Categories
Blog

Driving Compliance Culture: Lessons from a Skills-Based Approach to Cultural Change

Regarding compliance, the tone from the top is crucial—but culture eats tone for breakfast. Compliance professionals know that a robust compliance program is only as effective as the culture supporting it. Building and sustaining that culture, however, is no small feat. Enter the skills-based approach to cultural transformation, as laid out in Per Hugander’s article in the MIT Sloan Management Review, Take a Skills-Based Approach to Culture Change. This method provides a roadmap for embedding compliance values deeply into an organization by focusing on practical skill development and real-world problem-solving. I have adapted her skills-based approach to revolutionize compliance culture, explain why traditional methods often fall short, and provide actionable strategies for compliance professionals to lead this transformation.

Why Traditional Compliance Culture Efforts Fall Short 

Many culture-change initiatives rely on workshops, seminars, and training sessions to instill new values or behaviors. While well-intentioned, these efforts often fail to address the deeply ingrained assumptions that drive behavior. Hugander explains this through Edgar Schein’s Organizational Culture Model, which emphasizes that culture is rooted in employees’ underlying assumptions, those unconscious beliefs that determine how they think, perceive, and act.

This highlights a critical issue for compliance professionals: simply telling employees to act ethically or follow the rules isn’t enough. If underlying assumptions about risk, accountability, or success conflict with compliance values, those assumptions will prevail.

 The Skills-Based Approach: A Paradigm Shift

The skills-based approach focuses on building specific, actionable skills that directly impact critical challenges. These skills—such as perspective-taking or fostering psychological safety—are practiced in real business problems. Organizations create a feedback loop that reinforces new assumptions and behaviors by linking skill application to tangible outcomes.

For example, a compliance team could focus on enhancing perspective-taking to improve employees’ handling of ethical dilemmas. By training employees to consider different viewpoints—such as the customer, regulator, or broader community—they better understand how their actions align with the organization’s compliance goals.

Breaking the Capability Trap 

Hugander warns of the “capability trap,” a common pitfall where organizations abandon new initiatives before they yield results. This happens when the costs—time, focus, and effort—are immediate, but the rewards are delayed. To overcome this, the skills-based approach emphasizes creating short feedback loops by applying new skills to high-priority challenges. This allows employees to see the benefits of the new approach more quickly, generating momentum for change.

The capability trap might manifest in compliance when a new whistleblower program is launched but does not initially generate reports, leading leaders to doubt its effectiveness. The organization can build trust in the system and encourage broader use by coupling the program with communication training for managers and immediate action on even minor concerns raised.

Compliance Lessons from the Skills-Based Approach 

  1. Start Small, Go Deep. Hugander advocates beginning with a small team and focusing on intensive skill-building sessions tied to real challenges. This allows the team to build confidence in the new approach and generate success stories that can inspire broader adoption. This means the Chief Compliance Officer (CCO) or other compliance professional should select a pilot group, such as a high-risk department or business unit, and train them on a specific compliance skill, such as ethical decision-making or identifying conflicts of interest. Have them apply these skills to actual compliance challenges and measure the outcomes.
  2. Create Cultural Champions. Identifying and empowering influential individuals to champion new behaviors is critical. These champions provide proof of concept by demonstrating how the new skills lead to better outcomes in the organization’s context. For the CCO, work to cultivate champions within senior leadership and middle management. A senior executive might lead by example in applying transparency during a compliance audit, while a middle manager might model open discussions about ethical or integrity concerns.
  3. Link Compliance to Business Outcomes. A key feature of the skills-based approach is tying new skills to measurable business improvements. Perspective-taking and psychological safety led to increased customer acquisitions and market share in Amy Edmonson’s SEB case study. For the compliance professional, you can demonstrate how compliance initiatives support business goals. Show how enhanced due diligence processes reduce the risk of fines and improve supplier reliability, ultimately benefiting the bottom line.
  4. Address Skepticism Through Experience. Short workshops are often insufficient to win over skeptics. Instead, intensive, hands-on sessions that produce actual results are more likely to shift mindsets. Skeptics who experience success become the strongest advocates for change. Integrate compliance into strategic problem-solving sessions instead of relying solely on compliance training. This would allow the compliance function to use a compliance framework to resolve a cross-functional challenge, demonstrating its practical value.

