Categories
Compliance Tip of the Day

Compliance Tip of the Day: Executive Compensation and Compliance Incentives

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

In today’s episode, what is the role of executive compensation in compliance incentives?

For more information on the Ethico ROI Calculator and a free White Paper on the ROI of Compliance, click here.

To check out The Compliance Handbook, 5th edition, click here.

Categories
Great Women in Compliance

Great Women in Compliance: Amy Hanan – ‘Relentless Curiosity’ in Life and Work

While marketing professionals typically operate “behind the curtain,” Amy Hanan is taking center stage these days. As a chief marketing officer for LRN, she’s recently been a keynote speaker at a headline session for a major compliance event and is traveling the globe leading roundtables that connect top compliance & ethics professionals with the latest research trends.

Hanan’s career path has included the Associated Press (when the internet was in its infancy), along with B2B and legal marketing positions when marketing automation technology was brand new. Honing her professional skills—and her people skills—along the way, Hanan has blazed a trail in a niche where her passion for compliance and ethics serves her well.

Listen in as she talks about the things she’s learned along the way.

Highlights:

  • How raising your hand can change the trajectory of your career
  • The value of “relentless curiosity” in both life and work
  • Curating a leadership style
  • Learning from mistakes—and the power of exercise, tea & fuzzy socks

Resources:

Join the Great Women in Compliance community on LinkedIn here.

Categories
Blog

Navigating the New Frontier: SEC’s Enforcement Action on RR Donnelley and its Implications for Compliance

In the ever-evolving compliance landscape, the recent enforcement action by the Securities and Exchange Commission (SEC) against RR Donnelley is a significant case study. This incident underscores the importance of robust cybersecurity measures and highlights the SEC’s expanding reach into areas traditionally viewed outside its purview. As compliance professionals, understanding the intricacies of this case is crucial for adapting to the dynamic regulatory environment. Matt Kelly and I took a deep dive into the enforcement action in a recent Compliance into the Weeds episode.

RR Donnelley, a company historically known for its printing services and later for marketing services, faced an SEC enforcement action in November 2021 due to a cybersecurity breach. Hackers accessed and copied confidential corporate customer data, which was later posted on the dark web. The SEC’s main contention was that Donnelley failed to disclose this breach to investors promptly and had inadequate internal controls over its IT systems. Ultimately, the company was fined $2.1 million.

The SEC’s enforcement action was based on the premise that Donnelley’s cybersecurity measures were insufficient, leading to unauthorized access to its IT assets. Specifically, the SEC utilized provisions related to internal control over financial reporting to impose sanctions even though no direct accounting fraud or economic loss occurred. This approach represents a novel application of the SEC’s powers, using internal accounting control clauses to address cybersecurity issues.

Matt believes that the SEC’s enforcement hinged on the idea that poor cybersecurity equates to poor internal controls over assets. The SEC interpreted the Exchange Act to mean that access to a company’s assets, whether data or financial, should be controlled and authorized by management. Matt noted in his blog post that the statutory authority for that statement flows from the Exchange Act of 1934, which established the Securities and Exchange Commission and the anti-fraud securities laws we use today. The text of the Exchange Act states that companies must devise and maintain a system of internal accounting controls “sufficient to provide reasonable assurances” on four points:

  • Transactions executed according to management authorization;
  • Transactions are appropriately recorded;
  • Access to assets is permitted only according to management authorization;
  • Recorded accountability for assets is reconciled with existing assets.

The hackers’ ability to access Donnelley’s IT systems without authorization was viewed as a failure of these internal controls.

This interpretation broadens the scope of what compliance professionals must consider under the umbrella of internal controls. Traditionally, internal controls were seen in the context of financial reporting and safeguarding physical assets, most usually cash or cash equivalent. However, it is not simply cash as the only assets these requirements cover but all other corporate assets. Moreover, this case suggests that digital assets and the controls around them are equally critical.

Another critical aspect of the case was the failure to disclose the breach promptly. According to the SEC, Donnelley’s IT security team was aware of the breach but did not quickly escalate it to senior management. It took an external party’s notification for the CISO and senior executives to become fully aware and take action.

This scenario underscores the importance of having robust internal communication channels and protocols to ensure that significant cybersecurity incidents are promptly reported to senior management. Moreover, it highlights the need for transparency with investors regarding such breaches, aligning with the SEC’s mandate to protect investor interests.

Compliance professionals must now consider cybersecurity an integral part of internal control systems. Ensuring that IT systems are secure and that access to digital assets is tightly controlled should be a priority. This involves regular audits of cybersecurity measures, continuous monitoring of IT systems, and implementing robust access control mechanisms.

