPA Resource Guide, 2nd edition and U.S. Sentencing Guidelines. A Board’s duty under the FCPA is well-known. In the FCPA Resource Guide, 2nd edition, there are two specific references to the obligations of a Board. The first, in Hallmark No. 1, states: “Within a business organization, compliance begins with the board of directors and senior executives setting the proper tone for the rest of the company.” The second is found under Hallmark No. 3 and notes that the CCO should have “direct access to an organization’s governing authority, such as the board of directors and committees of the board of directors (e.g., the audit committee).” Further, under the U.S. Sentencing Guidelines, the Board must exercise reasonable oversight on the effectiveness of a company’s compliance program. The DOJ’s Prosecution Standards posed the following queries: 1) Do the Directors exercise independent review of a company’s compliance program? and 2) Are Directors provided information sufficient to enable the exercise of independent judgment? From the Delaware cases, a Board must not only have a corporate compliance program in place but actively oversee that function. Further, if a company’s business plan includes a high-risk proposition, there should be additional oversight. In other words, there is an affirmative duty to ask the tough questions. The specific obligations set out regarding the FCPA drive home these general legal obligations down to the specific level of the statute. Three key takeaways:

The Delaware courts have led the way with the In Re Caremark and Stone v. Ritter decisions.

Note the obligations of the Board under the Ten Hallmarks of an Effective Compliance Program.

The U.S. Sentencing Guidelines also require Board involvement and oversight.

A special thanks to this month's sponsor, Affiliated Monitors, Inc.  Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In this final episode for the month of July on 31 Days to a More Effective Compliance Program, I review the past month's offerings and preview the month of August where I take up the topic of Boards of Directors and Compliance.  Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In today's edition of 31 Days to a More Effective Compliance Program, I am joined by Vin DiCianni, founder of Affiliated Monitors. Vin provides insights into how the use of data can facilitate the management of third-parties after the contract is signed. 3 Key Takeaways

the process of collecting data cleans up much risk and provides cost savings.

More reliable data about third-parties will facilitate their more effective management.

Using data to management third-parties will further operationalize your compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas many companies do not focus on enough is possible corruption in their supply chain for goods and services provided on a company’s behalf. The FCPA risks can be just as great through those entry points as it can be through the sales side of an organization. You need to know who your company is doing business with through this channel as much as you need to know your agents seeking business opportunities on your behalf. Most companies have exponentially more vendors than sales agents, so this task may seem daunting. However, a well thought out plan to risk rank your company’s third-parties on the supply chain side can go a long way towards ameliorating this issue. The key is to set reasonable parameters and then management those third-parties which present true corruption risk to your organization. This determination of the level of due diligence and categorization of a supplier should depend on a variety of factors, including, such factors as whether the supplier is (1) located, or will operate, in a high risk country; (2) associated, or recommended or required by, a government official; (3) currently under corruption investigation, or has been recently convicted of any form of corruption; (4) a multinational publicly traded corporation with a recognized exemplary system of compliance and internal controls; or (5) a provider of widely available services and products that are not industry specific. You should note that any supplier, which has foreign government touch points, should move up into a higher level of scrutiny. My suggestion is that you create a three-tiered risk matrix consisting of (1) high-risk suppliers, (2) low-risk suppliers, and (3) minimal-risk suppliers. Below this final category is another category for providers of goods which are commonly available and pose almost no corruption risk. You need to risk rank the third-parties which your supply chain might engage with for FCPA exposure. It should be based on your company’s experience and risk going forward. As with all other third-party risk management issues, you must “Document, Document, and Document”. Three key takeaways:

Risk rank your supply chain based on well-conceived strata.

Consider not only the compliance risk but also your business risk.

Only manage those suppliers which present a corruption risk.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The FCPA world is littered with cases involving freight forwarders, brokers and agents in the shipping and express delivery arena. Both the DOJ and SEC have aggressively pursued third-party business relationships where bribery and corruption have been found. This is particularly true where companies are required to deliver goods into a foreign country through the assistance of a freight forwarder or express delivery service. If you utilize the services of a third-party for as a freight forwarders, brokers and agents in the shipping and express delivery arena, that company’s actions will go a long way in determining your company’s FCPA liability. You must have a thoughtful process and document that process. Three key takeaways:

Express delivery services and freight forwarders present unique compliance risks.

There must be a business justification to bring on new express delivery services or freight forwarders in high risk jurisdictions.

Consider constructing a risk matrix in this area.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the issues in any compliance program is the compensation paid to a third-party as FCPA exposure arises when companies pay money, either directly or indirectly, to fund bribe payments. Another area that leads to exposure from third-parties is with distributors. In a distributor relationship, the distributor purchases a product; taking risk of loss and title, at a discount from a manufacturer. The distributor resells at an uplift and that spread between purchase price and sales price is the distributor’s income. If a product is purchased at an inflated discounted rate and then sold, the difference between the purchase price and resale value could be used for corrupt purposes. Commission payments and excessive distributor discounts can be channeled to pay bribes. The FCPA Resource Guide, 2nd edition noted that common red flags associated with third-parties include “unreasonably large discounts to third-party distributors.” When companies grant distributors uncommonly steep discounts, bribes can result either: 1) because the distributor is instructed by the company to use the excess amounts to fund corrupt payments; or 2) because the distributor pays bribes on its own, without the express direction or implicit suggestion from the company, to gain some business advantage.  Three key takeaways:

The creation of well-thought out process which operationalizes your compliance program around distributor compensation, in a manner which documents your decision-making calculus is key.

Require multiple levels of approval for an out of range distributor discount.

Tracking distributor discounts globally make your company more efficient.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

At some point, you will be required to terminate a third-party and there will be multiple legal, compliance and business issues to navigate through. If you are stuck doing it in the middle of a FCPA or U.K. Bribery Act investigation, there may well be some tension to do so and do so quickly. If you have not thought through this issue and created a process to follow before a crisis occurs, you may well be in for a very tough road. Yet the 2020 Update specifically asked that question in the section entitled Real Actions and Consequences, when it posed the query Has a similar third party been suspended, terminated, or audited as a result of compliance issues?  Although rarely considered, the termination of a third-party relationship can be as important a step as any other in the management of the third-party lifecycle. While having the contractual right to terminate is a good starting point, it is only the starting point. You not only need to have a compliance and legal plan in place but a business plan as well. If you do not, the cost in both monetary and potential business reputation can be quite high. Three key takeaways:

Termination of third-parties is an oft-neglected part of the third-party risk management process.

Make certain you have the contractual right to terminate third-parties written into your compliance terms and conditions.

Have a strategy in place for termination before a crisis arises.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is third-party risk expansion and why is it a risk in compliance? Historically, people talked about simply an entity outside of your organization as a third party. However, that definition is broadening, to mean really that entity with which your company works. Obviously, this can be a supplier or vendor, it can be a service provider, a customer, a joint-venture (JV) partner and/or an intercompany affiliate. A broader view could include intercompany affiliates as third parties, even though many people would see them as just being another entity inside of a business. As the definition of third parties expands, this only makes life more complicated for anyone trying to do third party risk assessments and then the tiering just creates an exponential change.  Previously, a tier one supplier was a direct counterparties to your organization, directly through the sales channel. Next a tier two was one that your company’s tier one counterparty is working through. This means for risk managers assessing the various risks now have to go deeper and deeper. One way to do so is through trying to understand the connection between tiers one, two, three, four and so on. The problem is there are many risks that companies do not manage this risk because they cannot identify which companies are taking risks, alleged on their behalf. One of the most difficult issues for compliance professionals and risk managers is trying to get their arms around how to handle this issue. You should begin with mapping out and understanding the third-parties whose exposure needs to be assessed by your organization. Obviously, this includes both direct and indirect third-parties but in terms of the tiering, the best way for anyone to understand the risk is to have really good communication with their tier one third-parties to be able to discuss the risks to both businesses. Three key takeaways:

Has your third-party risk management program expanded with your third-parties?

Why is transparency a key for third-party risk management?

What is the financial health of your third-parties?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

It is universally recognized that third-parties are your highest FCPA risk. What if you could turn your third-party from a liability under the FCPA to an innovation partner to your compliance program? This is an area that not many compliance professionals have mined but once again in compliance, you are only limited by your imagination. In a 2015 Supply Chain Management Review article by Jennifer Blackhurst, Pam Manhart and Emily Kohnke, entitled “The Five Key Components for Supply Chain Innovation”, the authors identified five components common to the most successful innovation partnerships. They are:  Don’t settle for the status quo. This means that you should not settle for simply the status quo in compliance. Hit the road in order to hit your metrics. To truly understand your compliance risk from third-parties, you must get out of the ivory tower and hit the road. Send prospectors, not auditors. While an audit clause is critical in any third-party contract, both from a commercial and FCPA compliance perspective; you can establish a “point of contact as an innovation manager for your third-parties.” Show and tell. As with all relationships, trust plays an important role in third-party compliance innovation, as “Firms in successful innovations discussed a willingness to share resources and rewards and to develop their partners’ capabilities.” Who’s running the show? This means “who is doing what, but also what each firm is bringing to the relationship in terms of resources and capabilities.” Three key takeaways:

Use your third-parties as innovators to assist your compliance program.

Change your thinking about third-parties and make them your partners.

Do not settle for the status quo.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One area that has bedeviled CCOs and compliance practitioners is how to determine the ROI for your compliance program regarding third-parties. While it is still clear that third-parties are the greatest risk in FCPA enforcement actions, senior management often wants to know what is the monetary benefit to the company for this type of risk management.  When you couple the request for ROI with the 2020 Update, it may seem like a doubly daunting task. However, the requirement for operationalization of your compliance program actually lends itself to formulating ROI around the risk management of third-parties. This is because if you move third-party compliance into the organization as a business process, with a technological solution, the ROI becomes not only clearer but easier to calculate going forward. Three key takeaways:

Why is it important to demonstrate ROI on your third-party risk management program?

Determining ROI helps to demonstrate operationalizing your compliance program.

Determining third-party management program ROI can help to tear down compliance siloes.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the key themes from the 2020 Update was the use of data and data analytics in a best practices compliance program. This has specific application to third-parties. In the section entitled, Risk-Tailored Resource Allocation, the following question was posed, Does the company devote a disproportionate amount of time to policing low-risk areas instead of high-risk areas, such as questionable payments to third-party consultants, suspicious trading activity, or excessive discounts to resellers and distributors? Under the section entitled, Control Testing, the following question was posed, Has the company reviewed and audited its compliance program in the area relating to the misconduct? More generally, what testing of controls, collection and analysis of compliance data, and interviews of employees and third parties does the company undertake? Finally, under the section entitled, Payment Systems was the following query, How was the misconduct in question funded (e.g., purchase orders, employee reimbursements, discounts, petty cash)? What processes could have prevented or detected improper access to these funds? Have those processes been improved?  All of these questions make clear that the DOJ expects data analytics to be used to help detect or prevent bribery and corruption where the primary sales force used by a company is third-parties. A clear majority of FCPA violations and related enforcement actions have come from the use of third-parties. While sham contracting (i.e., using a third-party to channel the payment of a bribe) has lessened in recent years, there are related data analysis that can be performed to ascertain whether a third-party is likely performing legitimate services for your company and is not a sham. There are several more complex analytics that can be run in combination to identify suspicious third-parties, and some of the simplest can be to look for duplicate or erroneous payments. This final concept of finding patterns that can be discerned through the aggregation of huge amounts of transactions, is the next step for compliance functions. Yet data analysis does far more than simply allowing you to follow the money. It can be a part of your third-party ongoing monitoring as well by allowing you to partner the information on third-parties who might come into your company where there was no proper compliance vetting. Such capabilities are clearly where you need to be heading.  Three key takeaways:

Always remember to follow the money to see where a pot of money could be created to fund a bribe.

Transaction monitoring techniques around fraud monitoring translate to data analysis for compliance.

Do not forget to check names against known PEP and SDN lists.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Auditing of third-parties is critical to any best practices compliance program and an important tool in operationalizing your compliance program. This is a key manner in which a company can manage the third-party relationship after the contract is signed and one which the government will expect you to engage in going forward. As stated in the 2020 Update, under the section entitled, Management of Relationships, is the following query, Does the company have audit rights to analyze the books and accounts of third parties, and has the company exercised those rights in the past? This means you must not only have audit rights but also exercise them.  You should plan out the audit four to six weeks in advance, you should perform the audit with your legal counsel’s lead to preserve privilege, work with the Relationship Manager to establish key business contacts, discuss audit rights and processes with the third-party, you should prepare initial document request lists for financial information queries, take the time to review findings from previous audits and resolutions and also review details of opened and closed internal investigations, if there are any Code of Conduct questionnaires available take care to review and, finally, be cognizant of any related DOJ and SEC enforcement actions. Three key takeaways:

Be prepared.

It is not an investigative interview but an audit interview.

Listen, listen, and listen.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the lifecycle management of third-parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance programs, the issue of third-party management becomes more important. It is also the one where the rubber meets the road of operationalizing compliance. The key is to have a strategic approach to how you structure and manage your third-party relationships during the full lifecycle of the contract. This may mean more closely partnering with your third-parties to help manage the anti-corruption compliance risk. It would certainly lead towards enabling your company to manage the bribery and corruption risk while optimizing the performance of your third-parties.  Three key takeaways:

Have a strategic approach to third-party risk management.

Keep track of the financial stability of your third-parties.

Rank third-parties based upon a variety of factors including compliance and business performance, length of relationship, benchmarking metrics and KPIs.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In a 2015 speech before the SIFMA Compliance and Legal Society New York Regional Seminar, former Assistant Attorney General Leslie Caldwell for the first time, laid out metrics the DOJ would consider in evaluating a corporate compliance program around third-parties. Caldwell began with the following question, “Does the institution sensitize third-parties like vendors, agents or consultants to the company’s expectation that its partners are also serious about compliance?” This inquiry was brought forward into the DOJ’s 2017 Evaluation and all subsequent updates. In addition to monitoring and oversight of your third-parties, you should periodically review the health of your third-party management program. The robustness of your program will go a long way towards preventing, detecting and remediating any compliance issue before it becomes a full-blown FCPA violation. As with all the steps laid out herein, you need to fully document the steps you have taken so that any regulator can test your metrics. Caldwell’s remarks around compliance metrics portended the Evaluation and what the DOJ will be reviewing and evaluating going forward, so it is clear what will be expected from your company’s compliance program. You should also use these metrics to conduct a self-assessment on the state of your compliance program.  Three key takeaways:

It all starts with a Relationship Manager.

Have company oversight of all third-parties.

Audit, monitor, and remediate on an ongoing basis.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is satisfactory due diligence under the FCPA? That question seems to be more important after the story on Unaoil S.A.M. and the subsequent release of the Panama and Paradise Papers. However, both events largely focused on the “who” part of due diligence and the need to know with whom you are doing business with going forward. However, there is another important question which does not come up as often in due diligence, which is how? How does a third-party perform its services with or for your company? If it is on the sales side of things, howcan a third-party help you make sales? If a third-party comes through the supply chain, how do their products or services meet the needs of your company? If the third-party has a closer business relationship, such as a JV, teaming agreement or other similar arrangement, you may well need a much deeper understand of how this third-party does business because the relationship may well become so close you will be intertwined with the party. It may mean more than simply how does their product work but how does this third-party conduct themselves and their business? Under the FCPA, most companies understand the need to know with whom they contract for sales or vendor services. They also understand the need to know why they should do business with a proposed third-party (i.e., a business justification). However, the need to perform an investigation into how the third-party can actually deliver the contracted services is equally important. Three key takeaways:

The how question can be as critical as the who question.

The more integrated a third-party is into your operations the more important this question becomes.

Incorporate a how question into not only your due diligence but also your ongoing monitoring and auditing, after the contract is signed.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Resource Guide stated, “In addition to considering a company’s due diligence on third parties, DOJ and SEC also assess whether the company has informed third parties of the company’s compliance program and commitment to ethical and lawful business practices and, where appropriate, whether it has sought assurances from third parties, through certifications and otherwise, of reciprocal commitments. These can be meaningful ways to mitigate third-party risk.”  You should incorporate appropriate compliance terms and conditions into in every contract with third-parties. I would suggest that you prepare a template, which can be used as a starting point for your negotiations. The advantages of such a template are several and they include: (1) the contract language is tested against real events; (2) the contract language assists the company in managing its compliance risks; (3) the contract language fits into a series of related contracts; (4) the contract language is straight-forward to administer; and (5) the contract language helps to manage the expectations of both contracting parties regarding anti-bribery and anti-corruption. Many do not believe that they will be able to get the third-party to agree to such compliance terms and conditions. I have found that while it may not be easy, it is relatively simple to get a third-party to agree to these or similar terms and conditions. One approach to take is that they are not negotiable. When faced with such a position on non-commercial terms many third-parties will not fight such a position. There is some flexibility, but the DOJ will require the minimum compliance terms and conditions. But the best position I have found is that if a third-party agrees with these terms and conditions, they can then use that as a market differentiator. Three key takeaways:

Compliance terms and conditions are mandatory for any best practices compliance program.

A key clause is the right to audit clause.

Third-parties can favor robust compliance terms and conditions as a market differentiator.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

An important part of the job duties of any compliance practitioner is clearing red flags which might appear for a proposed third-party relationship during the due diligence process. It is mandatory that not only must all red flags be cleared but there also be evidence of the decision-making process to show to a regulator if one comes knocking. Around third-parties, consider what risks you face in both your sales and supply chain. If there is a key player several tiers down the line who creates or builds a key component or delivers a critical service, you may want to put more management around that relationship from the compliance perspective. For anything below a tier 2; you may be able to manage your risks through having your direct tier one counter-party take the lead in managing such compliance risks. But make sure that the expectation is communicated to your direct counter-party so that if the government comes knocking you can show that not only did you contractually obligate your direct counter-party to do so but that you provided them the tools and training to do so. Finally, you will need to be able to show that your direct counter-party did so. Three key takeaways:

There is no set formula for clearing of red flags or the evaluation of due diligence.

Know when to say enough has been done.

You must “Document, Document, and Document” your evaluation of any red flags.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Due diligence is generally recognized in three levels, each of which is appropriate for a different level of corruption risk. The key is for you to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward.  There are many different approaches to the specifics of due diligence. By laying out some of the approaches, you can craft the relevant portions into your program. The Level I, II and III trichotomy appears to have the greatest favor and one that you should be able to implement in a straightforward manner. But the key is that you must assess your company’s risk and then manage that risk. If you need to perform additional due diligence to answer questions or clear red flags you should do so. And do not forget to “Document, Document, and Document” all your due diligence.  Three key takeaways:

A Level I due diligence should only be used where there is a low risk of corruption.

A Level II due diligence is sufficient in a high-risk jurisdiction if there are no red flags to clear.

Level III due diligence is deep dive, boots on the ground investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Most companies fully understand the need to comply with the requirements around third-parties as they represent the greatest risks for bribery and corruption. However, most companies are not created out of new cloth but are ongoing enterprises with a fully up and running business in place. This means they may need to bring resources to bear to do so while continuing operating an ongoing business. This can be particularly true in the area of performing due diligence on third-parties. Many companies understand the need for a robust due diligence program to investigate third-parties but have struggled with how to create an inventory to define the basis of third-party risk and, thereby, perform the requisite due diligence required.  Getting your arms around due diligence can sometimes seem bewildering for the compliance practitioner. The information that you gathered in Steps 1-Business Justification and 2-Questionnaire of the third-party management process should provide you with the initial information to consider the level of due diligence needed. This leads to Step 3 of the third-party management process: due diligence. The 2020 Resource Guide stated, “as part of risk-based due diligence, companies should understand the qualifications and associations of its third-party partners, including its business reputation, and relationship, if any, with foreign officials. The degree of scrutiny should increase as red flags surface.” Three key takeaways:

Risk rank your third-parties and use this as a basis to begin with an adequate level of due diligence. 

Any red flags which appear must be cleared and there must be documented evidence of such clearance.

There must be documented evidence of review of the due diligence.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The next step in the five-step process is the questionnaire. The term ‘questionnaire’ is mentioned several times in the 2020 FCPA Resource Guide. It is generally recognized as one of the tools that a company should complete in its investigation to better understand with whom it is doing business. The questionnaire should be mandatory step for any third-party that desires to work with your company as it mandates the proposed business partner, commit to certain required information in writing prior to beginning the due diligence process. Remember if a third-party does not want to fill out the questionnaire or will not fill it out completely you should not walk but run away from doing business with such a party. One of the key requirements of any successful compliance program is that a company must make an initial assessment of a proposed third-party. The size of a company does not matter as small businesses can face quite significant risks and will need more extensive procedures than other businesses facing limited risks. The level of risk that companies face will also vary with the type and nature of the third-parties with which it may have business relationships. For example, a company that properly assesses that there is no risk of bribery on the part of one group of its third-parties will require nothing in the way of procedures to prevent bribery in the context of those relationships. By the same token the bribery risks associated with reliance on a third-party agent representing a company in negotiations with foreign government officials may be assessed as significant and, accordingly, requires much more in the way of procedures to mitigate those risks. The questionnaire fills several key roles in your overall management of third-parties. Obviously, it provides key information that you need to know about who you are doing business with and whether they have the capabilities to fulfill your commercial needs. Just as important is what is said if the questionnaire is not completed or is only partially completed, such as the lack of awareness of the FCPA, U.K. Bribery Act or anti-corruption/anti-bribery programs generally. Lastly, the information provided (or not provided) in the questionnaire will assist you in determining what level of due diligence to perform. Three key takeaways:

You must have enough information to fully identify the owners, UBOs and related parties to determine if there is foreign official involvement.

All commentary on best practices compliance programs requires questionnaires.

If a third-party refuses to fully respond to your questionnaire, run, don’t walk away from the proposed relationship.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2020 Update stated, “Prosecutors should also assess whether the company knows the business rationale for needing the third party in the transaction, and the risks posed by third-party partners, including the third-party partners’ reputations and relationships, if any, with foreign officials.” This standard articulates one of the most basic tools to operationalize your compliance program and should form the basis of your third-party risk management process. Indeed this is viewed as an internal control with the 2020 Update going on to pose the following question, “How does the company ensure there is an appropriate business rationale for the use of third parties?” Another way to think about this issue is by considering the competence of a foreign business partner to provide services to your organization. Such considerations include a review of the qualifications of the third-party candidate for SME, the resources to perform the services for which they are being considered and the third-party’s expected activities for your company. More detailed inquiries include requiring the relevant business unit which desires to obtain the services of any third-party to provide you with a business rationale including current opportunities in territory, how the candidate was identified and why no currently existing third-party relationships can provide the requested services. Your next inquiry should focus on the terms of the engagement, including the commission rate, the term of the agreement, what territory may be covered by the agreement and if such relationship will be exclusive. Remember, the purpose of the business rationale is to document the satisfactoriness of the business case to retain a third-party. The business rationale should be included in the compliance review file assembled on every third-party at the time of initial certification and again if the third-party relationship is renewed. This means “Document, Document, and Document”. Three key takeaways:

You should always have a business reason for using a third-party which is articulated by the business folks, not compliance.