Building Momentum for Compliance Culture Change 

The skills-based approach does not stop with a single team or project. Once initial successes are achieved, the organization can share these stories to build momentum. Hugander emphasizes the power of storytelling, using real examples to illustrate how new skills or behaviors lead to meaningful outcomes. Some strategies might be to develop case studies from early adopters of compliance initiatives within your organization. You can then share these stories through town halls, newsletters, or internal training sessions.  Finally, these success stories can be used to recruit additional teams to adopt the new compliance practices.

All of this will take a concerted effort. A one-and-done superficial effort like one-off workshops or values posters, which fail to address the deeper assumptions driving behavior, will not work. True culture change requires sustained effort, leadership buy-in, and a willingness to experiment and iterate. You must regularly assess the effectiveness of compliance initiatives through employee surveys, performance metrics, and feedback loops. Adjust strategies based on what works in practice, not just in theory.

Building a compliance culture requires more than policies and procedures; it demands a shift in the underlying assumptions and behaviors that define an organization’s operation. The skills-based approach offers a practical roadmap for achieving this transformation. By focusing on skill development, linking compliance to business outcomes, and creating cultural champions, compliance professionals can foster a culture that doesn’t just follow the rules but embraces compliance as a core value.

The journey will not be quick or easy, but the payoff of creating a resilient, ethical, and high-performing organization is well worth the effort. For compliance professionals ready to lead this charge, the skills-based approach provides the tools to turn vision into reality.

Categories
Great Women in Compliance

Great Women in Compliance – Compliance, Consistency and Agility with Lisa Beth Lentini Walker

In our 2025 kickoff episode, Lisa speaks with Lisa Beth Lentini Walker, Deputy General Counsel, Corporate Legal, and Assistant Secretary at Marqeta, the CEO and Founder of Lumen Worldwide Endeavors. Lisa Beth is also a mentor, advocate, and friend to many in the compliance community.

While many people consider a CECO role their ultimate career goal, others look to a more GC-focused role. In the past few years, Lisa Beth’s career has evolved in that way while she remains involved in compliance. In this episode, she talks about her role, how serendipity and planning helped her get to where she is, and how it is important to be intentional while staying open to new opportunities.

In discussing 2025, Lisa Beth notes that her theme of the year is “consistency” and how this is important not only in work but also in being present with family, friends, and community. In terms of the ethics and compliance landscape, they discuss how this will likely be a year of change in regulations in the US and globally and the importance of being agile.

Lisa Beth was recently certified by Women in AI Governance as a Founding Quantum Member. She discusses the importance of learning about AI for E&C professionals and says this is a good time to start a wide learning journey in AI as the field expands.

In the earlier GWIC iteration, Ellen Hunt joined Lisa every year to discuss the state of the function before she officially joined “Team GWIC,” we hope Lisa Beth will reflect with us next year, too.

Categories
Blog

Revolutionizing Compliance with AI-Powered KPIs 

In the modern corporate landscape, traditional key performance indicators (KPIs) are struggling to meet the demands of dynamic compliance environments. These legacy metrics often fail to align operations, prioritize resources, and drive accountability toward strategic objectives. For compliance professionals, these shortcomings are particularly critical: ineffective KPIs can lead to missed risks, inefficient processes, and poor decision-making, ultimately jeopardizing organizational integrity.

In a recent article in the Sloan Management Review, entitled The Future of Strategic Measurement: Enhancing KPIs With AI, authors Michael Schrage, David Kiron, François Candelon, Shervin Khodabandeh, and Michael Chu explored these and other issues, which I have adapted for the compliance professional.  By incorporating artificial intelligence (AI), organizations are reimagining what KPIs can accomplish—not just as performance trackers but as drivers of strategic differentiation and value creation.

The Shortcomings of Legacy KPIs in Compliance

Legacy KPIs often focus narrowly on outputs, such as the number of training sessions conducted or hotline calls logged. While these metrics provide valuable data, they frequently fail to provide solid information in various ways. The first is that legacy KPIs are taken in a vacuum with no appreciation of the interconnected nature of corporate risks. Just as compliance does not (or at least should not) operate in a vacuum, risks in one area often cascade into others, yet traditional KPIs rarely reflect these interdependencies. The retrospective nature of KPIs. Metrics rooted in historical data are inherently backward-looking, limiting their utility for forecasting and proactive risk management.

