Join Eric Morehead as he cuts through the complicated topic of compliance and ethics. Compliance Beat is the podcast for professionals looking for answers. Stay up to date on current trends in compliance and ethics so that your program stays effective.
Drawing again from his upcoming presentation at the SCCE Compliance and Ethics Institute on September 21, 2021, Eric discusses some key criteria to consider when evaluating or benchmarking a code of conduct.
Eric discusses the upcoming 20th Annual SCCE Compliance and Ethics Institute and his presentation "Lessons from Sixty Code of Conduct Projects: What Are Five Things You Need for a Best-In-Class Code?" (https://assets.corporatecompliance.org/Portals/4/PDFs/scce-2021-cei-brochure.pdf (scce-2021-cei-brochure.pdf (corporatecompliance.org)) and, in particular, we focus on some key points to keep in mind when you are going to launch your new (or revised) code of conduct.
In this episode Eric discusses the upcoming SCCE CEI event in Las Vegas (https://www.corporatecompliance.org/conferences/national/20th-annual-compliance-ethics-institute (20th Annual Compliance & Ethics Institute | SCCE Official Site (corporatecompliance.org))), and in particular, one of the sessions he will be co-presenting with Kathleen Grilli from the US Sentencing Commission, "Thirty Years of Organizational Sentencing Guidelines: Looking Back and Looking Forward". In particular, Eric discusses three data points from the USSC's dataset (https://www.ussc.gov/research/sourcebook-2020 (Sourcebook 2020 | United States Sentencing Commission (ussc.gov))) that could be especially useful for compliance professionals when discussing real-world consequences for compliance failures.
This time Eric spends a little time discussing why a company might want to have a third-party code of conduct, rather than relying only on their employee code of conduct. We discuss some of the reasons a third-party code is potentially a good idea, who the audience might be and what are some of the topics you might want to cover.
This time Eric reviews the top mistakes he's seen clients and others make when tackling an code of conduct revision or rewrite process. Codes of Conduct are the foundation of any effective program and taking the appropriate care and time to complete a code revision project is the key to success.
In this episode Eric discusses some considerations for a successful code of conduct launch. Often organizations spend a lot of time, effort and resources on revising and improving their code of conduct only to have little in the way of a launch effort. Eric discusses some ideas to avoid a failure to launch.
It's been a year! We've seen challenges and changes -- and we're still not completely out of the woods yet. In this episode Eric talks about three of those seemingly permanent changes that compliance and ethics programs have had to deal with and also discusses three things that are definitely not going to change.
After a extended hiatus, we're back! We're looking for your feedback on what to cover and what you'd like to hear about in the weeks going forward. Email us at: eric@moreheadconsulting.com
The world has changed since our last episode. Eric has some ideas for newly remote compliance officers handling newly remote workers. Communication is key, and the compliance team needs to make a special effort to be heard and involved.
This time Eric discusses three primary reasons an organization might want to work with a third party to conduct a compliance program assessment.
This time Eric walks through some categories to benchmark your code of conduct. Organizations are expected to regularly examine the effectiveness of their written standards and there are some common areas to review when taking stock of your code.
This time Eric discusses three keys for a successful conflicts of interest compliance process. Eric discusses communication, disclosure, certification and tools that organizations can use to better address conflicts of interest risk.
There are many ingredients for a successful compliance program assessment, but in this episode Eric focuses on three key components that are sometimes overlooked when an organization is either conducting their assessment internally or looking to a third-party to help them with a review.
This time Eric talks anonymous reporting mechanism. What is actually required? What does reporting data show an compliance officer? What is the most effective reporting channel for an organization? We talk about these important questions and debunk a few myths about anonymous reporting.
This time Eric spends some time talking about some practical considerations for organizations to consider when planning or revising their "informal" compliance communication program. This area of compliance has been changing quite rapidly and expectations are often high. To avoid disappointing results it is important for compliance officers and others charged with communication responsibilities to carefully consider the goals and realities of proposed program.
This is the second in a two-part discussion about perception and retaliation. This time we talk about solutions. How can an organization address the lingering perception of retaliation? We spend a few minutes looking at the data and discussing what you might do at your organization to address these issues.
This time Eric talks about retaliation. What does retaliation look like in an organization? How does perception of retaliation affect reporting? We spend a few minutes looking at the data and discussing what you should expect at your organization.
Getting your managers involved in your compliance program is a best practice and also the most effective way to address compliance culture locally. In this episode Eric talks about three key criteria to consider when putting together a plan for involving managers: training, resources and measurement. Eric discusses some practical ways to implement such a plan.
As more and more compliance professionals join the ranks from other disciplines, it’s important that we reinforce the role of the US Sentencing Commission, and maybe even more importantly, the public’s role in defining the compliance and ethics standards all of our programs are based on.
Listen to a short description of what the Sentencing Commission is, and their role in our profession — both past and future.
Also, join Eric for a webinar next week on Thursday, November 7th at 1PM ET: https://clearlawinstitute.com/shop/webinars/live-webinars/updating-your-code-of-conduct-best-practices-110719/ (Updating Your Code of Conduct: Best Practices).
There’s not a lot of data out there to tell us how the Department of Justice or other regulators view compliance initiatives, or what expectations really are. We know what the guidance tells us, but what happens in the real world when a company’s compliance program is looked at? We can get some indications from Sentencing Commission data that tells us what happens to those unlucky companies that face a Federal judge for sentencing.
For this episode Eric dives into the commonly conflated terms “substantial authority personnel” and “high-level personnel” that are defined in the Sentencing Guideline standards for an effective compliance and ethics program. Knowing which is which, and what the expectations are for a compliance program, is very important and not often discussed.
Also, check out our upcoming webinar with our friends at the Clear Law Institute, “https://clearlawinstitute.com/shop/webinars/live-webinars/updating-your-code-of-conduct-best-practices-110719/ (Updating Your Code of Conduct: Best Practices),” on November 7th at 1PM ET. You can register for the event https://clearlawinstitute.com/shop/webinars/live-webinars/updating-your-code-of-conduct-best-practices-110719/ (here).
Eric spends a few minutes looking back at CEI’s past — and talking about the threads and new trends in this year’s event. If you are visiting DC this week then come by and see Eric at Booth 106. If not, we hope to see you next time!
https://www.corporatecompliance.org/conferences/national/18th-annual-compliance-ethics-institute-2019 (https://www.corporatecompliance.org/conferences/national/18th-annual-compliance-ethics-institute-2019)
“SCCE’s annual Compliance & Ethics Institute is the primary educational and networking event for compliance professionals across all industries around the world. Each year we host more than 1,600 attendees from 40 countries.”
This time Eric is Teresa Troester-Falk to discuss the pending new privacy law from California, potential new laws in several states, and how it relates to GDPR and privacy compliance generally. This is the Second part of a two part conversation. If you haven’t listened to Part I we encourage you to do so.
Teresa is Chief Global Strategist for Nymity where she leads some of Nymity’s key accountability research initiatives and collaborates with other internal leaders to help innovate privacy accountability and compliance solutions and ensure organizational success. Teresa authors Nymity white papers and other publications and regularly speak at conferences, advanced privacy forums and on webinars. Teresa has over 20+years experience in law, including 14+ years as a global privacy professional. Prior to joining Nymity served as Associate General Counsel (Privacy) for Nielsen, where Teresa expanded the global privacy program as well as initiated and led key global and regional privacy and data protection programs and strategies, driving the relationships across internal and external stakeholders to advance the company’s privacy agenda.
Also, please check out Eric’s upcoming webinar with the Clear Law Institute, “What Do Compliance Communication Programs Look Like” on September 12th at 1PM ET. You can register for the webinar https://clearlawinstitute.com/shop/webinars/live-webinars/what-do-compliance-communication-programs-look-like/ (here.)
This time Eric is Teresa Troester-Falk to discuss the pending new privacy law from California and how it relates to GDPR and privacy compliance generally. This is the first part of a two part conversation. Join us next week for part two.
Teresa is Chief Global Strategist for Nymity where she leads some of Nymity’s key accountability research initiatives and collaborates with other internal leaders to help innovate privacy accountability and compliance solutions and ensure organizational success. Teresa authors Nymity white papers and other publications and regularly speak at conferences, advanced privacy forums and on webinars. Teresa has over 20+years experience in law, including 14+ years as a global privacy professional. Prior to joining Nymity served as Associate General Counsel (Privacy) for Nielsen, where Teresa expanded the global privacy program as well as initiated and led key global and regional privacy and data protection programs and strategies, driving the relationships across internal and external stakeholders to advance the company’s privacy agenda.
Also, please check out Eric’s upcoming webinar with the Clear Law Institute, “What Do Compliance Communication Programs Look Like” on September 12th at 1PM ET. You can register for the webinar https://clearlawinstitute.com/shop/webinars/live-webinars/what-do-compliance-communication-programs-look-like/ (here.)
This time, in anticipation for a Sentencing Guideline presentation next month at the SCCE’s CEI in Washington DC, we have another belated edition of Sentencing Commission Confidential. Eric talks about a commonly overlooked or misunderstood part of Chapter Eight of the guidelines that sets out responsibilities for reporting to the Board (or governing authority) of an organization. If you or your organization still struggles with what that conduit to the Board should look like, take a listen. Eric references parts of Chapter Eight of the guidelines which can be found https://www.ussc.gov/guidelines/2018-guidelines-manual/2018-chapter-8 (here.)
This time Eric discusses compliance program assessments – or risk assessments – or program benchmarking – or whatever you want to call the periodic review of your program that the Sentencing Guidelines, USDOJ guidance and best practices call for. Eric discusses three key pieces of the puzzle you might want to consider whether you are undertaking the assessment internally or evaluating outside assistance.
Eric mentions Chapter Eight of the Sentencing Guidelines in the podcast, the text of which can be found https://www.ussc.gov/guidelines/2018-guidelines-manual/2018-chapter-8 (here).
One of the questions raised by the recent updated USDOJ guidance is the question of “expertise” at or on the board of directors. Eric takes some time this week to discuss the guidance and the practical considerations about expertise in the boardroom.
If you are interested in the intersection of compliance and the board of directors, please join Eric for a webinar on the topic July 31st at 1PM ET. “What Should Your Board Know About Compliance and Ethics?” https://clearlawinstitute.com/shop/webinars/live-webinars/what-should-your-board-know-about-compliance-and-ethics/ (click here) for more information.
One of the areas many compliance teams still struggle with is getting a consistent, effective informal communication plan off the ground. Eric has a few ideas that might help focus informal communication efforts at your organization. Eric talks about being realistic regarding time and resources and thinking strategically about what might reach your audience.
After a dozen episodes detailing the new guidance, what are some parting thoughts? Eric talks a little about the memo’s impact and potential impact as well as highlighting some of the more important concepts the Department has chosen to highlight.
In Part 10 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric finishes discussing the memo! We will walk through Part III of the memo with a review of “Does the Corporation’s Program Work in Practice?”
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
In Part 9 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric finishes discussing Part II of the memo with a review of incentives and discipline expectations.
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Also, check out Eric “live” in Houston on June 20, 2019 – Hosted by the Federal Bar Association, Southern District of Texas Chapter, June 20, https://www.eventbrite.com/e/the-dojs-new-compliance-guidance-answering-the-three-key-questions-tickets-63139112786 (“The DOJ’s New Compliance Guidance:Answering the Three Key Questions”).
AND, check out the upcoming webinar on June 19, 2019 at 3PM ET/ 2PM CT: https://clearlawinstitute.com/shop/webinars/live-webinars/creating-an-effective-compliance-and-ethics-program-practical-considerations-and-regulator-expectations/ (“Creating an Effective Compliance and Ethics Program: Practical Considerations and Regulator Expectations”)
Both the live event in Houston and the webinar have been approved for CLE credit and the webinar has been approved for CCEP credit.
In Part 8 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric discusses the second topic in Part II of the memo: Autonomy and Resources.
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Also, please take a look at Ryan McConnell’s comparison review of the new memo and the 2017 USDOJ memo http://www.rmcconnellgroup.com/doj-fraud-guidance-comparison/ (here).
In Part 7 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric discusses the first topic in Part II of the memo: Commitment by Management — or tone from the top, middle and everywhere else!
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Also, please take a look at Ryan McConnell’s comparison review of the new memo and the 2017 USDOJ memo
In Part 6 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric discusses the fifth and sixth topic in Part I of the memo: the “care and feeding” of third parties.
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Also, please take a look at Ryan McConnell’s comparison review of the new memo and the 2017 USDOJ memo
In Part 5 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric discusses the fourth topic in Part I of the memo: reporting.
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Also, please take a look at Ryan McConnell’s comparison review of the new memo and the 2017 USDOJ memo http://www.rmcconnellgroup.com/doj-fraud-guidance-comparison/ (here).
In Part 4 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric discusses the third topic in Part I of the memo: training and communication.
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Also, please take a look at Ryan McConnell’s comparison review of the new memo and the 2017 USDOJ memo http://www.rmcconnellgroup.com/doj-fraud-guidance-comparison/ (here).
In Part 3 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric discusses the second topic in Part I of the memo: policies and procedures.
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download
In Part 2 of our special series discussing the new memo from the US Department of Justice on compliance expectations, Eric discusses the first topic in Part I of the memo: risk assessment.
Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Eric discusses the new memo from the US Department of Justice and its introduction and origins. Check out the memo itself here: https://www.justice.gov/criminal-fraud/page/file/937501/download (https://www.justice.gov/criminal-fraud/page/file/937501/download)
Just yesterday the USDOJ announced a new memo regarding the evaluation of compliance programs. Eric has some initial thoughts, but stay tuned for more podcasts diving into the details. You can find the new memo here: https://www.justice.gov/criminal-fraud/page/file/937501/download
Eric talks again about his favorite topic: code of conduct! This time we discuss three common code of conduct development myths. We talk about how longer does not equal better. How a global code that applies to everyone is better than a constellation of many codes. And finally Eric discusses how organizations should be realistic about the time and resources that go into a successful code of conduct project.
This time Eric talks about three aspects of Chapter 8 of the Sentencing Guidelines that you may not have noticed before.
This time Eric talks through conflicts of interest disclosures. Who do you want to capture, what do you need to tell them, should you use tools? Eric talks through all of this and also spends some time talking about the types of questions you will want to ask in the disclosure questionnaire.
Join Eric and the Clear Law Institute for another addition of his Code of Conduct Development webinar on April 4th 2019 at 1PM ET. You can register for the webinar https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-040419/ (here.)
An important topic that we don’t talk enough about. Just as small businesses make up the vast majority of companies out there, and employ over 50% of the workforce in the USA, they also make up the majority of companies that get in the worst trouble for compliance failures — even though we rarely read about it. Eric talks a little about the pitfalls and issues with small organizations and compliance.
Also, check out our next webinar with our partners at Clear Law Institute on April 4th — you can find out more https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-040419/ (here).
This time we discuss benchmarking. First we discuss how you might go about determining the peer codes of conduct (or other written compliance standards) that you can use for benchmarking purposes. You probably have a good idea of some peer organizations that might fit, but Eric also discusses some other thoughts about what gets put into the mix. Then we discuss some different areas and criteria you might want to consider when evaluating your written standards and comparing them to other written standards. We talk about content and presentation as well as different, specific content you want to be paying attention to.
Eric also extends a special offer to Compliance Beat listeners this week: send Eric your code and he will review it and discuss it with you and your team on the house. Send inquiries to Eric directly http://eric@moreheadconsulting.com (here).
This time Eric talks about compliance surveys. Eric discusses what sort of content you might consider including in the survey instrument, whether you might want to consider benchmarking, and finally Eric discusses some of the practical elements of putting together a survey.
This time Eric talks about three different areas to focus on when evaluating how you are reaching your remote workers to educate and inform them of the compliance program. Eric discusses use of local and existing resources, what resources should be developed by the compliance function and how technology can be put to use.
Eric is also speaking at http://www.corporatecompliance.org/Portals/4/PDFs/scce-2019-utilities-energy-brochure.pdf (SCCE’s Energy and Utilities Conference) in Houston on February 11th. Join us there if you can!
This time Eric discusses some considerations when looking at the role, responsibilities and relationships the board (or governing authority) of the organization with the operational personnel of the compliance and ethics program. There are a few key best practices to consider when evaluating the board’s role, including their training and knowledge of their responsibilities, their understanding of compliance risks and controls and their relationship with operational compliance.
Also, Eric mentions his upcoming speaking role at the SCCE’s Utilities Conference in Houston, February 10-12, 2019. If you are interested in attending, information is http://www.corporatecompliance.org/Portals/4/PDFs/scce-2019-utilities-energy-brochure.pdf (here).
In anticipation of our upcoming webinar on code of conduct development we talk today about what “requirements” for a code of conduct exist. Eric also provides a sneak peak into some of the content of the webinar by discussing the Department of Justice’s February 2017 memorandum and how that applies to code of conduct development.
You can find the DOJ’s memo https://www.justice.gov/criminal-fraud/page/file/937501/download (here), and you can register for the “https://clearlaws.com/clearlaw/updating-your-code-of-conduct-best-practices/?utm_source=Dedicated%20IP&utm_medium=Email&utm_campaign=1%2F17%20-%20Updating%20Your%20Code%20of%20Conduct%3A%20Best%20Practices (Updating Your Code of Conduct)” webinar https://clearlaws.com/clearlaw/updating-your-code-of-conduct-best-practices/?utm_source=Dedicated%20IP&utm_medium=Email&utm_campaign=1%2F17%20-%20Updating%20Your%20Code%20of%20Conduct%3A%20Best%20Practices (here).
How do you avoid all compliance risk? Hint: you can’t. This week Eric talks about some recent articles and discussions that suggest there might be a magic bullet or two (sometimes in the form of a new software tool) that will take away those pesky compliance concerns. We alk about the practical and the pragmatic view of this topic.
Also, please join us next week for a webinar on developing your code of conduct. We’re putting the webinar on with our friends at the Clear Law Institute on January 17th at 3PM ET. If you are interested in joining us for “https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-011719/ (Updating Your Code of Conduct: Best Practices)” you can register https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-011719/ (here).
If you email Eric at eric@moreheadconsulting.com he can send you a code for 35% off the webinar fee.