A Relationship Manager is the key going forward in operationalizing your compliance program through the life of the third-party relationship with your company.

Always remember to “Document, Document, and Document”.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Over the month of July, I will consider the risk management of third-parties in an operationalized compliance program. As every compliance practitioner is aware, third-parties still present the highest risk under the FCPA. You must assess whether the company has a business rationale for needing the third party in the transaction, and the risks posed by third-parties, including their reputations and relationships, if any, with foreign government officials. You should ensure that contract terms with third parties specifically describe the services to be performed, the third party is actually performing the work, and that its compensation is commensurate with the work being provided in that industry and geographical region.   Finally you must engage in ongoing monitoring of the third-party relationships, through updated due diligence, training, audits, and/or annual compliance certifications by the third party.  A well-designed compliance program should apply risk-based due diligence to its third- party relationships. As the DOJ noted “the need for, and degree of, appropriate due diligence may vary based on the size and nature of the company, transaction, and third party, prosecutors should assess the extent to which the company has an understanding of the qualifications and associations of third-party partners, including the agents, consultants, and distributors that are commonly used to conceal misconduct, such as the payment of bribes to foreign officials in international business transactions.” This means your compliance must have a process for the full life cycle of third-party risk management. There are five steps in the life cycle of third-party management.

Business Justification;

Questionnaire to third-party;

Due diligence on third-party;

Compliance terms and conditions, including payment terms; and

Management and oversight of third-parties after contract signing.

I will be exploring each of these steps in detail, so you will be able to fully operationalize your third-party risk management program. Three key takeaways:

Use the full five-step process for third-party management.

Make sure you have Business Development involvement and buy-in.

Operationalize all steps going forward by including business unit representatives.

For more information on how an independent monitor can help improve your company’s ethics and compliance program, visit this month’s sponsor Affiliated Monitors at www.affiliatedmonitors.com. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The concept of privilege in an internal investigation is critical. Two important privileges are the attorney-client privilege and the work product privilege. Unfortunately, both are often misunderstood, miss-applied and consequently lost. To determine whether you have a valid privilege claim, it is incumbent to understand the parameters of the attorney-client privilege. In presentation, entitled “Attorney-Client Privilege ”, David E. Keltner, Kelly Hart & Hallman LLP, Elizabeth Brummett and Adrienne Parham, both from University of Texas Law School, wrote that under U.S. federal law, the attorney-client privilege applies when the following are present:

A client is seeking legal advice or a lawyer’s services;

The person to whom the communication is made is a lawyer or his or her representative;

The communication relates to a fact disclosed from a client (a representative) to a lawyer (a representative);

Strangers are not present;

A client requires confidentiality.

In addition to the attorney-client privilege there is another privilege which can come into play around internal investigations. It is the attorney work-product doctrine. Keltner noted, “The attorney-client privilege and the attorney work-product doctrine are often asserted interchangeably. While there is some overlap between the two, the attorney-client privilege is significantly different than the attorney work-product doctrine.” Moreover as “codified in Fed R.Civ. P. 26(b)(3), [the attorney/work product] provides a qualified protection to materials prepared by party’s counsel or other representative in the anticipation of litigation.” The doctrine exists “because it permits lawyers to “work with a certain degree of privacy, free from unnecessary intrusion by opposing parties . . .”” Three key takeaways:

Note the differences in the attorney-client privilege and attorney work-product doctrine.

Both can be waived intentionally or through inadvertent conduct.

Take care on attorney work-product outside the U.S., where there may be no privilege at all.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Must an investigator warn an employee that concealing information from company lawyers conducting an internal FCPA investigation could be a federal crime? Even if the company attorneys provided the now standard corporate attorney Upjohn warning? Does a company attorney asking questions morph into a de facto federal agent during an internal company investigation regarding alleged FCPA violations and is the attorney thereby required to provide a Mirandawarning to employees during said investigation? Employees who are subject to being interviewed or otherwise required to cooperate in an internal investigation may find themselves on the sharp horns of a dilemma requiring either (1) cooperating with the internal investigation or (2) losing their jobs for failure to cooperate by providing documents, testimony or other evidence. Many U.S. businesses mandate full employee cooperation with internal investigations or those handled by outside counsel on behalf of a corporation. These requirements can exert a coercive force, “often inducing employees to act contrary to their personal legal interests in favor of candidly disclosing wrongdoing to corporate counsel.” Moreover, such a corporate policy may permit a company to claim to the government a spirit of cooperation in the hopes of avoiding prosecution in addition to increasing the chances of earning meaningful credit under the U.S. Sentencing Guidelines or the FCPA Corporate Enforcement Policy. Three key takeaways:

Make sure you provide an Upjohn warning.

If an employee demands counsel to represent them during an internal investigation, who bears the cost?

Always check state law requirements around internal investigations.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In September 2015, Sally Yates, then Assistant Attorney General, announced the Memo that bears her name (Yates Memo), saying, “we have revised our policy guidance to require that if a company wants any credit for cooperation, any credit at all, it must identify all individuals involved in the wrongdoing, regardless of their position, status or seniority in the company and provide all relevant facts about their misconduct. It’s all or nothing. No more picking and choosing what gets disclosed. No more partial credit for cooperation that doesn’t include information about individuals.” This statement tied directly into the first point of the Yates Memo, which stated, “To be eligible for any cooperation credit, corporations must provide to the Department all relevant facts about the individuals involved in corporate misconduct.”  More than three years after the announcement of the Yates Memo, the DOJ modified this course slightly. In 2018, then-Deputy Attorney General Rod Rosenstein relaxed the rigid approach required by the Yates Memo and inserting more flexibility and discretion to government investigators. Rosenstein said that the DOJ would continue to focus on individuals in its white-collar investigations, but he ended the Yates Memo’s approach requiring ALL relevant facts to be turned over to the DOJ. This permitted corporations to receive credit for their cooperation if they identify individuals who were significantly involved in or caused the criminal conduct and permitted greater flexibility and discretion in awarding cooperation credit in civil cases. Then Attorney General Jeff Sessions echoed these concepts in his Keynote remarks at the Ethics and Compliance Initiative in April 2017. He reiterated that the DOJ would focus on individual criminal misconduct in the context of enforcing the FCPA. This continued emphasis will mean that there is even more pressure on corporate compliance programs to get it right and get it right sooner rather than later. Three key takeaways:

What is a Yates binder?

While the Yates Memo required you to hand over ALL evidence, the Rosenstein Corollary added flexibility.

Senior management is now in the firing line.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Now that you have set your Board of Directors, investigations protocol, we consider some of the key factors which will lead to the successful conclusion of a Board-led investigation. Once again, the article, “Successful Board Investigations”, offers seven considerations to lead to the successful conclusion of a Board-led investigation. 

Consider whether you need independent outside counsel.

Consider hiring an experienced investigator to lead the internal investigation.

Consider the need to retain outside experts.

Analyze potential conflicts of interest at the outset and during the investigation.

Carefully evaluate whistleblower allegations.

Request regular updates from outside counsel, without limiting the investigation.

Consider whether an oral report at the conclusion of the investigation is sufficient.

The authors conclude their piece by stating, “By keeping in mind the issues addressed above, the Board will be better prepared for the investigation and readily able to exercise good judgment throughout the review. A well-conducted investigation by the Board may spare the company further disruption and costs associated with follow-on investigations by the regulators, or at the very least minimize the company’s exposure.” Three key takeaways:

Retain the right counsel. Consider conflicts and appearance.

Carefully evaluate all whistleblower allegations and reject retaliation.

Consider receiving oral reports on an ongoing basis and one lengthy oral report at the end of the investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Many companies have an investigation protocol in place when a potential compliance violation or other legal issue arises. However, many Boards of Directors do not have the same rigor when it comes to an investigation, which should be conducted or led by the Board itself. The consequences of this lack of foresight can be problematic, because if a Board does handle an investigation right, the consequences to the company, its reputation and value can be quite severe. The SEC considers a variety of factors around corporate investigations including: Did management, the board or committees consisting solely of outside directors oversee the review? Did company employees or outside persons perform the review? If outside persons, have they done other work for the company? There is also a SOX role in internal investigations, most particularly for audit. Section 301 establishes certain requirements for Audit Committees, including: (1) Procedures for receipt, retention, and treatment of complaints received by the issuer regarding accounting, internal accounting controls, or auditing matters; (2) Procedures regarding the confidential, anonymous submission by employees of the issuer of concerns regarding questionable accounting or auditing matters; (3) Authority to engage independent counsel and other advisers, as it determines necessary to carry out its duties; and (4) Funding to engage advisors as it deems appropriate. Three key takeaways:

The Board should have a written protocol for investigations prepared in advance.

Any Board led investigation must be both credible and objective.

The investigation must be thorough but the Board can be cost effective.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

You may find yourself in the position that you will have to have some very frank discussions about what to expect in terms of costs and time outlays. While much of these discussions will focus on the investigative process and costs, these discussions will allow you to begin to talk about remediation going forward and begin to explain why money must be budgeted for the process. Costs must be adequately discussed to set proper expectations. These include both direct costs and, even more importantly, a discussion of indirect costs to a company. Dan Chapman has noted that “the biggest cost to a company during an investigation is the diversion of management resources” and, as he further explained, “kind of everything stops to focus on the investigation.” This indirect cost comes through largely the time commitment of senior management. He further explained, “if senior management has to commit 20% of their time, that’s 20% that’s not going towards revenue generating, shareholder value protecting activities.” Three key takeaways:

A serious allegation gets the attention of the Board of Directors and senior management. Use this time to move the compliance program forward.

Be aware of how your investigation can impact and even inform your remediation efforts.

How do you deal with the dreaded ‘where else’ question?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There is nothing like an internal whistleblower report about a FCPA violation, the finding of such an issue or (even worse) a subpoena from the DOJ to trigger the Board of Directors and senior management attention to the compliance function and the company’s compliance program. Such an event can trigger much gnashing of teeth and expressions of outrage followed immediately by proclamations “We are an ethical company.” However, it may well be the time for a very serious reality check. In addition to robust investigation, a company must engage in remediation of the offending conduct. The 2020 Update to the Evaluation of Corporate Compliance Programs mandated the additional significance of this by providing that this process must be considered “both at the time of the offense and at the time of the charging decision and resolution”. When you consider the strictures around continuous monitoring and continuous improvement in compliance programs it is clear why this analysis is so important. Obviously, a key test of any compliance program is when a deficiency is found and a violation occurs. The question then becomes, what did you do about it.  But from the DOJ (and Securities and Exchange Commission) perspective, the key is to use the information to both fix the problem so that it does not occur again but also improve your compliance regime. Three key takeaways:

How does your investigation inform your remediation plan?

A compliance program failure offers a way to upgrade your regime.

Your investigative team must inform your remediation team.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Who to suspend during any investigation is always a delicate question to answer and is never easy to answer. As the VW emission-testing scandal reverberated, it brought up some very knotty questions, which have continued bedeviled many a CCO or compliance practitioner in multiple areas. De-confliction is also an issue which continues to bedevil investigators and internal investigations. Mara Senn has said “That is a very case-by-case difficult question to answer, but in general, I think it’s better to keep them around for as long as you may need them. Once they’ve been fired or otherwise disciplined, really, even if you keep them around, they’re going to be less cooperative with you and possibly, if you fire them, not cooperative at all. You can require them to be cooperative in the termination agreement, but obviously in practice, cooperation can mean a lot of different things.”  De-confliction, involves the government asking a company to halt its own investigation for the government to be the first to interview witnesses. Former DAG Lanny Breuer posed four questions which every investigator must consider in the area of de-confliction. (1) Would complying with the request be consistent with directors’ and corporate officers’ fiduciary duty of oversight? (2) How can a company make decisions without speaking with its employees? (3) How will a delay affect the company’s other regulatory obligations? and (4) How can external counsel advise a company without knowing the facts? Companies hire external counsel to conduct thorough investigations, evaluate their clients’ conduct, and provide informed legal advice. These tasks can be difficult if not impossible to accomplish where external counsel have their hands tied behind their backs. Three key takeaways:

The decision on whom to discipline and when are critical decisions during any investigation.

You should take a case-by-case approach.

The “de-confliction” question can be quite troubling during an internal investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In an article, entitled “Internal Investigations, How to Conduct an Anti-Corruption Investigation: Developing and Implementing the Investigation Plan”, Mara Senn, now Director & Senior Counsel, Global Compliance Investigations at Zimmer Biomet and Michelle K. Albert, former lawyer at Arnold & Porter discussed cross-border investigations. They considered the following issues. Offer interview translations. Avoid cultural pitfalls.       Observe data privacy restrictions. Comply with labor requirements. Be aware of other local requirements. Put forms in native translations. Preserve the attorney-client privilege. Prepare for local enforcement actions. Prepare for security risks. Protect whistleblowers. Three key takeaways:

Use translators and translations of key documents in witness interviews.

Use local counsel to facilitate the investigation and to help navigate any local anti-corruption investigation issues.

Never, never, never retaliate. The SEC will pay whistleblower bounties for non-U.S. citizens.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are the characteristics of a good interview in the context of an internal investigation? Is there one technique you can use which will provide you the results you want to achieve? How should you think through your questions and document review prior to the investigation? At this point in time, how do such issues play out in the time of Coronavirus?  There is no one right way to prepare for and conduct an interview. What is important is that you have a plan and execute on that plan. Begin by obtaining an understanding of what the various stakeholders want answers to. This could include the Board of Directors, C-Suite executives, the GC and legal department, the CCO and compliance function or up to government regulators such as the SEC or DOJ. Three key takeaways:

There is no one right way to prepare and do an interview.

The interview should not be confrontational.

The interview, like the entire investigation process, is a chess match.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are some of the top challenges you may well face during an investigation? Beyond the basics, a company must consider the intake process as a starting point, which Jonathan Marks noted is one of the biggest challenges. Rather surprisingly, he noted there are still companies without a hotline or anonymous reporting system, stating “we still see organizations whereby there is no formal ethics hotline except for the fact that they might send an email to some member of management or some member of the Board.” Planning your investigation, having the right team members involved and meeting the challenges which inevitably arise during an investigation can be difficult. However, beginning with the DOJ’s 2015 Yates Memo, the 2016 FCPA Pilot Program, and the 2017 and 2019 versions Evaluation of Corporate Compliance Programs, together with the 2020 Update and FCPA Corporate Enforcement Policy, the pressure on every CCO and company to get an investigation done quickly, efficiently and, most importantly, right is even greater now. Marks has laid out a concrete way for you to think through how to plan an investigation, staff it properly and meet the inevitable challenges. Three key takeaways:

The intake process may seem the most straight-forward but many companies drop the ball at this initial step.

You must never retaliate against employees who come forward in good faith.

Always think several steps ahead.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Beginning with the 2015 Yates Memo, 2016 FCPA Pilot Program, 2017 and 2019 Evaluations of Corporate Compliance Programs, with 2020 Update through to the FCPA Corporate Enforcement Policy; the DOJ has put even more pressure on every CCO, compliance practitioner and indeed company, to get an investigation done quickly, efficiently and, most importantly, right. This is even more true after the U.S. Supreme Court’s decisions in Digital Realty Trust v. Somers, which limited whistleblower protection and benefits to only those whistleblowers who go to the SEC, rather than initially report internally. What do all these documents tell who should be on your investigation team?   As with a decision on bringing in outside counsel to perform a compliance investigation, you will need to consider whether a forensic accountant should be retained as an outside consultant or hired as an employee. One critical reason to bring in an outside professional is so they will be not be governed by management or influenced by potential biases within a company. Lastly is the issue of privilege. If a forensic accountant is not assigned through your legal department or through outside counsel, you can kiss away even the chance of claiming privilege. Obviously, the GC would be involved to help protect the attorney client privilege if for no other reason. Further, an investigation needs to have compliance involved, to understand what compliance program was in place at the time of the incident in question, what procedures compliance had and understand if this truly was a gap in the compliance function or maybe there was an area within the compliance function that was not operating as prescribed, or maybe it was a little bit weak. Three key takeaways:

HR plays a key but often underused role in internal investigations.

The Board of Directors and senior management have different roles.

Use your legal department to protect the privilege.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Dan Dunne, in a Compliance and Ethics Professional article, entitled “Foxes and henhouses: The importance of independent counsel”, discussed what he termed a “critical element” in any investigation, which he denominated as “fair and objective evaluation.” Dunne wrote that a key component of this fair and objective evaluation is the Who question; that is, who should supervise the investigation and who should handle the investigation? Dunne’s clear conclusion is that independent counsel should handle any serious investigation. There are three reasons for a company to retain independent counsel for internal investigations of serious whistleblower complaints. First, André Agassi was right, perception is reality. Secondly, if regular outside counsel investigates their own prior legal work or legal advice, a very large and potentially messy number of loyalty and privilege issues can arise in the internal investigation. The third reason is the relationship of the regular outside counsel or law firm with regulatory authorities. If a company’s regular outside counsel performs the internal investigation and the results turn out favorably for the company, the regulators may ask if the investigation was a whitewash or at the very least, less than robust. If the SEC or DOJ cannot rely on a company’s own internal investigation, it may perform the investigation all over again with its own personnel. Further, these regulators may believe that the company, and its law firm, has engaged in a cover-up. This is certainly not the way to buy credibility. Three key takeaways:

Serious allegations demand a serious response, with seriously good lawyers leading the investigation.

The biggest thing that any person or company brings to the table when sitting across from the DOJ or SEC is credibility.

Use of regular corporate counsel can negatively impact your investigation because of the issues of loyalty and privilege.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Under Part 1, Section D. Confidential Reporting Structure and Investigation Process, it stated in part, Properly Scoped Investigation by Qualified Personnel –What steps does the company take to ensure investigations are independent, objective, appropriately conducted, and properly documented? How does the company determine who should conduct an investigation, and who makes that determination? These questions were presaged by the DOJ’s 2015 Yates Memo and the 2016 FCPA Pilot Program. The pressure on every CCO, and indeed company, to get an investigation done quickly, efficiently and, most importantly, right is even greater now.  Jonathan Marks began by cautioning that when considering any well run internal investigation, a CCO must be cognizant of the strictures laid out in the Evaluation. It all begins with who in-house is looking at the complaint and does the CCO, compliance practitioner or legal team have the skills and capabilities to handle the matter which has arisen? Obviously if there are esoteric accounting issues or significant internal control work-arounds and overrides, a CCO may not have those skills to really understand all the issues. Similarly, if the matter is a global FCPA or equivalent bribery and corruption matter, Marks related, these “come in different flavors, and because they come in different flavors you may not have the skills or capabilities to do an investigation that would take place in say Brazil or Russia or China or India.” Three key takeaways:

Always remember your ultimate audience may be the government.

You must understand both the business environment and extended business enterprise.

Communication and collaboration in any investigation are critical so you should begin early and continue to do so throughout the investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Under Part 1, Section D. Confidential Reporting Structure and Investigation Process, it stated in part, Properly Scoped Investigation by Qualified Personnel –What steps does the company take to ensure investigations are independent, objective, appropriately conducted, and properly documented? Your company should have a detailed written procedure for handling any complaint or allegation of bribery or corruption, regardless of the means through which it is communicated. The mechanism could include the internal company hotline, anonymous tips, or a report directly from the business unit involved. You can make the decision on whether or not to investigate with consultation with other groups such as the Compliance Committee of the Board of Directors or the Legal Department. The head of the business unit in which the claim arose may also be notified that an allegation has been made and that the Compliance Department will be handling the matter on a go-forward basis. Through the use of such a detailed written procedure, you can work to ensure there is complete transparency on the rights and obligations of all parties once an allegation is made. This allows compliance to have not only the flexibility but also the responsibility to deal with such matters, from which it can best assess and then decide on how to manage the matter. Three key takeaways:

A written protocol, created before an investigation, is a key starting point.

Create specific steps to follow so there will be full transparency and documentation going forward.

Consistency in approach is critical.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the things that I learned from the television series MAS*H was the need for triage. In the hospital setting, triage is the process of determining the priority of patients’ treatments based on the severity of their condition. In the 2012 FCPA Guidance, there is a short but succinct statement, “once an allegation is made, companies should have in place an efficient, reliable, and properly funded process for investigating the allegation and documenting the company’s response, including any disciplinary or remediation measures taken.” This is considered in more expansive language in the 2020 Update to the Evaluation of Corporate Compliance Programs. Under Part 1, Section D. Confidential Reporting Structure and Investigation Process, it stated in part, Properly Scoped Investigation by Qualified Personnel – How does the company determine which complaints or red flags merit further investigation?  Appropriate triage of allegations has several different impacts for any matter which comes to the attention of compliance. Obviously, it will help you to initially determine the seriousness of the matter. From there you can allocate an appropriate level of resources. It will also aid in your discussion with the DOJ if you must go that route. Finally, in the situation where facts come in, it provides the required documented evidence that a process was followed that you can show the government that a claim was properly scoped, as required under the Evaluation. But the key is to be prepared, not only in terms of having your investigation and notification protocols in place before an allegation comes in but also doing the proper triage so that you have an initial understanding of what you may be facing. Three key takeaways:

Compliance can learn from MAS*H about the need for triage.

Initial triage allows you to separate the wheat of serious allegations from the chaff of more inconsequential allegations.

A robust triage process allows for greater credibility with government regulators.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In Houston, we have experienced energy companies laying off upwards of 30% of their workforce, both in the US and abroad. Employment separations can be one of the trickiest maneuvers to manage in the spectrum of the employment relationship. Even when an employee is aware layoffs are coming it can still be quite a shock when Human Resources (HR) shows up at their door and says, “Come with me.” However, layoffs, massive or otherwise, can present some unique challenges for the FCPA compliance practitioner. Employees can use layoffs to claim that they were retaliated against for a wide variety of complaints, including those for concerns that impact the compliance practitioner. Yet there are several actions you can take to protect your company as much as possible. The reason for these actions are to allow you to demonstrate that any laid off employee was not separated because of a hotline or whistleblower allegation but due to your overall layoff scheme. However it could be that you may need this person to provide your compliance department additional information, to be a resource to you going forward, or even a witness that you can reasonably anticipate the government may want to interview. If any of these situations exist, if you do not plan for their eventuality before you layoff the employee, said (now) ex-employee may not be inclined to cooperate with you going forward. Also if you do demonstrate that you are sincerely interested in a meritorious hotline complaint, it may keep this person from becoming a SEC whistleblower. Three Key Takeaways

An employment separation is a critical time if an internal report has been made.