Finally, corporate silos, which are a perennial challenge in compliance, and static KPIs can reinforce them rather than foster cross-functional collaboration. Legacy KPIs do not promote alignment across disparate corporate functions. These limitations hinder a compliance professional’s ability to effectively anticipate, prevent, and address misconduct.

Enter Smart KPIs: A New Era of Compliance Metrics

AI-powered KPIs offer a smarter, more dynamic approach to performance measurement. These metrics are descriptive, predictive, and prescriptive. Such metrics will allow a corporate compliance function to provide new and different insights, such as some of the following.

  • Analyze past and current compliance performance to identify gaps.
  • Anticipate future risks and compliance trends based on patterns in data.
  • Recommend actions to mitigate risks and optimize outcomes.

For example, AI can transform a traditional metric like the “number of third-party audits conducted” into a prescriptive KPI that evaluates audit results, predicts the highest risk areas, and recommends corrective actions.

Case Study: Wayfair and the Evolution of Lost-Sales KPIs

The article discussed Wayfair’s reengineering of its lost-sales KPI and offers valuable insights for compliance professionals. Initially, the retailer calculated lost sales on an item-by-item basis, but AI analysis revealed that many “lost” sales were category retentions, as customers purchased alternative items. This revelation led Wayfair to redesign its KPI to measure category-based retention. The result? Smarter metrics aligned product placement with operational constraints, improving customer satisfaction and operational efficiency.

This case study provides a clear set of lessons for corporate compliance and the compliance professional. Compliance teams can use AI to rethink KPIs that do not fully capture performance nuances. For instance, instead of merely tracking the number of training completions, a smarter KPI could evaluate behavioral changes post-training or identify employees most at risk of ethical lapses based on historical data. This, in turn, could provide greater insight into training effectiveness and how a compliance professional might think about targeted training.

KPI Governance: A Compliance Imperative 

One of the most critical aspects of AI-enhanced KPIs is governance. Organizations need robust governance mechanisms to ensure KPIs evolve with strategic objectives and maintain their relevance over time. For a compliance professional, this means several different approaches.

  1. Continuous Review of Metrics. Regularly revisiting KPIs to ensure they remain aligned with evolving regulatory landscapes and business priorities.
  2. Meta-KPIs for Quality Assurance. Developing “KPIs for KPIs” to assess their accuracy, relevance, and effectiveness.
  3. Cross-Functional Oversight. Establishing governance structures that bring together compliance, legal, and operational teams to oversee metric design and implementation.

The bottom line is that accountability for KPI performance, both the metrics themselves and the outcomes they drive, must be embedded into the compliance framework.

How AI Enhances Compliance KPIs

AI-enhanced KPIs bring new capabilities to compliance programs in three key manners. First, in risk anticipation. Predictive KPIs can identify emerging compliance risks, such as regulatory changes, third-party risk management, or shifts in employee behavior, enabling proactive mitigation. The second area is holistic insights. By analyzing data across functions, AI can uncover hidden correlations, such as how employee hotline reports, visits to the compliance department website, or even the number of requests to FAQs might signal compliance risks in supply chain operations. Finally is the area of targeted recommendations. Prescriptive KPIs can suggest specific actions, like prioritizing high-risk vendors for audits or tailoring training to address observed knowledge gaps. For example, AI could analyze whistleblower reports alongside financial data to identify patterns indicative of systemic fraud, providing actionable insights for remediation. 

 This more holistic approach also addresses one of the key risk areas around KPIs: stagnate KPIs. The 2008 financial crisis underscores the dangers of relying on outdated KPIs. Banks’ dependence on “value at risk” metrics, which failed to account for the growing influence of subprime mortgages, contributed to catastrophic losses. Compliance professionals must guard against similar pitfalls by regularly challenging assumptions underpinning legacy KPIs. AI can aid in this process by continuously analyzing data to reveal when a metric is no longer fit for purpose.

Steps to Implement Smarter Compliance KPIs

Compliance professionals can take the following steps to transition from legacy to AI-enhanced KPIs.