Happy Holidays from Compliance Beat!
This week Eric discusses a few compliance program trends from the last year in the second of a two-part series here as we end 2018. This time Eric discusses leveraging opportunities, being part of the deal team and gaining better access to the board.
We have another upcoming webinar with our friends as the Clear Law Institute on January 17th at 3PM ET. If you are interested in joining us for “https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-011719/ (Updating Your Code of Conduct: Best Practices)” you can register https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-011719/ (here).
Happy Holidays from Compliance Beat!
This week Eric discusses a few compliance program trends from the last year in the first of a two-part series here as we end 2018. This time Eric discusses interesting developments in communications, data use and proactive risk assessment.
We have another upcoming webinar with our friends as the Clear Law Institute on January 17th at 3PM ET. If you are interested in joining us for https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-011719/ (“Updating Your Code of Conduct: Best Practices”) you can register https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-011719/ (here).
We all want a compliance program that prevents and detects compliance failures before they happen. That is usually not what happens. Even the best programs and the best corporate cultures occasionally will face issues of misconduct. It is important for organizations to spend some time thinking about and preparing for that eventuality. In this episode, Eric discusses some ways compliance officers can start preparing for the eventual issues that can come up.
This week Eric spends a few minutes discussing some key elements to think about when trying to get the message out about gifts and entertainment and managing those frequent holiday calls (and issues) that revolve around the giving season.
This week Eric talks about one of the hallmarks of the Sentencing Guidelines that is sometimes overlooked or not as carefully understood. Monitoring and auditing is sometimes reduced to reporting, but it is so much more. To guide us on the journey, Eric reviews the language and notes in the Sentencing Guidelines themselves and discusses the Department of Justice’s most recent guidance on the topic.
Eric refers to both Chapter 8 of the Guidelines, which you can find https://www.ussc.gov/guidelines/2015-guidelines-manual/2015-chapter-8 (here), and the February 2017 memo from DOJ, “Evaluation of Corporate Compliance Programs,” which you can find https://www.justice.gov/criminal-fraud/page/file/937501/download (here).
This week we celebrate our 100th episode of Compliance Beat! Thanks to everyone who has been a loyal listener. Instead of sending presents to us, we present a listener-requested topic, some practical discussions on how to prepare and put together manager-led communications — sometimes called manager toolkits. As always, please subscribe to the podcast if you haven’t done so already, and let us know if you have any feedback or suggestions — on to 100 more episodes!
Join us for Part II of a special interview with Roy Snell. Roy is our first guest to appear twice and he has graciously joined us again just as he is leaving his role as the CEO of the HCCA and the SCCE. In this episode Eric and Roy talk a little about the present and the future of the compliance profession and SCCE as Part II of the interview. If you haven’t listened to Part I, you can find it http://www.compliancebeat.com/roy-snell-interview-part-three-components-board-training/ (here).
TUNE IN NEXT WEEK FOR OUR 100th EPISODE! We’ll take a look back and present a listener requested topic.
This time Eric has a very special guest, and our first guest to appear twice, Roy Snell. Roy was on the 2nd Episode of Compliance Beat back in 2016 and he has graciously joined us again just as he is leaving his role as the CEO of the HCCA and the SCCE. In this episode Eric and Roy talk a little about the past and the present of the compliance profession and SCCE as Part I of the interview. Tune in next week to hear Roy’s thoughts about the future of compliance in Part II.
Eric also spends a few minutes talking big picture about the components compliance professionals should consider when preparing training for the board of directors.
Join us next week for Part II of the interview with Roy Snell and another compliance program topic.
We’ve been away and had some technical difficulties with our Compliance Beat website — but we’re back!
You can’t keep a compliance podcast down!
This week Eric talks about three creative ways to approach one of the more esoteric parts of an effective compliance program: informal communications.
Eric talks about thinking outside the box, using activities and integration with other messages — and provides examples.
This time Eric talks about three components that every code should have to be universally accepted by the organization’s stakeholders. First, the code should apply to everyone, from the top of the organization to those third parties that represent the organization. Second, there should be one code. Organizations that still have regional codes or different codes for different business units need to abandon this practice. Third, seriously consider making your waiver section a NO WAIVER section. If you have provisions you fear may need to be waived, you need to examine why that would be and whether that provision needs to revised or excised from the code.
Eric also talks about two upcoming webinars you can participate in. One, https://register.gotowebinar.com/register/5172309798303124483 (Bullying in the Workplace: A Comprehensive Ethics & Compliance Overview), on October 18th can be registered for https://register.gotowebinar.com/register/5172309798303124483 (here), and a second, https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-102618/?tab=credits&_ga=2.41934049.2114959359.1538584502-1229252845.1538584502 (Updating Your Code of Conduct: Best Practices), on October 26th, has a registration link https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-102618/?tab=credits&_ga=2.41934049.2114959359.1538584502-1229252845.1538584502 (here).
Please join us!
And please subscribe to the podcast and let us here from you!
Eric revisits the (still) ongoing issues surrounding misconduct, governance, compliance and crisis management that swirl around Baylor. After first discussing the different paths that Baylor and Penn State, for example, took back in our Compliance Beat Podcast in December 2016, we are still discussing the path that Baylor has taken — and the paths that lay untrodden. Eric also talks about two upcoming webinars you can participate in. One, https://register.gotowebinar.com/register/5172309798303124483 (Bullying in the Workplace: A Comprehensive Ethics & Compliance Overview), on October 18th can be registered for https://register.gotowebinar.com/register/5172309798303124483 (here), and a second, https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-102618/?tab=credits&_ga=2.41934049.2114959359.1538584502-1229252845.1538584502 (Updating Your Code of Conduct: Best Practices), on October 26th, has a registration link https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-102618/?tab=credits&_ga=2.41934049.2114959359.1538584502-1229252845.1538584502 (here). Please join us! And please subscribe to the podcast and let us here from you!
Check out Eric’s other podcasts on the Baylor crisis http://www.compliancebeat.com/compliance-failures-crisis-management-can-learn-baylor-university-penn-state/ (here) and http://www.compliancebeat.com/teaching-moments-can-learn-compliance-failures-baylor-university/ (here).
This week Eric talks crisis management, and in particular, Steve Denning’s Four Rules of Crisis Management. We talk about how the role of compliance intersects to crisis situations. Eric also talks about two upcoming webcasts, one Bullying in the Workplace: A Comprehensive Ethics & Compliance Overview will be on Thursday, Oct 18th at 1:00 PM EDT — the registration link is not yet up — but we will follow-up with more info as it becomes available. The second webinar is https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-102618/ (Updating Your Code of Conduct: Best Practices) which you can sign up for https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-102618/ (here) and will be on October 26th at 1PM EDT. ALSO, DON’T MISS ERIC AT SCCE CEI IN LAS VEGAS, October 21-23rd.
This time Eric talks about three different approaches compliance officers can take when dealing with a board of directors that is reluctant to spend time and resources on compliance, or when dealing with a board that is perhaps not as familiar with compliance and ethics concerns.
This time Eric walks through three different areas to consider when making the case internally for compliance resources or specific compliance initiatives. We discuss three different areas to cover, regulatory or risk issues, empirical data and benchmarking and making the functional business case. Eric provides a few examples and talks about how having a well-rounded argument will help with your stakeholders.
To compliance officers, very often, routine is good. But routine can lead to communication and training fatigue — and an overall program that doesn’t really reach the stakeholders you are trying to speak to. In this episode Eric talks about three different ways you might try to break the normal routine and have more success making a compliance connection with your audience.
We’re back! After a brisk summer holiday, Compliance Beat returns with a discussion about how to approach complex compliance topic discussions. Eric spends some time talking about using “real world” examples, leading with your organization’s policy and values, and figuring out some ways to get the stakeholders more directly involved — and hopefully invested. Join us for a practical discussion — and as always, contact us with any questions or suggestions.
This time Eric talks about three inquiries that compliance officers might want to make when considering their internal reporting process and resources. Often organizations spend a good deal of time on tools and other systems for reporting but really should first take a step back and investigate what is going on at the organization currently, how they might leverage local management most efficiently and how informal communication can be brought to bear on the issue of reporting.
This week as we get ready for the fireworks of July 4th here in the USA, let’s talk a little about the fireworks in your code document. Many organizations are focusing more on the design and look of their code documents, but what does that mean? Eric spends a little time discussing a few ideas to consider.
This week Eric takes up the topic of reporting and talks about 4 different areas an organization can concentrate on to encourage employees to come forward with their concerns.
Summer is here and Eric takes a few minutes to discuss some ideas on utilizing mission and values in your program’s communications and written standards. We talk often about bad culture, so let’s talk a little about leveraging good culture and strong values.
This week we have a special guest, Tom Fox, who discusses his new book “The Complete Compliance Handbook” with Eric. You can find out more about the new book, and how to order it, http://fcpacompliancereport.com/the-complete-compliance-handbook (here).
Also, don’t forget to join us and our friends at SAI Global for a FREE webinar (with 1.2 CCB CEU’s approved for your CCEP) on Thursday the 24th at 10AM CT / 11AM ET entitled “Cracking the Code: Understanding Regulatory and Stakeholder Expectations for Code of Conduct” — you can register (FOR FREE) https://register.gotowebinar.com/register/4783584056608484866 (here).
And, as always, don’t forget to subscribe to the podcast if you haven’t already! And please let us know if you have suggestions or questions at “eric@moreheadconuslting.com”.
This time Eric takes on a common question about some effective ways organizations can communicate, or roll-out, their new code of conduct. We get specific this time and talk about just three of the many ways you might try to get the word out. Posters, podcasts and personal reference cards, oh my! Get creative and try to meet your audience with different solutions.
On May 24th at Noon ET / 11AM CT, with our friends from SAI Global, “Cracking the Code of Conduct: Understanding Regulatory and Stakeholder Expectations for Written Compliance Standards.” You can register for that webinar FOR FREE https://register.gotowebinar.com/register/4783584056608484866 (here). This webinar is approved for 1.2 CCB credits for your CCEP.
This time we talk about how you can evaluate how (or if) to use your organization’s values in your code. First, we talk about the current use of the values and how that might help, or hinder, their use in the code. Second, we talk about two different ways you can leverage your organization’s values in the code. One way is to use the values to establish the document’s structure, the second way is to weave the values throughout the text. Eric talks about a few different ways to accomplish this.
Also, join us for TWO upcoming webinars on code of conduct!
On May 9th at 1PM ET: “Updating Your Code of Conduct: Best Practices” with the Clear Law Institute. You can register for that webinar https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices-050918/ (here). The webinar is approved for 1.5 CCB credits for your CCEP.
On May 24th at Noon ET / 11AM CT, with our friends from SAI Global, “Cracking the Code of Conduct: Understanding Regulatory and Stakeholder Expectations for Written Compliance Standards.” You can register for that webinar FOR FREE https://register.gotowebinar.com/register/4783584056608484866 (here) This webinar is approved for 1.2 CCB credits for your CCEP.
Has the role changed? Eric thinks it’s a definite yes and discusses three ways this week. First, expectations from stakeholders from the BOD on down are different today. Demands on the compliance function, and expected results, are far greater than they were. Second, the need to divorce any lingering corporate legal duty from some of the important functions of compliance is greater than ever before. We may not be able to serve two masters at all times. Third, along with those challenging expectations comes a higher profile — use it wisely.
This week we discuss three important topics for manager’s to discuss with their reports. What are some essential messages for manager’s to discuss? What topics sometimes get overlooked? Why are manager’s so important to the compliance communication process?
Eric discusses all of these topics this week and focuses on the type of dialogue you should be shooting for in these conversations between managers and their reports about compliance issues.
We are participating in another FREE webinar with our friends at SAI Global. On April 18th at 1PM Central join us (and get 1.2 hours for your CCEP!) as we discuss “The Relationship Between Ethics and Compliance in Business” with Dean Timothy Glynn from Seton Hall University Law School. You can register (for Free!) https://register.gotowebinar.com/register/3103530287684575747 (here).
This week Eric addresses a common question: how do you benchmark a code of conduct?
Eric focuses on three key areas to have a more successful benchmarking project. First, we talk about how you want to include peer codes outside your organization’s industry. Second, Eric discusses the fact that you don’t need to find “all things” in each code in your review. Find aspects you like in several codes, whether that’s content, design, language use, navigation. Find what you like, and include it. Lastly, we discuss how you need to include the team. Have a cross-functional and diverse group involved in the process to make sure you get some broad opinions and input.
We are participating in another FREE webinar with our friends at SAI Global. On April 18th at 1PM Central join us (and get 1.2 hours for your CCEP!) as we discuss “The Relationship Between Ethics and Compliance in Business” with Dean Timothy Glynn from Seton Hall University Law School. You can register (for Free!) https://register.gotowebinar.com/register/3103530287684575747 (here).
Since 2016 we have heard this question frequently. The popular media, particular in the United States, has championed the idea that “regulation” is disappearing. But, in the context of compliance expectations, is that really true? Eric takes a look at three different reasons why that might not really be the case. In these days when regulator expectations regarding compliance are still high, and popular notions about compliance may be sinking, it’s important for those who are responsible for compliance to have a handle on these issues and be ready to answer these questions.
Eric also would like for you to join us March 28th at 11AM ET for a new FREE webinar “https://register.gotowebinar.com/register/7036609824522251010 (You Did What? U.S. Department of Justice Expectations for Ethics and Compliance Programs in 2018)“. Approved for 1.2 CCB CEU’s for those of you with the CCEP.
This time Eric talks about three aspects of an effective response to conflicts of interest. First, we discuss written standards and how a code of conduct and other materials can interplay effectively to provide helpful resources on conflicts. Second, Eric discusses disclosures, the piece of the puzzle that many organizations still do not include in their program. Eric discusses a little on how to deploy a disclosure process and what content questionnaires should include. Finally, we discuss generally what you’ll want to cover with training and communication.
Eric also mentions a new FREE webinar that we will be having with SAI Global later this month. It’s titled “You Did What? U.S. Department of Justice Expectations for Ethics and Compliance Programs in 2018” and you can register for it https://register.gotowebinar.com/register/7036609824522251010 (here.)
This week Eric tackles what “monitoring” means in the context of a compliance and ethics program. We break it down into three main concepts. First, applying a “risk-based” process to monitoring means understanding your risks, applying those controls you have (including monitoring) and then evaluating those controls for effectiveness. Second, Eric spends a little time talking about the processes, tools and systems that generally comprise compliance monitoring. Finally, Eric talks about the important “feedback loop” of monitoring data that helps an organization spot trends and issues and improve their monitoring — and their entire program.
This time Eric discusses what makes a “risk-based” training program. Many organizations are in the thick of getting ready to roll out their training this spring, and it’s a good time to consider what you do to train your stakeholders on compliance risks. We talk about the February 2017 Ehttps://www.justice.gov/criminal-fraud/page/file/937501/download (valuation of Corporate Compliance Programs) memo from the Fraud Section at the Department of Justice. In particular, we focus on how recent guidance talks about “tailored” training programs, how we must focus on the training program process at the front AND back ends, and Eric also talks a little about the use of data to show effectiveness. All in all, getting to a risk-based training program has some clear goals and steps.
Eric also urges any last-minute participants to join him tomorrow, February 28, 2018, for an informative webinar on code of conduct development from the https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices/ (Clear Law Institute). Get your CLE or CCB credits!!
Eric, like a lot of people in the USA this Spring, is getting over a unexpected bout of the flu. It got him thinking about compliance during crisis events and how compliance interacts with business continuity planning. We spend some time talking about some ways compliance should be involved.
Apologies for the poor sound quality this week — Eric will be back about a whisper next week with a new topic!
Now Eric is going to rest and get some fluids. But please check out the webinar he’s giving on February 28th at 3PM ET on Code of Conduct best practices here: https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices/
This time we focus on the next horizon for “effective” written standards: the stand-alone compliance policy. While many organizations have tackled their code of conduct, written policies still woefully suffer from some of the same ailments we’ve cured in our codes. Eric takes time to talk about the differences between a code project and getting your arms around written policies, including the challenges with different stakeholders. We then discuss three different areas to keep in mind when starting a policy revision process.
For those interested in revising policies or code of conduct, Eric is leading a webinar on February 28th at 3PM ET, https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices/ (Updating Your Code of Conduct: Best Practices), just click the title for more information.
This week we have a conversation with Brian Oderkirk from https://www.edgepointlearning.com/about/ (Edgepoint Learning) about compliance training trends on the horizon.
Brian has been in the eLearning and training space for about twenty years and has done just about every role in the space and working from everywhere from higher education, to corporate training and training vendors. For the last seven years his focus has been helping clients find the right training solutions in the Governance, Risk and Compliance space.
Also note that Eric will be conducting a webinar on February 28th at 3PM ET on Updating Your Code of Conduct: Best Practices. If you are interested, information is here:
https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices/
It’s that time of the year when compliance professionals are dusting off their annual plans for the program. That nearly always includes planning for training, but less often does it include detailed plans for communications.
In this episode Eric talks about the US Sentencing Guideline standards and expectations regarding communication and then he provides three good areas to concentrate on.
First, we talk about having a written plan and what that communications plan might look like. Second, Eric discusses some different ways organizations can be more creative regarding their compliance communications. And lastly, Eric discusses how important it is to involve a diversity of voices in the communication effort.
For those interested, Eric is leading a webinar on February 28th on Code of Conduct development. Get your CLE or CCB (CCEP) credits! Check it out https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices/ (here).
Today Eric talks about three common areas he has seen clients experience issues when they undertake to update their code of conduct. First, Eric discusses getting the appropriate buy-in from all the applicable stakeholders. Involving the team and making sure everyone shares the appropriate vision is critical and failure can sometimes derail a project.
Next we discuss apportioning the right project management to make sure that the job gets done and gets done efficiently.
Finally, we discuss proper scoping. Organizations very often underestimate — or fail to estimate at all — what the update to their code will really look like. In our experience there is really very few situations where a simple scope or “lite” review has the results the organization really is looking for. Eric encourages project managers to be realistic about the real scope.