Have appropriate language in your separation agreement.

Treat terminated employees with dignity and respect.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are some best practices regarding an internal reporting system? The 2012 FCPA Guidance stated, “An effective compliance program should include a mechanism for an organization’s employees and others to report suspected or actual misconduct or violations of the company’s policies on a confidential basis and without fear of retaliation.”  This was expanded in the DOJ’s 2020 Guidance, in the section entitled “D. Confidential Reporting Structure and Investigation Process”, with the following language, “Another hallmark of a well-designed compliance program is the existence of an efficient and trusted mechanism by which employees can anonymously or confidentially report allegations of a breach of the company’s code of conduct, company policies, or suspected or actual misconduct. Prosecutors should assess whether the company’s complaint-handling process includes pro-active measures to create a workplace atmosphere without fear of retaliation, appropriate processes for the submission of complaints, and processes to protect whistleblowers.” Three Key Takeaways

Internal reporting systems are a clear indicia of a working, operationalized compliance program.

There must be a solid line of communication between the people who are doing the investigation and the people leading the remediation.

Your internal reporting mechanism must be trusted.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What are some best practices regarding an internal reporting system? The 2012 FCPA Guidance stated, “An effective compliance program should include a mechanism for an organization’s employees and others to report suspected or actual misconduct or violations of the company’s policies on a confidential basis and without fear of retaliation.” The 2019 Guidance further refined this basic requirement for a hotline with inquiries into the effectiveness of your corporate hotline, asking, “Effectiveness of the Reporting Mechanism – Does the company have an anonymous reporting mechanism, and, if not, why not? How is the reporting mechanism publicized to the company’s employees? Has it been used? How has the company assessed the seriousness of the allegations it received? Has the compliance function had full access to reporting and investigative information?” In this podcast, we detail some of the key best practices.  Three key takeaways:

Get the word out to your employees about your company hotline through a variety of mediums and platforms.

Train your employees on the use of the hotline.

Use data from your hotline to continually update and improve your compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Is your hotline working for you? In an article, entitled “Promoting Effective Use of the Company Compliance Hotline”, José Tabuena provided an excellent example of the power of a hotline. He provided a case study of a company which had not integrated its IT function into its regular compliance and ethics training programs. As such there were zero calls into the hotline by IT employees. This dynamic was changed and IT was integrated into the company’s regular compliance and ethics training. Thereafter, the hotline received several calls from IT employees indicating where there were two major areas of complaints. The first area regarded family members who were hired and perceptions of favoritism. The second related to allegations that certain managers were manipulating data to maximize their bonuses. This case study demonstrates the power of a hotline. The company’s Compliance Department “established the credibility of the helpline as a resource to raise issues and report misconduct. The concerns regarding nepotism and conflicts of interest were taken seriously, and although the  violations were not as widespread as the calls indicated, the review went a long way to clear the air.” Equally important, the helpline proved to be a successful management tool as well. The company was able to manage potential compliance issues and improve employee morale.  Three key takeaways:

Hotlines can be powerful tools for the compliance professional.

Simply because you have no hotline complaints does not mean you do not have any compliance or ethics issues which need review and resolution.

Adequate follow up is a key part of overall hotline effectiveness.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

While it is clear that the government expects companies to have an internal reporting system, there are benefits far beyond putting you in the government’s good graces. Companies with a more robust internal reporting system generated more reports. Dr. Welch found a group of companies he termed “power users”, which were high level users of whistleblower reporting systems who had more activity than the average entity. These “power user” companies have several interesting characteristics. First they are typically firms with a higher quality earnings reporting. They are more profitable entities. Finally, these “power user” companies were firms with higher quality governance, as rated by the Entrenchment Index which is used measure how entrenched management is in a company.   Conversely, companies which were observed to be a more limited user of whistleblower reporting systems are companies that were seen to have poor governance. They are more prone to financial accounting issues, such as discretionary accruals, which could prove problematic. These tend to be smaller and less mature firms. Their overall compliance programs were generally not seen as robust or as effective as those in larger, more mature organizations. Finally, these firms, probably because they were smaller and less mature, are more prone to extreme growth and the problems associated with trying to scale up quickly. All of this points to one unmistakable conclusion, a robust whistleblower reporting system facilitates a company’s resolution of problems before they become major problems or legal violations bringing the Securities and Exchange Commission (SEC) or DOJ calling. Three Key Takeaways

Companies with a robust whistleblower and reporting system had greater profitability and workforce productivity as measured by Return on Assets.

There were fewer material lawsuits brought against the company overall and there were lower settlement costs if a lawsuit did occur.

There were fewer external whistleblower reports to regulatory agencies and other authorities.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The call, email or tip comes into your office; an employee reports suspicious activity somewhere across the globe. That activity might well turn into a FCPA issue for your company. As the CCO, it will be up to you to begin the process which will determine, in many instances, how the company will respond. This chapter will provide you with the steps you will need to consider going forward. This chapter will detail the two parts; internal reporting and investigations. It would seem axiomatic that organizations understand the benefits of having an internal reporting system, whether it is called a hotline, helpline or something else. Just as plainly, a company should understand the need for effective investigations after a report comes in which might lead to a potential violation. Three key takeaways:

A robust internal reporting system will be one of the key indicia the DOJ considers.

Hotline reporting can bring a visibility to problems.

Hotline reports must be treated fairly and justly.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The next area for policies is extortion payments, which not are made illegal under the FCPA. Extortion payments are made for any action which threatens or demands payment for life, liberty, or health. These should be exempted out from your facilitation payments and your compliance program through specific language. You need to do this for a variety of reasons. First and foremost, your employees must understand that the company will support them if they are in any way threatened with harm, with arrest or physical detention, their health/safety is threatened. As a compliance professional, you need to make sure they understand they need to do whatever they have to do to get themselves out of such a situation.  Some of the situations your employees might face are along the lines of the following:

Employees are stopped by police, military or paramilitary personnel, or militia (uniformed or not) at designated or other checkpoints or other places and a payment is demanded as a condition of passage of persons or property;

Employees are stopped at the airport by customs or passport control personnel or military personnel and a payment is demanded for entry or exit of persons or property; or

Employees are asked by persons claiming to be security personnel, immigration control, or health inspectors to pay for an allegedly required inoculation or other similar procedure.

The key though is that it be properly documented. But more than simply the documentation is that you must specifically list extortion payments in your books and records, so you will not be suspected with hiding them by describing them as something else. The key is to train your employees specifically on the actions to take. In your policy state that if there is a threat to health, safety or liberty, it is not a facilitation payment but an extortion payment. Make sure that they understand what their rights are and what their obligations are to report it when they come back to the corporate office or their office. Always remember, an extortion payment is not a FCPA violation. Three key takeaways:

Extortion payments are not illegal under the FCPA.

Was the action an extortion or some other type of situation?

“Document, Document, and Document” your extortion payments, both the financial component and a description of the underlying events.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As every compliance practitioner is well aware, third-parties still present the highest risk under the FCPA. The DOJ 2019 Guidance devotes an entire prong to third-party management. It begins with the following: A well-designed compliance program should apply risk-based due diligence to its third-party relationships. Although the degree of appropriate due diligence may vary based on the size and nature of the company or transaction, prosecutors should assess the extent to which the company has an understanding of the qualifications and associations of third-party partners, including the agents, consultants, and distributors that are commonly used to conceal misconduct, such as the payment of bribes to foreign officials in international business transactions. This set of queries clearly specifies the DOJ expects an integrated approach that is operationalized throughout the company. This means your compliance program must have a process for the full life cycle of third-party risk management. There are five steps in the life cycle of third-party management: 1) business justification; 2) questionnaire to third-party; 3) due diligence on third-party; 4) compliance terms and conditions, including payment terms; and 5) management and oversight of third parties after contract signing. I continually give my mantra of compliance, which is “Document, Document, and Document”. Each of the steps you take in the management of your third parties must be documented. Not only must they be documented but they must be stored and managed in a manner that you can retrieve them with relative ease. The management of third parties is absolutely critical in any best practices compliance program. Three key takeaways:

Use the full five-step process for third-party management.

Make sure you have Business Development involvement and buy-in.

Operationalize all steps going forward by including business unit representatives.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

From the information provided by the DOJ in Opinion Releases and in enforcement actions, there are several different insights which may be drawn on regarding what should go into your policy on facilitation payments. Do not forget that facilitation payments must be accurately shown on the books and records of your company. In all cases the employee who requested permission to make the facilitation payment must be responsible for obtaining all required approvals and forwarding a copy of the approvals and any other relevant supporting documentation as required, so that the it is recorded as a facilitation expense in the books and records and maintained in a central file. Facilitation payments should not be recorded as consulting fees, entertainment expenses, or other types of expenses that may misrepresent the true nature of the payments.  There may be emergency situations when it will be difficult or impossible for employees to obtain approvals before having to decide whether or not to pay a facilitation payment. If the facilitation payment is made in an emergency, the employee reports the facilitating payment to the compliance department and explains the emergency as soon as practical after making the facilitation payment. Three key takeaways:

What was the amount of the facilitation payment?

Was the action truly routine?

How high up was the government official who received the facilitation payment? Was his or her decision discretionary?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the more confusing areas of the FCPA is in that of facilitation payments. Facilitation payments are small bribes but make no mistake about it, they are bribes. For that reason, many companies feel they are inconsistent with a company culture of doing business ethically and in compliance with laws prohibiting corruption and bribery. Further, the 2012 FCPA Guidance specifies, “while the payment may qualify as an exception to the FCPA’s anti-bribery provisions, it may violate other laws, both in Foreign Country and elsewhere. In addition, if the payment is not accurately recorded, it could violate the FCPA’s books and records provision.” Additionally, the 2012 FCPA Guidance states, “Whether a payment falls within the exception is not dependent on the size of the payment, though size can be telling, as a large payment is more suggestive of corrupt intent to influence a non-routine governmental action. But, like the FCPA’s anti-bribery provisions more generally, the facilitating payments exception focuses on the purpose of the payment rather than its value.” In addition to these clear statements about whether the FCPA should continue to allow said bribes; you should also consider the administrative nightmare for any international company. The U.K. Bribery Act does not have any such exception, exemption or defense along the lines of the FCPA facilitation payment exception. This means that even if your company allows facilitation payments, it must exempt out every U.K. Company or subsidiary from the policy. Further, if your company employs any U.K. citizens, they are subject to the U.K. Bribery Act no matter who they work for and where they may work in the world, so they must also be exempted. Finally, if your U.S. Company does business with a U.K. or other company subject to the U.K. Bribery Act, you may be prevented contractually from making facilitation payments while working under that customer’s contract. As I said, an administrative nightmare. Three key takeaways:

Do not forget the administrative nightmare of facilitation payments for international organizations.

The Kay decision made clear how narrow the “routine government action” exception is.

Facilitation payments will usually be an add-on as they are symptomatic of an ineffective compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The original version of the Foreign Corrupt Practices Act (FCPA), enacted in 1977, contained an exception for payments made to non-US officials who performed duties that were “essentially ministerial or clerical”. In 1988 Congress responded by amending the FCPA under the Omnibus Trade and Competitiveness Act to clarify the scope of the FCPA’s prohibitions on bribery, including the scope of permitted facilitation payments. An expanded definition of “routine governmental action” was included in the final version of the bill, reflecting the intent of Congress that the exceptions apply only to the performance of duties listed in the subcategories of the statute and actions of a similar nature. Congress also meant to make clear that “ordinarily and commonly performed actions”, with respect to permits or licenses, would not include those governmental approvals involving an exercise of discretion by a government official where the actions are the functional equivalent of “obtaining or retaining business for, or with, or directing business to, any person.” Three key takeaways:

Many companies still struggle with facilitation payments.

What are the five listed purposes for facilitation payments?

The facilitation payment exception is narrowly construed by both the courts and the Justice Department.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The FCPA states, “The FCPA’s anti-bribery provisions apply to corrupt payments made to (1) “any foreign official”; (2) “any foreign political party or official thereof”; (3) “any candidate for foreign political office”; or (4) any person, while knowing that all or a portion of the payment will be offered, given, or promised to an individual falling within one of these three categories. Although the statute distinguishes between a “foreign official,” “foreign political party or official thereof,” and “candidate for foreign political office,” the term “foreign official” in this guide generally refers to an individual falling within any of these three categories.” Government policies affect the commercial environment. A company is subject to legislation and regulation that affects how it conducts its business and generates value for its investors. Participating in the political process is part of a business strategy to protect a company’s interests. Most international businesses have strategy to engage in the political process with a view to the long-term interests of the company and to promote and protect its interests. All political contributions and expenditures on behalf of the Company and management reports on these political contributions and expenditures should be reported to the Board of Directors annually. No political contributions may be made or promised unless written pre-approval has been obtained from the corporate compliance function Three key takeaways:

Political candidates are covered by the FCPA.

What is the business purpose for the contribution?

Do not make contributions towards candidates who can award your company business.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What should your compliance policy and procedures on charitable donations look like? What should you prohibit or even caution against? The starting point is the 2012 FCPA Guidance regarding charitable donations. The information on the red flags from the Opinion Releases and the best practices, as set out in the 2012 FCPA Guidance, have been available for some time. From the Schering-Plough and Lilly enforcement actions, your policy should consider the timing of charitable donations to see if they are at or near the time of the awarding of new or continued business. Finally, in managing the relationship, you now need to look at overall increases in sales to determine if they are tied to a pattern of charitable donations. By looking at the timing and quantum of charitable donations, internal audit may be able to ascertain that a spike in sales is tied to corrupt conduct. Three key takeaways:

What are the basic inquiries to make around charitable donations?

Use all of the communication tools the DOJ has provided; written guidance, enforcement actions and Opinion Releases to inform your charitable donation policy.

“Document, Document, and Document” the basis of your charitable donations risk assessment.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Opinion Releases can provide valuable information for the compliance practitioner. I agree with the statement found in the 2012 FCPA Guidance that “DOJ’s opinion procedure is a valuable mechanism for companies and individuals to determine whether proposed conduct would be prosecuted by DOJ under the FCPA. Generally speaking, under the opinion procedure process, parties submit information to DOJ, after which DOJ issues an opinion about whether the proposed conduct falls within its enforcement policy.” In the areas of charitable donations, the DOJ has provided four Opinion Releases which give solid guidance on this tricky issue under the FCPA. In each Opinion Release, the DOJ indicated that it would not initiate prosecutions based upon the fact scenarios presented to it. Three key takeaways:

You can utilize the Opinion Release process for a wide variety of issue.

You must manage your charitable donations program even after the money has been donated.

Never forget the Mendelsohn common sense approach to charitable donations.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

When is a rose not a rose? When it is a charitable donation not made for philanthropic purposes and violates the FCPA. This was a feature of the Eli Lilly and Company (Lilly) FCPA enforcement action brought by the SEC in 2012, involving a bribery scheme utilized by Lilly in Poland. The scheme and FCPA violations mirrored an earlier FCPA enforcement action, also brought by the SEC as a civil matter, rather than by the DOJ as a criminal matter, against another U.S. entity Schering-Plough, for making charitable donations in Poland which violated the FCPA. One of the remarkable things about both of these enforcement actions, brought almost eight years apart, was that they involved improper payments to the same Polish charitable foundation to wrongfully influence the same Polish government official to purchase products from both of these companies.  Three key takeaways:

Every compliance practitioner should study both the Lilly and Schering-Plough enforcement actions.

What is the purpose of the charitable entity you are making a donation to?

“Document, Document, and Document” your due diligence around donors.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Prior to the 2012 FCPA Guidance, the DOJ issued two 2007 Opinion Releases which offered guidance to companies considering whether, and if so how, to incur travel and lodging expenses for government officials. Both Opinion Releases laid out the specific representations made to the DOJ, which led to them to approve the travel to the U.S. by foreign governmental officials. These facts provided strong guidance to any company which seeks to bring such governmental officials to the U.S. for a legitimate business purpose. In Opinion Release 07-01, the company was desired to cover the domestic expenses for a trip to the U.S. for a six-person delegation of the government of an Asian country for an educational and promotional tour of one of the requestor’s U.S. operations sites. In 07-02, the Company desired to pay certain domestic expenses for a trip within the U.S. by approximately six junior to mid-level officials of a foreign government for an educational program at the Requestor’s US headquarters, prior to the delegates attendance at an annual six-week long internship program for foreign insurance regulators sponsored by the National Association of Insurance Commissioners (NAIC). When Walmart Inc., Hewlett-Packard Company (HP) or GSK are in the news for alleged FCPA violations, it provides you a good reminder to review your compliance program. Not only from your compliance procedures perspective, but to test to determine if the policies and procedures are being followed or if there are issues which you might need to look at more closely. Three key takeaways:

Travel for foreign officials continues to plague companies for compliance violations.

The key is being reasonable in your costs.

Always remember to record travel expenses correctly based upon documented costs.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

If one were to reflect upon the providing of gifts and business entertainment to foreign governmental officials, one might reasonably conclude that after 40 years of the FCPA, companies might follow its prescriptions regarding gifts and business entertainment. However, there have been some notable FCPA enforcement actions in this area.  The 2012 FCPA Guidance clearly stated the FCPA does not ban gifts and entertainment. Indeed, it specified, “A small gift or token of esteem or gratitude is often an appropriate way for business people to display respect for each other. Some hallmarks of appropriate gift-giving are when the gift is given openly and transparently, properly recorded in the giver’s books and records, provided only to reflect esteem or gratitude, and permitted under local law. Items of nominal value, such as cab fare, reasonable meals and entertainment expenses, or company promotional items, are unlikely to improperly influence an official, and, as a result, are not, without more, items that have resulted in enforcement action by DOJ or SEC.” These guidelines must be coupled with active training of all personnel, not only on a company’s compliance policy, but also on the corporate and individual consequences that may arise if the FCPA is violated regarding gifts and business entertainment. Lastly, it is imperative that all such gifts and business entertainment be properly recorded, as required by the books and records component of the FCPA. And, as always, do not forget the gut check test. Three key takeaways:

Gifts and business entertainment continue to plague companies for compliance violations.

The key is not the amount but of having a policy and procedure and following it.

Always remember to record gifts and business entertainment expenses correctly.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Simply having a Code of Conduct, together with compliance policies and procedures is not enough. As articulated by former Assistant Attorney General Lanny Breuer, “Your compliance program is a living entity; it should be constantly evolving.” The 2012 FCPA Guidance stated, “When assessing a compliance program, DOJ and SEC will review whether the company Guiding Principles of Enforcement has taken steps to make certain that the Code of Conduct remains current and effective and whether a company has periodically reviewed and updated its code.” After considering these issues, you should benchmark your current policies and procedures against other companies in your industry. If you decide to move forward, I suggest a process which can be fully documented as a basis to include revisions to your compliance policies and procedures. These points are a useful guide to not only thinking through how to determine if your policies and procedures need updating, but also practical steps on how to tackle the problem. If it has been more than five years since the last updates, you should begin the process now. It is far better to review and update if appropriate than wait for a massive FCPA investigation to go through the process. Three key takeaways:

If you have not revised your compliance policies and procedures in the past five years, you should do so now

Set a timeline and budget and stick to it in the compliance policy and procedure revision process.

Document your process of revision to demonstrate more complete operationalization of your compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There are numerous reasons to put some serious work into your policies and procedures. They are certainly a first line of defense when the government comes knocking. The 2012 FCPA Guidance made clear that “Whether a company has policies and procedures that outline responsibilities for compliance within the company, detail proper internal controls, auditing practices, and documentation policies, and set forth disciplinary procedures will also be considered by DOJ and SEC.” And by using the word “considered” it is clear that this means the regulators will take a strong view against a company that does not have well thought out and articulated policies and procedures; all of which are systematically reviewed and updated. Moreover, having policies written out and signed by employees provides what some consider the most vital layer of communication and acts as an internal control. Together with a signed acknowledgement, these documents can serve as evidentiary support if a future issue arises. In other words, the “Document, Document, and Document” mantra applies just as strongly to this area of anti-corruption compliance. The specific written policies and procedures required for a best practices compliance program are well known and long established. The 2012 FCPA Guidance stated, “Among the risks that a company may need to address include the nature and extent of transactions with foreign governments, including payments to foreign officials; use of third parties; gifts, travel, and entertainment expenses; charitable and political donations; and facilitating and expediting payments.” Policies help form the basis of expectation and conduct in your company. Procedures are the documents that implement these standards of conduct. Three key takeaways:

The Code of Conduct, together with written compliance policies and procedures form the backbone of your compliance program.

The DOJ and SEC expect a well-thought out and articulated set of compliance policies and procedures.

The Fair Process Doctrineholds for the application of policies and procedures.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How can you work to operationalize your Code of Conduct as articulated in the DOJ 2019 Guidance? The 2019 Guidance focuses not on whether a company has a paper compliance program but whether a company is actually doing compliance. A company does compliance by moving it into the functional business units as a part of an overall business process. That is what makes a compliance program effective at the business level. There are several different parts of the 2019 Guidance that touch upon your Code of Conduct. The Code of Conduct design and implementation process enshrine your company’s values. Those are set by senior management and their input and support for any code project, whether initial draft or update, is critical. This gets to the heart of operationalization and demonstrates how a Code of Conduct can work to meet the DOJ requirements. As an early part of your design and drafting process, you should assemble a cross-functional team. This is important for several reasons. First, diversity in your team will help produce a more well-rounded final product. But having such team diversity will also assist in your benchmarking effort, coupled with those who are going to help you out looking at designs and maybe helping forge the design of the code. Finally, you can use a group to help in the drafting, redrafting and editing process. This diversity will help you to answer all of the DOJ questions from the 2019 Guidance in a manner consistent to support operationalization. All of these requirements point to getting out and making your Code of Conduct a part of the very fabric of your organization. By using some or all of these strategies, you will have a good starting point. But it is more than simply rollout and training. There must be ongoing communications as well. Three key takeaways:

What has been the role of senior management in the creation or update of your Code of Conduct?

How have you worked with employees outside the compliance function to lay the groundwork for fully operationalizing your Code of Conduct?