  1. Audit Existing KPIs. Assess whether current metrics adequately capture compliance risks and align with strategic objectives.
  2. Leverage AI for Data Analysis. Use AI tools to uncover hidden patterns in compliance data, such as correlations between employee turnover and ethics violations.
  3. Collaborate Across Functions. Work with IT, legal, and operations teams to ensure KPI redesigns reflect organizational priorities.
  4. Invest in Training and Culture. Equip compliance teams with the skills to interpret and act on AI-generated insights while fostering a culture of data-driven decision-making.
  5. Monitor and Improve KPIs. Establish processes for ongoing KPI evaluation, ensuring they evolve alongside regulatory and stakeholder input and business changes.

Challenges and Ethical Considerations 

While AI-enhanced KPIs offer immense potential, they also present challenges. These challenges include some of the following. Just as with more generative AI, algorithms can be biased. AI models are only as unbiased as the data on which they are trained. Compliance teams must ensure that their AI systems uphold principles of fairness and equity. Always remember the Human in the Loop to preclude over-reliance on AI. While AI can inform decision-making, it should not replace human judgment. Compliance professionals must strike a balance between algorithmic insights and ethical considerations. Finally, there are data privacy concerns. Collecting and analyzing large datasets for KPI development must comply with data privacy regulations.  

Conclusion: The Future of Compliance Metrics 

The rise of AI-enhanced KPIs marks a paradigm shift in measuring and managing compliance performance. By embracing smarter, more dynamic metrics, compliance professionals can gain deeper insights, anticipate risks, and drive better outcomes.  Much like Wayfair and other forward-thinking organizations, compliance teams must be willing to challenge the status quo, leverage technology, and prioritize continuous improvement. The era of static, backward-looking KPIs is over. In its place is a future where smart KPIs enable compliance functions to not only measure performance but actively enhance it—turning compliance from a cost center into a source of strategic value. The question is not whether your organization should adopt AI-powered KPIs but how soon your compliance program can reap the benefits. The time to act is now.

Categories
Blog

The Character Imperative in Leadership: A Lesson for Compliance Professionals

When discussing leadership transitions at troubled organizations, one recurring theme is often overlooked: character’s pivotal role in shaping culture and outcomes. In an MIT Sloan Management Review article entitled “Make Character Count in Hiring and Promoting,” Mary Crossan posited, “Most managers focus on competencies when evaluating candidates—but it’s a character that will transform the DNA of the organization.”

The recent challenges faced by Boeing serve as a cautionary tale for compliance professionals worldwide. Despite their technical prowess and storied history, Boeing’s leadership failures, rooted in compromised decision-making and a lack of character-driven judgment, led to catastrophic consequences for safety, public trust, and, ultimately, their bottom line.

The leadership debate at Boeing has focused narrowly on whether the next CEO should be an engineer or an accountant, emphasizing competencies over character. This approach underscores a persistent failure across industries to recognize that strong character-based judgment is a cornerstone of ethical leadership and compliance success.

This offers a critical lesson for compliance professionals: character matters as much as, if not more than, competence. The organizational culture we build reflects the character of the individuals we hire, promote, and retain. Compliance leaders must champion character as a vital element in talent development and how to embed this principle into their practices.

Competence vs. Character: Understanding the Difference 

Competence concerns what someone can do, their technical skills, knowledge, and experience. It varies by organization, role, and level within the hierarchy. In contrast, the character is about who someone is. It’s universal and intrinsic, shaped over a lifetime, and critical to ethical decision-making.

Research shows that character comprises 11 interconnected dimensions, each manifesting in observable behaviors. These dimensions include courage, humility, temperance, accountability, and judgment. Importantly, character isn’t static; it’s a habit that can be developed and refined over time.

When organizations equate character with a narrow set of qualities, such as drive and accountability, they risk embedding toxicity and poor judgment into their culture. For example, a leader with unrestrained courage may veer into reckless decision-making without the tempering force of humility. Such imbalances ripple through the organization, driving disengagement and turnover among those with stronger, more balanced character.

This interplay between character and culture is a leverage point for compliance professionals. We can foster ethical cultures prioritizing accountability, transparency, and trust by elevating character assessments to the same level as competence evaluations. 

Character Interviews: A Tool for Compliance Leaders

Traditional interviews focus on competencies through structured questions and rubrics. Character interviews, however, require a more nuanced approach. They are conversational and personalized, designed to explore a candidate’s life story and reveal their character dimensions.

