Categories
Innovation in Compliance

A Change in the System with Dan Zitting


 
Dan Zitting, previously Chief Product Officer, now holds the title of CEO at Galvanize, a software company that helps its clients achieve their goals and objectives. Tom Fox welcomes him back to this week’s show to talk about fraud risks, and what it means for the compliance professional.
 

 
A Period of Change
Rapid change during the pandemic is the main catalyst for the increase in fraud. The move to remote work created new susceptibility to cyber fraud. “The pandemic and the news, and noise created around it, created all kinds of new ways for clever social engineers to talk people into doing things they shouldn’t be doing,” Dan explains to Tom. It’s important for GRC professionals to be aware of and ready for change, he adds. We have to realize that change has sped up and will continue to do so in the business environment, regulatory environment, and social justice areas. The rate at which change will increase will be much greater in the future than it has been in the past.
 
Choosing The Right Technology
Choosing the right technology to support anti-fraud programs is important. GRC professionals have to shift controls and assess risk fast enough to deal with all the changes that are occurring around them. Having the proper technology on hand can help make their jobs easier. “A lot of technology is effectively built around manually filling out forms, and creating workflows between people to capture risk or assess risk or evaluate controls, and that is just far too slow-moving,” Dan remarks. We need to create automation primarily from data and technology that can evaluate very quickly. We also need to be able to leverage machine learning which will help us identify data that we might not have otherwise known.  
 
Fraud as a Bigger Focus & The Importance of Governance
How fraud connects to the broader array of cybersecurity risks makes it a major focus for CEOs and senior executives. Leaders are seeking to learn more and educate themselves on how compliance officials are analyzing and monitoring the risks, something that was not done as often in the past. Interest in governance within the compliance sector is also gaining headway. Dan explains to Tom that organizations need to have overarching governance strategies that dictate how they look at the incoming risks to the business. 
 
Resources
Dan Zitting | LinkedIn | Twitter 
Galvanize
 

Categories
Daily Compliance News

July 20, 2021 the Chicken Comes First edition


In today’s edition of Daily Compliance News:

  • Two Americans convicted of helping smuggle Carlos Ghosn out of Japan were each sentenced. (NYT)
  • J&J weighing whether to use bankruptcy laws to shield itself from talc lawsuits. (Reuters)
  • For WeWork, the chicken was to come before the egg. (WSJ)
  • Ackerman SPAC purchase of Universal Music squashed by SEC. (NYT)
Categories
Compliance Kitchen

FinCen Priorities


The Financial Crimes Enforcement Network (FINCEN) issued a policy on government-wide priorities (“Priorities”) for anti-money laundering (AML) and countering the financing of terrorism (CFT).  The Priorities identify and describe the most significant AML/CFT threats that the US is facing – the Kitchen is there to take a closer look at what goes into this recipe.

Categories
Innovation in Compliance

The Groundbreaking Guide to Third-Party & Supply Chain Risk Management: How Exiger’s TRADES Framework Revolutionizes TPRM & SCRM in 2021 and Beyond-Part 1, T for Transparency


Welcome to a special six-part podcast series, sponsored by Exiger, on the TRADES Framework, a conceptual, strategic and practical guide for Third-Party and Supply Chain Risk Management designed by Exiger to help organizations achieve supply chain resiliency and optimize risk management at any phase of maturity. Exiger was founded to fight financial crime, fraud and terrorist financing by introducing technology-enabled solutions to the market’s biggest supply chain, risk, investigation, litigation, and compliance challenges. A global authority on risk and compliance, Exiger serves the world’s largest banks, Fortune 1000 companies and government agencies and regulators. In this first episode, we consider transparency with Skyler Chi and Tim Stone.
The TRADES Framework is an important evolution in a rapidly evolving ecosystem of third party and supply chain risk management. There are a wide variety of risks that could be in your Supply Chain, including both distributor risks and vendor risks. The urgency of establishing best practices in this area was driven home most forcefully during the Coronavirus pandemic as governments at all levels were trying to secure the vaccines, Personal Protective Equipment (PPE) and pharmaceuticals that were needed. There has also been legislative initiatives with such laws as  the German Supply Chain Act starting to gain momentum. Of course modern slavery issues that were talked about before as well and the ESG revolution.
Tim Stone related that “T is for “Transparency of Current State”. There are different levels of transparency. He focused on Entity Level where the goal is to identify the full third-party ecosystem. Another way to think about it is “taking stock”. This stage involves illuminating your current state of affairs and identifying your vendor ecosystem.
The next step is how to build this initial tier of reliably accurate, validated, and de-duplicated entities that are mapped to business units, products, and use-case. You want as comprehensive a supplier and third-party ecosystem as possible. So how do you gain this transparency?
The first step is to identify, your internal supply data elements. You need to review your organization’s contracts and other paperwork, as well as engaging stakeholders across an organization in a fact-finding exercise, to arrive at a golden source of suppliers and vendors, and then mapping those entities to the products, business units, and use-cases across the organization. Next you should review external supply data elements.
“Transparency” is also about illuminating risk, which here means identifying the risks posed by the entities in a client’s supply chain. These risks are either inherent or imposed. Determining inherent risk, is where Exiger’s AI-powered due diligence platform, DDIQ, shines. DDIQ finds and categorizes risk information about focal companies and people. The platform searches hundreds of structured (e.g., watchlists) and unstructured (e.g., media) data sources and performs thousands of targeted queries – using proprietary search strings associated with different risk types and specific risky entities – to isolate and categorize risk information about a focal entity.
Next is imposed risk, which is “an aggregate view of a company’s upstream reliance on certain countries, such as China, for its receipt of goods. This extent of a higher risk country’s upstream footprint in a company’s supply chain is indicative of greater risk.” It also includes risk through downstream supply chain risk analysis to isolate where a company’s products are ultimately ending up.
Transparency also speaks to the governance and accountability associated with third-party (TP) and Supply Chain Risk Management (SCRM). There is a Strategic Level and a Program Level. As Skyler related you should create and document a TP&SCRM mission statement and purpose explanation, understand how mature your program is and create a baseline analysis of the program’s maturity. You then develop and maintain policies and procedures, which provide guidance and determine the right risk-area stakeholders and governance forums.
From this point, you should work to determine communication and workflows to operate the TP&SCRM program. This can be done through several steps, including data sourcing and right-sized technology aligned to the TRADES framework to ensure a single source of truth for each third party, supply chain, and overall program; continuous evaluation and improvements of the framework and periodic refreshes or reviews to assess industry/risk changes and best practices. Finally, it would lead to the creation of principles and guidance to help company stakeholders take risk-related decisions and actions.
Join us in our next episode, where we discuss the Risk Methodology with Theresa Campobasso and Matt Hayden.
Resources
Exiger TRADES Framework
Exiger Website
Skyler Chi
Tim Stone

