Welcome to this special podcast series, In Conversation with K2 Intelligence FIN: Jeremy Kroll on GRC Risks, Strategies, and the Future, sponsored by K2 Intelligence FIN. This week I visit with K2 Intelligence FIN, Chief Executive Officer (CEO) Jeremy Kroll on GRC Risks, Strategies, and the Future.
Over the week, we will review the current Governance, Risk, and Compliance (GRC) landscape, look at GRC at work, consider GRC and the investment community, review GRC and K2 Intelligence FIN and conclude with a look at GRC then and now. In this Part 1, we consider the current GRC landscape.
GRC aims to synchronize information, processes and practices across the enterprise to help entities operate more efficiently by enabling effective information sharing about risk, aligning risk mitigation with organizational goals, allowing for more accurate and effective risk insights, while avoiding wasteful redundancies. Kroll related that a high-level explanation of GRC is “governance is at the top of an organization, literally the very tone from the top. So, at the end of the day, it’s, how can you share information, align your plans, to organize your goals and create an environment where you get more accurate, more effective insights to help you mitigate or manage risk”. GRC ensures that the people who are in the position to avoid risk and effectuate risk avoidance activities can effect that change, alter the course before things go wrong, based upon having the right information.
We turned to risk appetite. Jeremy Kroll believes “organizations have evolved and now there is precious little time to really experiment and figure out not whether something is going to go haywire”. This make is more about business resiliency. To be able to start or expand a business in this competitive world, you have to have a certain appetite for risk. GRC provides a framework to not only “have that appetite, but also be able to take certain decisions; whether that is a geographic expansion and going into a new market or going from investing in a people based businesses, and then starting to pivot into technology.” You can take certain risks as you either evolve or even transform the organization or team. Kroll pointed out that GRC can allow for an “organizational design that allows the highest levels of the business to listen and have the information flow to them and then react quickly that an organization does not lose its way.”
We next turned to the components of a strong GRC framework. They include: tone at the top governance; an effective method to identify, assess and quantify the risk; the ability to train and enforce compliance requirements; independent testing of mitigation measures and to close gaps and remediate deficiencies; audit programs focused on continual improvement and reporting; and the ability to communicate all of the above up the chain of command to the decisionmakers and change agents where decisions can be made and adjustments that cascade back down through the organization.
With these components in place, Jeremy Kroll then expanded out on how they are used. It begins with identifying the risks and then assessing them. From there you create a risk management plan and “once you have that plan in place, being able to monitor it, which leads to training and the constant reassessment, not just of the systems, but the people in your organization.” Moreover, if there is a failure, how quickly can you react and remediate? Jeremy Kroll concluded that it is actually “putting your plan into practice.” He provided the example that if you are a senior inhouse counsel and you are having a conversation with an engineer out in the field, you must, “feel their pain, to understand what it’s like to perform at a high-pressure environment.”
He concluded that GRC has become a much broader part of the conversation across the board. For example, this has become a larger part of the due diligence process for investors examining portfolio companies or acquisitions. Please join us as we explore this and other GRC-related issues over this podcast series. Tomorrow we examine GRC at work.
Check out the LinkedIn page for K2 Intelligence FIN here.
Check out the K2 Intelligence FIN website here.
Author: admin
The FCPA Compliance Report is the longest running podcast in compliance. Today, I am extraordinarily honored to post my 500th Anniversary podcast. Today, I switch seats to be the guest as I am interviewed by Gregg Greenberg, the General Manager of CSuite Radio. We take a look back at some of the key trends, I have seen in compliance over the past 10 years, the top episodes, my favorite guests, the Liverpool Football Club, buffalo wings and much more.
Some of the highlights include:
- The biggest changes seen in compliance over the past 10 years.
- When, why and how did the FCPA Compliance Report begin?
- What are of my favorite episodes and some of my top guests? By the number and by guests.
- What I have learned in this journey?
- As The Voice of Compliance; why I am so passionate about podcasting as a communication tool.
