Categories
Compliance Tip of the Day

Compliance Tip of the Day – AI, Continuous Monitoring and Compliance

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we consider how AI can give your compliance program continuous monitoring going forward.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
Everything Compliance

Everything Compliance: Episode 158, The No to Corruption in Ukraine Edition

Welcome to this edition of award-winning Everything Compliance. In this episode, we have the quartet of Matt Kelly, Jonathan Marks, and Jonathan Armstrong, with Tom Fox, the Compliance Evangelist, sitting in as both host and a guest this week.

1. Matt Kelly looks at a couple of recent enforcement actions and what they may portend for enforcement under the Trump Administration. He shouts out to the people of Ukraine for fighting against corruption and rants about the DOJ cover-up of the Epstein files.

2. Jonathan Marks considers the leadership lessons from the recent imbroglio involving the NFL Players Association. He shouts out to Alexsys Thompson and her book, The Power of a Graceful Leader.

3. Jonathan Armstrong considers the new UK Failure to Prevent Fraud offense and highlights the city of Berlin and the people of Germany, who have taken ownership of their role in WWII.

4. Tom Fox looks at AI governance lessons through the lens of Star Trek TOS episode The Ultimate Computer and shouts out to the Lincoln Center Starbucks in NYC for supporting the Texas Hill Country and making him a part of its 5:30 AM family.

The members of Everything Compliance are:

The host, producer, and sometime panelist of Everything Compliance is Tom Fox, the Voice of Compliance. He can be reached at tfox@tfoxlaw.com.  The award-winning Everything Compliance is a part of the Compliance Podcast Network.

Categories
Blog

Failure to Prevent Fraud Mastery: Enhancing Due Diligence, Training, and Improvement

We conclude our deep dive into the Economic Crime and Corporate Transparency Act 2023, which has elevated the expectations for senior leadership and boards across large organizations. Our guide in this journey has been the UK government, which has put out a document entitled “Economic Crime and Corporate Transparency Act 2023: Guidance to organisations on the offence of failure to prevent fraud.” (The Guidance) Today, we conclude with the final three sections on Due Diligence, Training, Ongoing Monitoring, and Continuous Improvement.

As compliance professionals prepare diligently for the upcoming implementation of the Failure to Prevent Fraud (FTPF) offense, it becomes imperative to understand and apply comprehensive fraud prevention measures effectively. Central to a robust anti-fraud framework are due diligence, training, monitoring, and review processes. Each of these areas must be executed diligently, proportionately, and tailored specifically to address the unique risks faced by an organization.

Due Diligence: Building Trust Through Vigilance

Due diligence is a cornerstone of an effective fraud prevention strategy. Organizations must apply meticulous and proportionate due diligence procedures to mitigate fraud risks associated with individuals or entities performing services on their behalf.

For organizations facing heightened fraud risks, standard due diligence might not suffice. Comprehensive screening, including the use of technology-driven third-party risk management tools and vetting checks, becomes vital. Contracts should explicitly state compliance obligations and consequences of non-compliance, while mergers and acquisitions must include rigorous assessments of criminal, regulatory, and tax backgrounds.

Moreover, ongoing due diligence is essential; periodic reviews and updates ensure that an organization remains alert to emerging risks or changes in the status of associated persons. Continuous monitoring can detect potential red flags that may arise post-engagement, such as sudden changes in financial stability, reputation issues, or new regulatory concerns. Additionally, organizations should ensure transparency in their due diligence processes, clearly documenting their methods and findings. This not only enhances accountability but also ensures readiness in demonstrating compliance to regulatory bodies or stakeholders during audits or investigations.

Organizations might also consider collaboration with external experts or industry peers to refine their due diligence methodologies, leveraging collective insights to strengthen their anti-fraud defenses. Regular training and awareness sessions about due diligence expectations can further embed vigilance into organizational culture, ensuring that all stakeholders understand and uphold their roles in fraud prevention.

Five Key Takeaways on Due Diligence:

  1. Leverage Technology: Use advanced screening tools and third-party risk management platforms to enhance due diligence effectiveness.
  2. Contract Clarity: Clearly articulate compliance obligations and termination clauses for fraud breaches within contracts.
  3. Monitor Employee Well-being: Regular monitoring to identify stressors or workload issues that might increase susceptibility to fraud.
  4. Mergers and Acquisitions Scrutiny: Conduct thorough fraud prevention assessments during acquisitions, integrating robust prevention measures post-acquisition.
  5. Dynamic Review: Keep due diligence processes proportionate, up-to-date, and responsive to evolving risks.