For those interested in code development, and those that might want to get CLE credit or CBB credit, Eric is recording two webinars over the next two months on the topic. For more information follow these links:
https://clearlawinstitute.com/shop/webinars/code-of-conduct-development-and-rollout-involving-your-team/ (Code of Conduct Development: Involving Your Team)
https://clearlawinstitute.com/shop/webinars/updating-your-code-of-conduct-best-practices/ (Updating Your Code of Conduct: Best Practices)
This week Eric speaks to a Top Ten list, if you will, of topics to consider regarding the upcoming implementation of the EU’s new General Data Protection Regulation (GDPR). As with most compliance issues, small and medium sized organizations are likely to be the ones that are least prepared for this change, and a recent survey shows that almost one quarter of US companies hadn’t even heard about the new regulation. Since GDPR has a more expansive jurisdiction, it also will potentially cover many more organizations. Listen in as Eric walks through 10 things to consider when getting ready for the May 25, 2018 implementation.
After finishing another year we now embark on 2018 — and another yearly edition of trend predictions. In this episode Eric talks about a couple of key compliance risk topics that organizations will want to think about as they plan out their new year, including some significant changes that will be happening soon. We also discuss some of the new guidance we have seen at the end of the year and the possibility of new guidance as the new year progresses. Finally, Eric also discusses how to balance the rhetoric about deregulation with the realities of continued enforcement and how compliance professionals can adapt a business case argument to change up the the discussion around compliance and ethics. Happy New Year!
We are very, very pleased to conclude our special discussion about some very interesting new research and data about managers and ethics this week. If you have not yet listened to PART I, we suggest you do. We will be interviewing the principal authors of a new article just published in October, titled https://pubsonline.informs.org/doi/10.1287/orsc.2017.1153 (“Middle Managers and Corruptive Routine Translation: The Social Production of Deceptive Performance”).
As an early holiday gift, Compliance Beat is happy to provide a wide-ranging Q&A about middle managers, ethical decision-making and the intersection with compliance! Forget festive feasting and gift-giving, for compliance stalwarts this is truly a great gift: insight on a subject where there hasn’t been much research.
Join us as we speak to:
Linda K. Treviño, Ph.D., Distinguished Professor of Organizational Behavior and Ethics in the Department of Management and Organization in the Smeal College of Business at The Pennsylvania State University. Professor Treviño holds a Ph.D. in management which has contributed to her unique focus on ethics as a management issue. She has published 90 articles, many in the field’s top research journals. She has also co-authored three books, an academic book on organizational ethics, another on academic integrity, and a textbook on business ethics that is in its sixth edition. In 2007, she was elected a member of the Academy of Management Fellows, a group that recognizes and honors members of the Academy of Management who have made significant contributions to the science and practice of management. Professor Treviño has taught students at all levels and has spoken to many academic and practitioner audiences. Her views on business ethics have been quoted in the press including the New York Times, the Wall Street Journal, Newsweek, Business Week, and other publications and she has appeared on CNBC. Her research has focused on the impact of individual differences and ethical culture on employee behavior, ethical leadership, speaking up about ethical issues, and the role of values in organizations among other topics. She maintains an active research program with current research that includes a focus on how scandal affects leaders and organizations, moral advocacy in ethical decision making groups and emotions in ethical decision making. Ethisphere named her one of the 100 most influential people in business ethics in 2015.
And:
Niki den Nieuwenboer, an assistant professor of organizational behavior and business ethics at the University of Kansas. She holds a PhD in Management from Rotterdam School of Management, Erasmus University, the Netherlands. Her research focuses on understanding unethical behavior in the workplace. This includes work on social status drives and unethical behavior, the role of social structure in moral disengagement, and work on the identity and legitimacy challenges that ethics and compliance officers face in fulfilling the ethics role. More recently, Niki has also started a project to examine the challenges that dyslectics face in the workplace, and how they deal with those. Niki has published in Organization Science, Organizational Behavior and Human Decision Processes, Annual Review of Psychology, and in the Journal of Business Ethics, and recently won the Best Business Ethics Paper Award, sponsored by the Journal of Business Ethics, of the Social Issues in Management Division of the Academy of Management. Prior to earning her Ph.D., Niki worked for KPMG Forensic in Brussels, Belgium, as a consultant in ethics management.
We are very, very pleased to have a special discussion over the next two weeks about some very interesting new research and data about managers and ethics. We will be interviewing the principal authors of a new article just published in October, titled https://pubsonline.informs.org/doi/10.1287/orsc.2017.1153 (“Middle Managers and Corruptive Routine Translation: The Social Production of Deceptive Performance”).
As an early holiday gift, Compliance Beat is happy to provide a wide-ranging Q&A about middle managers, ethical decision-making and the intersection with compliance! Forget festive feasting and gift-giving, for compliance stalwarts this is truly a great gift: insight on a subject where there hasn’t been much research.
Join us as we speak to:
Linda K. Treviño, Ph.D., Distinguished Professor of Organizational Behavior and Ethics in the Department of Management and Organization in the Smeal College of Business at The Pennsylvania State University. Professor Treviño holds a Ph.D. in management which has contributed to her unique focus on ethics as a management issue. She has published 90 articles, many in the field’s top research journals. She has also co-authored three books, an academic book on organizational ethics, another on academic integrity, and a textbook on business ethics that is in its sixth edition. In 2007, she was elected a member of the Academy of Management Fellows, a group that recognizes and honors members of the Academy of Management who have made significant contributions to the science and practice of management. Professor Treviño has taught students at all levels and has spoken to many academic and practitioner audiences. Her views on business ethics have been quoted in the press including the New York Times, the Wall Street Journal, Newsweek, Business Week, and other publications and she has appeared on CNBC. Her research has focused on the impact of individual differences and ethical culture on employee behavior, ethical leadership, speaking up about ethical issues, and the role of values in organizations among other topics. She maintains an active research program with current research that includes a focus on how scandal affects leaders and organizations, moral advocacy in ethical decision making groups and emotions in ethical decision making. Ethisphere named her one of the 100 most influential people in business ethics in 2015.
And:
Niki den Nieuwenboer, an assistant professor of organizational behavior and business ethics at the University of Kansas. She holds a PhD in Management from Rotterdam School of Management, Erasmus University, the Netherlands. Her research focuses on understanding unethical behavior in the workplace. This includes work on social status drives and unethical behavior, the role of social structure in moral disengagement, and work on the identity and legitimacy challenges that ethics and compliance officers face in fulfilling the ethics role. More recently, Niki has also started a project to examine the challenges that dyslectics face in the workplace, and how they deal with those. Niki has published in Organization Science, Organizational Behavior and Human Decision Processes, Annual Review of Psychology, and in the Journal of Business Ethics, and recently won the Best Business Ethics Paper Award, sponsored by the Journal of Business Ethics, of the Social Issues in Management Division of the Academy of Management. Prior to earning her Ph.D., Niki worked for KPMG Forensic in Brussels, Belgium, as a consultant in ethics management.
Finally, tune in next week for the conclusion of this interesting interview.
Closing the loop on some trends we thought might be important back in January of 2017.
First, we all had (and still have) deregulation on our minds. So far, while there has been a lot of discussion about the possible effects of deregulation, it’s fair to say that compliance issues are still being driven by regulatory enforcement and there does not seem to be any fundamental difference to how (and how frequently) regulations are being enforced. As we discussed back in January, a real danger exists that some might think that all the talk about deregulation somehow means that there is to be less focus on compliance at organizations. Eric notes that whatever happens with regulators, organizations still need to hold the line on their values and their internal expectations.
Second, we talked back in January about reputational risk and, in particular, the impact of social media use on reputational risk. The intersection of compliance and these issues is still top of mind and key risk for many organizations.
Third, we certainly see that the risk-based approach to compliance remains an important and necessary piece of the puzzle. In 2017 we saw steps forward, including the https://www.justice.gov/criminal-fraud/page/file/937501/download (February 2017 Guidance from the Department of Justice), which have helped organizations better contemplate what makes a risk-based program for their organization. We should expect that there will continue to further developments on this front as we move forward.
Looking forward to tracking these trends, and others, as we head into a New Year!
What does the Deputy Attorney General’s recent comments about various Department memorandum and informal statements mean for compliance and ethics. For more information on the DAG’s October statement, you can review this excellent https://www.lw.com/thoughtLeadership/deputy-attorney-general-review-DOJ-corporate-enforcement-policies (commentary).
The statement suggests that many of the DOJ memos discussing corporate prosecutions we are familiar with may be consolidated (or revoked). The DAG has suggested all commentary should be within the https://www.justice.gov/usam/usam-9-28000-principles-federal-prosecution-business-organizations (US Attorney’s Manual). But Eric points out that the process of updating the https://www.justice.gov/usam/usam-9-28000-principles-federal-prosecution-business-organizations (USAM) may take some time. There may also be some opportunity for the community to make its opinions known about any changes or additions before the process is finished.
The bottom line is that the compliance and ethics community should pay attention to this process and any possible changes.
This time Eric reflects on the annual SCCE Compliance and Ethics Institute in Las Vegas.
While there are certainly other compliance and ethics events, the size and scope of the CEI is impressive and we noted three themes this year that apply not to just CEI, but the profession in general.
First, growth — and all that brings — including challenges. What does this mean and how does that apply to the role of compliance?
Second, we face a lot of uncertainty. But while organizations face a lot of regulatory uncertainty, and uncertainty generally, Eric talks about the resolve he sees with organizations moving forward with their compliance programs and their focus on ethical culture.
And finally, Eric talks about change. Changes in the profession abound and that means new expectations and best practices. The makeup of the profession, technological change and new ideas all mean that we have seen, and will continue to see, massive changes.
Eric also talks about the different topics discussed and resources that were on display in Las Vegas. Sessions covered a lot of ground and included a lot of practical information. An example would be several topical sessions on using social media, for example.
Also, we’d like to have you join us for our free webinar on building a risk-based program and you can sign up https://www.moreheadconsulting.com/no-more-risky-business/ (here).
Today Eric talks about third-party risks and some ideas for every organization to think about when thinking about third-party risk.
First, we encourage everyone to think outside the box and contemplate the actual third-party risks that their specific organization faces. We often think third-party risk just applies to organizations that operate overseas or have anti-corruption risks. Third-party risks are much broader and organizations should take time to consider it.
Second, Eric talks about how third parties are the “perfect storm” for risk. It’s hard to imagine any organization these days that doesn’t have third-party risk. Additionally, we talk a little about how third parties are logistically hard to monitor. Eric points out that despite these difficulties, organizations are liable for the actions taken on their behalf.
Third, there is a way to reasonable manage the risk organizations of all sizes and types face from third parties. Have a plan. Be consistent. Apply your limited resources based on a risk analysis. Guiding principles for due diligence include getting as much information about the third parties as you can, understanding the business rationale and establishing the ongoing relationship parameters.
Eric also talks a little about tiering or ranking risk. We list off several factors that you can consider when ranking the risk of a third party.
This time Eric talks about three practical areas to consider when evaluating and developing “tone from the top” at your organization.
First, we examine what the expectations should be for the CEO or top executive of the organization. The CEO should be “present” in a real way and this can be measured by both the frequency and content of messaging. We talk about specific issues that CEO’s can speak to, including retaliation, and how these specific, practical messages can have a real impact.
Secondly, we talk about the importance of a diversity of messages and messengers. Making sure there is broad involvement in compliance communication from leadership throughout the organization including operational business units.
Lastly, we talk about a often underutilized resource and voice for “tone from the top”: the board of directors. If you have an engaged board, harness that energy and interest to get them to communicate to the organization about the important matters of compliance and ethics. This can be really effective and can help[ strengthen those bonds between the compliance program and the board.
https://www.moreheadconsulting.com/no-more-risky-business/ (Join us) for our free November webinar on risk-based compliance and ethics programs.
This week, we prepare to go to the annual SCCE CEI in Las Vegas. Recent events make the trip more somber, but we look forward to seeing old friends and meeting new ones. Eric speaks with SCCE’s Adam Turteltaub to discuss what’s new this year at the Compliance and Ethics Institute and some of the thought that goes into planning and organizing the annual event.
Eric also talks a little about the concept of “right action” and moving forward with your goals despite conflict.
It was a year ago that we launched Compliance Beat as we were preparing for the Institute. A big thank you to everyone out there that listens to us weekly. We hope to continue to provide interesting and useful content on compliance and ethics for years to come.
What is the “bare minimum” an organization needs to have an effective compliance program? Today we have part II of our discussion of what minimum requirements for an effective compliance and ethics program might be.
Eric talks a little about the focus on organizational guidelines versus the https://www.ussc.gov/guidelines/2016-guidelines-manual/2016-chapter-8 (Sentencing Guidelines) as a whole. Eric also talks about the importance of reading the guidelines yourself and looking at the nuance of the standards themselves.
We pickup where we left off, discussing the last three hallmarks of the “Seven Hallmarks”.
Eric talks about monitoring and auditing, and how this broad category has no application notes from the Sentencing Commission to help guide the reader. We also discuss the “evaluating effectiveness” periodically and how this oft overlooked second part of hallmark five should be carefully considered. Finally Eric talks a little about anonymous reporting as contemplated by the guideline.
We also discuss hallmark six which discusses incentives and discipline. Eric spends some time talking about consistent enforcement and promotion — and how considering publicizing results and issues can help promote the program and aid in improving organizational justice. Eric also talks about implementation of incentives and what incentives might look like.
We talk about final hallmark lucky seven. When criminal conduct is detected, organizations must respond appropriately including making modifications to the compliance and ethics program. Eric talks about how this may include getting outside help.
Finally, Eric talks a little about 8B2.1(C) of the Guidelines, which talks specifically about the importance of periodically accessing compliance risk.
What is the “bare minimum” an organization needs to have an effective compliance program? Is that even the right question? Eric talks about a common inquiry that people often have about the “Seven Hallmarks” of the https://www.ussc.gov/guidelines/2016-guidelines-manual/2016-chapter-8 (Sentencing Guidelines), and that is: what must we do? In Part I of a two-part series, Eric talks about how the Guideline standards are really the floor for expectations. We spend some time also talking about the guidance in the Guidelines, in particular the importance of the http://www.compliancebeat.com/effective-board-directors-training-part-ii/ (Application Notes) of the Guidelines that are often overlooked.
Eric also discusses the treatment of different sized organizations regarding compliance commitment and resources. Eric also mentions that valuable data and information is available at thehttps://www.ussc.gov/guidelines/organizational-guidelines ( US Sentencing Commission’s website). We discuss the importance of compliance professionals being directly familiar with the Sentencing Guidelines.
Finally, Eric walks through the first four of the “Seven Hallmarks”. We discuss the fact that what the Hallmarks aren’t even necessarily agreed on all the time (see Joe Murphy’s discussion http://complianceandethics.org/what-are-the-sentencing-guidelines-seven-elements/ (here)). Eric talks about standards, individuals with a compliance program responsibilities, due diligence to ensure no bad actors with program authority and communicating the program.
Your board of directors must stay informed about their compliance duties and stay engaged in your compliance and ethics program to fulfill their obligations as board members. Training your board of directors is a key responsibility for compliance professionals. At times, training your board of directors can be a real challenge.
In this second part of a two-part podcast series, Eric again speaks to how can you effectively discuss compliance responsibilities and the key role of the board in compliance with board members and follows up the previous episode with two additional areas of training you should consider.
First, the board needs to be aware of, and educated on, the specific compliance risk for the organization and the board. There needs to be discussion on board-specific risks, or risks based on the director’s roles, and this often includes conflicts of interest, insider trading and other topics tailored to the board’s position and role. More importantly, the board needs to be trained on, and able to engage on, issues of critical risk for the organization. Remember, the USDOJ talks about the directors having “expertise” and being aware of the risks of the operation. They cannot be engaged and knowledgeable without study and training. Deciding what to train on is tied to your risk assessment and consider carefully what the board should be trained on based on the top tier compliance risks you face.
Additionally, Eric suggests that it is important to provide the “business case” for compliance and ethics at the board level. This is important since the board is ultimately responsible for the culture, so including important data and information about how compliance and ethics, particularly a strong ethical culture, will arm the board for their important role. Eric talks a little about some of the sources of information out there for compiling the business case, including the link between culture and performance, recruiting and retention and reputation.
Be sure to register for our upcoming webinar https://www.moreheadconsulting.com/code-of-conduct-webinar/ (“The Road to a New Code of Conduct: How to Use Best Practices to Update Your Code of Conduct”) on Wednesday, October 4 at 12:00pm CST. Register https://www.moreheadconsulting.com/code-of-conduct-webinar/ (here).
Your board of directors must stay informed about their compliance duties and stay engaged in your compliance and ethics program to fulfill their obligations as board members. Training your board of directors is a key responsibility for compliance professionals. At times, training your board of directors can be a real challenge. How can you effectively discuss compliance responsibilities and the key role of the board in compliance with board members, both new and old? What is the source law and standards for director’s responsibility for compliance? What risks do they face for not being on top of these responsibilities? Compliance is the responsibility of the full board, not just the audit or compliance committee. Eric talks about the expectations outlined in the Sentencing Guidelines and recent United States Department of Justice Fraud Sections’ new guidance, the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs). Finally, Eric talks about how important it is to provide real information to the board about the content and operation of the organization’s specific compliance and ethics program.
Be sure to register for our upcoming webinar https://www.moreheadconsulting.com/code-of-conduct-webinar/ (“The Road to a New Code of Conduct: How to Use Best Practices to Update Your Code of Conduct”) on Wednesday, October 4 at 12:00pm CST. Register https://www.moreheadconsulting.com/code-of-conduct-webinar/ (here).
This time Eric tackles some common (and stubborn) myths about regulatory enforcement and criminal liability. First, we tackle the “Trump Factor”, and the notion that reduced regulation and enforcement is on the way. Eric talks about what we really are seeing with enforcement and the statements coming from regulators and prosecutors, including the USDOJ. Eric also points out the long lead times for investigations and actions means that we are unlikely to see this effect anytime soon. Additionally, it’s important to remind ourselves that the costs associated with misconduct issues, internal investigations and ongoing enforcement inquiries can pile up. Eric also mentions using data, such as http://ussc.gov (sentencing statistics), to show that the rhetoric doesn’t match the reality. We also talk about a long-standing myth that some organizations are “too small” to be noticed by regulators and prosecutors. Eric debunks this often-repeated myth and cites the http://ussc.gov (US Sentencing Commission) statistics that show small organizations take the biggest hit more frequently than larger organizations. We also talk about how organizations in non-highly regulated industries still have liability and face similar consequences. Finally, Eric also talks about the myth that there are only few issues and risk areas that an organization faces. We discuss just how important is is to understand your organization’s specific compliance risk profile.