How have you measured the effectiveness of your Code of Conduct training?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What about the training on your finalized Code of Conduct? While there have been criticisms of code training, if you consider training as one source of your 360-degrees of compliance communications, the rollout of a new or updated code can be an opportunity. This rollout fits directly into the concept of 360-degrees of compliance communications as rollout is part of both communications and engagement. The delivery of a Code of Conduct is a key element of its effectiveness. By allowing your employees and other stakeholders to engage and interact with the code, through live or interactive training, the effectiveness can be better monitored and measured. Beginning with the DOJ’s 2017 Evaluation and continuing into the 2019 Guidance, is the DOJ’s emphasis in the effectiveness of training. I think everyone would understand you do need to train but now the government’s talking to us about effective training. Begin with live training that can be held at the corporate headquarters with senior management and executive involvement. Many companies will videotape a message from the CEO to help celebrate the rollout. Then there is the opportunity for localized training that gives employees an opportunity to see, meet, and speak directly with a compliance officer, not an insignificant dynamic in the corporate environment. Such personal training also sends a strong message of commitment to the Code of Conduct. It gives employees the opportunity to interact with the compliance officer by asking questions which are relevant to markets and locations outside the corporate office, which can often provide employees with the opportunity to have confidential in-person discussions. However, your Code of Conduct training should be an extension of the way you communicate compliance in your organization. If it is divorced from your 360-degrees of compliance communications style, you may well be missing an opportunity to drive better understanding of the code and denigrate the effectiveness of the training. Whatever approach is used, one of the critical factors is the length of time of the training session. Although lawyers and ethics and compliance professionals can (sometimes) sit through a multi-hour Code of Conduct lesson, it is almost impossible to keep the attention of business and operations employees for such a length of time. The presentation and number of PowerPoint slides must be kept to a manageable length before the attendee’s eyes start to glaze over.  Three key takeaways:

Consider a video message from your CEO to help roll out your Code of Conduct initiation or update.

Tailor your Code of Conduct training to your workforce.

Consider interactive and modular approaches to Code of Conduct training.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next is the design of your Code of Conduct. Through attention to detail in the design process, you should be able to come out at the end with a code which will help you to more fully operationalize your compliance program. You must begin with a determination of what you are trying to accomplish. It does not serve you to try and list every compliance risk you might think your company may encounter. You should determine the values you want to communicate, what the expectations are for employees and how to call the hotline. Under such an approach, a Code of Conduct can be the jumping off point for training on the issues stated in it. It can also form the hub of the wheel for other policies and procedures and written standards you want to communicate to relevant stakeholders. You should also consider how you are going to distribute your code to your employees and stakeholders. If it is through an Adobe .pdf document, which is accessible for most stakeholders across an organization or via another method. If a significant part of your workforce does not have access to computers, online production only will not work as the primary distribution platform. Three key takeaways:

Get your business folks involved in your Code of Conduct from the outset.

Your ethical values should be integrated into and integral to your Code of Conduct.

How have you operationalized your Code of Conduct?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next comes the evolution of the structure and format of a best practices Code of Conduct. Initially, my experience with this is that they were written by lawyers, largely for lawyers. This included ‘thou shalts’ and ‘thou shalt nots’ liberally sprinkled throughout a lengthy written document. This was what is now referred to as Code 1.0. The compliance community then evolved to Code 2.0, where the writing was less turgid, moved to more employee friendly language and then somewhere along the line we started putting in hyperlinks, pictures and videos. There are two factors which a company should consider on the structure of a Code of Conduct. The first is to consider how your organization generally communicates, overlaid with the most effective way to communicate with the various stakeholders who will read and use it. These stakeholders can include such diverse groups as employees, shareholders and third parties on both the sales and supply side of your business. This may require multiple approaches. Be sure to make your code readable. This is beyond simply eliminating legalese. It is writing English at a grade level that is sufficient for your employee population. It may be that an eighth-grade language level is appropriate for your work force. However, if you have a population consisting primarily of professionals, translating it into the appropriate languages it might be appropriate to aim for a higher level of language. Finally, you do not have to say the same thing, in multiple different ways. Three key takeaways:

Companies have moved past having a Code of Conduct written by lawyers for lawyers to a fully interactive code for all employees.

Consider how information is distributed at your organization as a basis for communication in your Code of Conduct.

Your Code of Conduct must be readable, in both in English and native language for non-English speaking employees.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the value of having a Code of Conduct? I have heard many business folks ask that question over the years. In its early days, a Code of Conduct tended to be a lawyer-written and lawyer-driven document to wave in regulator’s face during an enforcement action by using it to claim, “we are an ethical company”. Is such a legalistic code effective? Is a Code of Conduct more than simply your company’s law? What is it that makes a Code of Conduct effective? What should be the goal in the creation of your company’s Code of Conduct? How important is the Code of Conduct? Consider the 2016 SEC enforcement action involving United Airlines, Inc., which turned on violation of the company’s Code of Conduct. The breach of the code was determined to be a FCPA internal controls violation. It involved a clear quid pro quo benefit paid out by United to David Samson, the former Chairman of the Board of Directors of the Port Authority of New York and New Jersey, the public government entity which has authority over, among other things, United Airlines operations at the company’s huge east coast hub at Newark, NJ. The actions of United’s former CEO, Jeff Smisek, in personally approving the benefit granted to favor Samson violated the company’s internal controls around gifts to government officials by failing to not only follow the United Code of Conduct but also violating it. The $2.4 million civil penalty levied on United was in addition to United’s Non Prosecution Agreement resolution with the DOJ, which resulted in a penalty of $2.25 million. The scandal also cost the resignation of Smisek and two high-level executives from United. Three key takeaways:

Every formulation of a best practices compliance program starts with a written Code of Conduct.

The substance of your Code of Conduct should be tailored to the company’s culture, and to its industry and corporate identity

“Document, Document, Document” your training and communication efforts around your Code of Conduct.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The written standard requirements have long been memorialized in the U.S. Sentencing Guidelines, which contain seven basic compliance elements that can be tailored to fit the needs and financial realities of any given organization. From these seven compliance elements, the DOJ has crafted its minimum best practices compliance program, which is now attached to every DPA and NPA issued. These requirements were incorporated into the 2012 FCPA Guidance and brought forward in the 2019 Guidance and FCPA Corporate Enforcement Policy. The U.S. Sentencing Guidelines assumes that every effective compliance and ethics program begins with a written standard of conduct; i.e., a Code of Conduct.  Following your Code of Conduct is written policies and procedures required for a best practices compliance program are well- known and long established. The role of compliance policies is to provide guidance and to protect companies, despite an occasional hick-up. Policies provide a basic set of guidelines for employees to follow. They can include general do’s and don’ts, work process flows, specific issue guidelines. By establishing what is and is not acceptable compliance behavior, a company can mitigate the compliance risks posed by employees who might make foolish decisions or otherwise engage in unethical behavior. There are numerous reasons to put some serious work into your Code of Conduct, policies and procedures. They are certainly a first line of defense when the government comes knocking. This means the regulators will take a strong view against a company that does not have well thought out and articulated policies, procedures or Code of Conduct; all of which are systematically reviewed and updated. Written policies, signed by employees provide a vital layer of communication. Together with a signed acknowledgement, these documents can serve as evidentiary support if a future issue arises. In other words, the “Document, Document, Document” mantra applies just as strongly to this area of anti-corruption compliance. Three key takeaways:

A Code of Conduct, together with policies and procedures, have long been recognized as cornerstones of a best practices compliance policy.

Each level of written standards builds upon one another, so consider this integration step.

The Fair Process Doctrine applies to your written standards.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The cornerstone of any best practices compliance program is written protocols. This includes a Code of Conduct, policies and procedures. These elements have long been memorialized in the US Sentencing Guidelines; the Department Of Justice’s (DOJs) Opinion Releases regarding compliance programs, the 2012 FCPA Guidance, both DOJ and Securities and Exchange Commission (SEC) enforcement actions, the 2019 Guidance and FCPA Corporate Enforcement Policy.   There are three levels of standards and controls, Code of Conduct standards and policies and procedures. Every company should have a Code of Conduct that expresses its ethical principles. But a Code of Conduct is not enough. The Code of Conduct is implemented through your compliance policies. It is further operationalized through your compliance procedures. The DOJ spoke to their importance in the 2019 Guidance when it stated, “As a threshold matter, prosecutors should examine whether the company has a code of conduct that sets forth, among other things, the company’s commitment to full compliance with relevant Federal laws that is accessible and applicable to all company employees.” As a corollary, prosecutors should also assess whether the company has established policies and procedures that incorporate the culture of compliance into its day-to-day operations. At the end of the 31 Days you will have a very detailed grounding on better written standards for your compliance program. You will be able to utilize the information presented to implement a more effective compliance program for your organization.  Three key takeaways: 

The cornerstone of any best practices compliance program is its written protocols.

Written standards work to prevent, detect and remediate.

What are the specific written protocols you should have in your compliance program?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Over the course of this month, I have presented a variety of specific tools and techniques for the compliance practitioner to utilize to continuous improve their compliance regime. They include financial audit, the culture audit, controls monitoring, various risk management strategies which can become continuous monitoring. The tools are both quantitative and qualitative. Pick and choose the right tools for your company’s business and compliance profile. Continuous improvement through continuous monitoring or other techniques will help keep your compliance program abreast of any changes in your business model’s compliance risks and allow growth based upon new and updated best practices specified by regulators. A compliance program is in many ways a continuously evolving organism, just as your company is. You need to build in a way to keep pace with both market and regulatory changes to have a truly effective anti-corruption compliance program. The 2012 FCPA Guidance makes clear the “DOJ and SEC will give meaningful credit to thoughtful efforts to create a sustainable compliance program if a problem is later discovered. Similarly, undertaking proactive evaluations before a problem strikes can lower the applicable penalty range under the U.S. Sentencing Guidelines. Although the nature and the frequency of proactive evaluations may vary depending on the size and complexity of an organization, the idea behind such efforts is the same: continuous improve­ment and sustainability.” Three key takeaways:

Your compliance program should be continually evolving.

There are a variety of tools for continuous improvement which will enhance both your compliance and business processes.

DOJ and SEC will give meaningful credit to thoughtful efforts to create a sustainable compliance program if a problem is later discovered.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Compliance does not exist in a time-warp vacuum, with compliance programs living in 1977 when the first major anti-corruption legislation, the FCPA, was passed. The law has advanced since that time, as has compliance and society as well. One of the ways that you can engage in continuous improvement for your compliance program is based upon the two-way use of social media. Social media can be used not only to communicate with your employee base but also for your employee base to communicate with you, most particularly if you are prepared to listen. Twitter can be powerful tool for the compliance practitioner, as it allows you to both listen and communicate. It is one of the only tools that can work both inbound for you to obtain information and insight and in an outbound manner as well; where you are able to communicate with your compliance customer base, your employees. You should work to incorporate one or more of the techniques listed herein to help you burn compliance into the DNA fabric of your organization through continuous improvement. Three key takeaways: 

Social media is a two-way approach to communications.

Twitter or a similar tool can facilitate your compliance program improvement.

Study and embrace technology to move your compliance program forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The 2012 FCPA Guidance specified, “a good compliance program should constantly evolve. A company’s business changes over time, as do the environments in which it operates, the nature of its customers, the laws that govern its actions, and the standards of its industry. In addition, compliance programs do not just exist on paper but are followed in practice will inevitably uncover compliance weaknesses and require enhancements. Consequently, DOJ and SEC evaluate whether companies regularly review and improve their compliance programs and not allow them to become stale.” Continuous improvement through continuous monitoring will help keep your compliance program abreast of any changes in your business model’s compliance risks and allow growth based upon new and updated best practices specified by regulators. A compliance program is a continuously evolving organism, just as your company is continually improving its business processes. The 2012 FCPA Guidance makes clear the “DOJ and SEC will give meaningful credit to thoughtful efforts to create a sustainable compliance program if a problem is later discovered. Similarly, undertaking proactive evaluations before a problem strikes can lower the applicable penalty range under the U.S. Sentencing Guidelines. Although the nature and the frequency of proactive evaluations may vary depending on the size and complexity of an organization, the idea behind such efforts is the same: continuous improve­ment and sustainability.”  Three key takeaways: 

Ongoing monitoring is not limited to financial monitoring, a holistic approach would look at other indicia of corruption.

Where there is compliance smoke, there is most usually a compliance fire.

Continuous improvement can be achieved in a variety of efficient, cost-effective ways.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Continuous improvement can come in many different, shapes, sizes and packages. As with all things compliance, you are only limited by your imagination. Have you ever thought about a tech implementation as a way for continuous improvement? Probably not but it is also a way forward for continuous improvement. Think about that for a moment as this is taking the concept of continuous improvement and adding an ongoing tech solution. This is one of the areas both the Department of Justice (DOJ) and Securities and Exchange Commission (SEC) discussed in their jointly issued 2012 FCPA Guidance, as Hallmark 9 in the Ten Hallmarks of an Effective Compliance Program. This is not simply taking data from your compliance program and feeding it back in to create continuous improvement, but it is using a tech solution to not only make your compliance program run more efficiently but using that same tech solution to help continuously improve your compliance program. Such an approach uses the subject matter expertise (SME) of the tech solution provider to help the compliance professional come up with a more effective compliance program. For the compliance professional it is expanding out their reach and scope through the use of not only this tech SME but with the information from their own compliance program to create greater efficiencies and effectiveness.  Three key takeaways: 

Even in continuous improvement, you are only limited by your imagination.

The delivery of a tech solution for compliance can be beneficial in multiple ways.

Start your analytics at the transaction level and move upwards.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There are multiple areas in the DOJ’s 2019 Guidance which intersect with the area of continuous improvement. They include the following:  Prior Indications – Were there prior opportunities to detect the misconduct in question, such as audit reports identifying relevant control failures or allegations, complaints, or investigations? What is the company’s analysis of why such opportunities were missed?  Remediation – What specific changes has the company made to reduce the risk that the same or similar issues will not occur in the future? What specific remediation has addressed the issues identified in the root cause and missed opportunity analysis?  This ties to the 2012 FCPA Guidance, which made clear that compliance audits, with actionable remediation plans, are a key component of any effective compliance program. Another way to do achieve these multiple and intersecting goals is through proactive monitoring. Proactive monitoring is an excellent technique through which a company can engage in continuous improvement. Nonetheless, it has many other benefits including regulatory and evidence in a criminal investigation if needed under anti-corruption laws such as the FCPA. The bottom line is that all those scenarios might justify a company to engage a proactive monitorship to come in and do a complete ethics.  Three key takeaways: 

A proactive monitorship can be reactive proactivity to look at a specific issue...

…or used to test a compliance program…

…or used in a variety of legal and business manners.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Determining effectiveness is a key part of continuous improvement. Yet how to do so still bedevils many compliance professionals. You need to consider both outcomes and outputs. Outcomes will show you the results of specific actions, such as investigations and conclusions to them. Numbers are attractive because they can form a “straight line” about how your compliance program is functioning. But you must remember that the numbers only give you one view of a compliance program. You also need to consider the qualitative side of the equation. There is the need for both a quantitative and qualitative approach to measuring compliance program effectiveness. Numbers are important but they only tell part of the equation. Vin DiCianni has said, “Both are very important, but I think without having consideration of both sides of the equation, you will not obtain a full understanding of how effective compliance program is in its operation.” Three key takeaways:

You should test your compliance program effectiveness through both a qualitative and quantitative approach.

Bring in an outside party to interview your employees.

The Resource Guide is an excellent resource to consider compliance program effectiveness.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Vince Walden has posited that “the black box is dead”. He meant that there is no single tool to use to identify high-risk transactions, customer, employees or third parties. Yet, it is now even easier to ask big insightful questions from your data. Every compliance professional should embrace this. Properly seen, compliance is a business process. As such you should keep in mind certain queries, such as:

What are the company’s high compliance and ethics risks?

Who within the organization is responsible for managing these risks?

What controls are in place to manage these risks?

Are these controls working? Are they effective?

How do you know (or not) this?

The key is that through greater data mining and asking more insightful questions of that data you can truly move from a reactive-detect mode to a proactive-prescriptive mode. Three key takeaways:

The black box is dead.

What is driving your risk scoring?

Compliance as a business process must be driven by data.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Consider again the use of big data, this time to facilitate continuous improvement. Alistair Croll, in an eBook entitled “Planning for Big Data” published by O’Reilly Radar, informs this discussion of continuous improvement in a best practices compliance program. Croll believes that big data will allow continuous improvement through the “feedback economy.” This is a step beyond the information economy because you are using the information that you have generated and collected as a source of information to guide you going forward. Information itself is not the greatest advantage but using that information to prevent, detect and remediate in a compliance program going forward is. The three prongs of any best practices compliance program are prevent, detect and remedy. Whether you consider the OODA loop or the big data supply chain feedback, this process, coupled with the data that is available to you should facilitate a more agile and directed compliance program. The feedback components allow you to make adjustments literally on the fly. If that does not meet the definition of continuous improvement, I do not know what does. Three key takeaways: 

Use big data to continuously improve your compliance program.

The OODA loop is an excellent way to think about using data to continuously improvement.

Always remember the human element.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Keeping track of current events for continuous improvements a part of the mandates found in the 2019 Guidance. The DOJ clearly expects companies to update its risk assessment, policies, procedures and practices in light of changing circumstances. This means that if a third-party changes characteristics, so that it becomes subject to FCPA scrutiny, a company must be able to evaluate and react appropriately to such change. For the compliance practitioner, the Hitachi SEC enforcement action provides a valuable reminder that the FCPA covers more than foreign government officials and officials of state-owned enterprises. Political parties are also covered so that if part of your corporate social responsibility includes payments to political party front groups, your company could get into FCPA hot water. Yet it also means you will need to keep abreast of just who your counter-parties are during the entire course of your commercial relationship. This means that keeping up with current events is a must and can facilitate continuous improvement.  Three key takeaways: 

The Hitachi FCPA enforcement action demonstrates the need to keep track of current events for continuous improvement.

Many product and services providers in the compliance space provide ongoing monitoring for PEPs and SDNs.

Make sure your partners are still who they say they are!

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Another mechanism for continuous improvement of your compliance program is through risk-based monitoring. Under the topic of Control Testing DOJ’s 2019 Guidance posed the following questions, Has the company reviewed and audited its compliance program in the area relating to the misconduct? More generally, what testing of controls, collection and analysis of compliance data, and interviews of employees and third-parties does the company undertake? How are the results reported and action items tracked? Finally, the beauty of all these techniques articulated by Locwin is that they are tools that can make companies more efficient and, at the end of the day, more profitable. They also move compliance into the fabric and DNA of an organization or operationalize compliance. Her intonation to operationalize compliance speaks to the use of a wide variety of tools to input information, so you can continuously improve your compliance program. Risk-based monitoring is certainly one mechanism to obtain information and feed back into your compliance program in both the prevent and detect prongs.  Three key takeaways: 

How do you monitor manifested risks?

A risk-based monitoring approach allows you to see things in almost real-time.

Management of risk can serve your compliance program in a variety of ways.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A program manager in a power plant process group told me about the “mock audit” that his company performs in its power plants across the country. He explained that his industry is heavily regulated at both the state and federal level. Power plants are subject to numerous levels of oversight including various ISO standards to which they must comply. ISO is the International Organization for Standardization, and it develops and publishes International Standards for various industries and organizations. The DOJ has continually made clear that compliance audits, with actionable remediation plans, are a key component of any effective compliance program. The concept of the mock audit is one that can facilitate continuous improvement. It is a process designed to help your employees do business in a more compliant manner and it is a tool that should not be overlooked. Three key takeaways: 

Always remember compliance folks and the business folks wear the same color shirt.

Review your findings with the group being assessed.

Use the mock audit to both learn and educate.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Yet another way to consider using audit for continuous improvement is through the Integrity Audit. Mary Jo White in an article entitled “What I’ve Learned About White Collar Crime” provided insight into not only white-collar criminals but the integrity of companies. Her framework lays out a way for you to think through an underutilized tool for continuous improvement, the integrity audit. When Mary Jo White or Jonathan Marks write, you need to read, digest what they have to say and implement their suggestions. The ideas that they forward are not new, revolutionary or in the least bit controversial. Yet integrity is not often considered by compliance professionals. With the Business Roundtable’s Statement of Corporate Purpose integrity has been driven to the forefront in the rasion d’etre of a corporation. Failing to have integrity at the top or down through your organization can lead to significant corporate calamity. Three key takeaways: 

The Integrity Audit is an underutilized tool.

Ego and arrogance at the CEO level can lead to catastrophic corporate failures.

A robust report culture can demonstrate and facilitate corporate integrity.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Consider how a fraud audit using data analytics can help to detect or prevent bribery and corruption where the primary sales force used by a company are China based employees defrauding their company by using false expense reports to create a pot of money to use as a slush fund to pay bribes. Here you can think back to the Eli Lilly FCPA enforcement action up to the GSK problems as examples of where employees used their expense accounts not for personal use but for greater corporate malfeasance. This double dipping technique led to two anti-bribery compliance enforcement actions. One in the U.S. involving Eli Lily and a second in China involving the U.K. pharmaceutical entity GSK. The risk is real and by using ongoing data monitoring you might not only get ahead of the legal violation, but you would have a much more efficient business process going forward. Three key takeaways: 

The typical fraud audit will get down into the weeds with data analytics.

Split dollar expenses are key metric.

Double-dipping can lead to larger problems.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is organizational culture? Eric R. Feldman, SVP at Affiliated Monitors Inc. (AMI), has said it comprises the mission, vision and values of an organization. A similar way to consider it might be as a company’s values, visions, norms and beliefs. Whichever way you define it or look at it, corporate culture affects how groups within a company interact with each other. A key inquiry is whether the corporate incentive structure supports the articulated beliefs of a company. How does one measure or audit these articulations? Companies must have a high-performance corporate culture for doing business ethically. One of the ways to do so is through the culture audit. It can also be a powerful tool for continuous improvement going forward. Find out what your employees are saying about your corporate mission, vision and values and most importantly remediate if those mission, vision and values are found wanting.  Three key takeaways: 

What are the mission, vision and values of a company?

What are the compensation and promotion incentives in the culture?

Is your motto “Always be closing” or closer to “doing business ethically and in compliance”?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In my last corporate position, my company was at the compliance forefront because we required compliance related audits for vendors in the supply chain. This was cutting edge in 2007-08. However, now an audit for adherence to compliance requirements has become a standard best practice in the management of business relationships with third-party vendors in the supply chain. In several settlements of enforcement actions through both DPAs and NPAs, in the 2012 FCPA Guidance and, most recently, in the 2019 Guidance, the DOJ made it clear that a best practices compliance program includes the right to conduct audits of the books and records of its suppliers to ensure compliance. Many companies have yet to begin their audit process for FCPA compliance on vendors in their supply chain. This is a missed opportunity from both the compliance perspective and greater business efficiency. Any organization which audits a business partner in its supply chain should consult with legal, audit, financial and supply chain professionals to determine the full scope of the audit and a thorough and complete work plan should be created based upon all these professional inputs. After an audit, an audit report should be issued. This audit report should detail incidents of non-compliance with the compliance program and recommendations for improvements. Any reported incidents of non-compliance should reference the basis, such as contractual clauses, legal requirement or company policies.  Three key takeaways: 

Is your supply chain vendor committed to the audit process?