- If you are an LFC fan, why you will walk alone.
- What makes the perfect buffalo wing?
Check out the Lead Up Podcast Series
If you are interested in my podcast series from 5 top commentators on their reflections on the evolution of compliance over the past 10 years, check out the following:
- Episode 495 – Mike Volkov on changes in FCPA enforcement;
- Episode 496 – Matt Kelly on changes in compliance report from business journalism;
- Episode 497 – Jonathan Armstrong in changes GDPR, the UKBA and Modern Slavery law;
- Episode 498 – Jay Rosen on moving from reactive to proactive compliance; and
- Episode 499 – Jonathan Marks on how changes in internal audit both mirror changes in compliance professionalism.
In today’s edition of Sunday Book Review:
- Why Orwell Matters by Christopher Hitchens
- Masscult and Midcult by Dwight Macdonald
- The Bad Side of Books by DH Lawrence
- Typewriters, Bombs and Jellyfish by Tom McCarthy
In today’s edition of Daily Compliance News:
- HerbalLife settles long standing FCPA investigation. (FCPA Blog)
- Oil following coal into oblivion? (Houston Chronicle)
- So much for due diligence. (WSJ)
- Fraud in PPP. (NYT)
In an area of inquiry entitled Oversight, the 2020 Update asks three basic questions which we have explored throughout this chapter:
- What compliance expertise has been available on the Board of Directors?
- Have the Board of Directors held executive or private sessions with the compliance function?
- What types of information has the Board of Directors examined in their exercise of oversight in the area in which the misconduct occurred?
To facilitate the answers to these questions, consider this list of 20 questions to reflect the oversight role of directors. These are questions the Board should ask of both senior management and the Board should ask itself. The questions are not intended to be an exact checklist, but rather a way to provide insight and stimulate discussion on the topic of compliance. The questions provide directors with a basis for critically assessing the answers they get and digging deeper as necessary. Although the questions apply to most medium to large organizations, the answers will vary according to the size, complexity and sophistication of each individual organization.
Three key takeaways:
- The DOJ Evaluation requires active Board of Director engagement around compliance.
- Board communication on compliance is a two-way street; both inbound and outbound.
- Has the Board built an effective Compliance Committee for itself?
In this episode, I visit with Vin DiCianni, Chief Executive Officer (CEO) and founder of Affiliated Monitors, Inc. (AMI), We discuss how the use of independent monitors has expanded. DiCianni noted that the use of independent monitors has greatly expanded over the life of AMI. This expansion has been at all levels of domestic government: in the federal sector, in the state arena and down to the municipal level. It has also expanded into the international sphere as well as the private sector. The DOJ began using monitors in the early 2000s around money-laundering prosecutions. Independent monitors were used by a wide variety of other federal agencies, from the Department of Transportation to the Department of Defense.
As we move to our first non-PG podcast and channel our inner Chauncy Gardner with signature line, “I like to watch”, Tom and Jay continue to brave the surge in Covid cases by staying safe at home. They are back to look at top compliance articles and stories which caught their eye this week.
- What is monitoring and oversight? Matt Kelly draws compliance inspiration from Jerry Falwell who (allegedly) likes to watch his wife having sex with another man. In Radical Compliance.
- What is risk-based due diligence? Financial regulators opine. Mengqi Sun in the WSJ Risk and Compliance Journal.
- Bank/government partnership to fight financial crime. Dylan Tokar in WSJ Risk and Compliance Journal.
- Why fraud matters, the Steve Bannon indictment. Mike Volkov in Crime Corruption and Compliance.
- Why does the Palantir S-1 appear to be like the children of Lake Wobegon — stronger, better-looking, and above average? Francine McKenna explains on The Dig. Lucenda Shen sees a flag-waving, in Term Sheet.
- How bad was the sexual harassment on the Washington Football Club? Very Bad. Expose in the Washington Post.
- Are we losing the war on AML? Martin Woods says yes. In Compliance Week (sub red’d)
- More on McDonald’s suit against its former CEO? Fenwick West lawyers in the Harvard Law School Forum on Corp Governance.