This time Eric discusses case management and reporting benchmarking. First, why is it a good idea to have a plan in place to gauge the effectiveness of this aspect of your compliance program? Eric explores why it’s a good idea to have a business case put together so that you can budget for tools in the first place. We also talk about how “effectiveness” is not a black box and applies to everyone. Expectations include those detailed in the most recent https://www.justice.gov/criminal-fraud/page/file/937501/download (DOJ guidance). Measurement should look at the process you have in place. What’s the plan and how is it followed. Does compliance have access to all relevant data about reporting and case management? How does the program consider data from the cases and reports in making changes and addressing controls? These are all issues that will need to be explored. We also discuss what to look for (or what to be aware of) when looking at reporting data. Trend data and surveys are helpful data sources to consider as well. Resource benchmarking to peers is also something to consider. Check out the http://m1.corpedia.com/resource_database/CEPEReport.pdf (SCCE & NYSE CEPE Report) to find some of the data mentioned in the podcast that can be helpful for benchmarking reporting and case management resources.
In this episode Eric has a conversation with Ricardo Pellafone, the founder of http://www.thebroadcat.com/ (Broadcat). Eric and Ricardo have a wide-ranging discussion about compliance myths that seem to have a lot of staying power. Including, how having a lot of resources and being very busy does not necessarily equal an “effective” program. As Ricardo paraphrases Hui Chen: “doing more is not better, smarter is better”. They also discuss how compliance really must conform to the same business and effectiveness measures as any other part of the organization. Ricardo also talks about the business case for compliance and Eric talks about some concrete examples of how to make the case. Ricardo and Eric also talk about compliance officers feeling like they should “do it all” and discuss how outside resources can be thoughtfully used. They also talk generally about overstretched resources and multiple roles. Finally, Ricardo asks Eric about taking on the compliance role and they discuss commitment from the organization, “noisy exits” and the options that compliance officers have when things start to go sideways. Join us for a spirited conversation.
In this episode Eric delves in a little deeper on a common question: who should be involved in a code of conduct project? Of course this depends a lot on what kind of project is being undertaken. Should you revise internally or bring in an outside team? What resources are available to your organization to conduct the project? Often organizations have the expertise, vision and skills to complete a code project internally — but do they have the time? Eric addresses these common issues that come up with many, many organization’s code projects. Eric also discusses the thought process a team might want to go through when making the call right at the beginning when you are first scoping out such a project. Eric also walks through some of the stakeholder expectations you will want to consider when contemplating a code project. Finally, Eric also talks about goals. Like any successful project, a code of conduct project needs clear goals from the beginning.
Recently we’ve seen more activity from the Department of Justice (Fraud Section) and other regulators both in the United States and internationally that address compliance and ethics program standards and effectiveness. One topic that’s come up informally in some conversations is whether the Sentencing Guidelines still hold a central role in defining “effectiveness” for a compliance program. Eric addresses these recent questions head-on. The Sentencing Guidelines have staying power — going back to 1991. And they still underpin most, if not all, of the standards and guidance we see not only from the Department of Justice in the USA, but also internationally. Eric talks also about how the US Sentencing Guidelines’ success hinges on their unique nature and design. While new guidance and standards build and adapt these base standards, the origin and basics remain the same. The Guidelines aren’t going away. Bottom line. Guidance from the USDOJ and other organizations have changed and been abandoned over time and as administrations change in particular. While the https://www.justice.gov/criminal-fraud/page/file/937501/download (guidance) from the Fraud Section is new and evolutionary, it is subject to change in a way the Sentencing Guidelines are not.
Since incentives were first introduced in the Sentencing Guidelines there has been little guidance about what exactly make up incentives for compliance. It’s also probably no surprise that one of the most underdeveloped parts of many compliance and ethics programs is the application of incentives. In this episode Eric talks about some practical things organizations can do to consider incentives and talks about different ways that organizations have addressed incentives in the past and what probably has worked and what may not be so effective. Eric provides some advice on ways to approach the incentive issues and discuss the implementation of incentives with the applicable internal audience. Finally, Eric provides some practical advice for organizations on how to proceed in considering incentives past, present and future.
Should you have a web-based code of conduct? A common question that many organizations have when they are updating their code of conduct is should the code be a web-based document? If not, how might an organization use both internal and external-facing web resources? Eric has some ideas about adapting the code, and code content, for the web and how you might leverage these resources for a more useful implementation. Bottom line is that one size does not fit all and it’s important for organizations to really think about their audience and how best to reach them.
This time Eric talks about different ways compliance and ethics personnel can help keep the program and an ethical culture front of mind. Eric discusses how you can leverage slower times (often in the summer) to conduct site visits and otherwise engage in outreach. We also provide some practical examples of engagement activities to try and get the stakeholders to be more involved with the program through competitions and other activities. Eric talks about how getting people involved can be very powerful for both them and your program. Eric also encourages compliance programs to be creative and try something new, different or maybe even a little outside the box. This can be a good way to fill the common gaps around informal communication and reaching the stakeholders outside of normal channels and tools. Break out of the normal compliance mold!
In this episode Eric revisits a topic that is front-of-mind for many these days: involving managers in compliance. Eric discusses how research has shown involving the middle can improve concerns around retaliation and positively impact the culture of the organization. One way to better involve the middle is to make sure managers are armed with the knowledge and resources to be a successful conduit for the program. Eric provides some practical ideas on how, and with what, to arm the managers. Eric talks also about involving the managers in specific initiatives or projects and provides some specific examples of projects that can built excitement and engagement. Another way to get managers involved, and invested, is to tie reviews and performance evaluations of managers to their involvement in the program. Eric discusses some specific, objective ways to consider this. As a bonus, Eric also discusses informal communication through managers, a key piece of any program and a significant way managers can be involved. Eric describes some practical considerations for starting a manager communication plan from scratch.
What are some common mistakes that compliance professionals make when communicating about compliance? Since 1991, when the US Sentencing Guidelines first addressed the importance of communication in tandem with formal compliance training, compliance officers have occasionally struggled with how frequently and in what ways to address compliance communication. In this episode, Eric talks about some common issues organizations have faced when considering the more informal side of efforts to educate and inform employees and other stakeholders about compliance risks and issues. Eric also focuses on ways organizations can address these common situations and how the recent the Department of Justice’s recent guidance, the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs), and other standards effect communication requirements and expectations. Finally, Eric also offers some specific practical ideas for organizations to consider when addressing compliance communication efforts.
What are some strategies and options for the compliance officer that is aware of misconduct occurring at their organization? This can be one of the most complicated topics that a compliance officer can face. And there are not always a lot of good solutions. But what options should the compliance officer consider? And what should the compliance office expect from their organization? This week, Eric explores the answers to these questions.
Three Questions with https://www.linkedin.com/in/garin-bergman-90b43b12/ (Garin Bergman), President, http://getpalmtree.com/ (Guidant Technology, LLC)
Garin L. Bergman founded Guidant Technology in May 2016 after spending almost 15 years in various compliance roles.
Prior to Guidant, he spent five years at http://www.idexcorp.com/ (IDEX Corporation) as the Chief Compliance Officer and three years at http://www.dovercorporation.com/ (Dover Corporation) as Director Corporate Compliance where he developed formal compliance programs for thousands of employees around the world. While at both IDEX and Dover he focused his attention in a number of areas including data privacy, getting the company Safe Harbor certified, refreshing the Code of Conduct and the global hotline, establishing an online training program, developing compliance audit programs and updating and creating a number of compliance policies.
Garin spent six years at http://company.ingersollrand.com/ircorp/en/index.html (Ingersoll Rand) (IR) from 2002 – 2008 where he specialized in anti-corruption reviews and investigations as well as internal audit projects. He worked his way up from a senior auditor to an Audit Manager while spending 18 months in Shanghai setting up the IR Asia Pacific audit department.
When we think about third-party management, we often think of due diligence. The https://www.justice.gov/criminal-fraud (Department of Justice Fraud Section’s) new compliance and ethics guidance, the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs), only mentions due diligence one time. The Evaluation contemplates a holistic, ongoing approach to third-party management in which the process is integrated into other functions, such as procurement.
In this episode, Eric talks about three key takeaways from the Evaluation of Corporate Compliance with regards to organizations’ relationships to third-party. He looks at what a holistic approach to third-party management looks like, how to create management processes that integrate other business functions, and how to build a risk-based process that effectively identifies risk and responds to it.
Three Questions with http://www.lathropgage.com/thoush (Tedrick Housh), Partner, http://www.lathropgage.com/ (Lathrop & Gage, LLC)
With an extensive employment litigation practice, Tedrick practices in the rapidly developing legal world of data security and privacy. Tedrick serves as a leader of Lathrop & Gage’s work on data privacy, website terms of service, data security and data breach issues. He assists clients with the technological, logistical and legal issues arising from the loss or disposal of personally identifiable information and personal health information. Tedrick is a frequent presenter on data privacy and security, social media, employment law and the workplace.
The new https://www.justice.gov/ (Department of Justice)‘s guidance, https://www.justice.gov/criminal-fraud/page/file/937501/download (the Evaluation of Corporate Compliance Programs), discusses the “design and accessibility” of written standards, such as your code of conduct. Does this focus on “design” in particular mean that organizations should reconsider or review the use of interactivity for their code? What does the Department’s focus on “communication” and “evaluation” of written standards affect how an organizations evaluates and implements any interactive features? Eric discusses what the new focus on design and accessibility might mean and how organizations can address these expectations in their code of conduct review, revision and development processes.
Eric also finishes his interview with https://www.bsr.org/ (BSR’s) Alison Taylor. Her recent https://www.bsr.org/en/our-insights/report-view/the-five-levels-of-an-ethical-culture (white paper), The Five Levels of Organizational Culture, provides a lot of food for thought on how to implement ethical culture in an organization. She examines five different levels of ethical culture that need to be considered and we walk through the last half of her findings. In this final part of a two part interview, we talk about group socialization, the wider organizational culture and how organizational culture impacts outside the organization. Alison heads the sustainability management practice at https://www.bsr.org/en/about/staff-bio/alison-taylor (BSR).
To see how an interactive code of conduct works, check out https://www.youtube.com/edit?o=U&video_id=VakiFb9tEKo (Eric’s demonstration of our sample interactive code of conduct).
You can also download our sample interactive code of conduct on our https://www.moreheadconsulting.com/resources/ (resource page).
How does the new Department of Justice’s new guidance, the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs), from February 2017 approach the requirements for written standards, including code of conduct? Eric walks through three key takeaways from the Evaluation of Corporate Compliance Programs on how organizations should document and conduct their code of conduct development and review process. We also have Part One of a two part Special Interview with Alison Taylor of https://www.bsr.org/ (BSR) on her new white paper, https://www.bsr.org/our-insights/report-view/the-five-levels-of-an-ethical-culture (The Five Levels of Organizational Culture).
While neither the new guidance, nor the Sentencing Guidelines that proceeded it by 25 years, speak specifically about code of conduct, it does establish standards for development, maintenance and assessment of “policies and procedures” — much as the Sentencing Guidelines speak to “written standards”. Reading this new guidance should be a wake-up call for organizations that do not currently have an established process for review and revision of their code and other written standards. There is a clear expectation that organizations will have a plan, involve a cross-functional team and periodically assess their progress and success. In this podcas,t Eric will talk about those expectations and what organizations should consider.
https://www.bsr.org/en/about/staff-bio/alison-taylor (Alison Taylor’s) recent https://www.bsr.org/en/our-insights/report-view/the-five-levels-of-an-ethical-culture (white paper), The Five Levels of Organizational Culture, provides a lot of food for thought on how to implement ethical culture in an organization. She examines five different levels of ethical culture that need to be considered and we walk through her findings. In Part One of a two part interview, we talk about the intersection of individual ethics and the broader corporate culture. Alison heads the sustainability management practice at https://www.bsr.org/en/about/staff-bio/alison-taylor (BSR).
As an alumni of https://www.baylor.edu/ (Baylor University), Eric has closely followed the allegations that Baylor University http://www.wacotrib.com/news/courts_and_trials/baylor-legal-filing-calls-claims-of-women-suing-school-under/article_b4c69255-fb60-567a-9876-7a05411a37d1.html (violated its obligations under Title IX). Six months after his first episode looking at this issue, Baylor University, unfortunately, is still in the news. What’s going on? What lessons can compliance professionals learn from Baylor University and how this compliance failure has been handled?
Baylor University’s Board of Regents have provided a playbook of what not to do when responding to a compliance failure. When looking at how Baylor has handled this situation, Eric considers three key teaching moments. First, Baylor’s problems dispel any belief that private companies or private universities can handle these issues internally and without public scrutiny. Second, he considers how Baylor’s response continued to damage its reputation and how reputational harm damages the University overall. Third, he talks about the importance of transparency.
At the end of the episode, Eric lays out three steps that https://www.baylor.edu/mediacommunications/news.php?action=story&story=180522 (Baylor University’s new president, Dr. Linda Livingstone,) should take to repair the reputational harm and restore confidence in the University. The allegations that Baylor faces are compliance failures and evidence that the organizational culture needs to change. Dr. Livingstone has a hard road in front of her. But it is possible to come back from this sort of scandal when you commit to transparency and creating a strong ethical culture.
What’s the difference between compliance and corporate culture? Is there a difference? How do they work together? In this episode, Eric looks at how two airlines, United and Delta, responded recently to challenges they faced and how their responses speak to their corporate cultures. Both airlines faced operational failures. The juxtaposition of their responses are excellent teaching moments and examples that compliance professionals can give to demonstrate the relationship between compliance and corporate culture.
https://www.nytimes.com/2017/04/11/business/united-airline-passenger-overbooked-flights.html?rref=collection%2Ftimestopic%2FUAL%20Corporation&action=click&contentCollection=business®ion=stream&module=stream_unit&version=latest&contentPlacement=9&pgtype=collection (United has a bad week.) Much attention has been focused on the gentleman who was recently physically and forcefully removed from a plane. But there is a much bigger issue of corporate culture that ought to be the focus here. It is clear that several United employees who witnessed this incident abdicated authority or failed to question actions of other employees. This inaction speaks to United’s culture in way that ought to be of more concern more than the incident.
When considering what happened when United employees, we must look at how many individual failures had to happened for this to occur and what this tells us about United’s culture. When employees don’t stand up for what’s right, you have to look at corporate culture.Tweet This Compliance and corporate culture aren’t in a box that you take off a shelf. Growing an ethical culture is hard work. Corporate culture and compliance are integral to everyday operation. United’s challenge show us that corporate culture greatly affect what happens when frontline employees witness misconduct and fail to report it. These failures affect how an organization conducts its business.
https://www.usatoday.com/story/news/nation-now/2017/04/08/thousands-delta-flights-canceled-days-after-storms/100205960/ (Delta had to cancel 3,000 flights when extreme weather shut down Atlanta’s airport.) It was a difficult situation and a much bigger disruption to operations than the incident United faced. But there was a night and day between how the airlines addressed the problem as Eric witnessed firsthand when he was stuck at Atlanta’s airport because his Delta flight was cancelled. Each Delta employee he encountered had an attitude that recognized the extent of passengers’ inconvenience and also tried to make their experience better.
When looking at two operational failures and the airlines’ reactions, you can the impact of a strong ethical culture and the apparent lack of one. Delta’s culture was flexible to take on operational failure. How would United employees handle the cancellation of 3,000 flight?
How do you approach a culture like Delta’s? There’s no easy answer when you are considering how to fix an unhealthy corporate culture. Clearly, one part of fixing corporate culture is the message from the top of the organization. The tone from the top must be strong about values and the fact that you can come forward and speak up when others act unethically or illegally. These two examples are important examples for your business units because they show the real consequences of corporate culture on organizations’ bottom lines.
Special Interview with https://www.linkedin.com/in/laura-kidd-cordova-4ab4391b/ (Laura Cordova), Former Assistant Chief, https://www.justice.gov/ (Department of Justice), Criminal Division and Partner, https://www.crowell.com/ (Crowell & Moring, LLP)
Before joining Crowell & Moring, Laura prosecuted healthcare fraud in the Fraud Section of the Department of Justice. In this interview, Eric and Laura discuss what the Department of Justice looks for in an effective corporate compliance program and how the government makes charging...
As Eric returns from the Society for Corporate Compliance & Ethics European Ethics & Compliance Institute in Prague, he shares the hot topics of discussion at the conference. He discusses his three main takeaways from the conference.
First, there is strong interest in corporate culture in Europe. Focus on ethical culture and compliance can vary between countries and cultures. In the past, many have held the belief that emphasis on compliance programs is not as strong in Europe as it is the US. But that’s not a fair assumption. There is a strong recognition that healthy corporate culture is essential to an effective compliance program.
Second, Eric found that European compliance professional recognized strongly the impact of collecting data and using that data to inform the development of their compliance programs. He saw a very strong commitment to benchmarking programs and a strong focus on gathering data internally for measuring performance of compliance programs.
Third, there was discussion and reaction to political changes in US and in Europe. There was particular concern about President Trump’s statements during the campaign about rolling back regulations and how this may impact perception of the need for strong compliance programs.
Just a few years ago, Europe was considered behind the United States in compliance and ethics. That is not the case today. Eric looks at three hot topics in compliance and ethics in Europe as he prepares to leave for the http://www.europeancomplianceethicsinstitute.org/ (Society of Corporate Compliance and Ethics European Compliance & Ethics Institute) in Prague this week.
In some areas, European compliance and ethics standards are exceeding the United States’ standards. In recent years, regulators in Spain, France, and other countries have consistently recognized the importance of compliance and ethics programs. In the context of anti-corruption, the http://www.legislation.gov.uk/ukpga/2010/23/contents (United Kingdom’s Anti-Bribery Act), the Brazilian Clean Companies Act, and other efforts to curb corruption, Europe has leapfrogged the https://www.justice.gov/criminal-fraud/foreign-corrupt-practices-act (Foreign Corrupt Practices Act), which used to be the primary legal mechanism internationally for fighting corruption. For instance, the UK Anti-Bribery Act is clearly a newer law than the FCPA and expands coverage. This leads to the questions: Will Europe become the new leader in defining what makes an effective compliance and ethics program?