Capture the data, analyze the data, report on the data.

Supply chain audits are no longer cutting edge but are now simply best practices.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Continuous improvement can take many ways, shapes and forms. One thing that is most generally not considered is the financial health of the third-party. It turns out such an oversight may have some significantly ramifications for an accurate picture of a third-party. The financial health of third-parties is not only a key metric but also a key due diligence tool which allows a more robust assessment prior to contract signing and in managing the relationship after the contract has been signed.  Continuous improvement through monitoring of ongoing financial health is a tool where technological solutions can have an impact. Understanding the financial viability of third-parties can help the compliance practitioner meet the DOJ requirement to more fully operationalize a compliance program. It can also lead to more and better operational stability and with that ever-sought increase in corporate profitability. As compliance moves into the business process, this type of review should become part of your compliance toolkit going forward.  Three key takeaways: 

What is the financial health of your third-parties?

Poor financial results can open a company to engaging in risky behavior.

Financial health monitoring can be used as continuous improvement.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How can data analytics be used for continuous improvement where the primary sales force used by a company is third-parties? A clear majority of FCPA violations and related enforcement actions have come from the use of third-parties. While sham contracting (i.e., using a third-party to conduit the payment of a bribe) has lessened in recent years, there are related data analysis that can be performed to ascertain whether a third-party is likely performing legitimate services for your company. There are several more analytics that can be run in combination to identify suspicious third-parties and some of the simplest can be to look for duplicate or erroneous payments, all of which can lead to continuous improvement. Here we focus on the question posed by the 2019 Guidance, How does the company monitor its third parties? The final concept of finding patterns that can be discerned through the aggregation of huge amounts of transactions, is the next step for compliance functions. Yet data analysis does far more than simply allow you to follow the money. It can be a part of your third-party ongoing monitoring as well by allowing you to partner the information on third-parties who might come into your company where there was no proper compliance vetting. The opportunity for continuous improvement through a feedback loop is obvious and a clear step you should take going forward.   Three key takeaways: 

Always remember to follow the money to see where a pot of money could be created to fund a bribe.

Transaction monitoring techniques around fraud monitoring translate to data analysis for compliance.

Do not forget to check names against known PEP and SDN lists.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Third-parties still present the highest risk around compliance. Indeed, in the area of third-parties the 2019 Guidance, posed the following question in a section entitled, Management of Relationships – How has the company considered and analyzed the compensation and incentive structures for third parties against compliance risks? How does the company monitor its third parties? Does the company have audit rights to analyze the books and accounts of third parties, and has the company exercised those rights in the past?  It is therefore critical that you use monitoring and auditing when it comes to continuous improvement for this high-risk area. Next, we consider three aspects of a company’s audit program for its compliance function: the types and purpose of third-party audits, planning for third-party audits and interviewing third-parties. Three key takeaways: 

Start planning your third-party audit 4-6 weeks in advance of the actual audit.

Use your business sponsor to help facilitate the process with the third-party.

This is not a “gotcha” interview but an open Q&A process where you have a golden opportunity to educate as you ask questions.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Most CCOs and compliance practitioners understand the need for continuous monitoring. Whether it be as a part of your overall monitoring of third-parties, employees, or to test the overall effectiveness of internal controls and compliance, continuous monitoring is clearly a part of a best practices compliance program. Further, while most compliance practitioners are aware of the tools which can be applied for continuous monitoring, they may not be as aware of how to engage in the process. Put another way, how do you develop a methodology for building a continuous controls monitoring process that yields sustainable, repeatable results?  Joe Oringel, co-founder and principal at Visual Risk IQ uses a five-step process. The steps are: 1) brainstorm, 2) acquire and map data, 3) write queries, 4) analyze and report, and 5) refine and sustain. If you can establish your extraction and mapping rules, using common data models within your organization, you can use them to generate risk and performance checks going forward. Finally, through thoughtful use of continuous monitoring parameters, you can create metrics that you can internally benchmark your compliance regime against over time to show to any regulators who might come knocking.  Three key takeaways: 

Create a process to monitor your controls.

Use a compliance SME to work with your internal controls specialist to develop queries from the compliance perspective.

Finally, do not forget the feedback loop nature of the process by integrating your results going forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next, we consider how the internal audit (IA) function can be used to facilitate more effective continuous improvement. According to the Institute of Internal Auditors’ own definition, internal audit is “an independent, objective assurance and consulting activity designed to add value and improve an organization’s operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, control, and governance processes.” Some of the key compliance activities of IA are to maintain its independence; to conduct auditing activity of awareness and adherence to policies, procedures, internal controls and corporate governance, including those relating to legal, compliance and ethics risks; to ensure there is follow up of recommendations made in IA reports, including those relating to compliance and ethics risks, including to track and report on management follow up; assist and collaborate on internal investigations, including having IA provide audit expertise in dealing with internal controls and financial data; assist in both design and auditing of internal controls and follow up as required. Clearly this is a function which is and should be integrated into compliance. For its part, the compliance function can leverage IA resources and professionals on audit techniques and analysis of internal controls and such integration extends the corporate compliance influence through the company’s IA network. Finally, it allows the corporate compliance function to be made aware of relevant concerns uncovered during audits, so compliance is more fully able to participate in recommendations and follow up. Three key takeaways: 

Internal audit can be used to provide continuous improvement to and for compliance.

Internal audit can also fill a gatekeeper role in your compliance regime.

Compliance should leverage IA resources and professionals, on audit techniques and analysis of internal controls.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One clear best practices to gauge the compliance culture and evaluate the strength of controls, is to conduct periodic audits to ensure that controls are functioning well. Interestingly, compliance in many ways follows some of the paths laid out by corporate safety departments some 20-30 years ago when safety became much more high profile in U.S. corporations. The safety committee and safety audits became mainstays of any best practices in the area of safety for a company. These techniques inform any anti-corruption best practices compliance program. Indeed, audits were specifically delineated as far back as the 2012 FCPA Guidance to assist in the continuous monitoring of your compliance regime. Such an audit can be thought of as a systematic, independent and documented process for obtaining evidence and evaluating it objectively to determine the extent to which the compliance criteria are fulfilled. There are three factors which are critical for a compliance audit to have a chance for success: 1) an effective audit program which specifies all necessary activities for the audit; 2) having competent auditors in place; and 3) an organization that is committed to being audited. Auditing is a more limited review that targets a specific business component, region or market sector during a timeframe to uncover and/or evaluate certain risks, particularly as seen in financial records. However, you should not assume that because your company conducts audits that it is effectively monitoring. In other words, the protocol is simple, everyone understands you need to audit, but try and cut costs or corners and you will pay for it in the long run. Three key takeaways: 

Auditing takes a deep dive into your high-risk compliance areas.

Internal audit should test your key compliance risk areas as a part of their regular auditor rotation.

The findings uncovered in an audit must be used in your compliance regime going forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In this month's podcast series, I consider what techniques to use to create continuous improvement in your compliance program. As the DOJ stated in the 2019 Guidance “One hallmark of an effective compliance program is its capacity to improve and evolve.” Its implementation should help you to uncover and evaluate areas of risk and opportunities for improvement. Moreover as your business changes over time, in such areas as the environments in which it operates, the nature of its customers, the laws applicable to it and industry standards; your compliance program must change as well. All of this simply means business is dynamic and your compliance regime must be so as well. Continuous improvement through continuous monitoring or other techniques will help keep your compliance program abreast of any changes in your business model’s compliance risks and allow growth based upon new and updated best practices specified by regulators. A compliance program is in many ways a continuously evolving organism, just as your company is constantly evolving. Three key takeaways: 

Your compliance program should be continually evolving.

Have a mechanism to incorporate lessons learned from oversight into your compliance program.

The DOJ and SEC will give meaningful credit to thoughtful efforts to create a sustainable compliance program if a problem is later discovered.

For more information on Affiliated Monitors, visit their website, www.affiliatedmonitors.com.  Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

With the DOJ Evaluation’s emphasis on operationalizing your compliance regime, innovation is an important tool for you to use in this journey, yet one that is too often overlooked. We have considered a variety of innovations in compliance; from innovations in structure, use of social media tools and concepts, to new and different ways to consider your internal resources as ways to innovate in your compliance regime. The DOJ has consistently said that a compliance program must evolve. It must evolve to meet new or updated risks, new opportunities or different regulations. Innovation is one of the best ways to evolve. Finally, and perhaps most importantly as a compliance practitioner, always remember that you are only limited by your imagination.  Three key takeaways:

Innovation is one of the most overlooked and under-utilized tools in compliance.

Operationalizing your compliance program will require innovation in your compliance program going forward.

As with most CCO initiatives, you are only limited by your imagination.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Given the paucity of leadership coming out of Washington during this crisis, I thought it would be a ripe time to consider some innovations in compliance leadership. While many compliance departments may have begun more as a command and control function, set up by lawyers to comply with anti-bribery laws such as the Foreign Corrupt Practices Act (FCPA), this type of leadership model is now becoming outmoded in today’s world. It is not that employees are interested in the ‘why’ they should do business ethically and in compliance with such laws but it is more that power is shifting inside corporations. Given the paucity of leadership coming out of Washington during this crisis, I thought it would be a ripe time to consider some innovations in compliance leadership. While many compliance departments may have begun more as a command and control function, set up by lawyers to comply with anti-bribery laws such as the Foreign Corrupt Practices Act (FCPA), this type of leadership model is now becoming outmoded in today’s world. It is not that employees are interested in the ‘why’ they should do business ethically and in compliance with such laws but it is more that power is shifting inside corporations. As the compliance profession matures, it will become more a component of a company’s business function. This means less of a lawyer’s top down mentality of do it because I said to do it, to more collaboration. Three key takeaways:

The lawyer-driven command and control method for compliance is outmoded and outdated.

Innovation in compliance leadership is recognizing the bi-lateral nature of power and communications in an organization.

A feedback loop can be used in the leadership function as well.

For more information on our sponsor, Affiliated Monitors Inc. check out their website, by clicking here.  Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Candice Tal is the founder and Chief Executive Officer (CEO) of Infortal Worldwide, and one of the top experts around on due diligence. In an interview, I asked Tal about the use of AI in investigative due diligence and specifically how AI has led innovation in investigative due diligence. Tal believes that AI will be a “game changer” in compliance. Massive data sets require some type of AI to sort through and analyze the information. This is particularly important for internal controls and accounting books and records provisions to identify massive fraud. This is yet another area which is still developing. Tal stated, “I’ll frame that by saying at least in the next few years, there will still be a need for the traditional investigative approach that the boots on the ground, one where an investigator goes out and physically checks on facilities. Artificial intelligence is going to have limited ability to do that.” While drones may become part of an investigators tool kit, Tal believes that AI will be used “in a similar way to most data aggregators today. They find about 80% of the information. Yet there will always be the remaining 20% which they cannot find and you will need human intervention on the investigative side.” Looking down the road to the veiled land of the future, Tal sees continued innovation facilitating investigative due diligence. While AI is more than simply on the horizon, she said it “is a tried and tested methodology that has existed for many years, in terms of how you look for and locate shell companies.” It is also true about finding information about people who are trying to deliberately hide information. The bottom line is some of these investigative techniques involve old-fashioned shoe leather or simply hard diligent investigative work and “that’s not new”. Yet AI and other technological tools can make investigations more efficient and more cost effective, while giving better results. At the end of the day, AI can be used to sharpen and hone the due diligence process. Three key takeaways:

AI can help change the face of due diligence.

AI will facilitate data aggregation in due diligence investigations.

Always remember the human element.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Innovation can come in various forms for an organization. Innovation can appear in a structural form. You can move compliance more deeply into your organization with new or different structures. One I have seen have success is a Compliance Committee more closely tied to the geographic market in the field or the Regional Compliance Committee.  All of this works to adds a dimension not often seen or even discussed in the compliance profession. The accountability and oversight down to the regional level and the compliance monitoring, reviewing, assessing and recommending that is deemed to be necessary will provide additional endorsements up through the organization that it is actually doing compliance. In compliance, it is execution where the rubber meets the road. A Regional Compliance Committee can provide your compliance program a unique structure to perform these functions.  Three key takeaways:

Innovation can occur in structural changes to your compliance function.

A Regional Compliance Committee puts compliance closer to the ground in geographic regions outside the U.S.

A Regional Compliance Committee facilitates execution of your compliance program.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

This is still a tricky area for most legally trained compliance professionals as law schools are far behind the business world in teaching these skills. Yet, not only data analysis but also the presentation of data in a visual format will be a key skill for every Chief Compliance Officer (CCO) and compliance practitioner going forward. However, if you do not possess those skills yourself, you can create a kitchen cabinet of experts, from the talent available across your company, which you can call upon to help you going forward. For the CCO, this will require extensive out of the box thinking to help you not only understand the data and analytics but think through how to present it in the most efficient manner to your leadership. Three key takeaways:

Look for talented and curious employees to be a part of your data science team.

Encourage cross-mentoring to facilitate skills learning and transference.

Moving the final mile is the most challenging.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The compliance profession seems to be an inflection point, moving away from the lawyer-driven written policies and procedures to a more operationalized regime where compliance is a part of the overall ecosystem embedded directly in business process focused discipline. Seen in this manner, compliance will be seen not as a cost center but as a value creation center, helping the company to make business processes more efficient and then more profitable. To be the orchestrator and prime mover of a compliance ecosystem, you need a superior compliance service that is hard to replicate. This means some combination of compliance, a large network of internal users and strong branding.  Compliance is undergoing a paradigm shift as a result of technological and digital innovation. CCOs who cannot interpret the data from their own systems will likely find themselves consigned to the dustbin of corporate luddites. Compliance is moving into a new era of collaboration and connection to more fully operationalize compliance to make all business stakeholders more efficient and at the end of the day more profitable. Three Key Takeaways:

Compliance is undergoing a paradigm shift as a result of technological and digital innovation.

to be the orchestrator and prime mover of a compliance ecosystem, you need a superior service that is hard to replicate.

Compliance should help other corporate functions.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Name any catastrophic corporate compliance failure and every root cause analysis will show there were silos which compliance could not break through. In the Boeing 737 Max design failure there was the siloed nature of the entire design, creation, training, regulatory and implementation team for the safety feature, the failed Maneuvering Characteristics Augmentation System (MCAS). At Wells Fargo, it was the siloed nature of the commercial banking group from other corporate disciplines such as legal, internal audit, human resources and even the Board of Directors. The over-riding theme was the number of compliance miss-steps that led to these disasters. While the siloed nature of these organizations processes led to a literal number of very small steps which contributed to the final disaster, it demonstrated to me even more clearly why compliance must not only have a seat the table but also be embedded throughout your organization. Three Key Takeaways:

Every major corporate scandal involves silos.

Compliance should rotate senior leadership through its function.

A CCO must be curious.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One thing is certain going into 2020 and beyond is that technology that will improve the efficiency of compliance and will assist in the operationalization of compliance into fabric of every business which embraces it. I would posit that the compliance professional who incorporates the techniques they advocate into their organization’s compliance program will not only move their compliance program forward but also make their company run more efficiently and, at the end of the day, more profitably. AI is a step which weds the human interaction and experiences with the data which is available to every company - its own internal information which is most generally sitting in siloed verticals and not being used. This data can provide the foundation for business research and risk-forecasting models and AI. When you couple this data with the insights into what humans do well or poorly; you can pair the best of these two seemingly disparate incongruities. Moreover, when a compliance function embraces the use of AI and embraces this human and technological approach for forecasting and risk assessments and then keeps improving their risk management techniques, it will create a sustainable strategic business, compliance and intelligence advantage over its competition. Three Key Takeaways:

Use the big data in your own organization.

Break down silos to get the data.

Using the data in your own organization will drive greater business efficiency and greater profitability.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Design thinking is another innovation which can help the CCO move forward in a cutting-edge manner to make a compliance program not only more robust but also operationalize it into the fabric of the company. Such a mechanism would help to drive compliance into the operational nature of a company. This design thinking protocol can help to create a more effective ethics and compliance training model by using employees to provide the initial input to improve its effectiveness and relevance to the front-line employees. The compliance team then implements several proposed solutions until the most operative one or ones becomes apparent. These are then rolled out companywide for better and more effective compliance training. As the entire process is documented, when the regulators, such as the DOJ or SEC, come knocking, you will have the ability to not only explain your training but also demonstrate its effectiveness. Three key takeaways:

Design thinking concepts are not simply for product innovation but for culture innovation.

Design thinking works around the users’ needs rather internal operating efficiencies. For a compliance program, this means employees, third-parties and customers.

Design thinking works to improve your compliance regime by building from the ground up rather than a legalistic top-down approach.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the most significant innovations in compliance will come through the incorporation of blockchain into compliance. I see great value propositions for the compliance function. There are two specific areas where I see blockchain directly impacting the compliance profession. The first is with third-parties. The second area where blockchain provides a potential game changer is contracts, specifically around compliance terms and conditions.  This final point is operationalizing compliance. It will be interesting to see when the DOJ or SEC will begin to comment on blockchain as a part of a best practices compliance program. Three key takeaways:

Blockchain has great potential for the compliance profession.

Blockchain can facilitate the third-party due diligence and update requirements.

Blockchain can provide a clear trigger for compliance terms and conditions.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Imagine that as a CCO, you could create a team which might well dramatically improve your company’s compliance and risk forecasting ability, but to do so you would be required to expose just how unreliable the professional corporate forecasters have been. Could you do so and, more importantly, would you do so? Most generally this is the predictive capability that organizations have used. However, the new “superforecasting” movement, led by Philip E. Tetlock and others, has been gaining strength to help improve this capability. The concepts around superforecasting came of age after the intelligence failures leading up to the Iraq War. This led to the founding of the Good Judgment Project, which had as a key component a multi-year predictive tournament, which was a series of gaming exercises pitting amateurs against professional intelligence analysts. The results of the Good Judgment Project. Today, I explain its applicability to compliance. Three key takeaways:

Imagine you could create a team which might well dramatically improve your company’s compliance and risk forecasting ability.

It is essential to track the prediction outcomes and provide timely feedback to improve forecasting going forward.

Like any innovation, there must be a commitment from management on moving forward.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

How can you use the tools of Artificial Intelligence (AI) and data analytics in a best practices compliance program. Vincent M. Walden, a partner at Alvarez and Marsal (A&M), wrote an article entitled “Profit & Loss-of-One” (P&L-of-One) where he detailed how he and his then colleagues at Ernest & Young (EY) worked in conjunction with the General Electric (GE) compliance function to “improve compliance by using forensic data analytics to provide behavioral insights to their compliance program.” They did this through the innovative use of “digital twins” which Walden described as “digital replicas of physical assets that organizations can use for multiple purposes such as the maintenance of power generation equipment, jet engines and heavy machinery. The innovation demonstrated through the P&L-of-One shows how the digital transformation of compliance through true operationalization will not only burn compliance into the fabric of an organization but illustrates how more robust compliance can make a company run more efficiently and, at the end of the day, more profitably. Walden concludes by stating, “The compliance vision of the future seeks to further move compliance towards a more proactive, advocacy role, which helps organizations by providing needed communications, trainings and responses in an automated, intriguing and relevant fashion. This is the compliance vision of the future and what the authors call the P&L-of-One.” Three Key Takeaways:

The inspiration of this innovation in compliance came from manufacturing.

Test through a pilot program.

Making your messaging automated, intriguing and relevant.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the lessons we have learned from various Foreign Corrupt Practices Act (FCPA) enforcement actions over the years is how complexity in business organizations can work to defeat compliance programs. Whether a corrupt employee is working to actively hide a pot of money, which can or will be used to pay a bribe, or an improper payment slips through the cracks; complexity can work to defeat a best practices compliance program. If a compliance function does not have visibility into a business unit, how it does business and where its payments are going; it may be due to design or inadvertent complexity. Compliance is now in an era of brisk innovation and evolution. It is prone to technological change and rapid obsolescence of the lawyer-driven, spreadsheet and word document based compliance programs. Going forward the compliance professional needs to understand that a “package of resilience, adaptability, coordination, and inimitability becomes more attractive than the package of efficiency, understandability, manageability, and predictability.” The key is to learn how to harness complexity on a sustainable basis. Three Key Takeaways:

If a business is too complex for the compliance function to understand; it is in greater danger of illegal or unethical activity.

Taming complexity starts with simple operating principles.

Always remember to fix, repair and prune.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In the compliance world, consistency is one of the keys to a successful compliance program. One of those areas where consistency is mandated is in contracting. Having consistency in the compliance terms and conditions of any contract is a critical aspect of the compliance professional. While there will certainly be negotiation over a wide variety of terms and conditions, from the financial and payment terms, to the operational terms, to the legal terms, companies need consistency with their compliance terms and conditions. This is particularly true given the paucity of compliance terms which should be put in place. For the compliance professional this means that less may well slip through the cracks and you will not be in an after the fact position of finding out that your agent or distributor in a high-risk venue does not have an audit clause. Three Key Takeaways:

AI contracting software can make you contracting process more efficient.

AI contracting software is scalable.

AI contracting software can allow you to move from a detect to preventative mode.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

We previously considered how AI can be used as a business advantage for compliance. The power of AI can extend the more traditional functions of prevention, detection and remediation. The first way is in simply the mass amount of data which could inundate a compliance practitioner. Many compliance practitioners are overwhelmed about the amount of data available to them and do not know how or even where to begin. Patrick Taylor has said that AI allows the compliance practitioner to understand the “subtle clues in that pattern of activity that will clue me in to take a different look.” He likened it to seeing “patterns in raked leaves” which allows you to then step in and take a deeper and broader look at an issue, either through an audit or investigation. This is where compliance practitioner can step back and literally keep an eye on the big picture and longer term as opposed to just the immediate numbers and information in front of them. It may also be the best hope for finding that kind of systemic fraudulent behavior. Three key takeaways:

Do you know what your information means?

AI can help both the detect and prevent prongs in a best practices compliance program.

AI can help you to see the patterns in raked leaves.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next, we consider the four practices that create the conditions for delivering an AI solution to compliance. Using these four practices can lead to enhanced operational excellence, more efficient business processes, and a more robust compliance experience. They are: (1) developing clear, realistic use cases, (2) managing AI learning, (3) continuous Improvement and (4) thinking cognitively. By applying these practices, business leaders can full operationalize AI applications for compliance into their organizational DNA and set themselves up to reap those rewards. It is a continuous cycle. The capabilities enable employees to execute the practices, and the practices themselves exercise and strengthen the capabilities. This cycle helps companies continually adapt at developing and using AI applications that make operations more efficient and create business value through greater profitability. Three key takeaways:

AI is not a panacea.

It is not simply about reading numbers, it is thinking critically.