- This month on The Compliance Life, I am joined by Louis Sapirman. In Part 1, we looked at Louis personal and professional journey into compliance. In Part 2, we discussed the qualities of a successful CCO. In Part 3, communication as a driver of compliance. In this month’s final episode Part 4, Sapirman takes a look at the CCO role down the road.
- On Compliance and Coronavirus we had a week of Exiger. Tuesday had Brandon Daniels on Data Management and Data Security Moving out of Covid-19, Michael Beber on on M&A, IPOs and SPACs During and After Covid-19; and Anna Osborn on managed services and outsourced compliance.
- On the Compliance Podcast Network, on 31 Days to a More Effective Compliance Program, this month focuses on the role of the Board in compliance. This week saw the following offerings: Monday– BOD and succession planning; Tuesday-incorporating compliance strategy into long-term BOD planning; Wednesday-areas of BOD inquiry into compliance; Thursday– special guest Vin DiCianni on 3 specific BOD inquiries on compliance; and Friday-20 questions. The month of August is being sponsored by Affiliated Monitors. Note 31 Days to a More Effective Compliance Program now has its own iTunes channel. If you want to binge out and listen to only these episodes, click here. Please join us in September where I take a deep dive into Internal Controls.
- Join Jay and Tom at Converge20. Convercent’s top compliance conference is going virtual this year. Check at the agenda and register here.
- There’s a place where True Crime meets Compliance, and its name is Fraud Eats Strategy. Check out this new show by Scott Moritz of FTI consulting, and catch all the episodes, notes, resources and more on the Compliance Podcast Network! We’d love to hear what you think of the show, and we’d love it even more if you shared it with a friend, colleague or that one guy you think might be a secret oligarch. Check out this great new podcast series here.
- This week on the FCPA Compliance Report, some of the top commentators in compliance have joined Tom to discuss some of the top developments in compliance over the past 10 years. The schedule for this week is as follows:
- Monday, Aug. 24 – Episode 495 – Mike Volkov on changes in FCPA enforcement;
- Tuesday, Aug. 25 – Episode 496 – Matt Kelly on changes in compliance from the business journalist perspective;
- Wednesday, Aug. 26 – Episode 497 – Jonathan Armstrong in changes in data protection/data privacy compliance;
- Thursday, Aug. 27 – Episode 498 – Jay Rosen in changes to proactive monitoring from the business development perspective; and
- Friday, Aug. 28 – Episode 499 – Jonathan Marks on how changes in internal audit both mirror and even foreshadow some of the changes he has seen in compliance.
It is all leading up to the 500th anniversary episode which will run Monday, August 31. Tom Fox is the Compliance Evangelist and can be reached at tfox@tfoxlaw.com. Jay Rosen is Mr. Monitor and can be reached at jrosen@affiliatedmonitors.com.
Welcome to the newest addition to the Compliance Podcast Network, Compliance and Coronavirus. As the Voice of Compliance, I wanted to start a podcast which will help to bring both clarity and sanity to the compliance practitioner and compliance profession during this worldwide health and healthcare crisis. In this episode, I visit with Anna Osborn is Senior Vice President of Growth and Marketing at Exiger. She discusses cultivating collaborative working environments and building process into an organization’s compliance relationship management activities, during the era of Covid-19.
Some of the topics include:
- What are the top 3 challenges you are as we move into Q3 and Q4 of this year?
- Do you anticipate they will change in 2021?
- How can senior management create a narrative around these changes?
- What is the future of managed services?
- How can a CCO ‘spread the peanut butter too thin?”
- What is the role you see for outsourced compliance?
Resources
For more information, check out Exiger’s website here.
In today’s edition of Daily Compliance News:
- It just gets worse with McDonald’s and Easterbrook.
- TMZ had toxic workplace? Shocked, just shocked.
- Laura a CAT 4 be safe out there.
- SEC votes for less corp disclosure.