There are a number of similarities between what is happening in Europe and the United States. Compliance professionals all over the world are focusing on corporate culture, measuring employees through surveys, and addressing issues like retaliation and observed misconduct. The notion that Europe is behind in compliance and ethics is not accurate anymore. We are now on the same page.
As much as we see similarities, there continue to be significant differences, particularly in data security. http://www.eugdpr.org/ (European Union’s General Data Protection Regulation) (GDPR) will go into effect in spring of 2018. This year is the last year to come into compliance with the GDRP. Organizations need to look carefully and determine whether they have any exposure under the GDRP because there are no safe harbor provisions.
When we are talking about risk assessment and the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs), there are three areas to really focus on. First, the Evaluation considers how organizations create and use their methodology for risk assessment. Second, this new guidance focuses on how the data you gather informs the choices you make in your compliance and ethics program. Third, the Evaluation introduces the notion of manifested risk.
The Evaluation asks specifically: what methodology has the company used to identify, analyze and address the particular risks it face? The DOJ doesn’t want you to just have any risk assessment process, but have a process that is tailored to your company.Tweet This It’s similar to the teacher who asks you to show your work. Here, you must show how you developed your methodology and why. You must also consider the risk assessment’s recommendation and explain why you choose, or don’t choose, to implement the recommendations. Eric walks you through this process and explains how you can meet these standards.
This new guidance also suggests that the DOJ wants to know how you gather your information to analyze. What metrics, information and data are you collecting to help detect misconduct? How has it informed the compliance program? Many organizations gather data in a number of ways—through hotline reports, direct reports to management, and other human resources data. The Evaluation is a clarion call for organizations to aggregate data and show how the information you collect affects your program.
The Evaluation raises the idea of manifested risk, which is a new concept to many people. Manifested risk is risk that is likely to occur in your organization. For instance, if you know that the risk of bribery is high and there have been reports of bribery in the past, then bribery is a manifested risk for your organization. Many organizations spend time and money addressing risks that they are not likely to face. You want to look at your organization’s history and its operation to determine what your real risks are and then address those risks. You cannot be willfully blind.
When considering risk assessment, you must always consider the frequency of your assessments. There’s no hard and fast rule, but you should complete a risk assessment periodically.
Three Questions with https://www.linkedin.com/in/mkelly1971/ (Matt Kelly), Editor & CEO at http://www.radicalcompliance.com/ (Radical Compliance)
Matt Kelly started his career in compliance and ethics as the managing editor of https://www.complianceweek.com/ (Compliance Week) magazine. He spent over ten years of his career at Compliance Week, achieving the position of Editor and Publisher. Before working at Compliance Week, Matt was a freelance newspaper writer. After leaving Compliance Week, Matt founded his own company, Radical Compliance. Radical Compliance provides consulting and commentary on corporate compliance, audit, governance, and risk management. Radical Compliance also serves as http://www.radicalcompliance.com/posts/ (Matt’s personal blog). Matt writes and speaks frequently on corporate compliance, audit, and governance, and now works with various private clients to understand the those fields and to develop go-to-market strategies or provide other assistance in reaching audiences of compliance professionals.
What does the https://www.justice.gov/criminal-fraud (Department of Justice Fraud Section’s) new https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs) say about your compliance officer’s relationship with your Board of Directors? There are three salient points that you can take away from the Evaluation of Corporate Compliance Programs with regard to the Board of Directors. Some of these points aren’t necessarily new concepts, but they certainly give us more guidance in terms of what the Department of Justice is looking for when considering this relationship. In this episode, Eric takes a deep dive into the Evaluation of Corporate Compliance and how it relates to your Board of Directors.
The Evaluation of Corporate Compliance Programs asks: What compliance expertise has been available on the Board of Directors? What does this mean? Does the DOJ care about the personal experience of you Board members with regard to compliance? Compliance expertise is not only about what individual Board members bring to the table, but also the type of expertise that Board members develop as they sit on your Board of Directors. Compliance expertise can be developed through training. This is a very good reason to think about how you are training your Board of Directors and what type of expertise that you are helping them develop. Eric talks about training your Board of Directors to ensure that they have the type of compliance expertise that this new guidance contemplates.
We already know from the http://www.ussc.gov/guidelines (Federal Sentencing Guidelines) that the person in charge of the day-to-day operation of your compliance and ethics program should have regular access to your Board of Directors. The Evaluation of Corporate Compliance Programs reinforces this idea of regular contact between the Board of Directors and you compliance officer. It’s important to note that this new guidance asks about private meetings between your Board and your compliance officer. Eric discusses what this means and how you might accomplish private meetings effectively.
An interesting new point that the Evaluation of Corporate Compliance raises is your compliance officer’s access to external auditors. In this guidance, the Department of Justice talks about your compliance officer’s access to the Board of Directors and/or external auditors. This is surprising and different than previous guidance.
The Evaluation of Corporate Compliance Programs also asks about the information that your Board of Directors has examined. What kind of information gets to your Board of Directors in quarterly reports? You need to consider what you are providing and why so that you have justifiable reasons for the type of information that you give the Board quarterly. There are good reasons not to do a data dump, but you must think about what information gets to the Board of Directors. You may want to think about making reports to the Board of Directors outside of the quarterly meeting.
The relationship between your Board of Directors and your compliance function is a key relationship. This relationship is as important as your organization’s ethical culture. Without a strong relationship between your compliance officer and your Board of Directors, you will be facing trouble down the road.
Three Questions with https://www.linkedin.com/in/jmlevyny/ (Jean-Marc Levy), Chief Executive Officer of http://www.complysci.com/ (ComplySci)
Jean-Marc came to the field of compliance as the former Vice President of the https://www.nyse.com/index (New York Stock Exchange) and the Head of Global Issuer Services. He has extensive experience in the financial services industry. Jean-Marc has a track record of building fast-growing information and services businesses. He was Chief Financial and Business Development Officer with TheMarkets.com, a financial technology firm he helped grow to a user base of more than 2,400...
The Department of Justice Fraud Division released the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs) in middle of February without any announcement or fanfare. Is it a checklist? It looks like a checklist, but the DOJ says it’s not a checklist or formula. Some of the information in the Evaluation you’ve heard before, but the “checklist” expands on it. If it’s not a checklist, what does it all mean? How can it help you? Eric examines each of the Sample Topics and Questions that the DOJ puts forth in this new guidance.
In this first of what has turned into a three part series, Eric discusses in depth five of the Sample Topics and Questions covered in the Evaluation. In this edition, Eric talks about:
Remedying Misconduct
Involvement of Senior and Middle Management in the Program Compliance Autonomy and Resources
Policies and Procedures
Risk Assessment
This week, in part two of this special edition, Eric delves into:
Training and Communication
Confidential Reporting and Investigations
In part three, Eric will cover:
Incentives and Disciplinary Measures
Continuous Improvement, Periodic Testing and Review
Third Party Management
Mergers and Acquisitions
If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Read Full Transcript
Welcome to Compliance Beat, the podcast for compliance and ethics professionals. We provide practical insights and answer your questions about compliance and ethics. Together we'll stay up to date on current treads so that your program stays effective. Brought to you by Moorhead Compliance Consulting. Here's your host Eric Moorhead.
Hi and welcome to the third part of a three part special edition of the podcast where we're talking about the evaluation of corporate compliance programs document that came out of the fraud section at the US Department of Justice just a few weeks ago. We've been talking, walking through the different parts of the document and I'm gonna continue on today and finish finally gonna finish today talking about the last few sections.
If you haven't already subscribed to Compliance Beat please do that on our website or on iTunes. Please give us a review, if you have the time to do so, we sure appreciate it. And also check us out at moreheadconsulting.com. We have some other additional resources there that you might wanna check out.
The next part, incentives and disciplinary measures, looks into an area that I think, as also kind of commonly, I wouldn't say overlooked, but less well developed. The first section, which talks about accountability and discipline, and how a company resolves and responds to misconduct. It relates to the things we were just talking about.
Were managers held accountable, is a question. Did the company's response and consider disciplinary actions for supervisors? So they're really looking at what the company did to discipline in a systematic way for the failure or misconduct. And they're focusing, really, really focusing on data and risk evaluation here because they ask, what is the company's record?
E.g. Number and type of disciplinary actions on employed disciple relating to the types of conduct and issue. So what's the history here? What are the trends? So you need to be able to show when there's been a failure or something of this kind. And that, or an investigation that has led to disciplinary action.
How does that...
The Department of Justice Fraud Division released the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs) in middle of February without any announcement or fanfare. Is it a checklist? It looks like a checklist, but the DOJ says it’s not a checklist or formula. Some of the information in the Evaluation you’ve heard before, but the “checklist” expands on it. If it’s not a checklist, what does it all mean? How can it help you? Eric examines each of the Sample Topics and Questions that the DOJ puts forth in this new guidance.
In this first of what has turned into a three part series, Eric discusses in depth five of the Sample Topics and Questions covered in the Evaluation. In this edition, Eric talks about:
Remedying Misconduct
Involvement of Senior and Middle Management in the Program Compliance Autonomy and Resources
Policies and Procedures
Risk Assessment
This week, in part two of this special edition, Eric delves into:
Training and Communication
Confidential Reporting and Investigations
In part three, Eric will cover:
Incentives and Disciplinary Measures
Continuous Improvement, Periodic Testing and Review
Third Party Management
Mergers and Acquisitions
If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Read Full Transcript
Welcome to Compliance Beat, the podcast for compliance and ethics professionals. We provide practical insights and answer your questions about compliance and ethics. Together, we'll stay up to date on current trends so that your program stays effective. Brought to you by Moorhead Compliance Consulting. Here's your host, Eric Moorhead.
Hello and welcome to the second part of what's now going to be a three part special edition of Compliance Beat podcast. We're talking about the checklist that's not a checklist that came from our friends at the fraud division within the division of the Department of Justice. The document known as the Evaluation of Corporate Compliance Programs came out just under a month ago.
And we are walking through the different parts of the guidance that was provided within that document. If you haven't already, please listen to part one, where we talk about the first five. Sections. Also before we go too far, I've been remiss in the past in not saying this on the podcast, but if you haven't already, please, please go to compliancebeat.com or iTunes or wherever you happen to pick us up and subscribe.
We really appreciate it. It means a lot to us and it also helps us Move the podcast forward. And secondly, if you have time, please visit us at moreheadconsulting.com where we have resources related both to this issue and many others for you to take a look at and we recently redesigned our website as well.
So last week, we talked about the introduction and some of the background regarding this new document. And then also walk through the first five sections. Section six of the document talks about training and communication Training in communication obviously is something that's very familiar to everyone who's been building a program based on the guidelines standard for an effective program.
Training and communications are part and parcel of any effective program. I believe in the least of couple of additions before compliance we've talked about training and communication. And also talk about the fact that often times there's a lot of focus upfront...
The Department of Justice Fraud Division released the https://www.justice.gov/criminal-fraud/page/file/937501/download (Evaluation of Corporate Compliance Programs) in middle of February without any announcement or fanfare. Is it a checklist? It looks like a checklist, but DOJ says it’s not a checklist or formula. Some of the information in the Evaluation you’ve heard before, but the “checklist” expands on it. If it’s not a checklist, what does it all mean? How can it help you?
In this first of a two part series, Eric discusses in depth five of the eleven topics covered in the Evaluation as well as their subtopics. In this edition, Eric talks about:
Remedying Misconduct
Involvement of Senior and Middle Management in the Program Compliance Autonomy and Resources
Policies and Procedures
Risk Assessment
Next week, in part two of this special edition, Eric will discuss the remaining topics:
Training and Communication
Confidential Reporting and Investigations
Incentives and Disciplinary Measures
Continuous Improvement, Periodic Testing and Review
Third Party Management
Mergers and Acquisitions
If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
This is another episode in our ongoing series: Sentencing Commission Confidential. The http://www.ussc.gov/ (United States Sentencing Commission) is the steward of the organizational sentencing guidelines. It’s helpful to understand how the United States Sentencing Commission decides to amend certain guidelines before we answer this episode’s questions. Eric explains how the Sentencing Commission sets its amendment priorities, the comment process and how to participate in it, and the actual amendment process. The Sentencing Commission could amend the organizational sentencing guidelines every year, but these guidelines have been very infrequently amended. In the past, organizational guideline amendments have been very evolutionary, reflecting changes in compliance and ethics in the years preceding their amendment. In this episode, Eric answers:
What factors should we consider as we think about when the guidelines many be amended?
Who influences the Sentencing Commission’s amendment priorities for the year?
What areas of the organizational guidelines are more likely to be amended?
The Upshot
The Upshot this week is when you are thinking about when the organizational guidelines may be amended, take a close look at the Sentencing Commission’s priorities that come out in May or June of each year and keep an eye on who President Trump appoints to the Commission. As far as what might be amended, more talk and guidance around the concept of incentives is in order. There might be some consideration of making the fine provisions of Chapter 8 more applicable to offenses that are currently carved out.
Three Questions with http://www.joemurphyccep.com/ (Joe Murphy)
For 40 years, Joe Murphy, CCEP, has been a tireless champion of compliance and ethics in organizations and has done work in this field on six continents. Joe has published over 100 articles and given over 200 presentations in 17 countries. Joe is author of 501 Ideas for Your Compliance & Ethics Program and A Compliance & Ethics Program on a Dollar a Day. He is a Certified Compliance & Ethics Professional and a member of the board of the Society of Corporate Compliance & Ethics. Joe was named one of The National Law Journal’s 50 Governance, Risk and Compliance Trailblazers and Pioneers 2014.
If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Eric often encounters three myths that organizations believe when considering the liability they may face because of third-party partners’ or agents’ conduct. In this episode, Eric explains why believing these myths creates liability risks for your company.
Myth No. 1: Many people believe that third-party compliance is only anti-corruption, anti-bribery, and/or potential https://www.justice.gov/criminal-fraud/foreign-corrupt-practices-act (Federal Corrupt Practices Act) (FCPA) violations. Your risks, however, are much broader than just those three risk areas. Eric explains why you should be concerned about your third-party agents’ or partners’ compliance in many other risk areas.
Myth No. 2: Many organizations believe that if they are operating purely domestically and don’t conduct any business overseas, they don’t have third-party compliance concerns. It is important to realize that if your third-party agent is working overseas, you may have liability related to the third-party’s conduct overseas. Eric looks at some risk areas that you may not realize you face from third-party’s conduct overseas and how you can protect yourself from those risks.
Myth No. 3: You can rely on a third-party’s compliance program to protect your organization from liability resulting from the third-party’s conduct. Many people recognize that smaller organizations that don’t have as robust a compliance program can present a greater liability risk that larger organizations that have robust compliance program. No matter how extensive a third-party’s compliance program may be, you still face risk. Eric discusses the https://www.justice.gov/opa/pr/oil-services-companies-and-freight-forwarding-company-agree-resolve-foreign-bribery (settlements of FCPA violations related to Panelpina World Transport Ltd.), a large publicly trade, multinational corporation. In these cases, many organizations faced liability due to Panelpina’s conduct overseas. Eric explores what this means for your reliance on a third-party’s compliance program.
Three Questions with http://www.affiliatedmonitors.com/about/our-staff/eric-r-feldman/ (Eric Feldman), http://www.affiliatedmonitors.com/ (Affiliated Monitors, Inc.)
Eric Feldman is the Senior Vice President, Managing Director, Corporate Ethics and Compliance at Affiliated Monitors. Eric retired from the CIA in 2011 with over 32 years of experience in Inspector General oversight and federal auditing in the executive and legislative branches of government. He has served in executive positions with Offices of Inspector General at the Department of Defense, Defense Intelligence Agency, and CIA, and was the longest serving Inspector General of the National Reconnaissance Office (NRO) from 2003-2009. At the NRO, he presided over a highly successful procurement fraud prevention and detection program, widely recognized by the Department of Justice as a model throughout the federal government. Eric is a sought-after speaker in the field of compliance and ethics. Eric’s background and experience give him unique insight into the importance of corporate culture and the future of compliance and ethics. In this interview, Eric’s discussion goes far beyond the three questions, discussing issues that range from recent newsworthy compliance failures to the future of compliance and ethics.
If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
According to http://m1.corpedia.com/resource_database/CEPEReport.pdf (benchmarking data), less than half of organizations currently have third-party codes. There’s a current trend of partners asking each other to “sign off” or certify to codes of conduct. You must first assess your risk before answering whether you need a third-party code. Other controls you already have in place, such as contracting language, may fill the need. Third-party codes should be purpose made and they often cover far less information than employee codes of conduct. In this episode, Eric answers:
Why would your organization need a third-party code?Tweet This
What do these documents look like?
What type of information should they contain?
Eric also talks about the standards and tools you should use when composing a third-party code as well as thinking about the risk topic coverage you will need. The Upshot
When considering a third-party code, take a hard look at the purpose and audience you are trying to reach. Also consider accessibility and the communication tools you use for your employee code when drafting these documents. Three Questions with https://www.linkedin.com/in/kelly-clark-0560651/ (Kelly Clark), Senior Vice President, Safety, Environmental and Regulatory Services for Holland America Group
At Holland America Group, which includes Princess Cruises, Holland America Line, Seabourn, P&O Cruises Australia, and Holland America-Princess Alaska land operations, Kelly oversees fleet compliance efforts including safety and environmental operations, emergency response organization, policy and procedure development and implementation, and training. As the group’s Chief Ethics Officer, she spends much of her time improving awareness and education throughout the organization on the importance of working with integrity, honesty and ethics at all levels. Under her stewardship, Princess Cruises, Holland America Line and Seabourn have been Ethics Inside Certified®, and the Holland America Line has been named to the list of the World’s Most Ethical Companies® for five consecutive years. Kelly was also named to Ethisphere’s list of “Attorneys Who Matter” in the area of Ethics & Compliance in 2015 and 2016.