Continuous improvement is a key by product of using AI in compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Next we consider the crucial capabilities which a compliance function must have to implement an AI solution. Over the next several pieces, I will use the article Using AI to Enhance Business Operations by Monideepa Tarafdar, Cynthia M. Beath as an introduction into the how the corporate compliance function can use an Artificial Intelligence (AI) program to not only enhance the compliance function but also business operations. Generating value from AI programs is not easy for compliance professionals as there can be multiple roadblocks to successful design and implementation. The problem is, many companies which desired to benefit from AI programs failed to do so have failed to develop the necessary organizational capabilities. The authors identified five capabilities that companies need to splice into their organization’s DNA to create an effective AI program, have adapted for the compliance function. Three key takeaways:

What is the power of an AI application?

What are the foundations of AI application competence?

What are some of the roadblocks to AI competence?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Today, I want to consider the article Strategy For and With AI by David Kiron and Michael Schrage. The authors premise is, “A company’s strategy is defined by its key performance indicators. Artificial intelligence can help determine which outcomes to measure, how to measure them, and how to prioritize them.”  Their article had several insights for the Chief Compliance Officer (CCO) or compliance practitioner who is looking to employ Artificial intelligence (AI) to help move their compliance program up a level. One of the first key insights is that it is not enough to simply have a strategy for AI. The authors stated, “Creating strategy with AI matters as much — or even more — in terms of exploring and exploiting strategic opportunity. This distinction is not semantic gamesmanship; it’s at the core of how algorithmic innovation truly works in organizations. Real-world success requires making these strategies both complementary and interdependent. Strategies for novel capabilities demand different managerial skills and emphases than strategies with them.” This makes clear that AI does not supplant the compliance function or the compliance professional, AI complements what the compliance professional can do with the information available to them. Yet the authors believe that when it comes to machine learning, an appropriate compliance strategy is defined by the key performance indicators (KPIs) leaders choose to optimize. This means that a CCO who cannot clearly identify and justify their strategic KPI portfolios has no strategy. The bottom line? AI plays a critical role in determining what and how compliance KPIs are measured and how best to optimize them. Optimizing carefully selected compliance KPIs becomes AI’s strategic purpose in the compliance function. Understanding the value of optimization is key to aligning and integrating strategies forand with AI and machine learning. KPIs create accountability for optimizing strategic aspirations, including compliance. Three key takeaways:

Use KPIs to define and measure your innovation strategy.

AI should only supplement, not supplant a compliance professional.

What are your compliance KPIs?

For more information on how an independent monitor can help improve your company’s ethics and compliance program, visit this month’s sponsor Affiliated Monitors at www.affiliatedmonitors.com. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The Department Of Justice and Securities and Exchange Commission have both made it clear that they expect companies to be more robust in their use of data analytics in compliance programs. This means using data to not only detect and prevent illegal conduct but also in the remediation prong of any best practices compliance program as well through continuous improvement. Former Deputy Assistant Attorney General Matthew Miner said in a speech that the DOJ will inquire whether compliance departments have access to internal data that could help them identify misconduct and whether compliance officers make adequate use of data analytics in their reviews of companies under investigation. Since at least 2016 in the Foreign Corrupt Practices Act (FCPA) enforcement action involving Key Energy Services, Inc., the SEC has been communicating to compliance professionals of the need for increased use of data and data analytics in any compliance program.  The new DOJ Antitrust Division released its Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations (Antitrust Guidance), was the clearest regarding this mandate when it stated, “Does the company use any type of screen, communications monitoring tool, or statistical testing designed to identify potential antitrust violations?” For the anti-corruption compliance professional, this means you need to incorporate a statistical analysis into your ongoing monitoring to see if there are any anomalies which could be indications of FCPA violations. The bottom line is that it is not if but when you begin to incorporate corporate information into your compliance program to make your compliance program more efficient and your business process run more effectively. My suggestion is that you begin now to identify the data you have access to and the data to which you currently do not have access. Find a way to bridge that gap. Three key takeaways:

What advantages can data bring to your compliance regime?

Both the DOJ and SEC have said companies need to be using data in their compliance programs.

Data will make your compliance program more effective, your business process more efficient and your company more profitable.

For more information on how an independent monitor can help improve your company’s ethics and compliance program, visit this month’s sponsor Affiliated Monitors at www.affiliatedmonitors.com. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Innovation in compliance is one of my passions for every Chief Compliance Officer (CCO) and compliance practitioner. So much so that I dedicate an entire podcast series to the topic, aptly named Innovation in Compliance. I was therefore intrigued with a recent Harvard Business Review (HBR) article, entitled What Kind of Chief Innovation Officer Does Your Company Need?, by Darko Lovric and Greig Schneider. They developed six-character types for innovators, which I have adapted for the different skills set a CCO might need to create innovation in compliance.

Research skills - research skills allow folks to come up with new ideas and garner insights from large amounts of data.

Engineering Skills - Engineering skills are used to build something that works, as in now.

Investor skills- investors see innovation as the means to an end, and that end is growth.

Advocacy skills - Advocacy skills help to deliver something new for the end user.

Motivational skills- motivational skills in innovation but the authors found they work to unleash the employees’ imaginations.

Organizational skills- Organizational skills are the true process focused skill set, focusing on extents like key performance indicators (KPIs), metrics, and stage gates.

While you may not find one person with all of those skills, by identifying them a CCO might be able to bring a range of skills to an innovation project. Further, by tempering some of the more extreme aspects of each skill set by partnering it with a countervailing skill set, a CCO can bring a much more robust response to innovating. Also remember that innovation in compliance does not necessarily require a high cost of entry. You can innovate by looking to process improvement and moving outwards. Three key takeaways:

Do you have an innovation expert in your compliance team?

What skills do compliance professionals have that lend themselves to innovation.

Think about broadening out your compliance reach through innovation.

For more information on how an independent monitor can help improve your company’s ethics and compliance program, visit this month’s sponsor Affiliated Monitors at www.affiliatedmonitors.com. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What will be the role of AI in compliance going forward? LawTech disrupted the legal profession and reshaped many areas of private practice. I believe there will is a nascent ComTech industry lurking down the road with multiple implications for the compliance function. Obviously, document review is one area where ComTech would be most useful. There are many companies which provide key word searches and these same concepts translate readily into the compliance world through massive database searches for key words, such as an ongoing review through email sweeps. There is yet another set of AI tools that can review contracts to see if any specific types of clauses are non-standard. Soon compliance will be pushed more to the forefront in AML. AI will allow a more robust KYC approach. Another area where compliance is often left behind is in the arena of M&A. AI can help in this area. There are companies which have software that allows thousands of documents to be reviewed in the M&A context. A prime example of where AI can assist the compliance function is with third-parties in supply chain management. There have always been technological innovations which help make compliance disciplines run more efficiently, more smoothly and more profitably. AI is simply another step in this line of technological developments. There is certainly no reason to be afraid of using it. Given the disruption which has impacted the legal profession through LawTech; disruption is not far behind in the compliance world through ComTech.  Three key takeaways:

AI has already disrupted the legal profession; the compliance profession will be next. ComTech will be the result.

Document review will be the first area of significant AI use in compliance.

Beware the limitations and disadvantages of ComTech.

For more information on how an independent monitor can help improve your company’s ethics and compliance program, visit this month’s sponsor Affiliated Monitors at www.affiliatedmonitors.com. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In this chapter, we will consider innovation in compliance from a variety of angles including artificial intelligence (AI) and computer technology (ComTech), structural innovations, tools and tactics and innovation in leadership. This will provide you a number of solid ideas you can use to move your compliance program forward. Begin by considering the starting point, which is an innovation strategy. In the most recent DPAs and NPAs issued by the DOJ they all include an element along the following strictures: The Company will conduct periodic reviews and testing of its anti-corruption compliance code, policies, and procedures designed to evaluate and improve their effectiveness in preventing and detecting violations of anti-corruption laws and the Company’s anti-corruption code, policies, and procedures, taking into account relevant developments in the field and evolving international and industry standards.  This means that the DOJ expects innovation in your compliance program to keep up with evolving international and industry standards. This requires you to implement an innovation strategy. Three key takeaways:

Both the DOJ and SEC expect innovation in your compliance program.

Innovation in compliance should have a strategy going forward.

The key is to demonstrate how the compliance innovation will benefit the business going forward.

For more information on how an independent monitor can help improve your company’s ethics and compliance program, visit this month’s sponsor Affiliated Monitors at www.affiliatedmonitors.com. Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As we end this month on the intersection of HR and compliance, I have developed a series of goals and objectives which you might want to use as a starting point for operationalizing your compliance initiatives through your corporate HR function. 

How are compliance goals cascaded down to individual workers?

Does anyone complain that your compliance targets are too complex?

How do you deal with repeated compliance failures in a specific business segment or compliance program area?

How does your company show that attracting and developing talent who will engage in ethical business conduct is a top priority?

How long is compliance underperforming tolerated?

What makes it distinctive to work at your company?

How do compliance programs that are not working typically get exposed and remediated?

What key compliance indicators do you use for compliance tracking?

For a given compliance problem, how do you identify the root cause?

What are you doing to retain your top employees from the compliance perspective?

Compliance practitioners continually face the challenge of keeping up with the ever-evolving compliance best practices with little or no budget increase. By asking yourself and of your compliance program these questions you may create a road map to more fully operationalize your compliance regime. Three key takeaways:

What are the unique compliance targets you have set and how interconnected are they to your business unit goals?

Use a root cause analysis to determine why compliance initiatives are not successful.

Retraining employees in compliance is an under-utilized tool.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Hopefully you now understand that many of the traditional functions of HR can be seen as compliance internal controls. At every touchpoint in the lifecycle of the employment relationship there is a HR touchpoint. Fulfilling those touchpoints can be controls for compliance. If you think of multiple HR functions as compliance internal controls, one of the questions becomes how can you determine if HR is meeting the standards of a best practices compliance program? One place to start is with a gap analysis to determine what HR has in place that can facilitate your company’s compliance program. Finally, work with HR to create a consolidated Human Resources Compliance Audit Checklist that can be used to audit (and document) the company’s HR Compliance Program. The key to compliance, in my opinion, is having the proper structure to identify the issues, implement policies and procedures to address the issues, audit for compliance and “Document, Document, and Document”.  Three key takeaways:

A gap analysis is a key component in the risk assessment process.

The ultimate responsibility should lie with the business units and functional discipline to fully operationalize compliance.

The role of the compliance department is to oversee, provide subject matter expertise and coordinate.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the most important focuses of the DOJ’s 2019 Guidance was around culture. This means how far has the culture of compliance been driven down into an organization. The 2019 Guidance posed the following: Culture of Compliance – How often and how does the company measure its culture of compliance? Does the company seek input from all levels of employees to determine whether they perceive senior and middle management’s commitment to compliance? What steps has the company taken in response to its measurement of the compliance culture? These questions point to a CCO or compliance practitioner demonstrating how a culture of compliance is being burned into the very fabric of an organization. While leadership at and from the top has long been considered by both the DOJ and compliance professionals as a key element to move compliance forward, the 2019 Evaluation has also crystalized thinking around compliance culture throughout the organization, including at the bottom Too often, strategies to move a compliance program or even an initiative come from the top of an organization and are pushed down. To fully operationalize compliance, you must have leadership in compliance further down the organization which (hopefully) has been a part of the design process and can lead the implementation throughout an organization. Three key takeaways:

While tone at the top is critical, the tone at the bottom can work to more fully operationalize compliance.

95% of the work is done at this bottom level.

Use HR to come up with a strategy to move compliance into the bottom for more complete operationalization.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The DOJ has made clear that middle management is a critical part of any compliance program’s success. While it does all start at the top, with the Board of Directors and senior executives setting the tone for the rest of the company; prosecutors are mandated, under the 2019 Guidance to “how middle management, in turn, have reinforced those standards and encouraged employees to abide by them.” Moreover, the 2019 Guidance posed several question directly to middle management including the following: What actions have middle-management stakeholders taken to demonstrate their commitment to compliance or compliance personnel, including their remediation efforts? Have they persisted in that commitment in the face of competing interests or business objectives?  It is clear that the DOJ expects compliance to be operationalized down into the middle management level. Further experience has widely shown that employees prefer to speak to their direct supervisors about issues or potential compliance violations they become aware of. The question is how can a corporate compliance function reach middle management. This is a key area of assistance that can be provided by Human Resources as one of the ways that HR can help to operationalize compliance is to assist each level of an organization to have a proper tone, specifically, the middle of an organization You must think about your lines of communication and your communication skills when conveying your message of compliance down from the top into the middle of your organization. Three key takeaways:

While tone at the top is critical, the tone in the middle can actually work to more fully operationalize compliance.

How do you train middle managers?

What compliance tool kit do you provide to middle managers?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The role of HR in corporate compliance programs, is often underestimated. If your company has a culture where compliance is perceived to be in competition or worse yet antithetical to HR, the company certainly is not hitting on all cylinders and maybe moving towards dysfunction. Another way you can operationalize compliance is in HR’s involvement in employee promotion. Such compliance embedded into the promotion process can also be considered an internal compliance control. By doing so, your compliance may well work to create an effective internal controls regime as mandated by the FCPA and other anti-corruption laws.  Three key takeaways:

Denying a promotion or award due to an employee’s ethical lapses.

Use promotions to reinforce your company’s commitment to compliance and ethics.

Should you wait for great?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The exit interview can be a further mechanism to operationalize compliance. This type of interview is used when someone voluntarily departs from a company, as opposed to a lay-off or reduction in force exercise. Typically departing employees are more willing to share about their experiences, concerns and issues which led to their employment departure. Three key takeaways:

The exit interview is an excellent opportunity to obtain information to inform your compliance program.

Use the exit interview to create advocates from departing employees.

Use the exit interview for probing and insightful questions around compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Employment separation and layoffs can present some unique challenges for the compliance practitioner. Employees can use layoffs to claim that they were retaliated against for a wide variety of complaints, including those for concerns that impact the compliance practitioner. Yet there are several ways that operationalization will help to protect your company as much as possible. The reasons for these actions are to allow you to demonstrate that any laid off employee was not separated because of a hotline or whistleblower allegation but due to your overall layoff scheme. However, it could be that you may need this person to provide your compliance department additional information, to be a resource to you going forward, or even a witness that you can reasonably anticipate the government may want to interview. If any of these situations exist, if you do not plan for their eventuality before you lay off the employee, said (now) ex-employee may not be inclined to cooperate with you going forward. Also, if you do demonstrate that you are sincerely interested in a meritorious hotline complaint, it may keep this person from becoming a SEC whistleblower. Three key takeaways:

Treat departing employees with dignity.

Make sure your separation documents meet SEC requirements regarding disclosures re: whistleblowing.

You must check your hotline and anonymous reporting systems to make sure you do not lay off a whistleblower.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What should a company do when it desires to hire a CCO? To do so, a company needs to fully understand and appreciate what it needs from such a position going forward. Unfortunately, many companies do not have this insight at the beginning of the recruitment process. The key company stakeholders need to understand the full hiring process. Obviously, this will include HR and others involved in the hiring process for a CCO for the company. It could include the CEO, COO, CFO, CISO, Head of IA and others. They may need to rethink their approach to focus on what they will ask the new hire to accomplish because typically there is a disconnect between what the company thinks it needs and what it really needs. Three key takeaways:

Bring in your key stakeholders to flesh out the job description.

Consider the top four things you would like a new CCO to accomplish in the first year.

For a new CCO to succeed, the company must have a realistic expectation developed before the process begins.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the ways to operationalize compliance and to drive it into the DNA of an organization is through a performance review. Indeed, the 2019 DOJ Guidance stated: Incentive System…Have there been specific examples of actions taken (e.g., promotions or awards denied) as a result of compliance and ethics considerations? Who determines the compensation, including bonuses, as well as discipline and promotion of compliance personnel? Most HR experts will opine that properly executed performance appraisals are crucial to organizational productivity as well as the development of employee skills and employee morale. Moreover, they can serve a couple of different functions for a best practices compliance program. First, and foremost, they communicate to each employee their job performance from a compliance perspective. However, one key is not to approach the performance appraisal review as an isolated event but rather a continual process. This means that instead of trying to play catch-up at the last minute, supervisors should provide feedback and assess job performance throughout the year so annual reviews are grounded in a year’s worth of experience. This includes the compliance component of each job. The second area performance appraisals impact is compensation. The DOJ expect that your compliance program will have both discipline and incentives. But those incentives need to be based upon something. The score or other performance appraisal metrics will provide to you a standard which you can measure and use to evaluate for other purposes such as employee promotion or advancement to senior management going forward. Three key takeaways:

To incentivize compliance, you must be able to accurately appraise senior managers and employees around compliance.

Clearly communicate your compliance expectations, then fairly evaluate employees on them.

Consider conducting an ongoing review.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Another area where Human Resources can help to more fully operationalize compliance is in succession planning. Succession planning is just as important as governance, enterprise risk management and strategic oversight. In other words, it is just as important. Sadly, many companies fail to give it the attention it requires. A PricewaterhouseCoopers (PwC) survey, found nearly one-half of the more than 1,000 directors gauged reported dissatisfaction with their companies’ succession plans. Imagine what that number would be if they took into account the compliance aspect of succession planning. Some of the questions you might consider are the following. How did you fully operationalize compliance into the business unit that you managed? What controls did you put in place? And then what did you do when you found out about it? Every time I perform a risk assessment and speak to the company’s HR lead, they immediately understand the role than can play in moving forward a company’s compliance program. Even if the HR role is limited in the hiring process, they can ask potential candidates their views to determine underlying business ethics. HR can also begin the compliance inculcation process, even pre-hiring, by talking about the company’s values in the interview process. This sets an expectation that can be built upon if a candidate is selected and in every HR touch point going forward, including looking at employees in the succession planning process. Three key takeaways:

Succession planning is just as important as governance, enterprise risk and strategic oversight.

Do not begin your succession planning when a senior manager announces their retirement.

You are always being evaluated (or you should be).

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Companies have finally come to realize that institutional justice and fairness are perhaps the most basic tenet of any successful workplace. If employees believe they will be treated fairly, it will engender a level of trust that can work to not simply motivate employees but lead to a more successful workplace and, at the end of the day, a more profitable company. This encompasses the entire lifecycle of the employment relationship, from hiring through separation. It works in areas as seeming disparate as compensation and incentives, discipline, promotion and internal reporting. The issue of Institutional Justice is most clearly seen in the area of discipline. This can be in the overall application of a compliance program to all employees, Board members and senior managers. One of the areas which Human Resources can operationalize your compliance program is to ensure that discipline is handed out appropriately and consistently across an organization and to reward those employees who integrate such ethical and compliant behavior into their individual work practices. In addition to providing a financial incentive for ethical behavior, it also provides a sense of institutional justice. Institutional justice comes from procedural fairness and is one area that will bring credibility to your compliance program Three key takeaways:

The DOJ and SEC have long called for appropriate and consistent application of both incentives and discipline.

The Fair Process Doctrine will help set institutional justice as the norm in your organization.

Inconsistent application of discipline will destroy your compliance program credibility.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In the DOJ’s 2019 Guidance, Incentives and Disciplinary Measures it stated:  Incentive System – Has the company considered the implications of its incentives and rewards on compliance? How does the company incentivize compliance and ethical behavior? Have there been specific examples of actions taken (e.g., promotions or awards denied) as a result of compliance and ethics considerations? Who determines the compensation, including bonuses, as well as discipline and promotion of compliance personnel? When considering how a company could use incentives to further a compliance program and the role of HR in this process, we should also consider how incentives might lead to the converse, as they did in the now-infamous Wells Fargo fraudulent-accounts scandal. When you misalign these two concepts with a faulty sales strategy it can lead to a catastrophic failure, literally costing the company millions of dollars in fines, loss of business and depreciation of shareholder value. Whatever your incentive structure, there will be employees who try to game the system. Some will do it with the tacit or explicit approval of management. You, as the CCO, may be required to act. Three key takeaways:

Even a benign sales incentive program came become skewed.

A sales incentive program can become high risk or illegal if not properly monitored.

If there is alignment between the strategy, purpose and structure of an incentive system, it often makes the difference between a good and a bad one.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A 2015 New York Times article by Gretchen Morgenson, entitled “Ways to Put the Boss’s Skin In the Game”, dealt with a long-standing question about how to make senior executives more responsible for corporate malfeasance? Her article had direct application to compliance programs and compensation for senior management tied to compliance. Morgenson said the issue was “Whenever a big corporation settles an enforcement matter with prosecutors, penalties levied in the case - and they can be enormous - are usually paid by the company’s shareholders. Yet the people who actually did the deeds or oversaw the operations rarely so much as open their wallets.” She went on to explain the economic phenomenon of “perverse incentives” wherein executives are encouraged to take excessive risk because they can profit so much from them, all the while knowing they probably won’t have to pay any fines or face other costly consequences of their actions. To help remedy this situation, the idea has come to the fore about senior managers putting some “skin in the game. Three key takeaways:

Perverse incentives are named that for a reason; they really are bad.

How can you create positive incentives in your organization?

There is a business response to the legal issue. Employ it.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas that many companies have not paid as much attention to in their anti-corruption compliance programs is designing their compensation system to more fully operationalize compliance. However, the DOJ and SEC have long made clear that they view monetary structure for compensation, rewarding those employees who do business in compliance with their employer’s compliance program, as one of the ways to reinforce the compliance program and the message of compliance.  There are three key questions you should ask yourself in modifying your compensation structure. First, is the change simple? Keep the compensation plan simple and even employee KISS, (Keep It Simple Sir), when designing your program. Second, is the changed aligned with your company values? As the CCO or compliance practitioner, you need to posit the most important compliance goal your entity needs to achieve. From there you should determine how your compensation program can be aligned with that goal. Third, is the effect on behavior immediate due to the change? Finally, under immediacy, it is important that such structures be put in place “immediately” but in a way that incentives employees. Three key takeaways:

The DOJ and SEC have long advocated compensation to motivate employees into ethical and compliant behaviors.

Keep the compliance aspects of your compensation structure simple and easy for your employees to understand.

Have full transparency in the frame of your compensation structure.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Most compliance professionals understand the need to discipline employees who may have violated ethics and compliance programs or otherwise engaged in bribery and corruption. However, many Chief Compliance Officers (CCOs) and compliance practitioners do not focus as much attention to compliance incentives. I have developed six core principles for incentives, adapted from Spring 2014 MIT Sloan Management Review article, entitled “Combining Purpose with Profits”, and formulated them for the compliance function in an anti-corruption compliance program. 1.     Compliance incentives don’t have to be elaborate or novel.  2.     Compliance incentives need supporting systems if they are to stick. 3.     Support systems are needed to reinforce compliance incentives. 4.     Compliance incentives need a “counterweight” to endure. 5.     Compliance incentive alignment works in an oblique, not linear, way. 6.     Compliance incentive initiatives can be implemented at all levels. Obviously, this list is not exhaustive. Yet it is now more important than ever that you demonstrate tangible incentives for your employees to gain benefits, both financial and hierarchical, through doing business ethically, in compliance with your own Code of Conduct and most certainly in compliance with relevant anti-bribery laws. It is also a requirement that such actions be documented so they can be demonstrated to the regulators, if they come knocking.  Three key takeaways:

Compliance incentives do not have to be elaborate or novel.