Here are key considerations for conducting effective character interviews:

  1. Prepare by Developing Your Own Character. To assess the character of others, interviewers must first reflect on their biases and imbalances. For instance, understanding the dimension of justice requires recognizing how systemic privileges and inequities shape perceptions of fairness.
  2. Engage in Genuine Conversations. A character interview should feel less like a formal assessment and more like exploring the candidate’s experiences, motivations, and values. This approach uncovers the layers of their character organically.
  3. Probing Questions and Observational Insights. Start with broad, open-ended questions and follow the threads of the candidate’s responses. For example, if candidates emphasize their innovative drive, explore how they’ve balanced it with temperance or collaboration.
  4. Cluster Dimensions to Identify Strengths and Weaknesses .Character dimensions are interconnected and should be evaluated holistically. A candidate with strong accountability and courage but weak temperance might struggle to balance ambition with thoughtful decision-making.
  5. Assess the Interviewer’s Character. Character interviews reveal the interviewee’s strengths and weaknesses as well as the interviewer’s. Candidates often assess organizations based on the character of those conducting the interviews.

Character in Promotions and Talent Development

Promotions signal what qualities an organization values most. When those decisions prioritize competence over character, they risk elevating individuals whose imbalances could undermine ethical culture.

One effective approach is integrating character assessments into 360-degree reviews for promotion candidates. For example, an organization identified a highly competent leader whose humility and collaboration needed development. By assigning him to an unfamiliar overseas role, they created an environment where he had to rely on others and build relationships, strengthening his weaker character dimensions.

Compliance professionals can advocate for similar strategies, ensuring that promotions are about past performance and readiness for ethical leadership.

Building Character-Based Cultures in Compliance

Embedding character into hiring and promotion decisions isn’t just about individual roles; it’s about shaping organizational DNA. Here is how compliance teams can lead this transformation:

  1. Educate on the Importance of Character. Host workshops or training sessions on the 11 dimensions of character and their relevance to compliance and ethical decision-making.
  2. Develop Character Assessment Tools. Create structured yet flexible frameworks for evaluating character in interviews, performance reviews, and succession planning.
  3. Provide Feedback for Development. Constructive feedback helps individuals recognize and address character imbalances. Compliance leaders can normalize character development as an ongoing process.
  4. Model Character-Driven Leadership. Compliance teams should exemplify the values they seek in others, demonstrating integrity, transparency, and humility in their interactions and decision-making.

The Compliance Professional’s Role

Character-driven leadership is essential to navigating today’s complex ethical landscape. For compliance professionals, this means advocating for systems that value character alongside competence. It means challenging the status quo in talent management and championing leaders who embody integrity, humility, and balanced judgment.

Boeing’s leadership failures are a stark reminder of what happens when a character is sidelined. By prioritizing character in our organizations, we can mitigate risk and build cultures that inspire trust, accountability, and long-term success.

Your corporate compliance function’s future and your entire organization depend on it.

Categories
Blog

Lessons in Corporate Governance from the NRA

Corporate governance often shines brightest in times of crisis, and few organizational crises have unfolded as publicly or contentiously as the litigation involving the National Rifle Association (NRA). In a recent Order from the years of ongoing litigation in New York state, the Court mandated sweeping governance reforms, providing a treasure trove of lessons for compliance professionals seeking to strengthen Transparency, accountability, and oversight in their organizations. Regardless of your personal or political views on the NRA, this case underscores universal principles of good governance. Let’s unpack these lessons and explore how they can be applied across organizations of all types and sizes. Matt Kelly wrote about this topic in a blog post, and we explored its implications for compliance professionals in a recent episode of the Compliance into the Weeds podcast.

What Happened at the NRA?

The NRA’s troubles began with allegations of rampant mismanagement under long-time CEO Wayne LaPierre. The New York Attorney General’s lawsuit in 2020 detailed years of financial abuses, including excessive salaries and lavish spending billed to the organization, conflicts of interest, and questionable vendor relationships, held together by a structurally weak board that served as a rubber stamp for LaPierre’s decisions. The fallout included four years of litigation, a jury finding LaPierre liable for abuses, and, ultimately, a court-mandated series of governance reforms designed to ensure the NRA could never again fall victim to such mismanagement.