What does the flurry of indictments against individuals at Volkswagen and Takata tell us about compliance officer liability after the Yates Memo? Eric revisits the impact of the Yates Memo on compliance officer liability with the news of these prosecutions. The https://www.justice.gov/dag/file/769036/download (Yates Memo), written by Deputy Attorney General Sally Yates and released on September 9, 2015, addresses individual liability for corporate wrongdoing. In the memo, DAG Yates lays out new guidance to Department of Justice attorneys who are prosecuting individuals involved in corporate wrongdoing. An earlier episode, “Does the Yates Memo increase my liability as a compliance officer?”, examines data collected by the http://www.ussc.gov/ (United States Sentencing Commission) regrading the rates of criminal prosecutions for individuals involved in corporate wrongdoing.
In this episode, Eric tells you why he holds to his original statement that the most important function of the Yates Memo is to open the door to and encourage important discussions about corporate culture and strong compliance and ethics programs. Volkswagen and Takata can serve as cautionary tales about the impact of a weak culture and compliance and ethics program.
Eric also goes beyond the news stories and examines the affidavit in support of the https://www.justice.gov/opa/press-release/file/923686/download (criminal complaint) against VW’s compliance officer, Oliver Schmidt. He talks about the conduct that Schmidt allegedly engaged in that led to his arrest. He also discusses what compliance officers can do to avoid individual criminal liability.
https://moreheadcomplianceconsulting.leadpages.co/leadbox/14406ef73f72a2%3A137e36ed6946dc/5730082031140864/ (Click Here to Subscribe to Our Mailing List)If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Question Homepage question form
Your Name Email Address
Question*
jQuery(document).bind('gform_post_render', function(event, formId, currentPage){if(formId == 2) {if(typeof Placeholders != 'undefined'){ Placeholders.enable(); }} } );jQuery(document).bind('gform_post_conditional_logic', function(event, formId, fields, isInit){} ); jQuery(document).ready(function(){jQuery(document).trigger('gform_post_render', [2, 1]) } );
How do you create tone from the middle?Tweet This Middle managers are some of the most important members of your compliance and ethics team. Research shows that employees are more likely to report concerns about misconduct to their direct manager or supervisor rather than use a hotline. Eric discusses this data more specifically in http://www.compliancebeat.com/can-prevent-retaliation-encourage-employees-report-misconduct-three-questions-che-hembrey/ (“What can you do to prevent retaliation and encourage employees to report retaliation?”) and http://www.compliancebeat.com/episode-title-lorem-ipsum-dolor-sit-amet-consectetur-adipiscing-elit/ (“Why does no one call the helpline?”). Giving managers the resources to be effective leaders and engaging managers in your compliance and ethics program is one of the best ways to prevent compliance failures.
Many managers are already involved in one area of training. They are often charged with overseeing their reports’ completion of computer-based training. This can be a fairly rote exercise in which managers remind employees to complete training. Managers should really have a more proactive role in training and communication about compliance and ethics issues in order for you to maintain an effective compliance and ethics program.
In this episode, Eric discusses three ways to engage managers. Managers need to become trainers in your compliance and ethics program. Online training is hard to beat when you must train hundreds or thousands of employees on the same issues. But online training shouldn’t replace live training. In live training, there is a give and take that more effectively teaches employees about risk topics. This simply can’t be replaced by online training. Eric tells you simple ways to give managers the tools to be effective trainers and to create a manager-training program that is simple to implement.
Managers also need to be part of your continuing communication around compliance and ethics issues. Communication is one of the http://www.ussc.gov/guidelines/2015-guidelines-manual/2015-chapter-8 (Sentencing Guidelines Seven Hallmarks of an Effective Compliance Program). We often talk about training and communication together, but they should be two distinct parts of your program. Training encompasses those formal courses. Communication is more informal and more frequent. Eric discusses easy ways to give managers the resources to engage their reports in these discussions around risk topics and other compliance and ethics issues on a regular basis.
Even more broadly than compliance, you should help your managers engage in team building. Encouraging managers to implement policies, such as open-door policies, that good rapport and open discussions with their reports will help create an environment where managers can be more effective in training and communication. Eric talks about ways that to create an environment where people talk frequently and are encouraged to come forward to talk about issues before there’s a compliance failure.
The Upshot
If you are looking for ways to involve your managers in your compliance and ethics program, three places to start are engaging managers in training, giving managers tools to engage in regular communication about compliance and ethics issues, and helping managers build strong teams and good rapport with their direct reports.
Three Questions with https://business.illinois.edu/responsibility/people/executive-director/ (Gretchen Winter), Executive Director, https://business.illinois.edu/responsibility/ (Center for Professional Responsibility in Business and Society at the College of Business at the University of Illinois at Urbana-Champaign)
Gretchen is well known figure in the field of compliance and ethics. As the Executive Director of Center for Professional Responsibility in Business and Society at the College of Business, Gretchen also serves as a Visiting Professor at the Universite de Cergy-Pontoise...
In order to answer this question, it’s important to first look at the data on retaliation. In https://www.ethics.org/research/gbes (three different reports), two in 2012 and one in 2015, the https://www.ethics.org/home (Ethics and Compliance Initiative) examined the percentage of employees that report witnessing misconduct. These reports found that 40% to 50%, or approximately four out of ten employees, witnessed misconduct. The percentage of employees that then report misconduct is around 60%. Of the employees that report, 21% employees, or about one out of five, reported experiencing retaliation after reporting. These reports also found that retaliation spikes with organizational change.
In order to prevent retaliation, we have to understand what it looks like. Fear of retaliation is the number one reason why employees don’t report misconduct. What is and isn’t retaliation can be very nuanced. The key is to look at retaliation from the perception of the person experiencing it. Most of the people who experience retaliation cite being treated differently, such as being intentionally ignored or excluded. Retaliation can also take more pernicious forms, such as losing one’s job and verbal abuse.
In this episode, Eric examines the data on retaliation and discusses how to prevent and address it as well as create an environment in which employees feel comfortable reporting misconduct. He answers:
How can you ensure that employees feel comfortable reporting misconduct?Tweet This
To whom do employees most frequently report misconduct?
What factors of a compliance program and of corporate culture create an environment that encourages reporting misconduct?
The Upshot
When addressing concerns about reporting misconduct and retaliation in your organization, you should focus on an effective compliance and ethics program that includes structural pieces, such as clear communication that addresses employees’ fears of retaliation and strong corporate culture.
Three Questions with https://www.linkedin.com/in/che-hembry-0bb3b6?authType=NAME_SEARCH&authToken=XaUh&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A985103%2CauthType%3ANAME_SEARCH%2Cidx%3A1-1-1%2CtarId%3A1484500009083%2Ctas%3AChe%20H (Che Hembrey), Executive Director, Compliance at http://www.hill-rom.com/usa/ (Hill-Rom Holdings, Inc.)
Like many compliance professionals, Che’s path to his current position as Executive Director, Compliance at Hill-Rom was a bit circuitous. He started his career as an IT consultant. Che left IT consulting for a job in sales at LION, Inc. From sales, Che became a manager in Ethics and Compliance Audit at a pharmaceuticals company where he helped establish the company’s first ethics and compliance audit function. He rose to a Senior Manager position in R&D Compliance Programs when Che left to join Hill-Rom’s compliance division. Che was hired at Hill-Rom to restructure, develop, and implement a comprehensive risk-based compliance program focused on managing the company’s U.S. and global risk. In his current position, he is responsible for developing, updating and executing the strategic plans, and the associated activities specific to compliance auditing and monitoring, written standards, communications and training. Eric and Che discuss how his background helps him in his current position and Che’s predictions for upcoming trends in compliance and ethics.
https://moreheadcomplianceconsulting.leadpages.co/leadbox/14406ef73f72a2%3A137e36ed6946dc/5730082031140864/ (Click Here to Subscribe to Our Mailing List)If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)...
What are going to be the overarching trends in compliance and ethics in 2017? Tweet This In this episode, Eric talks about compliance and ethics program trends that will affect every company, no matter your size and no matter whether you are in a highly regulated space.
First, in the past year there has been lots of discussion deregulation. Will potential deregulation lessen the importance of compliance? How can you make the case for continued focus on compliance? How can you keep up the conversation within you organization? As part of his discussion, Eric references the data in the http://www.corporatecompliance.org/Resources/View/tabid/531/ArticleId/5209/Compliance-and-Ethics-Program-Environment-Report.aspx (SCCE and NYSE Compliance and Ethics Program Environment Report).
Second, no matter what happens with regard to deregulation, all organizations face reputation risks.Tweet This As we’ve all seen, social media amplifies these risks and information can go viral quickly. Eric makes the case that organizations need to consider potential reputation risks and ways to mitigate these risks.
Last, Eric predicts that defining what a risk-based approach to compliance will be a big trend in 2017. The idea of risk-based approach to compliance comes out of FCPA guidance. What does it mean to take this approach? Your organization should think about the empirical reasons for your approach to compliance and ethics. How can you use that data that you collect internally to determine where your risk areas are? How can you make the business case for investing in compliance?
https://moreheadcomplianceconsulting.leadpages.co/leadbox/14406ef73f72a2%3A137e36ed6946dc/5730082031140864/ (Click Here to Subscribe to Our Mailing List)If you have a question you want answered on the podcast be sure to reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Get in Touch
Name*
First
Last
Email*
Enter Email
Confirm Email
Website
Comments
jQuery(document).bind('gform_post_render', function(event, formId, currentPage){if(formId == 1) {} } );jQuery(document).bind('gform_post_conditional_logic', function(event, formId, fields, isInit){} ); jQuery(document).ready(function(){jQuery(document).trigger('gform_post_render', [1, 1]) } );
When you are updating, refreshing, or rewriting your code of conduct, you should consider whether or not to create an interactive code of conduct. An interactive code of conduct is a digital document that a reader truly connects with. This document, which may be an interactive PDF (Adobe Portable Document Format), has clickable functions, such as learning aids, comprehension aids, videos, and/or links to other policies or documents. These elements allow readers to interact with the document as they read through it. A learning aid may ask a question, allow the reader to select an answer, and then tell the reader whether the answer is correct or incorrect as well as the reasons why. A discussion of a risk topic may link to a more specific policy. While interactivity can enhance your code of conduct, not every organization wants or needs an interactive code. In this episode, Eric explores how organizations should determine whether an interactive code is right for them and explores what type of questions you should ask when considering whether to create an interactive code. Eric discusses the three questions an organization should ask:
Do you intend for your employees and other stakeholders to interact with your code of conduct digitally or as a paper document?
How do you generally communicate with employees? What is your communication style?
What kind of internal resources in terms of IT and design do you have? How do you plan to maintain an interactive code?
The Upshot
When determining whether to use an interactive design, be sure to spend some time thinking about these three questions: How do your stakeholders interact with your current code of conduct? What is your organization's communication style? How do you maintain your code of conduct?
Three Questions with https://www.linkedin.com/in/ricardo-pellafone-419bb65?authType=NAME_SEARCH&authToken=vFea&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A17906133%2CauthType%3ANAME_SEARCH%2Cidx%3A1-1-1%2CtarId%3A1483388520193%2Ctas%3ARicardo%20Pellafone (Ricardo Pellafone), Founder & Creative Director at http://thebroadcat.com/ (Broadcat)
As the founder of Broadcat, Ricardo’s mission is to get people excited about compliance. He brings a fresh perspective in compliance and ethics. Broadcat uses simple, task-based, graphic content to help employees grasp compliance obligations quickly, making it easy for them to know who to call and what to do when tough situations arise. Before founding Broadcat, Ricardo was the in-house investigations leader for a tech company in California and a sovereign-owned company in the United Arab Emirates. He has also worked conducting internal investigations for clients at a larger law firm. Eric and Ricardo discuss the importance of working in compliance outside of the United States, planning for the best case scenario, and the decline of best practices as the only metric for a compliance program.
If you have a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com/ask-eric/ (here) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Helvetica,Arial,sans-serif; } / Add your own MailChimp form style overrides in your site stylesheet or in this style block. We recommend moving this block and the preceding CSS link to the HEAD of your HTML file. /
Receive a FREE Sample Interactive Code of Conduct & Subscribe to Our...
The short answer is yes, you must train your governing authority, which may be your Board of Directors, on your compliance and ethics program. The http://www.ussc.gov/ (U.S. Sentencing Guidelines) require that you do so because the Board is required to oversee your program. How does this look in practical terms? Eric discusses what he calls the three pillars of Board of Directors’ training:
Compliance Risk Topic Specific Training. These topics may include conflicts of interest, anti-corruption, data protection, data privacy, insider training and other specific risk topic training.
Periodic Review/Discussion of Board of Directors’ Responsibilities. This should address what the Sentencing Guidelines expect of the Board of Directors or other governing authority, including their responsibility for the oversight of the compliance and ethics program.
Annual Code of Conduct Training/All Hands Training. This is the broader training that goes out to the vast group of employees and other stakeholders that receive training in your organization. Code of Conduct training kills two birds with one stone because it addresses the Board’s oversight role of the compliance and ethics program and it provides actual training to the Board. At a minimum, the Board or governing authority should receive the information that is provided in training and details of how the training is in administered.
As well as exploring these topics, Eric also answers:
How often should the Board receive training?
How should Board training be accomplished?
The Upshot
When training your Board of Directors, you should address the three pillars in board training: risk specific topic, regular review of the Board’s responsibility to oversee the compliance and ethics program, and a comprehensive review of employees’ and other stakeholders’ code of conduct training.
Three Questions with https://www.linkedin.com/in/joannmahoney (JoAnn Mahoney), Senior Director of Regulation & Compliance, http://www.equifax.com/about-equifax/company-profile (Equifax, Inc.)
At Equifax, JoAnn wears many hats, like many compliance professionals. She is the compliance subject matter expert for the business units at Equifax of mortgage, healthcare, insurance, data and analytics, mobile commerce, and new product innovation. JoAnn has worked in the financial services industry since working at a credit union during college. Before joining Equifax, JoAnn held role in compliance within the financial services industry, including at Bank of America and Cornerstone Bank. In this segment, JoAnn talks about her career journey. She also discusses the importance of compliance professionals to see themselves as a member of an organization’s team so that you gain credibility within your company. She also talks about future trends in the financial industry.
If you have a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com/ask-eric/ (here) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Sexual assault allegations rocked two prestigious university football programs, http://www.psu.edu/ (Penn State) and http://www.baylor.edu/ (Baylor University). Both universities took two different paths to addressing the underlying compliance, governance and risk problems that led to the scandals. Penn State embraced a transparent approach to addressing the problems. In contrast, Baylor’s Board of Regents have blocked stakeholders’ efforts to understand the root causes of their compliance failures.
In fall of 2011, Jerry Sandusky, a former assistant football coach for the Penn State Nitany Lions, was charged and convicted of multiple counts of sexual abuse of children. Several Penn State University officials, whose alleged actions were questioned in terms of whether they met ethical, moral, and legal obligations in reporting any suspected abuse, were also charged. In response, the Board of Trustees commissioned an independent investigation by former FBI director Louis Freeh and his law firm. The Freeh Report found several high ranking school administrators knew about allegations of child abuse on Sandusky’s part as early as 1998 and were complicit in failing to disclose them. In so doing, Freeh stated that the most senior leaders at Penn State showed a “total disregard for the safety and welfare of Sandusky’s child victims” for 14 years and “empowered” Jerry Sandusky to continue his abuse. Penn State released the full Freeh report to the public and addressed the governance, risk and compliance issues openly.
Baylor, however, has adopted a less than transparent approach to addressing allegations that football players sexually assaulted women on campus and that the university knew and failed to act. Unlike Penn State, when the Board of Regents commissioned a report, they released a heavily edited statement to those outside of the Board. Baylor has seen substantial backlash from many stakeholders, including prominent alumni.
In the episode, Eric, a Baylor alumni, asks:
What can organizations in crisis learn from other organizations that have gone through similar trials?
How can transparancy be weilded effectively to counter-act even the most serious instances of misconduct?
What are the fundamental differences between the crisis managment approaches these two organizations have taken?
If you have a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com/ask-eric/ (here) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
The https://www.justice.gov/dag/file/769036/download (Yates Memo), written by Deputy Attorney General Sally Yates and released on September 9, 2015, addresses individual liability for corporate wrongdoing. In the memo, the DAG Yates lays out new guidance to Department of Justice attorneys who are prosecuting individuals involved in corporate wrongdoing. When you review the data over the years preceding the Yates Memo, the data shows that the DOJ does a pretty good job of prosecuting individuals involved in corporate wrongdoing. From data collected by the http://www.ussc.gov/ (United States Sentencing Commission), we know that in just about 60% of cases where an organization is charged with criminal conduct, an individual is charged too. In 50% of those cases, a high level employee is charged. We will have to look at 2016 data when it is released to see if the Yates Memo has any real impact on the rate of prosecution. In this episode, Eric explores the possible impact of the Yate Memo. He answers:
What is the most immediate impact of the Yates Memo?
Does the Memo mean more liability for compliance officers?
What impact might the Memo have in the future?
The Upshot
As a compliance officer or a compliance professional, the Yates Memo puts us all on notice that our responsibilities are no different than our expectations for other managers, supervisors and leaders within an organization. Our condoning of, participation in, or turning a blind eye to misconduct or violations of the law can result in us individually having some criminal liability for those actions. We’re now on notice.
Three Questions with http://www.scharfbanks.com/who-we-are/attorneys/theodore-l-banks (Ted Banks), Partner, http://www.scharfbanks.com/ (Scharf Banks Marmor, LLC)
As a partner at Scharf Banks Marmor, LLC, Ted’s practice focuses on general corporate and anti-trust matters. He’s also President of http://www.complianceconsultants.com/ (Compliance and Competition Associates), a firm that provides consulting services to assist corporations in developing or improving their compliance and ethics programs, including records management, employee training and confidential investigations. As the former Chief Counsel – Global Compliance at Kraft Foods, Ted had responsibility for antitrust, general litigation, corporate transactions, sales, legal computer applications and public policy coordination. He’s an adjunct professor of law at Loyola Univeristy Law School where he teaches corporate compliance. Ted has been appointed as a corporate compliance monitor by the Federal Trade Commission and Competition Bureau of Canada to oversee compliance programs of respondent companies. Ted is a thought leader in the field of compliance and ethics and is a well known author and speaker.