Training: Empowering Prevention Through Knowledge

Training is critical to embedding an anti-fraud culture within an organization. A clear and regular communication strategy ensures all associated persons fully understand and internalize the organization’s fraud prevention policies and procedures.

Proportionate training tailored to the specific risks of roles within the organization, especially high-risk positions, is essential. Training must detail the nature of the FTPF offense, the particular procedures required, and the clear protocols for whistleblowing. Continuous evaluation and updates ensure training remains practical and relevant, particularly as personnel change. Effective training should also encompass interactive and engaging methods such as workshops, simulations, and scenario-based exercises, which help employees understand the real-world implications of fraud and the critical importance of adhering to procedures.

Incorporating case studies of relevant fraud incidents can significantly enhance learning by illustrating practical examples and reinforcing key lessons. Organizations should also regularly evaluate the impact of training through assessments, quizzes, and feedback surveys, ensuring that employees retain the information and can effectively apply it in their roles. Integrating fraud prevention messages into routine communications, such as team meetings and newsletters, can further reinforce an anti-fraud mindset. Ultimately, a robust training program not only builds awareness but also empowers employees to identify and address potential fraud risks proactively.

Five Key Takeaways on Training:

  1. Risk-Based Training: Deliver bespoke training programs specifically targeted at roles identified as high risk.
  2. Integration with Existing Programs: Leverage and integrate fraud prevention messages into broader financial crime training initiatives.
  3. Effective Communication: Communicate internal policies, the importance of whistleblowing, and the procedures to follow.
  4. Regular Updates: Keep training modules current with evolving fraud risks, regulatory updates, and personnel changes.
  5. Monitoring Effectiveness: Regularly assess and monitor training efficacy through feedback and performance evaluations.

Monitoring and Review: Continuous Improvement and Adaptation

Monitoring and review constitute the continuous feedback loop critical to fraud prevention. Organizations must regularly assess and refine fraud detection systems and response protocols based on real-world performance and evolving risks.

Monitoring involves detecting fraud, conducting robust investigations, and assessing the effectiveness of preventative measures. Organizations should ensure that sophisticated data analytics and AI-driven detection tools are employed effectively. Investigations must be independent, well-resourced, fair, and transparent, with results communicated to stakeholders.

Review processes ensure organizations adapt and improve continuously. Regularly scheduled reviews, supplemented by event-driven assessments in response to incidents or significant changes in risk, underpin an agile and resilient fraud prevention strategy. Utilizing external feedback and industry-wide insights, organizations can benchmark their strategies and implement best practices.

Five Key Takeaways on Monitoring and Review:

  1. Regular and Responsive Reviews: Schedule regular evaluations, complemented by prompt reviews triggered by specific fraud incidents or risk changes.
  2. Data-Driven Detection: Invest in advanced data analytics and AI tools to proactively detect fraud and fraud attempts.
  3. Independent Investigations: Ensure fraud investigations are conducted independently and transparently, with clearly documented processes and outcomes.
  4. Continuous Adaptation: Maintain flexibility in fraud prevention measures, promptly adapting strategies based on review outcomes and industry developments.
  5. Sectoral Benchmarking: Collaborate and engage with external entities and industry peers to adopt best practices and maintain practical fraud prevention standards.

Concluding Thoughts

As the countdown to the FTPF offense go-live continues, compliance professionals are tasked with a critical responsibility: to ensure their organization’s preparedness through meticulous due diligence, targeted training, and robust monitoring and review practices. Each component is integral to creating an effective, proportionate, and responsive fraud prevention strategy. By embedding these practices into the organizational fabric, compliance professionals not only safeguard their organizations but also reinforce ethical standards, protecting both reputation and long-term sustainability.

Categories
Hill Country Hustlers

Hill Country Hustlers – Fitness, Community, and Entrepreneurship with Katie Cosper

In an episode of the Hill Country Hustlers podcast, host Zachary Green sits down with Katie Cosper, owner of Hill Country Mecca gym and Pax Coffee Shop. Katie shares her journey from being a competitive athlete to becoming a nationally ranked Olympic weightlifter and transitioning to bodybuilding. She discusses the challenges and rewards of running a gym and a coffee shop in Kerrville, Texas, emphasizing the importance of community and the unique demographics of the Hill Country area. Katie also touches on the significance of empowering young women in the fitness world and the lessons she’s learned about managing time and employees. The episode wraps up with a look at upcoming events and exciting new ventures for both Hill Country Mecca and Pax Coffee Shop.