The case also highlights the necessity of clear and effective disclosure practices. Compliance teams should ensure that there are well-defined procedures for reporting cybersecurity incidents internally and disclosing them to investors when necessary. This might include setting up rapid response teams and informing senior management immediately of significant breaches.

Given the technical nature of cybersecurity, collaboration between compliance and IT departments is essential. Compliance officers should work closely with CISOs and IT security teams to understand potential risks and ensure appropriate controls are in place. This partnership is vital for creating a comprehensive compliance strategy that addresses traditional financial risks and emerging digital threats.

The SEC’s approach, in this case, signals that regulators are willing to use existing frameworks to address new types of risks. Compliance professionals should prepare for increased scrutiny and be proactive in ensuring their organizations meet regulatory expectations. This may involve regular training, staying updated with regulatory changes, and conducting thorough risk assessments.

The RR Donnelley case serves as a wake-up call for compliance professionals, emphasizing the need to adapt to an evolving regulatory landscape. By broadening the scope of internal controls to include cybersecurity and enhancing disclosure practices, compliance teams can better protect their organizations and meet regulatory expectations. Collaboration with IT and staying vigilant about regulatory trends will be vital to navigating this new frontier in compliance. Perhaps more ominously, Matt, in another blog post on the United Healthcare cyber-attack in Q1 2024, asked, ” If the SEC applied that theory of enforcement against Donnelley, shouldn’t that same theory now be applied against UnitedHealth? At this point, we should discuss exactly how UnitedHealth’s breach happened. Change Healthcare had not implemented multi-factor authentication on a critical computer server, which allowed attackers to use stolen employee credentials to gain access. In other words, UnitedHealth had allowed poor access control on a critical system.”

In other words, Watch This Space.

Categories
Trekking Through Compliance

Trekking Through Compliance – Episode 45 – Leadership Lessons from The Gamesters of Triskelion

In this episode of Trekking Through Compliance, we consider the episode The Gamesters of Triskelion, which aired on January 5, 1968, and occurred on Star Date 3211.7.

Kirk, Uhura, and Chekov prepare to beam down to Gamma 2 and are whisked away from the transporter platform. They are captured and fitted with “collars of obedience” by Galt, master Thrall of the planet Triskelion. Spock finds them 11.630 light-years away but is prevented from beaming down.

The providers who started all this threaten to destroy Kirk and the Enterprise, but Kirk makes a bet with the gamekeepers about his ability to survive in combat. If he wins, the Providers must free Kirk and the Thralls. If he loses, he offers the entire Enterprise crew up as Thralls. Amazingly enough, Kirk wins, even after one of the opponents is replaced by Shahna. Kirk, Chekov, and Uhura are returned to the Enterprise, leaving behind a saddened Shahna.

Commentary

The episode features Captain Kirk, Uhura, and Chekov being abducted to a planet where they are forced to participate in gladiatorial games run by the Providers. Fox delves into the storyline, discussing key plot points and the leadership and ethical lessons that can be drawn, such as ethical decision-making, effective communication, empowerment, resilience, and collaborative problem-solving. Additionally, a fun fact reveals that Sulu was initially intended to be a significant character in the episode, but George Takei’s filming commitments for ‘The Green Berets’ precluded his participation. The episode is examined for its mix of serious and lighthearted elements and Biblical allusions. Fox ties these elements back to modern compliance and leadership practices, offering valuable insights for compliance leaders.

Key Highlights

  • Episode Overview: The Gamesters of Triskelion
  • Fun Facts and Behind the Scenes
  • Leadership Lessons from The Gamesters of Triskelion

Resources

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

 

Categories
Daily Compliance News

Daily Compliance News: July 16, 2024 – The Leisure Sickness Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee and listen to the Daily Compliance News. All from the Compliance Podcast Network.

Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

In today’s edition of Daily Compliance News:

  • Are you getting sick when you have time off? (FT)
  • An ex-bankruptcy judge is now under criminal investigation.  (WSJ)
  • The X lawyers kicked off the case.  (Reuters)
  • Ex-Mozambique minister to stand trial in the US over tuna-bond fraud. (Bloomberg)

For more information on the Ethico ROI Calculator and a free White Paper on the ROI of Compliance, click here.

Categories
Compliance Tip of the Day

Compliance Tip of the Day: Designing Compensation to Operationalize Compliance

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

In today’s episode, we consider how to design your compensation program to operationalize your compliance regime?

For more information on the Ethico ROI Calculator and a free White Paper on the ROI of Compliance, click here.

To check out The Compliance Handbook, 5th edition, click here.