If you have a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com/ask-eric/ (here) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Written standalone policies, along with your code of conduct, form the foundation of an effective compliance and ethics program. Often organizations focus on rewriting and redesigning code of conduct to meet current best practices and do not consider rewriting standalone policies, even though most codes of conduct reference these other policies. It is important to note that the Sentencing Guidelines don’t mention code of conduct specifically, but the Guidelines do require that an organization establish standards and procedures to prevent and detect criminal conduct. When you are updating your code of conduct, you should also be considering the policies it references. Many of best practices developed over the past few years focus on rewriting your code of conduct to make it more accessible. These same lessons apply to writing effective policies. In this episode, Eric answers:
How do you ensure your policies are reasonably capable of preventing and detecting criminal conduct as required by the Sentencing Guidelines?
What lessons can you apply to writing standalone policies from code of conduct best practices?
How do you create consistency across all your organization’s policies?
How do you effectively work with subject-matter experts and other stakeholders within your organization to rewrite policies?
The Upshot
There are some key things to keep in mind when you are planning to update your standalone policies. The types of stakeholders and subject-matter experts who you will have to consult with are wider and broader than the ones you consult with when rewriting your code of conduct. It will take planning to get them aligned with the end goal. Just as you would in a modern code of conduct, you need to pay attention to the language you use in your policies. Try to reduce jargon and have a conversational tone. Consider design and interactive learning aids where possible. Also, develop a template so that you have a consistent approach across your policies.
Three Questions with https://www.linkedin.com/in/wesley-bizzell-06368918 (Wesley Bizzell), Assistant General Counsel and Director of Political Law and Ethics Programs, External Affairs for http://www.altria.com/Pages/default.aspx (Altria) Client Services Inc.
At Altria Client Services, Wes provides in-house legal counsel on matters relating to the political, legislative, and lobbying activities of Altria Group, Inc., its services companies, including Altria Client Services, and its operating companies, including Philip Morris USA Inc., U.S. Smokeless Tobacco Co. LLC, John Middleton Co., and Ste. Michelle Wine Estates Ltd. He’s responsible for ensuring that Altria and its companies comply with all laws and regulations regarding federal, state, local, and international campaign finance, government ethics, gifts to government officials, lobbying disclosure and reporting, and charitable giving. Overseeing a comprehensive compliance system covering the regulation of government affairs, Wes provides advice and guidance on political law compliance for more than 75 jurisdictions. He also heads the legal team that supports Altria’s public policy activities, providing services related to legislative and regulatory drafting and interpretation. Mr. Bizzell is a member of Altria’s Compliance Leadership Team and its Anti-Corruption Compliance Working Group.
If you have a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com/ask-eric/ (here) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
As your organization approaches a regular assessment of your compliance and ethics program, consider whether you need to include personnel interviews as part of the process. Many organizations rely solely on benchmarking data and surveys to assess their programs. Time constraints can often prevent a deeper dive into program effectiveness. While not every regular assessment may need to include interviews, interviewing personnel from across the organization can provide helpful insights. Interviews can uncover issues that you simply cannot discover when relying solely on the data. During the interview process of an assessment, many organizations regularly talk to the usual suspects, including human resources, legal, audit, compliance, and upper level management. But in order to see the full picture and assess all the pieces of the puzzle, organizations should also include operational management and the rank and file. In this episode, Eric answers:
When including interviews as part of the assessment, what should the interview process look like?
Aside from the usual suspects, how do you determine who to interview?
What steps can you take before and during the interview to ensure that your interviews reveal the full picture?
The Upshot
When you’re planning the interview process as part of an assessment of your compliance and ethics program, spend some time considering what data and documentation you will review beforehand. The data you review beforehand will help inform who you are going to interview. Also take some time ensuring that you get a broad good sample of interviewees from the top to the bottom of the organization. Lastly make sure to set the right tone: inform the interviewees about your project goals because that will sometimes free them up to give you the information that you really need for an effective assessment.
Three Questions with https://www.linkedin.com/in/kathleen-grilli-cooper-4559a617?authType=NAME_SEARCH&authToken=avKg&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A59191553%2CauthType%3ANAME_SEARCH%2Cidx%3A1-1-1%2CtarId%3A1480348898412%2Ctas%3AKathl (Kathleen Grilli), General Counsel of the http://www.ussc.gov/ (United States Sentencing Commission)
As in many small organizations, Kathleen is not only the General Counsel of the United States Sentencing Commission, but also its Compliance Officer. Like many of you, she understands the difficulties of wearing two hats in a small organization. In her interview with Eric, Kathleen discusses her career from a criminal defense attorney in Florida to General Counsel of the Sentencing Commission. Her background and positions at the Commission as well as her experiences as a criminal defense attorney bring a unique perspective to the future of compliance.
In 2013, Kathleen was appointed General Counsel of the USSC. Kathleen has served the Commission as Deputy General Counsel since 2007, having joined the agency as an assistant general counsel in 2003. During Kathleen’s tenure at the Commission, she has played an instrumental role in the drafting of key Commission publications including the Commission’s 2006 report to Congress on the impact of the Booker decision on the federal sentencing guidelines and its comprehensive 2011 report to Congress on mandatory minimum penalties. In addition, Kathleen co-chaired the Commission’s symposium on economic crime in 2013 and a symposium on alternatives to incarceration in 2008. Kathleen has conducted training on white collar crime and the organizational guidelines at numerous Commission training events. Prior to joining the Commission in 2003, Kathleen served as staff counsel at the United States Court of Appeals for the Fourth Circuit, in Richmond, Virginia. Previously she worked in private practice and as an assistant federal public defender in Miami, Florida.
If you have a question you want answered on the podcast be sure to submit it on...
The Wells Fargo fraud allegations show that there can be a tremendous disconnect between the C-Suite’s perception of an organization’s ethical culture and the actual culture in the local workplace. Former Wells Fargo CEO John Strumpf testified before Congress that he firmly believed that executives had created an ethical culture at the bank. Where did Wells Fargo go wrong? “Tone from the top” is an often used phrase in the compliance and ethics space. But as the Wells Fargo allegations show us, tone from the top isn’t always enough to ensure that employees on the ground act ethically. In this special edition episode, Eric discusses the lessons learned about corporate culture from the allegations about Wells Fargo. Eric answers:
If tone from the top isn’t enough, then who else defines the tone of the organization?
What does “tone from the middle” mean?
How can you create a tone from the middle that fosters an ethical culture for employees on the ground?
A Conversation with https://www.oldnational.com/about-us/about-old-national/old-national-and-the-banking-industry/index.asp (Robert G. Jones), Chairman and CEO of https://www.oldnational.com/ (Old National Bancorp)
Under Bob’s direction as CEO and President of Old National Bancorp, the company has received national recognition for its coporate culture. Since 2012, the prestigious Ethisphere Institute recognized Old National as one of the World’s Most Ethical Companies. In their conversation, Eric and Bob discuss how Old National Bancorp maintains an ethical corporate culture even as ONB continues to expand across the Midwest. Bob talks about the importance that ONB places in maintaining an ethical corporate culture, how ONB integrates new acquisitions into their current culture, and how to create a tone from the middle so that employees on the ground embrace and maintain an ethical culture.
Bob has appeared on Fox News, Fox Business News, CNBC, and Bloomberg Television, as a spokesman for Old National and community banking. He is very active in his local community and been named to the boards of the University of Evansville, Chairman of the Evansville Regional Business Council, Riley Children’s Hospital, Evansville Business Leaders Roundtable for Education, WNIN, Central Indiana Corporate Partnership, Mid-Size Bank Coalition (Chair Elect), International City/County Management Association-Retirement Corporation (ICMA-RC), and the American Bankers Council.
Among other honors, Former Indiana Governor Mitch Daniels presented Bob with the select Sagamore of the Wabash award and the Distinguished Hoosier Award. He has also been inducted into the Evansville Regional Business Hall of Fame and the Evansville Vanderburgh School Corporation Hall of Fame.
If you have a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com/ask-eric/ (here) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
When considering whether to translate your Code of Conduct into other languages, there are some surprising nuances. If your organization typically translates documents, you may be familiar with the basic process. Translating a Code of Conduct, however, is a little different than other documents because there are more factors to consider. Among them, you need to consider the process of translating the layout and design as well as text and who your audience is in each country in which you have operations.
What factors do you need to consider when determining whether to translate and, if so, which languages to choose if you are a multinational corporation?
If your organization is based solely in North America, do you even need to consider translations?
What type of guidance do government agencies provide in terms of translations and accessibility of your Code to your employees?
Eric answers these questions and more in this episode of Compliance Beat.
The Upshot
When it comes to translations, there’s more to consider than meets the eye. It’s important to think about translating your Code of Conduct, even if you are a purely domestic organization. The key is to look closely at your employee population and your stakeholder population to determine what languages are necessary. Lastly don’t forget to take a close look at your English version. If your English is too complicated, then your translations will be too complicated.
Three Questions with https://www.linkedin.com/in/ronald-feldman-8b7357?authType=NAME_SEARCH&authToken=TyuW&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A863563%2CauthType%3ANAME_SEARCH%2Cidx%3A1-1-1%2CtarId%3A1479312523978%2Ctas%3ARonny%20Fel (Ronnie Feldman), Founder of http://learningsentertainments.com/ (Learning & Entertainments).
Ronnie has a truly unique route to compliance and ethics. He started off his career with an MBA and worked for a boutique consulting firm which provided strategic planning to companies in the healthcare industry. Ten years into his career, he fell in love with improvisation comedy and left the corporate world to join an improv troupe. Ronnie left the improv troupe to build a corporate education business with Second City Works, the B2B arm of the famed improv comedy institution. Listen to how Ronnie has become an improvisational evangelist for thinking in the workplace. His new complany, Learning & Entertainments, brings comedy, fun and creativity to compliance and ethics training that truly engages employees.
If you a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com (ComplianceBeat.com) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
The US Sentencing Guidelines require that individuals within an organization be delegated with day-to-day operational responsibility for the compliance program. When defining the role of this individual, the Guidelines say that the person with day-to-day operational authority shall report to high level personnel, and when appropriate, the governing authority of the organization on the effectiveness of the program. In addition, the Guidelines require that the individual responsible for the compliance program have adequate resources, appropriate authority, and direct access to the governing authority. Does this mean that the chief compliance officer or the employee tasked with day-to-day operation of the compliance program have complete independence? Should this person report solely to the Board of Directors or a sub-group of the Board of Directors? What does “adequate resources” and “appropriate authority” mean? Eric answers these questions and discusses how to ensure that your program meets the requirements of these Guidelines.
Eric also asks https://www.linkedin.com/in/jennifer-badgley-1a47157?authType=NAME_SEARCH&authToken=ZSiL&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A22673356%2CauthType%3ANAME_SEARCH%2Cidx%3A1-1-1%2CtarId%3A1478799011736%2Ctas%3AJennifer%20Bad (Jennifer Badgley), Director of Compliance & Ethics at https://www.linkedin.com/company/5548?trk=tyah&trkInfo=clickedVertical%3Acompany%2CclickedEntityId%3A5548%2Cidx%3A2-1-2%2CtarId%3A1478799034834%2Ctas%3Apremera (Premera Blue Cross), Three Questions. Listen to her talk about her journey to compliance after working in internal audit at Bank of America and learn why she finds compliance to be a personally rewarding field.
If you a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com (ComplianceBeat.com) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
The United States Sentencing Commission is charged with collecting a vast amount of data regarding the sentencing of criminal defendants in federal courts. Among this data is a surprising amount of information regarding the organizations that take convictions in federal court for compliance and ethics failures. Many times, compliance and ethics professionals rely solely on current news to garner what information on compliance and ethics failures. The news, however, only covers a small fraction of the organizations that are charged with federal crimes. The data from the Sentencing Commission tells us the full story—a story that has more surprising outcomes than you might expect. In this episode, Eric explores the 2015 data on organizational sentences. You may be surprised to learn that 90% of organizations that take federal convictions have less than 1000 employees.
What size organizations are most at risk?
What types of crimes are organizations being charged with?
You’ll learn that many of the hot topics in compliance and ethics, like https://www.justice.gov/criminal-fraud/foreign-corrupt-practices-act (FCPA) violations, make up a very small percentage of the crimes that organizations take convictions for. It’s not just organizations that get charged, but often individuals with a relationship to the organizations will be charged as well. Eric discusses the data regarding these individuals and how you can use this data to help you make the case internally about the importance of strong compliance program.
The Upshot
The U.S. Sentencing Commission’s data can tell us some very interesting and helpful things about the size of organizations that get in trouble, the types of offenses or actually the multiplicity of offenses that organizations find themselves charged with probably most importantly can talk very specifically about the collateral damage if you will that comes with a federal prosecution in the form of individuals that get prosecuted. These are all helpful pieces of information and you’re making the case internally for the necessity of compliance.
Three Questions with https://www.linkedin.com/in/amylilly09?authType=NAME_SEARCH&authToken=uV15&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A14174090%2CauthType%3ANAME_SEARCH%2Cidx%3A1-1-1%2CtarId%3A1478194551951%2Ctas%3Aamy%20lil (Amy Lilly), the Director of Corporate Ethics and Compliance at http://www.centerpointenergy.com/en-us/ (CenterPoint Energy) in Houston Texas
At CenterPoint Energy, Amy integrates value-based ethics into a compliance-based company. Amy is a leader in Houston’s compliance and ethics professional community and has an interesting perspective on the future of compliance and ethics.
If you a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com (ComplianceBeat.com) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Read Full Transcript
What do the Sentencing Commission data tell us about ethics and compliance programs? The Sentencing Commission, besides providing the seven guidelines for an effective ethics and compliance program, has a couple of other functions that are worth exploring. One is the vast amounts of data it collects annually and makes available to compliance officers. For many people in compliance their number one source of information about problems with compliance is through news reports. While using the news of the current corporate scandals that are making the headlines can be useful,...
Training is one area where the http://www.ussc.gov/guidelines/2015-guidelines-manual (Sentencing Guidelines) give us specific information about what’s expected for an effective program. Is your training program clear? Does it effectively communicate the company standards? Is everyone meeting these standards?
Another important effective training issue is coverage. Who is receiving it? Does it include remote employees? Does it include management, the board of directors, etc.?
The Guidelines specify “periodic” training but does not define this term. What does it mean?
How can an organization test to find out if it’s training is practical? One way is to select a sample or focus group. And we’ll discuss a few more.
The Upshot
Keep your training effective, periodic and practical. Periodic doesn’t mean once and it’s done, it means periodic. Practical means testing to ensure that the program is working. And finally, use consistent and interesting methods to ensure effectiveness.
Three Questions with https://www.linkedin.com/in/david-searle-458a229?authType=NAME_SEARCH&authToken=sQFK&locale=en_US&srchid=888300891477672252253&srchindex=1&srchtotal=181&trk=vsrp_people_res_name&trkInfo=VSRPsearchId%3A888300891477672252253%2CVSRPtargetId%3A29407748%2CVSRPcmpt%3Aprimary%2CVSRPnm%3Atrue%2CauthType%3ANAME_SEARCH (David Searle,) Chief Compliance Officer and Associate General Counsel at Bristow Group
Read Full Transcript
What do the Sentencing Guidelines say about training?
Training is one area where the Sentencing Guidelines give us specific information about what's expected for an effective program. Training must be effective, periodic and practical. It must succeed in communicating the company's standards to the broadest possible audience. Terms like “clear, concise and interesting” are often applied to training programs that are developed to communicate these standards. Unfortunately, often the training is not “clear” and this can have serious consequences. For example, a few years ago we worked with an organization to develop its program on conflicts of interest. Interestingly, this company specifically allowed for and discussed the hiring of family members and close friends. This was a family-owned business and it would have been impossible to have a conflicts-of-interest policy that forbade nepotism. Indeed, the C.E.O.'s daughter was a General Manager, a well-known fact within the company. While working with this company we discovered that their “off the shelf” training procedures specifically stated that they could not hire family members no matter what. This was an obvious and unintended oversight. So, in the code of conduct training’s module on conflicts of interest there was a provision that directly conflicted with what the actual policy of the organization was. This sort of thing happens more frequently than you might imagine particularly with the proliferation of off-the-shelf, standardized-type training programs.
Another common scenario is when you have a company that has been acquired, or one with several separate subsidiaries, one of its divisions may have policies, procedures, and documents that are in direct conflict with its other divisions. Clear communication must be included not only in the required training but also in any written standards or informal communications that might be out there.
When we talk about clarity and effectiveness much of it comes down to consistency. It is surprising the number of times that inconsistencies occur that cause confusion for the employees and others who are receiving that information.
Another important effective training issue is coverage. Who is receiving the training? Does it include remote employees? Does it include management, the board of directors, etc.?
Indeed, the Sentencing Guidelines specifically say that the people to be trained include members of the governing...
Should we be investing in an anti-corruption program?
Anti-corruption risk is a “high severity/low likelihood” risk for nearly all organizations. But, if it does happen it can be very serious. Eric will look at data between the Department of Justice and various corporate defendants.
If you are asking, “Should we be investing in an anti-corruption program?” it’s probably not the question you should be asking. There are more important questions– “What are the compliance risks for this organization?” “Have you done a compliance risk assessment? “Have you evaluated what risks you face as an organization?” “How have you done that and how recently?” “How comfortable are you with that risk assessment?
You also have to ask before you get to a more specific question about anti-corruption is “What are we doing about those risks?” “What is in-place to address those risks at this point?”
The Upshot
While anti-corruption is a very serious risk it is one with very low likelihood for many organizations. Every organization needs to understand their own particular risks. By doing that you will know if you need to have an anti-corruption program.
Three Questions with https://www.linkedin.com/in/douglas-veivia-a431a854?authType=NAME_SEARCH&authToken=PJda&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A191574483%2CauthType%3ANAME_SEARCH%2Cidx%3A1-1-1%2CtarId%3A1477352468429%2Ctas%3Adoug%20Veivia (Douglas Veivia), VP, International Compliance at https://www.linkedin.com/company/1852?trk=prof-exp-company-name (Prudential Financial Inc).
If you a question you want answered on the podcast be sure to submit it on http://www.compliancebeat.com (ComplianceBeat.com) or reach out below.