Key highlights:

  • Katie Cosper’s Fitness Journey
  • Running a Gym: Challenges and Community
  • Hill Country Mecca: Growth and Vision
  • Owning Pax Coffee Shop
  • Balancing Entrepreneurship and Family
  • Advice for Aspiring Entrepreneurs
  • Shoutouts and Upcoming Events

Resources:

Zach Green on LinkedIn

Katie Cosper on Facebook

PAX Coffee Shop on Facebook

Hill Country Mecca on Facebook

Categories
Daily Compliance News

Daily Compliance News: July 30, 2025, The Corruption Kill Business Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Bain & Co. leaves South Africa. (FT)
  • The Trump Administration guts the Antitrust Division. (WSJ)
  • Starbucks has a bad vibe. (BBC)
  • Meta is under investigation in Italy (again). (Reuters)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief here.

Categories
Great Women in Compliance

Great Women in Compliance – The Power of Vulnerability with Cricket Snyder

Lisa Fine speaks with Cricket Snyder, the first Chief Compliance Officer for the Jefferson County Commission in Birmingham, Alabama, a role that was mandated by a US Federal District Court decree.

Cricket shares her experiences in shifting the compliance culture in Jefferson County from one where she was initially viewed as an extension of the monitoring to one where she overcame employee skepticism and built trust, connecting with people throughout the county.

Cricket also emphasizes the importance of vulnerability, particularly in a new, challenging role. She also reminds us of the power of being open about what you don’t know and how doing so helped foster a more transparent and collaborative environment. She also received support from the broader compliance community.

Lisa and Cricket also discuss strategies to increase engagement. Cricket introduced “Compliance Week” to Jefferson County, transforming compliance education into engaging, themed events. These have increased trust in the function among all county employees, leading to a positive culture shift.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – AI and 3rd Party Risk Management

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we consider how you can bring predictive analytics into your program to make it proactive rather than reactive.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
Blog

Right-Sizing Your Fraud Defense: Building Proportionate Prevention Procedures

We continue our deep dive into the Economic Crime and Corporate Transparency Act 2023, which has elevated the expectations for senior leadership and boards across large organizations. Fortunately, the UK government has put out a document entitled “Economic Crime and Corporate Transparency Act 2023: Guidance to organisations on the offence of failure to prevent fraud.” (The Guidance). Section 3.3 of the official guidance, titled “Proportionate risk-based fraud prevention procedures,” should be required reading for every compliance professional seeking to build a credible, defensible, and sustainable anti-fraud culture.

Central to this preparation is the concept of proportionate, risk-based fraud prevention procedures. The keyword here is “proportionate,” that is, the measures your organization takes should directly correspond to the level and types of fraud risks identified. These procedures must be clear, practical, accessible, effectively implemented, and robustly enforced. Today, we take a deep dive into what a top-level commitment is.

Understanding Proportionality

The cornerstone of effective fraud prevention lies in creating procedures proportionate to the identified risks. Simply put, the greater the potential risk and impact of fraud, the more stringent and comprehensive your procedures must be. Conversely, lower-risk scenarios justify lighter-touch measures. It is imperative that your organization documents decisions around fraud prevention measures, especially when opting not to implement specific controls due to limited risk. Such documentation must include the rationale, the authorizing individual’s identity and role, and regular review cycles.

Leveraging Existing Controls and Procedures

Organizations subject to a variety of regulatory requirements, from financial reporting to environmental and health and safety, often already have robust compliance measures. It is prudent to evaluate whether these existing controls sufficiently address fraud risks highlighted in your fraud risk assessment. However, relying solely on regulatory compliance to satisfy the FTPF offense requirements is not sufficient. Organizations must actively validate and, if necessary, augment these controls to target fraud prevention specifically.