Categories
Everything Compliance - Shout Outs and Rants

Everything Compliance: Shout Outs and Rants – Episode 137, The Boeing Edition

Welcome to the only roundtable podcast in compliance as we celebrate our second century of shows.

In this episode, we welcome Karen Moore as a permanent panelist. She is joined by Jonathan Marks, Jonathan Armstrong, Matt Kelly, and Tom Fox for shout-outs and rants.

  1. Karen Moore shouts out to the UK for their seamless transition of power after the July 4 election and to the Men’s Football team for making the UEFA Cup Final.
  2. Matt Kelly rants about Tractor Supply, which ditched its DEI and sustainability efforts based on one Twitter campaign.
  3. Jonathan Armstrong shouts out to the new British Prime Minister, Sir Keir Starmer.
  4. Jonathan Marks rants about Board members who do not understand Board governance.
  5. Tom Fox shouts out to Pittsburgh rookie Paul Skenes for his great first season and being named Starting Pitcher for the All-Star Game.

The members of Everything Compliance are:

  • Jonathan Armstrong is a partner at Punter Southall in London.
  • Karen Moore is an Adjunct Law professor at the Fordham School of Law.
  • Matt Kelly is the founder of Radical Compliance.
  • Jonathan Marks is a partner at BDO.

The host of Everything Compliance is Tom Fox, who is the founder of the Compliance Podcast Network.

Categories
Innovation in Compliance

Innovation in Compliance: Anne van de Heetkamp – Exploring Global Trade Intelligence and AI Integration in Supply Chain Management

Innovation comes in many forms, and compliance professionals must be ready for and embrace it. In this episode, Tom Fox visits Anne van de Heetkamp, Vice President of Product Management at Descartes, and discusses global trade compliance and the integration of AI in supply chain management.

They discuss Anne’s extensive career in global trade, Descartes’s comprehensive suite of supply chain management tools, and Anne’s specific role in the Global Trade Intelligence pillar. Key topics include the challenges companies face in regulatory compliance, the role of AI in mitigating supply chain disruptions, and the importance of data quality in leveraging advanced technologies for risk management. The conversation spans current automation levels, future AI evolution, and practical approaches to enhancing data transparency and compliance processes within the supply chain framework.

Key Highlights:

  • Anne’s Professional Journey
  • Global Trade Intelligence at Descartes
  • Microservices and Data Privacy
  • AI and Supply Chain Disruptions
  • Data Quality Issues in Compliance
  • Future of AI in Supply Chain Management

Resources:

Anne van de Heetkamp on  LinkedIn

Descartes

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Trekking Through Compliance

Trekking Through Compliance – Episode 44 – Compliance Lessons from The Trouble with Tribbles

In this episode of Trekking Through Compliance, we consider the episode The Trouble with Tribbles, which aired on December 29, 1967, Star Date  4523.3

The Enterprise is called to Deep Space Station K7 by a priority 1 distress call. A Klingon ship arrives at the space station and requests that its crew be granted shore leave. Meanwhile, the intergalactic trader Cyrano Jones gives Uhura a thrilling creature called a tribble, who brings it to the Enterprise, where it promptly begins reproducing.

The tribbles begin proliferating throughout the Enterprise. After Kirk finds that tribbles have spread aboard the Enterprise through air vents, he becomes concerned that they may have also infested the grain storage lockers on the space station. However, Spock notes that many of the tribbles are dead inexplicably.

When the station transporter room is being cleared of tribbles, one of them yelps at Baris’s assistant Darvin. Kirk verifies that Yelp for Klingons. McCoy verifies that Darvin is a Klingon and reveals that the grain was poisoned. The tribbles are finally removed from the Enterprise when Scotty transports them aboard the Klingon ship.

Commentary

This episode’s storyline calls attention to various compliance lessons, such as the importance of product safety and quality control, supply chain management, incident response, compliance culture, and regulatory awareness. The show also delves into fun facts about the episode’s popularity and discusses David Gerrard’s impactful yet strained relationship with Gene Roddenberry. Finally, Fox offers actionable compliance takeaways for organizations inspired by the episode.

Key Highlights

  • Story Synopsis: The Trouble Begins
  • The Klingon Conflict
  • The Tribble Infestation
  • The Big Reveal: Darvin’s True Identity
  • Fun Facts About the Episode
  • David Gerrard’s Journey
  • Compliance Lessons from Tribbles

Resources

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

Bridging The Speak-Up Gap: Insights from The 2024 Ethisphere Ethical Culture Report

In a recent episode of the FCPA Compliance Podcast, we discussed the 2024 Ethisphere Ethical Culture Report, “Closing the Speak Up Gap,” with Erica Salmon Byrne. As an expert in ethical culture and a familiar voice to our audience, Erika shared invaluable insights into this comprehensive report’s genesis, findings, and implications. Today, we delve into the critical aspects discussed in the podcast, focusing on how organizations can bridge the speak-up gap and foster a more ethical workplace culture.