Key Governance Failures

The NRA’s dysfunction stemmed from several structural weaknesses common to organizations suffering from poor governance. An overpowering CEO, LaPierre, exerted an outsized influence enabled by a lack of checks and balances. There needed to be stronger board oversight, with 76 members. The board needed to be bigger and more cohesive to provide effective governance. A small faction, aligned with the CEO, controlled key decisions. There needed to be more financial controls. This absence of robust controls allowed the CEO to withhold critical information from the board. These issues, while prominent in the NRA, are not unique. Theranos, Wynn Resorts, and countless other organizations have fallen prey to similar patterns.

The Reforms: A Blueprint for Good Governance

Judge Cohen’s final ruling laid out a series of governance reforms that every compliance professional should study and consider incorporating into their organization. The Court strengthened the NRA Audit Committee in various ways. First, the entire board now elects Audit Committee members, ensuring independence. Equally importantly, former audit committee members from 2014 to 2022 are barred from future service to eliminate cronyism.

Board refreshment was given importance. The Nominating and Governance Committee must propose 20 new director candidates annually for five years, injecting fresh perspectives and reducing entrenchment. The Court created a committee on board effectiveness, recommending measures to make the large board more functional, possibly through a smaller, empowered executive committee.

There were significant areas for the compliance function and the Chief Compliance Officer (CCO). The first was a mandate that the CCO deliver an annual report detailing travel expenses, related-party transactions, and whistleblower hotline activity.  This report ensures that the board has visibility into high-risk areas. There was a section on CCO empowerment and protection. The CCO now has employment protections, including a three-year contract and two years’ severance pay if terminated without cause. These measures give the CCO the independence to address risks without fear of retaliation. Finally, there is a mandate for independent oversight, with an external consultant assisting the CCO in developing and implementing governance improvements.

Universal Lessons for Compliance Professionals

The reforms imposed on the NRA are not merely punitive; they are a masterclass in building robust governance frameworks. There are several important points for every compliance officer.

1. Empower Your Compliance Function. An independent compliance officer is a figurehead. Employment protections, direct reporting lines to the board, and clear mandates are essential to ensure the CCO can act as an effective watchdog.

2. Prioritize Transparency. Transparency must be embedded in governance structures. Mechanisms like annual compliance reports provide critical insights into organizational risks and ensure the board has the information needed to fulfill its oversight role.

3. Strengthen the Board. Boards should be diverse, independent, and active in their oversight responsibilities. Critical steps include refreshing board membership and ensuring committees are free from undue influence.

4. Focus on Financial Controls. Weak financial controls are a common thread in governance failures. Organizations should implement robust policies to monitor executive spending, conflicts of interest, and other high-risk areas.

5. Learn (and Use) from Templates The Court Order includes detailed templates for compliance reports, employment contracts, and governance policies. While tailored to the NRA’s specific issues, these documents can serve as starting points for any organization seeking to strengthen its governance practices.

Good Governance Is Universal

Good governance transcends an organization’s specific mission or values. Whether your entity is a nonprofit like the NRA, a public company, or a private enterprise, strong governance principles, an empowered board, Transparency, and accountability remain constant. Judge Cohen’s reforms highlight the importance of building durable structures that withstand the pressures of powerful personalities and shifting priorities. These reforms serve as a reminder that governance is not just about preventing crises but ensuring the organization stays true to its mission.

The NRA’s governance overhaul is a cautionary tale and an opportunity for all compliance professionals. By studying the Court’s findings and implementing similar reforms, organizations can build stronger foundations for accountability and ethical leadership.

In the words of Matt Kelly, “Good governance is a universal principle dependent on building durable structures for transparency and vigorous oversight.” Let this case inspire your efforts to create governance frameworks that protect your organization’s integrity, irrespective of its mission or values.

Categories
Compliance Into the Weeds

Compliance into the Weeds: NRA Governance Reforms: A Compliance Case Study

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode, Tom Fox and Matt Kelly dive into the intricate and unusual story of the National Rifle Association (NRA) and its recent corporate governance overhaul.

Matt and Tom explore Judge Joel Cohen’s final ruling, which mandates extensive corporate governance reforms for the NRA. These reforms address significant issues, such as a structurally weak board, poor financial controls, and an overpowering CEO in Wayne LaPierre, who misused the organization’s resources. Necessary measures discussed include revamping the board’s audit committee and introducing annual compliance reports, along with significant protections for the role of the Chief Compliance Officer.