You must create support systems for your compliance incentives. 

Compliance incentives should be implemented at all levels. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the key points that representatives of the DOJ and Securities and Exchange Commission (SEC) have continually raised when discussing any best practices compliance program. The 2012 FCPA Guidance is clear that there should be incentives for not only following your own company’s internal Code of Conduct but also doing business the right way, i.e., not engaging in bribery and corruption. On incentives, the 2012 FCPA Guidance said, “DOJ and SEC recognize that positive incentives can also drive compliant behavior. These incentives can take many forms such as personnel evaluations and promotions, rewards for improving and developing a company’s compliance program, and rewards for ethics and compliance leadership. Some organizations, for example, have made adherence to compliance a significant metric for management’s bonuses so that compliance becomes an integral part of management’s everyday concern.” But it also recognizes that incentives need not only be limited to financial rewards as sometimes simply acknowledging employees for doing the right thing can be a powerful tool as well Incentives can be integrated into the DNA of a company through the hiring and promotion processes. There should be a compliance component to all senior management hires and promotions up to those august ranks within a company. Your HR function can be a great aid to your cause in driving the right type of behavior through the design and implementation of such structures. Employees know who gets promoted and why. If someone who is only known for hitting their numbers continually is promoted, however they accomplished this feat will certainly be observed by his or her co-workers.  Three key takeaways:

The DOJ 2019 Guidance specifically calls out incentives for doing business ethically and in compliance.

HR can lead the efforts around incentives.

Incentives go beyond financial rewards.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As far back as 2004, in Opinion Release 04-02, the DOJ realized this was an important part of an overall compliance program when it approved a proposed compliance program that had the following requirement, "Clearly articulated procedures which ensure that discretionary authority is not delegated to persons who the company knows have a propensity to engage in illegal or improper activities." One tool that is often overlooked in the hiring process is the reference check. Many practitioners feel that a reference is not of value because prospective candidates will only list references that they believe will provide glowing recommendations of character. This leads to a pro forma reference check. The hiring of someone who will perform business activities in compliance with anti-corruption laws such as the FCPA will continue to be as much art as science because the hiring of quality employees for senior management positions is similarly situated. But that does not mean a company cannot work to not hire those persons who might have a propensity to engage in bribery and corruption if the situation presented itself. The hiring process is just one more tool that can be utilized to build an effective and operationalized compliance program. 

Three key takeaways:

The hiring process is the first step in operationalizing your compliance program.

The DOJ spoke to hiring as part of a best practices compliance program as far back as 2004.

Reference checks are an underutilized part of the hiring process and a key internal HR control. 

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the conventional wisdoms about compliance training is that you will never be able to reach 5% of your workforce with compliance training because they are predisposed to lie, cheat and steal anyway. Whether they are simply sociopaths, scumbags or just bad people; it really does not matter. No amount of training is going to convince them to follow the rules, as they do not think such laws apply to them. They will lie, cheat and steal no matter what industry they are in and what training you provide to them. But knowing such people exist and they may be able to lie, con or otherwise dissimilate their way into your organization does not protect your company from FCPA liability when they inevitably violate the law by engaging in bribery and corruption. It is still the responsibility of your company to prevent and detect such conduct and then remediate if it occurs. This is where your HR function has a dual role, with both their traditional hiring role and in a compliance function. They can work to help weed out such miscreants and to communicate your corporate values of doing business ethically, in compliance and aligned with your corporate values of integrity. Through a structured series of questions, however, a properly trained HR professional can begin to assess whether an employee might have a propensity to engage in bribery and corruption. By adding information about your company’s values towards doing business ethically and in compliance, you can introduce this topic at either the interview evaluating process or in the promotion process. While true sociopaths will most certainly lie to you, perhaps even convincingly, by introducing the topic at such a pre-employment stage, they may be encouraged to take their skills elsewhere Three key takeaways:

Use the interview process to determine who will be an ethical and compliance fit for your organization.

Consider the skill, will and fit approach.

Ask open-ended questions.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The Evaluation of Corporate Compliance Programs, 2019 Guidance, makes clear that operationalization of compliance into an organization should be done at multiple levels. The 2019 Guidance also called out culture as a key indicia for an ethical culture. Creating an ethical culture is an important step for any company to burn compliance into the DNA of a business. It must be done at every level of an organization on a continuous basis. Human Resources (HR) can play a key role in both the creation and maintenance of an ethical culture. Ethics and compliance blend together in the corporate world. It is not just the responsibility of CCOs and compliance practitioners but of HR to support those employees who want to do the right thing. While written protocols are significant in both detection and prevention, one should never lose sight of a corporate culture as a way to positively impact your workforce and company going forward. Three key takeaways:

Beware of the three obstacles to creating an ethical culture.

What really matters in your company?

A speak up culture will improve the operational performance of your business.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Ed. Note-my series in January, 31 Days to a More Effective Compliance Program, was so popular, I decided to extend it through 2020. Each month, I will focus on one topic in a best practices compliance program. I begin in February with the role of Human Resources in compliance. The series has its own iTunes channel, 31 Days to a More Effective Compliance Program. I hope you will find these podcasts useful. Tom Fox

I have long advocated for a greater role of Human Resources (HR) in compliance. Indeed, one sign of a mature compliance and ethics program is the extent to which a company’s HR Department is involved in implementing a compliance solution. While many practitioners do not immediately consider HR as a key component of a best practices compliance solution, it can be one of the lynch pins in spreading a company’s commitment to compliance throughout the employee base. HR can also be used to ‘connect the dots’ in many divergent elements of a compliance and ethics program. Even more important is the operationalization of compliance into the fabric of the business. One of the key indicia of compliance program effectiveness is how thoroughly each separate corporate discipline incorporates compliance into its everyday job functions. An active and functioning compliance program will literally be alive in each department in an organization. HR has as many touchpoints as any other corporation function with employees. From interviews to onboarding, through evaluations and performance appraisals, even to the separation process; HR leads many of the corporate touchpoints. Each one of these touchpoints can be used to teach, educate and reinforce the message of doing business ethically and in compliance with anti-corruption laws Three key takeaways:

What are the HR-employee touchpoints at your company?

HR professionals can bring new, dynamic and innovative techniques to compliance

Go down and have a cup of coffee with the head of your corporate HR department. Find out what they do and how they do it.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Due diligence is generally recognized in three levels: Level I, Level II and Level III. Each level is appropriate for a different level of corruption risk. The key is to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward. The question becomes how you use the information you obtained in the business justification and the questionnaire to determine an appropriate level of due diligence for the next step in the five-step process of third-party management. A three-step approach of varying levels of due diligence is the appropriate analysis to take going forward. A three-step approach was discussed in Opinion Release 10-02, in which the DOJ discussed the due diligence that the requesting entity performed. This Opinion Release sets out a clear break which every compliance practitioner should use in considering an appropriate level of due diligence to engage with your third-party risk management process or when considering the level of due diligence required on a potential business venture partner. A very good description of the three levels of due diligence was presented by Candice Tal, Founder and CEO of Infortal Worldwide, in an article entitled “Deep Level Due Diligence: What You Need to Know” Three key takeaways:

A Level I due diligence should only be used where there is a low risk of corruption.

A Level II due diligence is sufficient in a high-risk jurisdiction if there are no red flags to be cleared.

Level III due diligence is deep dive, boots on the ground investigation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

We previously considered the Prong in the Evaluation that was not present in the Ten Hallmarks of an Effective Compliance Program; that being root cause analysis. The requirement was first raised in the 2017 Evaluation. It was then carried forward as a requirement in the FCPA Corporate Enforcement Policy, later in 2017. It was discussed again in the 2019 Guidance. You should begin with the question of who should perform the remediation; should it be an investigator or an investigative team which were a part of the root cause analysis? Jonathan Marks, believes the key is both “independence and objectivity.” It may be that an investigator or investigative team is a subject matter expert and “therefore more qualified to get that particular recourse”. Yet to perform the remediation, the key is to integrate the information developed from the root cause analysis into the solution. Marks further noted that the company may also have deficiencies in internal controls. More importantly, the failure to remediate gaps in internal controls “provides the opportunity for additional errors or misconduct to occur, and thus could damage the company’s credibility with regulators” by allowing the same or similar conduct to reoccur. Finally, with both the 2019 Guidance and FCPA Corporate Enforcement Policy, the DOJ has added its voice to prior SEC statements that regulators “will focus on what steps the company took upon learning of the misconduct, whether the company immediately stopped the misconduct, and what new and more effective internal controls or procedures the company has adopted or plans to adopt to prevent a recurrence. Three key takeaways:

The key is objectivity and independence.

The critical element is how did you use the information you developed in the root cause analysis?

The key is that after you have identified the causes of problems, consider the solutions that can be implemented by developing a logical approach, using data that already exists in the organization.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Well known fraud investigator Jonathan Marks, defined a root cause analysis as “a research based approach to identifying the bottom line reason of a problem or an issue; with the root cause, not the proximate cause the root cause representing the source of the problem.” He contrasted this definition with that of a risk assessment which he said “is something performed on a proactive basis based on various facts. A root cause analysis analyzes a problem that (hopefully) was previously identified through a risk assessment.” He went on to note a, “Root cause analysis is a tool to help identify not only what and how an event occurred, but also why it happened. When we are able to determine why an event or failure occurred, we can then recommend workable corrective measures that deter future events of the type observed.” Marks also contrasted a root cause analysis with an investigation. He noted, “in an investigation we are try to either prove or disprove an allegation.” This means that in a compliance investigation you may be trying to prove or disprove that certain transactions could form the basis of a corrupt payment or bribe by garnering evidence to either support or refute specific allegations. You do not assess blame and that is the point where a root cause should follow to determine how the compliance failure occurred or was allowed to occur Three key takeaways:

A root cause analysis is now required if you have a reportable compliance failure.

There is no one process for performing a root cause analysis. You should select the one which works for you and follow it.

To properly perform a root cause analysis, you need trained professionals who really understand what they’re doing.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Your company has just made its largest acquisition ever and your CEO says they want you to have a compliance post-acquisition integration plan on their desk in one week. Where do you begin? A good place to start would be the 2012 FCPA Guidance language: Pre-acquisition due diligence, however, is normally only a portion of the compliance process for mergers and acquisitions. DOJ and SEC evaluate whether the acquiring company promptly incorporated the acquired company into all of its internal controls, including its compliance program. Companies should consider training new employees, reevaluating third parties under company standards, and, where appropriate, conducting audits on new business units. As reported by New and Trahanas, in a July 2018 speech, former Deputy Assistant Attorney General Matthew Miner emphasized that DOJ would apply the principles contained in the FCPA Corporate Enforcement Policy to successor companies that discover potential violations subsequent to an acquisition, as well as to acquirers who detect potential corrupt activities during the due diligence process. He also encouraged acquiring companies to seek guidance through the FCPA Opinion Procedures. Miner said the DOJ would apply the principles contained in the FCPA Corporate Enforcement Policy to acquiring companies that uncover potential FCPA violations in the mergers and acquisitions context. This means if you meet the four requirements under the FCPA Corporate Enforcement Policy, the default DOJ position would be a declination would be granted Three key takeaways:

Planning is critical in the post-acquisition phase.

Build upon what you learned in pre-acquisition due diligence.

You literally need to be ready to hit the ground running when a transaction closes.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A company that does not perform adequate due diligence prior to a merger or acquisition may face both legal and business risks. Perhaps most commonly, inadequate due diligence can allow a course of bribery to continue - with all the attendant harms to a business’s profitability and reputation, as well as potential civil and criminal liability. While most compliance practitioners have been long aware of the requirement in the post-acquisition context, the 2012 FCPA Guidance focused many compliance practitioners of the need to engage in robust pre-acquisition due diligence. This was expanded again in the 2017 Evaluation but the 2019 Guidance made even more clear the need for a robust compliance presence in the pre-acquisition phase. It stated, “A well-designed compliance program should include comprehensive due diligence of any acquisition targets. Pre-M&A due diligence enables the acquiring company to evaluate more accurately each target’s value and negotiate for the costs of any corruption or misconduct to be borne by the target. Flawed or incomplete due diligence can allow misconduct to continue at the target company, causing resulting harm to a business’s profitability and reputation and risking civil and criminal liability. Three key takeaways:

The results of your pre-acquisition due diligence will inform your post-acquisition integration and remediation going forward.

Periodically review your M&A due diligence protocol.

If red flags appear in pre-acquisition due diligence, they should be cleared.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas articulated in the 2019 Guidance was around payments and payroll. For the both the compliance professional and the corporate payroll function, there is a significant role to play in the operationalization of a corporate compliance program. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) was replete with references to payment and its critical nature to any best practices compliance program. This includes references to payments to foreign officials, payments to third parties and hiding bribes in payments to distributors. The 2019 Guidance begins with an admonition to stop wasting time on low hanging fruit when there are much higher risks in your business operations. It stated: Risk-Tailored Resource Allocation – Does the company devote a disproportionate amount of time to policing low-risk areas instead of high-risk areas, such as questionable payments to third-party consultants, suspicious trading activity, or excessive discounts to resellers and distributors? Does the company give greater scrutiny, as warranted, to high-risk transactions (for instance, a large-dollar contract with a government agency in a high-risk country) than more modest and routine hospitality and entertainment?  The 2019 Guidance then drills down into the payment and payroll system, stating: Appropriate Controls – How does the company ensure there is an appropriate business rationale for the use of third parties? If third parties were involved in the underlying misconduct, what was the business rationale for using those third parties? What mechanisms exist to ensure that the contract terms specifically describe the services to be performed, that the payment terms are appropriate, that the described contractual work is performed, and that compensation is commensurate with the services rendered?   Taken together, these questions may not seem particularly new, innovative, or even something different from what payroll currently does for an organization. However, the 2019 Guidance , clearly demonstrates the role of payroll in compliance. The 2019 Guidance requires that payroll not only form a part of any best practices compliance program, but when it comes to the specific subject matter expertise, payroll is on the front lines of any attempts to prevent, detect, and then remediate anti-corruption compliance violations. Three key takeaways:

Payroll can be a key prevent and detect control.

The Evaluationspecified the tying of the corporate compliance function to the corporate payroll function.

Offshore payments remain a key indicator for a red flag.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The role of the compliance professional and the compliance function in a corporation has steadily grown in stature and prestige over the years. When it came to the corporate compliance function, 2012 FCPA Guidance, under Hallmark Three of the Ten Hallmarks of an Effective Compliance Program, simply noted the government would “consider whether the company devoted adequate staffing and resources to the compliance program given the size, structure, and risk profile of the business.” This Hallmark was significantly expanded in both the 2019 Guidance and the FCPA Corporate Enforcement Policy. And in so doing, the DOJ has increased the prestige, authority and role of both the corporate compliance function. The 2019 Guidance has four general areas of inquiry around the corporate compliance function. (1) What is the seniority and stature of the compliance function within an organization? (2) What are the experience and stature of the compliance personnel with an organization? (3) What is the funding and resources made available to the compliance function? (4) How much autonomy does the compliance function have to report to the Board of Directors? Three key takeaways:

How is compliance treated in the budget process?

Has your compliance function had any decisions over-ridden by senior management?

Beware outsourcing of compliance as any such contractor must have access to company documents and personnel.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The role of the CCO has steadily grown in stature and prestige over the years. In the 2012 FCPA Guidance, under Hallmark Three of the Ten Hallmarks of an Effective Compliance Program, it focused on the whether the CCO held senior management status and had a direct reporting line to the Board; stating: In appraising a compliance program, DOJ and SEC also consider whether a company has assigned responsibility for the oversight and implementation of a company’s compliance program to one or more specific senior executives within an organization. Those individuals must have appropriate authority within the organization, adequate autonomy from management, and sufficient resources to ensure that the company’s compliance program is implemented effectively. Adequate autonomy generally includes direct access to an organization’s governing authority, such as the board of directors and committees of the board of directors. This Hallmark was significantly expanded in both the 2019 Guidance and the FCPA Corporate Enforcement Policy. And in so doing, the DOJ has increased the prestige, authority and role of both the CCO and corporate compliance function. The 2019 Guidance has four general areas of inquiry around the CCO and corporate compliance function. (1) How does the CCO salary and stature within the organization compare to other senior executives within the company. (2) What are the experience and stature of the CCO with an organization? Does the CCO have appropriate training for the role? (3) How much autonomy does the CCO have to report to the Board of Directors? How often do the CCO meet with directors? Are members of the senior management present for these meetings with the Board of Directors or of the Audit Committee? (4) Is the compliance function run by a designated chief compliance officer, or another executive within the company, and does that person have other roles within the company? Three key takeaways:

How can you show the CCO really has a seat at the senior executive table?

What are the professional qualifications of your CCO?

Does your CCO have true independence to report directly to the Board of Directors?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the critical elements found in the 2019 Guidance is the need to use the information you obtain, whether through risk assessment, root cause analysis, investigation, hotline report or any other manner to remediate the situation which allowed it to arise. It stated: Evolving Updates – How often has the company updated its risk assessments and reviewed its compliance policies, procedures, and practices? Has the company undertaken a gap analysis to determine if particular areas of risk are not sufficiently addressed in its policies, controls, or training? What steps has the company taken to determine whether policies/procedures/practices make sense for particular business segments/subsidiaries? Your company should establish a regular monitoring system to spot issues and address them. Effective monitoring means applying a consistent set of protocols, checks, and controls tailored to your company’s risks to detect and remediate compliance problems on an ongoing basis. To address this, your compliance team should be checking in routinely with local finance departments in your foreign offices to ask if they have noticed recent accounting irregularities. Regional directors should be required to keep tabs on potential improper activity in the countries in which they manage. These ongoing efforts demonstrate that your company is serious about compliance.  Three key takeaways:

Innovation can come through a new way to think about and use data going forward.

Have a plan in place to use the information garnered in your monitoring incorporated back into your compliance program.

Always remember that Document Document Document is critical if the regulators come knocking.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Control Testing – Has the company reviewed and audited its compliance program in the area relating to the misconduct? More generally, what testing of controls, collection and analysis of compliance data, and interviews of employees and third-parties does the company undertake? How are the results reported and action items tracked?    Fortunately, the Committee of Sponsoring Organizations of the Treadway Commission (COSO) 2013 Internal Controls Framework considers assessing compliance internal controls. In “Internal Controls – Integrated Framework, Illustrative Tools for Assessing Effectiveness of a System of Internal Controls”, COSO laid out its views on assessing the effectiveness of internal controls. It noted that an effective system of internal controls provides “reasonable assurance of achievement of the entity’s objectives, relating to operations, reporting and compliance.” Moreover, there are two over-arching requirements that can only be met through such a structured protocol. First, each of the five components are present and functioning. Second, that the five components operate in an integrated fashion with each other. One of the most critical components of the COSO Framework is that it sets internal control standards against those which you can audit to assess the strength of your compliance internal controls. Three key takeaways:

An effective system of internal controls provides reasonable assurance of achievement of the company’s objectives, relating to operations, reporting and compliance.

There are two over-arching requirements for effective internal controls. First, each of the five components are present and function. Second, are the five components operating together in an integrated approach.

For an anti-corruption compliance program, you can use the Ten Hallmarks of an Effective Compliance Program as your guide to test against.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) was very clear about the need for continuous improvement in any compliance program. It stated quite succinctly, “One hallmark of an effective compliance program is its capacity to improve and evolve. The actual implementation of controls in practice will necessarily reveal areas of risk and potential adjustment. A company’s business changes over time, as do the environments in which it operates, the nature of its customers, the laws that govern its actions, and the applicable industry standards. Accordingly, prosecutors should consider whether the company has engaged in meaningful efforts to review its compliance program and ensure that it is not stale.” This was further specified in the DOJ’s 2019 Guidance which listed three types of continuous improvement, each further refined with multiple attendant questions. It also added a new area of inquiry that every compliance practitioner needs to incorporate into their assessment, improvement and management cycles; culture.  Three key takeaways:

Your compliance program should be continually evolving.

Monitoring and auditing are different, yet complimentary tools for continuous improvement.

Culture assessment and monitoring are also now required as well.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There is nothing like an internal whistleblower report about a compliance violation, the finding of such an issue, or (even worse) a subpoena from the DOJ or notice letter from the SEC to trigger the Board of Directors and senior management attention to the compliance function and the company’s compliance program. Such an event can trigger much gnashing of teeth and expressions of outrage followed immediately by proclamations “We are an ethical company.” However, it may well be the time for a very serious reality check. Three key takeaways:

A serious FCPA allegation gets the attention of the Board and senior management. Use this time to move the compliance program forward.

Be aware of how your investigation can impact and even inform your remediation efforts.

Be prepared to deal with the dreaded “where else” question.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

After the internal report comes in and you have properly triaged the matter, you need to scope out and investigate it, promptly, thoroughly and with competent personnel. Your company should have a detailed written procedure for handling any complaint or allegation of bribery or corruption, regardless of the means through which it is communicated. The mechanism could include the internal company hotline, anonymous tips, or a report directly from the business unit involved. You can make the decision on whether or not to investigate with consultation with other groups such as the Audit Committee of the Board of Directors or the Legal Department. The head of the business unit in which the claim arose may also be notified that an allegation has been made and that the Compliance Department will be handling the matter on a go-forward basis. Through the use of such a detailed written procedure, you can work to ensure there is complete transparency on the rights and obligations of all parties, once an allegation is made. This allows the compliance team to have not only the flexibility but also the responsibility to deal with such matters, from which it can best assess and then decide on how to manage the matter.  Three key takeaways:

A written protocol, created before an investigation, is a key starting point.

Create specific steps to follow so there will be full transparency and documentation going forward.

Consistency in approach is critical.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The call, email or tip comes into your office; an employee reports suspicious activity somewhere across the globe. That activity might well turn into a FCPA issue for your company. As the CCO, it will be up to you to begin the process which will determine, in many instances, how the company will respond going forward. This scenario was driven home by the SEC in a 2015 FCPA enforcement action involving Mead Johnson Nutrition Company. In this enforcement action, the company performed two internal investigations into allegations that its Chinese business unit was engaged in conduct which violated the FCPA. Unfortunately, the first investigation, performed in 2011, did not turn up any evidence of FCPA violations. It was not until 2013, when the SEC made an inquiry to the company that it performed an adequate internal investigation which uncovered FCPA violations. Three key takeaways:

The DOJ and SEC put special emphasis on internal reporting lines.