The 2024 report builds on the foundation laid by last year’s inaugural culture report, which provided a broad overview of trends in ethical culture based on data collected over several years. Recognizing the value of this data-driven approach, Ethisphere committed to making the culture report an annual publication. This year’s report draws on data from approximately 2 million employee responses collected since the beginning of 2020, offering a current and comprehensive perspective on workplace culture during and after the pandemic.

Erica outlined the eight pillars of an ethical culture, which serve as the backbone of the report.

  • Awareness of Ethics and Compliance (E&C) Program and Resources
  • Perceptions of the Effectiveness of the E&C Function – Training, Communications, etc.
  • Observing and Reporting Ethical Misconduct
  • Pressure to Compromise Standards to Meet Goals
  • Organizational Justice – Perceptions of Wrongdoer Accountability Across Roles
  • Manager Perceptions – Supervisor Conduct and Ability to Approach with Concerns
  • Perceptions of Conduct, Values, and Communications of Senior Leadership
  • Perceptions of Values and Priorities Among Peers and Environment

These pillars are grouped into three categories that ethics and compliance teams should prioritize:

  1. Knowledge and Training: Do employees know what to do, and is the training effective?
  2. Willingness to Report: Will employees speak up when they see something wrong?
  3. Influence and Leadership: Who influences employee behavior the most?

These pillars provide a framework for understanding and measuring an organization’s various dimensions of ethical culture.

One of the most significant findings from this year’s report is the persistence of the “speak-up gap” – the difference between employees observing misconduct and those reporting it. Approximately 50% of respondents indicated they do not report observed misconduct. This gap is particularly pronounced among younger employees, who exhibit the least faith in the system and are the least likely to speak up.

Retaliation remains a significant barrier to reporting misconduct. Despite years of discussion and policy implementation, there still needs to be more clarity between what organizations believe they are doing to prevent retaliation and what employees fear. Employees’ concerns about retaliation extend beyond illegal acts, including any negative treatment following a report. This fear of retaliation and belief that nothing will change continue to discourage employees from speaking up.

A critical insight from the report is the importance of managers in the reporting process. The data revealed that 60% of employees report misconduct to their immediate managers. This underscores the need for compliance programs to equip managers with the skills and knowledge to handle these reports effectively. Managers must be trained to receive reports and support their teams inappropriately making ethical decisions and escalating issues.

Another intriguing aspect of the report is the “tenure smile,” a pattern where new and long-tenured employees are more likely to speak up. In contrast, those in the middle of their tenure are less inclined to report misconduct. This phenomenon may be linked to career aspirations and established relationships within the organization, which can create a reluctance to report issues that might jeopardize professional advancement or personal connections.

Based on the report’s findings, several strategies can help organizations bridge the speak-up gap:

  1. Enhance Manager Training: Invest in training programs that prepare managers to handle reports of misconduct effectively. This includes teaching them how to listen, respond appropriately, and escalate issues as needed.
  2. Improve Reporting Channels: Simplify and promote reporting mechanisms to ensure employees know how to report misconduct and feel confident that their concerns will be addressed.
  3. Data Integration and Analysis: Use data from various sources, such as HR, audit, and safety, to identify patterns and pockets of silence. This holistic approach can help pinpoint areas where reporting may be suppressed.
  4. Address Retaliation Concerns: Develop comprehensive anti-retaliation policies and communicate them clearly to employees. Ensure that any negative treatment following a report is addressed swiftly and transparently.

The 2024 Ethisphere Ethical Culture Report offers many actionable insights for compliance professionals. By focusing on enhancing manager training, improving reporting channels, and addressing retaliation concerns, organizations can make significant strides in closing the speak-up gap. As Erika emphasized, building a culture of integrity requires ongoing effort and commitment. By leveraging the findings of this report, compliance teams can better support their organizations in fostering an ethical workplace culture.

The conversation with Erika Salmon Byrne highlighted the importance of data-driven insights in understanding and improving organizational ethical culture. As compliance professionals, we must continue to advocate for and implement strategies encouraging employees to speak up and ensure their voices are heard. The 2024 Ethisphere Ethical Culture Report provides a roadmap for achieving these goals and underscores the critical role of managers in the process. By taking these insights to heart and applying them in our work, we can create a more transparent, ethical, and supportive workplace for all employees.