Categories
FCPA Compliance Report

Jason Mefford


In this Episode of the FCPA Compliance Report, I am joined by Jason Mefford, a top thought leader in internal controls. We discuss his podcast Jamming with Jason, his online academy cRisk Academy and a unified theory of risk management. Highlights include:

  1. Why he began his podcast.
  2. How professionals consume information and content in 2021.
  3. Why he founded cRisk Academy.
  4. Unified risk management.
  5. What’s new in internal controls.
  6. The current state of live music.

Resources 
Jason Mefford on LinkedIn
Jamming with Jason
cRisk Academy

Categories
Daily Compliance News

July 19, 2021 the Speed v. Perfection edition


In today’s edition of Daily Compliance News:

  • Wal-Mart tagged for $125 in discrimination suit. (NYT)
  • Speed v. Perfection in IT. (WSJ)
  • Texas RRC to consumers: it wasn’t natural gas (but it was). (Houston Chronicle)
  • Eliminate animal based meat in 15? Impossible foods CEO says yes. (WaPo)
Categories
Sunday Book Review

July 18, 2021, the Tour De France edition


In today’s edition of Sunday Book Review:

Categories
Daily Compliance News

July 17, 2021 the Is Crypto Legit? edition


In today’s edition of Daily Compliance News:

  • SEC announces SPAC enforcement action. (SEC Press Release)
  • Banking regulators seek comments on 3rd risk management. (WSJ)
  • Swiss arrest German attorney in tax fraud case. (GAN Newsletter)
  • Is crypto legit? (NYT)
Categories
Compliance Kitchen

FCA Settlement and More Belarus Sanctions


In this episode, the Kitchen explores a recent DOJ settlement with a US government contractor that was brought about through a whistleblower, under the False Claims Act. Next, we take a peek at what is cooking in Switzerland, as the government joins the rest of the world and issues sanctions against Belarus.

Categories
Greetings and Felicitations

Journey to Babel and the Medicine of TOS


In this podcast we consider the TOS episode Journey to Babel as a starting point for the consideration of the medicine portrayed in the Original Series. The Enterprise transports ambassadors to a conference to discuss the admission of Corridon, a star system composed of many mutually combative races, to the Federation. Corridon contains a nearly unlimited supply of dilithium crystals, but its small population and lack of strong government has allowed illegal mining operations by outsiders seeking to exploit its natural resources.
To Kirk’s surprise, Sarek the 102.437-year-old ambassador from Vulcan and his his wife Amanda, who is human, are Spock’s parents. Sarek reveals that he has had three previous Vulcan heart attacks and has been taking Bengacydrine to combat it. He requires an open-heart operation, but the ship’s stores do not have a sufficient supply of blood, especially of Sarek’s rare Vulcan T negative blood. Despite the fact that Spock’s blood is a mixture of human and Vulcan factors, he provides a blood transfusion to Sarek after McCoy uses an experimental stimulant to increase the rate of blood production. The Enterprise is then attacked by alien ship while Sarek and Spock are on the operating table, endangering both their lives. Spock, who is recovering from the operation, surmises that the perpetrators were from Orion, since Orions are known to have been smuggling dilithium from Corridon and are anxious to prevent interference.  
Highlights include: 
1.   Why is the TriCorder such a significant piece of medical technology, even up to today?
2.   What are the diagnostic aspects of the TriCorder?
3.   What is augmented reality and how is it being used in medical treatment today?