Test your hotline on a regular basis to make sure it is working.

Have a triage protocol in place before the call comes in so you will be ready to go and not required to scramble to create a protocol.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance programs, the issue of third-party management becomes more important. It is also the one where the rubber meets the road of operationalizing compliance. It is also an area the DOJ specifically articulated in the 2019 Evaluation that companies need to consider. The key is to have a strategic approach to how you structure and manage your third-party relationships. This may mean more closely partnering with your third parties to help manage the anti-corruption compliance risk. It would certainly lead towards enabling your company to control risk while optimizing the performance of your third parties. Three key takeaways:

Have a strategic approach to third-party risk management.

Rank third parties based upon a variety of factors including compliance and business performance, length of relationship, benchmarking metrics and KPIs for ongoing monitoring and auditing.

Managing the relationship is where the real work begins.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

As every compliance practitioner is well aware, third parties still present the highest risk under the FCPA. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) devotes an entire prong to third-party management. It begins with the following: A well-designed compliance program should apply risk-based due diligence to its third-party relationships. Although the degree of appropriate due diligence may vary based on the size and nature of the company or transaction, prosecutors should assess the extent to which the company has an understanding of the qualifications and associations of third-party partners, including the agents, consultants, and distributors that are commonly used to conceal misconduct, such as the payment of bribes to foreign officials in international business transactions.   This clearly specifies that the DOJ expects an integrated approach that is operationalized throughout the company. This means you must have a process for the full life cycle of third-party risk management. There are five steps in the life cycle of third-party risk management, which will fulfill the DOJ requirements as laid out in the 2012 FCPA Guidance and in the Ten Hallmarks of an Effective Compliance Program. They five steps in the lifecycle of third-party management are:

Business Justification;

Questionnaire to Third-party;

Due Diligence on Third-party;

Compliance Terms and Conditions, including payment terms; and

Management and Oversight of Third Parties After Contract Signing.

Three key takeaways:

Use the full 5-step process for third party management.

Make sure you have business development involvement and buy-in.

Operationalize all steps going forward by including business unit representatives.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

After you complete your risk assessment, you must then translate it into a risk profile. If your estimate of where your bribery risk is greatest is wrong, it will be an effort to address it. As Ben Locwin explained in his  BioProcess International article, entitled “Quality Risk Assessment and Management Strategies for Biopharmaceutical Companies”: Once we have assessed risks and determined a process that includes options to resolve and manage those risks whenever appropriate, then we can decide the level of resources with which to prioritize them. There always will be latent risks: those that we understand are there but that we cannot chase forever. But we need to make sure we have classified them correctly. With a good understanding of each of these, we are in a better position to speak about the quality of our businesses. A way to evaluate risks as determined by the company’s risk assessment is through a risk matrix. Once risks are identified, they are then rated according to their significance and likelihood of occurring, and then plotted on a heat map to determine their priority. The most significant risks with the greatest likelihood of occurring are deemed the priority risks, which become the focus of your remedial efforts or for continuous auditing. A variety of solutions and tools can be used to manage these risks going forward, but the key step is to evaluate and rate these risks. All your actions should flow from the risk ranking. Three key takeaways:

Even after you complete your risk assessment, you must evaluate those risks for your company.

The DOJ and SEC are looking for a well-reasoned approach on how you evaluate your risk.

Create a risk matrix and rank your risks; then remediate and monitor as appropriate.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based upon a risk assessment, to understand your organization’s business from the commercial perspective, how your organization has identified, assessed, and defined its risk profile and, finally, the degree to which the program devotes appropriate scrutiny and resources to this range of risks. As far back as 1999, in the Metcalf & Eddy enforcement action, the DOJ has said that risk assessments that measure the likelihood and severity of possible FCPA violations should direct your resources to manage these risks. The 2012 FCPA Guidance stated it succinctly when it said, “Assessment of risk is fundamental to developing a strong compliance program and is another factor DOJ and SEC evaluate when assessing a company’s compliance program.” This language was supplemented in the 2017 FCPA Corporate Enforcement Policy, which stated, “The effectiveness of the company’s risk assessment and the manner in which the company’s compliance program has been tailored based on that risk assessment.” A risk assessment determines the areas at greatest risk for FCPA violations among all types of international business transactions and operations, the business culture of each country in which these activities occur, and the integrity and reputation of third parties engaged on behalf of the company. The reason is straightforward; one cannot define, plan for, or design an effective compliance program to prevent bribery and corruption unless you can measure the risks you face.  Three key takeaways:

Since at least 1999, the DOJ has pointed to the risk assessment as the start of an effective compliance program.

The DOJ will now consider both your risk assessment methodology for identifying risks and gathered evidence.

You should base your compliance program on your risk assessment.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Companies have finally come to realize that institutional justice and fairness are perhaps the most basic tenet of any successful workplace. If employees believe they will be treated fairly, it will engender a level of trust that can work to not simply motivate employees but lead to a more successful workplace and, at the end of the day, a more profitable company. This encompasses the entire lifecycle of the employment relationship, from hiring through separation. It works in areas as seeming disparate as compensation and incentives, discipline, promotion and internal reporting. Three key takeaways:

The DOJ and SEC have long called for appropriate and consistent application of both incentives and discipline.

The Fair Process Doctrinewill help set institutional justice as the norm in your organization.

Inconsistent application of discipline will destroy your compliance program credibility.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the areas that many companies have not paid as much attention to in their compliance programs is compensation. However, the DOJ and SEC have long made clear that they view monetary structure for compensation, rewarding those employees who do business in compliance with their employer’s compliance program, as one of the ways to reinforce the compliance program and the message of compliance. As far back as 2004, then SEC Director of Enforcement Stephen M. Cutler noted that integrity, ethics and compliance needed to be part of promotion, compensation and evaluation processes: “At the end of the day, the most effective way to communicate that “doing the right thing” is a priority, is to reward it.” The 2012 FCPA Guidance stated the “DOJ and SEC recognize that positive incentives can also drive compliant behavior. These incentives can take many forms such as personnel evaluations and promotions, rewards for improving and developing a company’s compliance program, and rewards for ethics and compliance leadership.” This same concept around compensation and incentives was brought forward in the 2019 Guidance - Incentives and Disciplinary Measures, which read: Incentive System – Has the company considered the implications of its incentives and rewards on compliance? How does the company incentivize compliance and ethical behavior? Have there been specific examples of actions taken (e.g., promotions or awards denied) as a result of compliance and ethics considerations? Who determines the compensation, including bonuses, as well as discipline and promotion of compliance personnel? The first question posed in the 2019 Guidance requires you to start with the basic question of what does your employee compensation consist of? Is it a straight salary? Is it variable? If so, what does the variable component consist of? Is it a discretionary bonus based upon the overall success of the entire business enterprise or some small subset such as a business unit or geographic region? Is it solely personal? Or is it some combination of all of the above? Three key takeaways:

The DOJ and SEC have long advocated compensation as a way to motivate employees into ethical and compliant behaviors

Keep the compliance aspects of your compensation structure simple and easy for your employees to understand

Have full transparency in the framework of your compensation structure

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

One of the key goals of any compliance program is to train employees in awareness and understanding of the FCPA; your specific company compliance program; and to create and foster a culture of compliance. While it seems axiomatic that compliance training is a mainstay of any best practices compliance program, the conversation around training has evolved over the years. The 2012 FCPA Guidance started the conversation. Beginning in the fall of 2016, through the announcement of the FCPA Enforcement Pilot Program, the DOJ began to talk about whether you have determined the effectiveness of your training. This conversation continued with the 2017 Evaluation where it asked, “How has the company measured the effectiveness of the training?” This point has bedeviled many compliance professionals yet is now a key metric for the government in evaluating compliance training. It evolved further in the 2019 Guidance with the mandate that training must be “truly effective”. Finally, the training must be presented in a language in which the employees understand, which means in a local language, if the training is outside the US or other non-English-speaking countries. Also raised in the 2017 Evaluation was the focus of your training programs, where the DOJ inquired into whether your training was “tailored” for the audience. This added two requirements. The first was to assess your employees for risk to determine the type of training you might need to deliver by risk ranking your employees. Obviously, the sales force would be the highest risk but there may be others who are deserving of high-risk training as well. From this risk ranking, you were required to develop tailored training for the risks those employees will face. The 2019 Guidance spells this out in greater detail. Not only in the design but who receives it, all coupled with backend determination of effectiveness. Finally, all of this must be documented. Three key takeaways:

How and why have you tailored your compliance training?

The DOJ has mandated demonstrating the effectiveness of compliance training

How is your training presented: both in languages and media?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the message of compliance inside of a corporation and how it is distributed? In a compliance program, the largest portion of your consumers/customers are your employees. Social media presents some excellent mechanisms to communicate the message of compliance going forward. Many of the applications that we use in our personal communications are free or available at very low cost. Why not take advantage of them and use those same communication tools in your internal compliance marketing efforts going forward? Why should you do so? Start with the tech-savvy nature of the today’s workforce. It is not simply about having a younger workforce but a workforce whose primary tool for communication is social media. If your company is in the services business, it probably means your employee base is using technological tools to deliver business solutions. Finally, consider the data-driven nature of business today so using technological tools to deliver products and solutions is something your company most probably does now. Finally, never forget the social part of social media. Social media is a more holistic, multiple-sided communication. Not only are you setting out expectations but also these tools allow you to receive back communications from your employees. You can also see that if you have several concerns expressed it could alert you earlier to begin some detection and move towards prevention in your compliance program. Three key takeaways:

Incorporation of social media into your compliance communications can pay big dividends.

Focus on the ‘social’ part of social media.

Use internal corporate social media to facilitate a 360-degree conversation.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

A 360-degree view of compliance is an effort to incorporate your compliance identity into a holistic approach so that compliance is in touch with and visible to your employees at all times. It is about creating a distinctive brand philosophy of compliance which is centered on your consumers. In other words, it helps a compliance practitioner to anticipate all the aspects of your employees needs around compliance. This is especially true when compliance is either perceived as something that comes out of the home office or is perceived as the “Land of No.” A 360-degree view of compliance gives you the opportunity to build a new brand image for your compliance program. This is important as the Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) mandates that for a compliance program to be effective, it must be understood by a wide variety of stakeholders. Communications is often thought of as a two-way street - upward and downward, inbound and outbound, or side-to-side. However, it is better to think of it as a 360-degree effort. You simply can no longer effectively communicate in just two ways. You now communicate in a more holistic manner, and in multiple ways. If you are just thinking about communications in the classic form, you are missing something that is happening around you. 360-degrees of compliance communication is not just a classic form of communication but rather it is a communication in the concept of every interaction, whether they be planned or accidental interactions. It is all a form of communication. This is particularly true if you are a compliance professional, practitioner or Chief Compliance Officer. The things you do, the way you act, and the way people see you, you are always communicating. It is not simply communicating one to one as often you may be communicating to a group across siloed boundaries, to the constituencies you had not even planned to communicate with initially. Three key takeaways:

Remember the definition of 360-degrees of communication. It is an effort that moves the compliance identity into a holistic approach so compliance is in touch and visible to your employees at all times.

What is your objective? What are you trying to do with your 360-degrees of communications and how are you using that mechanism to deliver the objectives of your compliance program?

Evaluate. You need to evaluate three factors: 1) has the message been delivered; 2) has it been heard; and 3) is it being implemented?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What specifically are internal controls in a compliance program? The starting point is the FCPA itself, which requires issuers to devise and maintain a system of internal controls that can reasonably assure:

Transactions are executed in accordance with management’s general or specific authorization;

Transactions are recorded as necessary (I) to permit preparation of financial statements in conformity with generally accepted accounting principles or any other criteria applicable to such statements, and (II) to maintain accountability for assets;

Access to assets is permitted only in accordance with management’s general or specific authorization; and

The recorded accountability for assets is compared with the existing assets at reasonable intervals and appropriate action is taken with respect to any differences.

The DOJ and SEC, in the 2012 FCPA Guidance, stated: Internal controls over financial reporting are the processes used by compa­nies to provide reasonable assurances regarding the reliabil­ity of financial reporting and the preparation of financial statements. They include various components, such as: a control environment that covers the tone set by the organi­zation regarding integrity and ethics; risk assessments; con­trol activities that cover policies and procedures designed to ensure that management directives are carried out (e.g., approvals, authorizations, reconciliations, and segregation of duties); information and communication; and monitoring. … The design of a company’s internal controls must take into account the operational realities and risks attendant to the company’s business, such as: the nature of its products or services; how the products or services get to market; the nature of its work force; the degree of regulation; the extent of its government interaction; and the degree to which it has operations in countries with a high risk of corruption. Three key takeaways:

Effective internal controls are required under the FCPA.

Internal controls are a critical part of any best practices compliance program.

There are four significant controls for the compliance practitioner to implement initially. (a) Delegation of authority (DOA); (b) Maintenance of the vendor master file; (c) Contracts with third parties; and (d) Movement of cash/currency.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

There are numerous reasons to put some serious work into your compliance policies and procedures. They are certainly a first line of defense when the government comes knocking. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) made clear that “Any well-designed compliance program entails policies and procedures that give both content and effect to ethical norms and that address and aim to reduce risks identified by the company as part of its risk assessment process.” This statement made clear that the regulators will take a strong view against a company that does not have well thought out and articulated policies and procedures against bribery and corruption; all of which are systematically reviewed and updated. Moreover, having policies written out and signed by employees provides what some consider the most vital layer of communication and acts as an internal control. Together with a signed acknowledgement, these documents can serve as evidentiary support if a future issue arises. In other words, the “Document, Document, and Document” mantra applies just as strongly to policies and procedures in anti-corruption compliance. The specific written policies and procedures required for a best practices compliance program are well known and long established. According to the 2012 FCPA Guidance, some of the risks companies should keep in mind include the nature and extent of transactions with foreign governments (including payments to foreign officials); use of third parties; gifts, travel, and entertainment expenses; charitable and political donations; and facilitating and expediting payments. Policies help form the basis of expectations for standards of conduct in your company. Procedures are the documents that implement these standards of conduct. Compliance policies do not guarantee employees will always make the right decision. However, the effective implementation and enforcement of compliance policies demonstrate to the government that a company is operating professionally and ethically for the benefit of its stakeholders, its employees and the community it serves. Three key takeaways:

Written compliance policies and procedures, together the Code of Conduct, with form the backbone of your compliance program.

The DOJ and SEC expect a well-thought out and articulated set of compliance policies and procedures and that they be adequately communicated throughout your organization.

Institutional fairness for the application of policies and procedures demands consistent application across the globe.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

What is the value of having a Code of Conduct? In its early days, a Code of Conduct tended to be lawyer-written and lawyer-driven to wave in regulator’s face during an enforcement action as proof of ethical overall behavior. Is such a legalistic code effective? Is a Code of Conduct more than simply your company’s internal law? What should be the goal in the creation of your company’s Code of Conduct? How important is the Code of Conduct? Consider the 2016 SEC enforcement action involving United Airlines, Inc., which turned on violation of the company’s Code of Conduct. The breach of the Code of Conduct was determined to be a FCPA internal controls violation. It involved a clear quid pro quo benefit paid out by United to David Samson, the former Chairman of the Board of Directors of the Port Authority of New York and New Jersey, the public government entity which has authority over, among other things, United’s operations at the company’s huge east coast hub at Newark, NJ. The actions of United’s former CEO, Jeff Smisek, in personally approving the benefit granted to favor Samson violated the company’s internal controls around gifts to government officials by failing to not only follow the United Code of Conduct but also violating it. The $2.4 million civil penalty levied on United was in addition to its 2016 Non-Prosecution Agreement (NPA) settlement with the DOJ, which resulted in a penalty of $2.25 million. The scandal also cost the resignation of Smisek and two high-level executives from United. In the 2012 FCPA Guidance, the DOJ and SEC states: A company’s Code of Conduct is often the foundation upon which an effective compliance program is built. As DOJ has repeatedly noted the most effective codes are clear, concise, and accessible to all employees and to those conducting business on the company’s behalf. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) further specified “As a threshold matter, prosecutors should examine whether the company has a code of conduct that sets forth, among other things, the company’s commitment to full compliance with relevant Federal laws that is accessible and applicable to all company employees.” The Department of Justice (DOJ) Antitrust Division, Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations (Antitrust Guidance) also specified “If the company has a Code of Conduct, are antitrust policies and principles included in the document?” Three key takeaways:

Every formulation of a best practices compliance program starts with a written Code of Conduct.

The substance of your Code of Conduct should be tailored to the company’s culture, and to its industry and corporate identity.

“Document, Document, and Document” your training and communication efforts.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

In addition to a company’s senior management, there is a Board of Directors at the top. Yet the role of the Board is different than that of senior management. For the Board of Director, the Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) stated: Oversight – What compliance expertise has been available on the board of directors? Have the board of directors and/or external auditors held executive or private sessions with the compliance and control functions? What types of information have the board of directors and senior management examined in their exercise of oversight in the area in which the misconduct occurred?  The DOJ Antitrust Division’s Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations (Antitrust Compliance Program Guidance) was even more explicit in announcing  their expectation for robust Board oversight of a corporate compliance function. The Antitrust Compliance Program Guidance stated “For the antitrust compliance program to be effective, those with operational responsibility for the program must have sufficient autonomy, authority, and seniority within the company’s governance structure, as well as adequate resources for training, monitoring, auditing and periodic evaluation of the program. The Antitrust Compliance Program Guidance then went on to ask the following questions: Who has overall responsibility for the antitrust compliance program? Is there a chief compliance officer or executive within the company responsible for antitrust compliance? If so, to whom does the individual report, e.g., the Board of Directors, audit committee, or other governing body? How often does the compliance officer or executive meet with the Board, audit committee, or other governing body? How does the company ensure the independence of its compliance personnel?   Three key takeaways:

The DOJ Evaluation requires active Board of Director engagement and oversight around compliance.

Board communication on compliance is a two-way street; both inbound and outbound.

Does the Board of Directors have a Compliance Expert?

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Mike Volkov, in a blog post entitled “Mood in the Middle Versus Tone at the Top”, said, “Even when a company does all the right things at the senior management level, the real issue is whether or not that culture has embedded itself in middle and lower management. A company’s culture is reflected in the values and beliefs that exist throughout the company.” To fully operationalize your compliance program, you must articulate the message of ethical values and doing business in compliance and then drive that message from the top down, throughout your organization. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) made clear a company must have more than simply good ‘Tone-at-the-Top’; it must move down through the organization from senior management to middle management and into its lower ranks. This means that one task is to get middle management to respect the stated ethics and values of a company, because if they do so, this will be communicated down through the organization. The 2019 Guidance stated: Shared Commitment – What actions have senior leaders and middle-management stakeholders (e.g., business and operational managers, finance, procurement, legal, human resources) taken to demonstrate their commitment to compliance or compliance personnel, including their remediation efforts? Have they persisted in that commitment in the face of competing interests or business objectives? This requirement speaks to the greater role of non-compliance functions in fully operationalized compliance program. Indeed, one sign of a mature compliance and ethics program is the extent to which a company’s other corporate disciplines are involved in implementing and then taking forward a compliance solution. This approach can act as a lynch pin in spreading a company’s commitment to compliance throughout the employee base. It can also be used to ‘connect the dots’ in many divergent elements of a corporate compliance and ethics program. Three key takeaways:

Tone at the top - direct supervisors become the most important influence on people in the company.

Give your middle managers a Tool Kit around compliance so they can fully operationalize compliance.

Organizational justice is an additional way to help operationalize compliance.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Obviously, in every compliance program, the ethical tone of a company and accountability all starts at the top and most specifically senior management. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) stated, “The company’s top leaders – the board of directors and executives – set the tone for the rest of the company. Prosecutors should examine the extent to which senior management have clearly articulated the company’s ethical standards, conveyed and disseminated them in clear and unambiguous terms, and demonstrated rigorous adherence by example. Prosecutors should also examine how middle management, in turn, have reinforced those standards and encouraged employees to abide by them.” To assist companies in understanding this requirement the 2019 Guidance sets out the following inquiries. Conduct at the Top – How have senior leaders, through their words and actions, encouraged or discouraged compliance, including the type of misconduct involved in the investigation? What concrete actions have they taken to demonstrate leadership in the company’s compliance and remediation efforts? How have they modelled proper behavior to subordinates? Have managers tolerated greater compliance risks in pursuit of new business or greater revenues? Have managers encouraged employees to act unethically to achieve a business objective, or impeded compliance personnel from effectively implementing their duties? This requirement is more than simply the ubiquitous “tone-at-the-top,” as it focuses on the conduct of senior management. The DOJ wants to see a company’s senior leadership actually doing compliance. The DOJ asks if company leadership has, through their words and concrete actions, brought the right message of doing business ethically and in compliance to the organization. How does senior management model its behavior on a company’s values and finally, how is such conduct monitored in an organization? Three key takeaways:

Senior management must actually do compliance; walk-the-walk, not simply talk-the-talk.

Use your CEO to talk about current events and how those ethical failures are lessons to be learned for your organization.

CEO as Compliance Ambassador.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

Operationalizing your compliance program can take many shapes and forms. Using the entire risk management process to embed your compliance program within the contours of your organization is an important key step that will allow you to have full visibility of your compliance risks through a longer life cycle. Forecasting allows you to consider your business strategy and wed the risks you can foresee. Risk assessments allow you to evaluate and measure known risks. Risk-based monitoring allows you to monitor both the compliance risks you know about and detect those you do not know, on an ongoing basis. Three key takeaways:

The risk management process is an important backbone of operationalizing compliance.

You should be able monitor and measure both known and unknown risks.

All of these steps help a business to run more efficiently and more profitably.

Learn more about your ad choices. Visit megaphone.fm/adchoices

View Details

2019 was a very significant year for every compliance practitioner and compliance program. Not only was it the year with the single highest amount of FCPA enforcement actions, fines and penalties assessed against corporations but it also saw the greatest number of individual prosecutions. Yet perhaps most significantly there were three noteworthy releases of information by the federal government which directly impacted compliance professionals in 2019. Two came from the Department of Justice (DOJ) and one came from the Department of Treasury, Office of Foreign Asset Control (OFAC). These three guidances contributed to the continued evolution of what constitutes a best practices compliance program. Three key takeaways:

The 2019 Compliance Guidance asks three key questions of every corporate compliance program and adds a mandate for culture assessment, management and improvement.

The OFAC Framework mandates due diligence on not only third parties in the sales cycle but also vendors in the Supply Chain and customers as well.

The Antitrust Division Compliance Evaluation adds a requirement for data analytics and statistical analysis in monitoring and continuous improvement.

Learn more about your ad choices. Visit megaphone.fm/adchoices