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.linkedin.com/in/eric-morehead-7626958?authType=NAME_SEARCH&authToken=ufpp&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A25577210%2CauthType%3ANAME_SEARCH%2Cidx%3A1-3-3%2CtarId%3A1476465491710%2Ctas%3Aeric (LinkedIn -Eric Morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Read Full Transcript
Should we be investing in an anti-corruption program?
Anti-corruption risk is a “high severity/low likelihood” risk for nearly all organizations. This means that if it happens it can be very serious, can impact the company for many years, cost millions of dollars, and may mean that individual employees spend time in federal prison. This is very high severity. Low likelihood risk means that the actual overall risk is not as “highly likely” as is often perceived by the compliance community-at-large.
Looking at enforcement numbers from 2015, the last full year of available data, there were 100 non-prosecution (NPA) and deferred prosecution (DPA) settlements entered between the Department of Justice and various corporate defendants. For those of you who understand anti-corruption, or the Foreign Corrupt Practices Act (FCPA), you already know that NPA and DPA agreements are the mechanism by which the Department of Justice and defendants can settle a potential criminal case without it ever being filed, or by deferring the case for a period of time until the company can complete the terms-of-agreements made in the settlement.
These NPAs and DPAs have become very popular over the last decade or so as a way to resolve corporate cases that could otherwise result in potential criminal charges for the organization. They are perhaps best known for resolving FCPA cases but they are used in many other types of cases. In fact, of the 100 cases in 2015 only two of the cases, just 2%, were for FCPA.
If we look at the 2015 U.S. Sentencing Commission’s data on organizational sentencing, i.e. companies who pled guilty to felony offenses in federal court and received sentences, there are 181 organizations. None of these involved FCPA...
There are both potential positives and negatives when you market or publicly announce your particular commitment to compliance and ethics. Or as more organizations are doing in recent years, seeking to certify that their program meets certain standards.
Let’s focus on a couple of the potential downsides or negatives. When you market your program as being a “best practices” program you need to expect that external forces and maybe even some internal forces will want to investigate. Be prepared to support and show that the program does indeed meet the standards. This may seem obvious, but beyond the hallmarks of the http://www.ussc.gov/guidelines/2015-guidelines-manual (Sentencing Guidelines) for an effective program there are a lot of “best practices” in existence that go above and beyond the guideline standards. If you are going to hold up your compliance program as a “best practices” program either through a formal certification or otherwise then you need to make sure that the homework has been done. You will want an assessment that goes through the organizational program piece by piece and thoroughly benchmarks the program against peer organizations. Don’t be caught in a situation where you are called out for not meeting “best practices.” The second potential downside is commitment to the program. If you are going to promote the effectiveness of your program you have to remain committed to applying the resources and time to assure that that program remains a “best practices” program. Once you publicly commit to the notion that the program is a “best practices” program, there is no going back. This may be a good thing if you’re trying to continue to encourage resources and enthusiasm for the program across the enterprise. But it’s a consideration before you embark on any kind of certification process or any kind of public acclamation of the success of your program. I’ve seen this go awry when an organization puts together a program they believed was a “best practices” program. It included a lot of resources including regional compliance officers, compliance committees and consistent and detailed procedures which includes certifications that these individuals had to engage in on a regular basis. The problem surfaced down the road when the organization had to cut. They cut the committees and regional compliance officers with very specific responsibilities but it was still documented as part of the program. At year-end, when the certifications were presented to the Board of Directors, they were inaccurate. The resources had been cut because the program at least in that incarnation had been unsustainable. So that’s what you don’t want to get into. You don’t want to report to have a program that has certain aspects or meet certain standards, if that’s not something you willing to continue. Another potential downside is employee perception. If the proclamation of an effective compliance program or a positive ethical culture doesn’t jibe with the perception of your employees they’re going to sense the disconnect. You will want to make sure that your evaluation of the relative success of the program jibes with the perception of the employee base. It’s like anything else, if management is proclaiming something that the rank and file do not perceive to be accurate then it’s going to ring hollow and that will obviously engender some problems internally that might affect reporting down the road. It certainly also could affect the employee’s overall negative perception of the program itself.
The upside and potential advantages when you market the success of your program or market the organization culture can affect both internal and external stakeholders. Externally, the stakeholders, whether it be shareholders, regulators or the public at large look to organizations to have an ethical culture. They expect...
This is part of a continuing series called Sentencing Commission Confidential. Let’s take a look at the history and operation of the sentencing guidelines and in particular chapter 8 of the sentencing guidelines that have to do with organizations. Let’s go back in time to 1984, this was before the United States Sentencing Commission. In 1984, there was a bipartisan movement in Congress to reform overall federal sentencing practices. If you remember the 80’s, you might remember parachute pants, Michael Jacksons’ “Thriller” and let’s not forget http://www.businessinsider.com/meet-ivan-boesky-the-infamous-wall-streeter-who-inspired-gordon-gecko-2012-7 (Ivan Boesky) and https://en.wikipedia.org/wiki/Michael_Milken (Michael Milken), junk bond kings—insider traders. We are all too familiar with corporate scandals that have happened over the last twenty years. Let’s remember, at that time compliance and ethics as a profession wasn’t even a glimmer in the eye of anyone. There were no compliance and ethics officers, no dedicated compliance and ethics professional organizations, no professional field of study, with the exception of the highly regulated industry of finance. There was very little talk about corporate culture and certainly not in relation to how affected ethical behavior and compliance. These were the years of the original Gordon Gekko and introduced into that mixture was the ongoing sentencing reform effort that was underway in Congress at the time. This resulted in the https://en.wikipedia.org/wiki/Sentencing_Reform_Act (Sentencing Reform Act) and this act was primarily concerned with reforming the sentencing of individuals in federal court. It did this in broad strokes by eliminating parole and creating a determinant sentencing regime. This meant that the sentence announced by the judge should be very close to the sentence actually served. The hope was to create more transparency in the sentencing system and reduce disparities in sentencing that happened regionally across the United States. Congress wanted to alleviate scenarios where somebody charged with exactly the same offense in Massachusetts would not necessarily receive the same sentence as somebody charged with that sentence in Florida. In order to accomplish these goals the Sentencing Commission was created by the Sentencing Reform Act. The commission is an independent agency with seven voting members, both judges and and non—judges. Its role is to develop sentencing guidelines for use by federal courts in the United States to study and research sentencing issues. It collects all sentencing information and helps to educate about this topic. Importantly, Congress mandated that the Sentencing Commission consider guidelines for organizations in the new regime. So the Sentencing Commission took up creating organizational sentencing guidelines that would allow federal judges to sentence organizations that have been convicted of federal offenses. These initial organizational guidelines came into effect 25 years ago—in 1991, Happy Silver Anniversary to the http://www.ussc.gov/guidelines/2015-guidelines-manual (Sentencing Guidelines)! A guiding principle behind these new guidelines was to provide a foundation for an organization to self-police its own conduct through effective compliance and ethics programs. Although that exact terminology wasn’t used in the original guidelines and they’ve gone through iterations since then, the genesis was there in 1991. It meant to encourage compliance through this framework of principles. The idea was to reward and incentivize organizations to create effective compliance programs by mitigating their punishment in the case of a criminal violation. Basically, the organization gets credit for cooperation and for having a program. The sentencing guidelines talk about compliance and ethics because it’s the carrot that leads to mitigation for organizations that might be charged with offenses in...
This week’s question is “What’s the best defense against a whistleblower?”
A few years ago, the SEC announced their bounty program and there was much discussion about it. Is this a good idea for organizations? Does this stop an individual from coming forward with reports? We’ll discuss the reasons I am against financial compensation.
What happens to the company culture when you have a whistleblower? Let’s look at Cortland Kelley, head of GM’s inspection program, who raised alarms about the Cavalier and Cobalt vehicles. How did this affect the culture at GM?
So, what is the first thing an organization can do to respond to the potential for a whistleblower? What questions does your organization need to be asking? You will need to to measure the perception of the culture from the perspective of the employees and look at all levels of your organization, especially middle management.
One last thought about responding to potential whistleblowers is to consider very specifically your retaliation within the organization. This is key to avoidance of whistleblowers and can be key to addressing how you encourage people to come forward internally. This goes hand in hand with working on the culture and also encouraging managers to be primary communicators about all of these issues.
THE UPSHOT
If you want to avoid having a whistleblower you need to focus on your culture.Tweet This Invest in middle management and understand the perception of retaliation in your organization these three things overlap and there are vitally important to keeping people reporting inside your organization.
Three Questions with https://www.linkedin.com/in/dick-dube-9bb4701a?authType=NAME_SEARCH&authToken=E9yX&locale=en_US&trk=tyah&trkInfo=clickedVertical%3Amynetwork%2CclickedEntityId%3A66833567%2CauthType%3ANAME_SEARCH%2Cidx%3A1-2-2%2CtarId%3A1476465295378%2Ctas%3Adick%20dube (Dick Dube), EVP – Chief Audit Executive & Ethics Officer at Old National Bancorp
Read Full Transcript
This week's question is “What's the best defense against a whistleblower?”
A few years ago, the SEC announced its bounty program and there was much discussion about it. At that time, I was working with an organization which was seriously discussing offering an internal reward to individuals who come forward with reports. Wisely, this organization decided not to move forward with the offer. I think there are two good reasons for this decision. One is very practical—how could an internal body match the financial value in some of the recent FCC settlements. The second reason is that it really sends the wrong message. Most organizations have focused on reporting and open communication, wanting a culture that speaks up. We want to make sure that everybody is comfortable coming forward, asking questions and making reports when they feel necessary. I really think that's key in answering the question—how you respond to a whistleblower? The Global Business Ethics Survey, formerly called the National Business Ethics Survey, by the Ethics and Compliance Initiative, actually has data on this. They have been looking at this issue for many years now. One particular metric that's come up repeatedly is that individuals that find themselves in weak or weak leaning cultures are much less likely to report as opposed to those that perceive a strong or strong leaning culture.
Cortland Kelley was a 3rd generation GM employee and had been the head of GM’s inspection program when he raised the alarm about issues with the Cavalier and the Cobalt vehicles. He repeatedly raised concerns and felt like no one seemed to be concerned and there were no actions taken. It got to the point that he actually became a whistleblower, he filed suit in 2002. GM denied the wrongdoing and the case was dismissed, the allegations contained therein later turned out to be true. But at the time GM had a victory and Mr Kelly's career as was...
The Code of Conduct is the Foundation
Why does the Department of Justice and the SEC call the Code of Conduct the foundation of an effective compliance and ethics program? This question is something that has come up often over the last few years and this terminology— the foundation has become a buzzword. Let’s take a step back and look at where the Code of Conduct became such a vitally important piece of the puzzle for a compliance program. If we look back at the original U.S. Sentencing Guidelines standards for organizations, which by the way are going to be celebrating their 25th anniversary in November 2016, we don’t find code of conduct. There just wasn’t a focus on code of conduct when these initial compliance and ethics program standards were being developed. It’s only been a sharper focus in the last 5 to 10 years. Today, standards could be mere individual policies, they could also be other written documents. They definitely could be code of conduct which could encompass things like your employee handbook.
So this term foundation—what does it mean? There are some fundamental pieces of the compliance and ethics program puzzle that the code of conduct can often be a part of. So, when we talk about a foundation what do we expect from a foundation? We expect the foundation to be solid, we expect it to be well planned. Just like a a foundation for a building, it should should reflect everything that’s going to stand on top of it, it is the support system. We also know that foundations for buildings need to be maintained on a regular basis. The same goes for your compliance and ethics program. It needs to be revisited on a regular basis, that’s really important and sometimes overlooked.
Practically speaking, you should also consider a mission statement when talking about what a foundation means. What are the expectations of your organization? Code of conducts often have a statement from the CEO or chief executive in the front of the document, this can serve as a mission statement for compliance at the organization. It wasn’t always there 10 years ago but certainly that personal message stands for something, for ideals and principles, it establishes the tone of the conversation. The tone that you’re going to continue to have with your employees about these issues. It can be individual risk topics or discussions of things like reporting. It can be considered the hub of the wheel or base of operations for your compliance program.
Another key aspect of a foundation is that it’s basic, it’s simple, it’s structural. I think that really lends itself to talking about the broad values that underpin your compliance and ethics program. And the bottom line here is you want people to be familiar with these values, Familiar with the basic premises from the code of conduct.
I think as compliance professionals we are “glass half-empties” type of people. So when we think about the code of conduct and discussion of risk topics we’re trying to put together a resource to help people remediate problems. We need to think more like “glass half-full” people. The code should be aspirational, it should be the values platform of the organization. I think we tend to forget that and concentrate more on the mitigation or the clean up afterwards rather than the aspirational piece and I think that’s important to consider when you’re talking about a foundation. It’s a values foundation, a values platform for the organization as a whole and in their compliance and ethics program.
This notion of a foundation and using that kind of terminology is a very clear cue that the Department of Justice & SEC expect to see a code of conduct. A foundation that talks about values. A foundation that talks about big picture expectations. A foundation that supports a real bonafide program. So let’s take them at their word. Let’s make sure that the foundation is strong.
If you a...
The SCCE Compliance and Ethics Institute Conference in Chicago on September 24-27, 2016 is the stage for this podcast. Eric Morehead, host of Compliance Beat was in attendance at the SCCE conference, along with 1700 compliance professionals and shares conference highlights and emerging trends in this Special Edition. The profession continues to grow and expand and more importantly people want to continue to grow and learn as they find themselves responsible for compliance issues.
Trends A surprising & interesting trend is to now find newly appointed compliance officers or professionals wearing multiple hats. It’s fair to say in the past, especially in larger organizations, the trend was to apply more resources and have people that had compliance as their sole responsibility. This may be anecdotal, but it seems there is some retrenchment there. Could we be seeing this change due to lack of resources? One benefit at least–someone is now nominally in charge of the program. But on the flip-side could be wearing so many hats they may not have the time or expertise to devote fully to compliance.
As an exhibitor, Eric spent many hours in the exhibit hall at the SCCE conference, this allowed him to spend quality time with both vendors and service providers. One of the trends in the hall seems to be consolidation, which makes it feel like there are fewer choices. One example of this is Hotline services, in previous year there were many large providers. That’s not to say, that consolidation has caused any decrease in customer service, it’s just that choice is a good thing. In larger companies, you need to have some additional choices, especially when RFP’s are required. It was still good to see quite a few, newer and small organizations offering innovative tools and services. Many like Morehead Compliance Consulting were 1st time exhibitors.
A continuing trend involves training. The 45-minute training is disappearing unless mandated by statutory requirements. Training is becoming shorter in length, think of it as bite-sized pieces with more engagement, humor and entertainment. This does cause some concern for companies that are just not comfortable yet with mixing humor with compliance issues, they aren’t sure if this diminishes the importance of this issue. But, overall think many companies are realizing the value.
Another trend that came up was integration. It was common thread in many of the sessions. It was great to see the overall maturity of many of the programs. Companies have the basic pieces in place, but now are trying to get more integrated, trying to partner in a way that hasn’t been done in the past. They are starting to realize the importance of partnering with the employees in all departments–the “boots on the ground” so to speak.
You many not have been at the SCCE conference, but would love to hear any feedback on any trends you are seeing in the industry. Be sure to reach out and say Hello. eric@moreheadconsulting.com
https://twitter.com/eric_morehead (https://twitter.com/eric_morehead)
https://www.facebook.com/compliancebeat/ (https://www.facebook.com/compliancebeat/)
Do you have to be the person that says “no”? Compliance officers often struggle with the push and pull of keeping the lines of communication open and also having to deliver difficult answers to their stakeholders. What are some strategies for avoiding being known as the person who always says “no”? We discuss some ideas for collaboration for compliance officers. Also, we have Three Questions with… Richard Bistrong. Richard has an incredibly compelling story to tell about making the wrong choices and how to come back from the consequences.
The USDOJ has required an independent compliance function in some recent corporate settlements, but is this the official position of the Department? We discuss the the intersection of these recent developments, the US Federal Sentencing Guidelines and how this might relate to whether your compliance officer has the necessary independence to craft and maintain a compliance program that is effective. Just what are the expectations from the Department and can we ensure that that our compliance function will meet those standards? In this episode, Eric answers these questions and discusses just what independence a compliance officer must have to maintain an effective program. Eric also asks 3 questions of Bill Brown, Chief Compliance Officer of the Knights of Columbus. Bill Brown comes to the compliance and ethics field after many years service as a prosecutor. His background provides a unique perspective into the compliance and ethic space and great insight into the future.
Program note: this podcast references a Compliance Beat podcast discussing compliance officer independence standards in the US Federal Sentencing Guidelines. That podcast has not yet been released but will be released in the near future — check back soon!
A compliance committee can be a powerful component of an compliance and ethics program. Forming one, however, leads to many questions. Who needs to be on it? How do you determine the committee’s purpose? What should the scope of their involvement be in the overall compliance and ethics program. Leveraging the talent you have inside the organization can be very powerful, but how do you do this? Eric answers these questions and many more in this informative episode. He also talks with Adam Turteltaub just in time for the close of another successful SCCE Compliance and Ethics Institute Conference. Adam brings a unique perspective to compliance and ethics because he comes from a very different background than many of us involved in the field.
In this episode, we conduct our Board of Directors Lightning Round. What are six common questions that directors might ask the compliance staff? We talk about explaining the importance of a risk-based program to discussing the Federal Sentencing Guidelines with your board. We also have Three Questions with… Kathleen Edmond. Kathleen is a rockstar among compliance officers. She ran the compliance program at a high-profile retailer. She has been cutting edge with her well-known blog and her use of social media. We take a few moments to hear about her path to a compliance profession and some of her lessons learned.
In this episode we tackle a common question: why do so few people seem to be calling our hotline or helpline? Learn how you might evaluate the performance of your compliance hotline or helpline. Our special quest Roy Snell answers Three Questions. As the face of SCCE and HCCA Roy has done much to move the compliance and ethics profession forward, and we stop to ask him about his journey and his thoughts about the future.
In this introductory episode, get to to know Eric Morehead, Host for Compliance Beat podcast. Eric talks about the goals for the show. He tells you a little about himself and his compliance and ethics journey. We are excited about this show and invite you to join us in this journey. Please be sure to subscribe.