The episode highlights the universal principles of good governance, asserting that the NRA’s reforms can serve as a valuable lesson for other organizations. Regardless of the political or ethical stance on the NRA’s activities, the implemented governance structures underscore the necessity of transparency, an empowered compliance function, and robust oversight mechanisms to prevent misuse of organizational resources. These insights are illustrated through sample agreements and templates in the court ruling, which can guide other organizations in strengthening their governance and compliance programs.

Key highlights:

  • Corporate Governance Reforms Ordered by the Court
  • Specifics of the Court-Ordered Reforms
  • Audit Committee and Board Reforms
  • Compliance and Governance Templates
  • Universal Principles of Good Governance

Resources

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

The Role of Compliance in Employee Retention

The fight to attract and retain top talent has long been a concern for corporate leaders, but the stakes are even higher for compliance professionals. The insights from the Harvard Business Review (HBR) article Why Employees Quit the authors offer actionable lessons that compliance professionals can integrate into their strategic efforts. Let’s explore how fostering a meaningful employee experience can mitigate compliance risks and strengthen organizational integrity.

The Compliance Costs of Employee Attrition

Employee turnover is more than a budgetary concern; it is also a compliance risk. When experienced employees leave, they take with them institutional knowledge, including an understanding of the organization’s policies, culture, and compliance framework. The cost of replacing employees ranges from 6 to 9 months of their salary—and for executive roles, it can double their annual pay. More insidiously, high attrition rates may signal deeper issues, such as cultural dysfunction or ethical lapses, which could attract regulatory scrutiny.

For the compliance professional, employee retention is not simply about the cost of replacement and retraining but about sustaining a culture of ethics and compliance. Addressing the root causes of turnover is an investment in long-term corporate resilience.

Understanding Employee Quests for Progress

The authors identify four primary motivations driving employees to switch jobs:

  1. Getting Out- escaping from toxic environments or dead-end roles.
  2. Regaining Control- seeking autonomy and work-life balance.
  3. Regaining Alignment – a desire for respect and utilization of skills.
  4. Taking the Next Step- pursuing growth opportunities.

Each of these quests resonates with compliance principles. For example, consistent policy enforcement may frustrate employees seeking alignment, while those striving for growth may feel supported by a lack of training or mentorship.

Compliance Takeaway: A compliance program should ensure adherence to laws and regulations and foster an environment where employees feel valued and empowered.

Proactive Measures: Compliance as a Partner in Employee Retention

The authors recommend three strategies for aligning employee experiences with organizational goals. Here’s how compliance can lead the charge:

  • Interview Employees Early and Often

Exit interviews should be conducted more often, but they should be too late. Instead, compliance professionals can implement regular “pulse checks” to assess the ethical climate and identify areas where employees feel unsupported. Consider aligning these efforts with the DOJ’s emphasis on continuous monitoring in compliance programs. As a practical step, include ethical climate questions in employee surveys and encourage anonymous reporting to surface hidden concerns.

  • Develop Shadow Job Descriptions

Official job descriptions often need to capture the dynamic realities of roles, leading to mismatched expectations. Compliance can play a pivotal role in ensuring these descriptions reflect the ethical responsibilities associated with the job. Your corporate compliance function should work closely with HR to include clear expectations for ethical behavior, reporting obligations, and compliance training in every role.

  • Collaborate with HR to Align Roles with Employee Progress

Flexible role design can create opportunities for employees to grow while adhering to compliance standards. This approach satisfies employees’ quests for progress and reduces the likelihood of ethical lapses driven by disengagement or frustration. This ties directly into what the DOJ wants to see around non-financial incentives for employees doing business ethically and in compliance. The 2024 ECCP speaks directly to this issue, and once again, compliance should partner with HR to design roles that balance individual aspirations with organizational needs, ensuring compliance remains a core element and fully incentivizes employees in and around compliance.