Proactive Reduction of Fraud Opportunities

Fraud prevention procedures should aim primarily at minimizing opportunities for fraud. This can include thorough pre-employment vetting, ongoing background checks for high-risk roles, and consistent anti-fraud training. Regularly evaluate the effectiveness of such training through monitoring and feedback loops. Systematically assessing emerging risks, conducting fraud impact assessments for new services or business partners, and ensuring robust fraud management throughout the P2P procurement cycle (in addition to the QuoteToCash cycle) are also critical steps.

Moreover, consider best practices such as segregation of duties, stringent account reconciliations, suitable approval arrangements, rigorous conflict-of-interest policies, and robust data security measures to minimize potential opportunities for fraud.

Addressing Motivations and Rationalizations

Understanding and managing the human elements of motive and rationalization behind fraudulent actions are crucial. Motive can often stem from incentive structures such as aggressive bonus schemes or time-sensitive pressures encouraging shortcuts. Evaluate and adjust these incentives to discourage fraudulent behaviors.

Rationalization, the mental justification individuals employ to legitimize unethical behavior, can erode even the most robust control environments. Combat this through proactive ethics training, reinforcing the adverse impacts of fraud on both the organization and broader society, and embedding strong ethical reminders within performance evaluations.

Establishing Clear Consequences

Effective fraud prevention strategies must communicate the internal disciplinary procedures for fraud. Organizations should transparently share the outcomes of fraud investigations with employees and other associated parties, reinforcing a zero-tolerance stance. Visible and consistent consequences serve as powerful deterrents, underpinning organizational integrity and commitment to ethical practices.

Preparing for Emergency Scenarios

Crises and emergency scenarios inherently elevate fraud risks. Whether facing economic downturns, natural disasters, or other unforeseen events, your organization must proactively embed emergency scenario planning within your fraud prevention strategy. Prepare detailed contingency measures and ensure rapid transition back to normal operational controls post-crisis, meticulously documenting all measures implemented and actions taken.

Ongoing Monitoring and Continuous Improvement

Your fraud prevention strategy should never be static—ongoing monitoring and validation of your prevention measures through independent internal reviews or external audits. Using external resources such as the Fraud Advisory Panel, Cifas, or specific industry insights can enrich your approach and ensure comprehensive risk coverage. Publicly available cases of fraud prosecutions or Deferred Prosecution Agreements (DPAs) can further inform and improve your prevention strategies.

Five Key Lessons Learned for Compliance Professionals:

  1. Proportionality is Essential: Always tailor your fraud prevention procedures directly to the level of identified risk. Document any decisions about reduced measures clearly and comprehensively.
  2. Do Not Rely Solely on Existing Compliance Mechanisms: Existing regulatory compliance processes may help prevent fraud, but are not automatically sufficient to meet FTPF obligations. Active validation and enhancement are necessary.
  3. Proactive Risk Mitigation is Crucial: Take active steps to mitigate fraud opportunities through regular vetting, comprehensive training, and robust management of procurement processes and sensitive information.
  4. Understand and Address the Human Element: Reduce motivations and rationalizations by managing incentives, fostering a strong ethical culture, and ensuring transparent and communicated consequences for fraudulent actions.
  5. Prepare and Continuously Test Emergency Measures: Integrate emergency scenarios into your fraud prevention plans and consistently test these strategies through independent assessments, ensuring your organization remains prepared and resilient.

As we approach the FTPF offense’s implementation, compliance professionals must reinforce their strategic roles, embedding robust, proportionate fraud prevention measures. This comprehensive approach not only safeguards organisations from fraud but also positions compliance as a proactive, essential pillar of organizational integrity and resilience. By continuously reviewing, refining, and reinforcing these measures, compliance teams will effectively mitigate potential fraud risks, uphold organizational values, and maintain stakeholder trust. Proportionate fraud prevention is not merely regulatory compliance; rather, it is a strategic imperative vital to your organization’s long-term success and sustainability.

Join us tomorrow as we consider due diligence, training, ongoing monitoring, and continuous improvement.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Bringing Predictive Analytics into Your Compliance Regime

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we consider how you can bring predictive analytics into your program to make it proactive rather than reactive.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
Daily Compliance News

Daily Compliance News: July 29, 2025, The Is CEO Conduct Ever Personal Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • US states are leading the charge to break up big pharma. (FT)
  • What image does it have for profits: UnitedHealth. (NYT)
  • Does any CEO have Personal Conduct? (Bloomberg)
  • Corruption and battlefield failures. (NYT)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief here.