The Compliance Implications of “Pushes” and “Pulls”

The authors identify joint “push” factors, such as lack of trust, poor management, and generally poor culture, as well as “pull” factors, including alignment with values, flexibility, and a more positive corporate culture in job switches. Push Factors include a lack of trust in leadership, which often correlates with higher compliance risks. Employees disengaged from management will typically disengage from compliance initiatives. Conversely, Pull Factors enhance values-driven employees. Such employees are more likely to thrive in organizations that prioritize ethical behavior. Compliance professionals should pay close attention to these dynamics in their organizations. Moreover, for corporate compliance professionals, as the holders of Institutional Justice and Institutional Fairness in an organization, addressing push factors and amplifying pull factors can help create a culture where compliance is not merely a requirement but a shared value.

Technology’s Role in Enhancing the Employee Experience

Advanced compliance monitoring tools like AI-driven analytics can support compliance objectives and employee retention efforts. These tools can provide real-time insights into employee sentiment, flagging potential compliance risks while highlighting areas for improvement in the employee experience. Compliance professionals can utilize analytics to monitor ethical climate indicators, including response rates to compliance training and engagement in whistleblower programs.

Building a Workplace Employees Want to “Rehire” Every Day

Compliance professionals have a critical role in shaping an ethical, engaging workplace. By embedding employee-focused strategies into compliance initiatives, organizations can reduce turnover, strengthen their ethical culture, and build a more resilient compliance program.

The employee experience is no longer a “soft” issue; it is now imperative for compliance. By proactively addressing why employees leave, compliance leaders can ensure their organizations retain talent and integrity. For the CCO, you should ask: Are you engaging your employees in ways that align with compliance priorities? If not, it’s time to reimagine compliance as a partner in the employee experience. This intersection of compliance and employee experience is an opportunity to drive meaningful change. Compliance professionals need to seize it and move your entire culture forward.

Categories
Blog

Auditors and Compliance: Part 2 – Ten Key Takeaways for Compliance Professionals

The PCAOB’s recent information release, SPOTLIGHT Auditor Responsibilities for Detecting, Evaluating, and Making  Communications About Illegal Acts, is a critical guide for compliance professionals. The SPOTLIGHT sets out the role of auditors in assessing a company’s compliance with laws and regulations, particularly how auditors must identify, evaluate, and communicate potential illegal acts. However, for compliance officers, the SPOTLIGHT highlights areas where compliance and audit functions intersect and emphasizes collaboration’s importance to maintaining regulatory adherence and upholding financial integrity. Yesterday, we reviewed the roles and duties assigned to auditors. Today, we will dive into the 10 key takeaways for compliance professionals, outlining what they need to know to align their efforts with audit processes and effectively support their organization’s commitment to compliance.

  • Understand the Auditor’s Role in Identifying Illegal Acts

Auditors have a duty to detect and evaluate illegal acts that could materially impact a company’s financial statements. This includes assessing the potential effect of any illegal activity on the company’s financials and reporting these issues to management, the audit committee, and sometimes to the SEC. Compliance professionals need to understand this role to support auditors in fulfilling these obligations, especially by maintaining a strong compliance program that actively monitors regulatory adherence. Compliance should ensure that internal policies align with PCAOB standards and legal requirements, helping auditors conduct a thorough risk assessment as part of their evaluation.

  • Maintain Transparent and Open Communication Channels

Transparency and open communication are vital for a successful compliance-audit relationship. Auditors depend on information from management, the audit committee, and legal counsel to identify and evaluate potential violations. Compliance professionals should facilitate open communication with auditors and provide timely access to relevant information. This includes documentation from internal investigations, responses to auditor inquiries, and any corrective actions taken to address potential illegal acts. Proactively sharing information about compliance efforts demonstrates a commitment to ethical practices and supports auditors’ work to provide an accurate assessment of the company’s financial statements.

  • Foster a Strong Internal Reporting Culture

Auditors must inquire about complaints and tips, including those from whistleblower programs. For compliance professionals, this highlights the importance of fostering an internal reporting culture where employees feel safe raising concerns. A robust whistleblower program and other internal reporting mechanisms help identify potential illegal acts early, allowing the company to take action before issues escalate. Compliance teams should ensure employees know how to report concerns confidentially and clearly communicate that the company prohibits retaliation against whistleblowers. This can help create a steady pipeline of information that aids both compliance and audit functions in proactively addressing potential issues.

  • Document Document Document

Thorough documentation is crucial in every compliance arena, whether regulatory reporting, high-value transactions, or industry-specific regulations. (The Tom Fox Mantra Document Document Document.) Compliance professionals should maintain clear records of all compliance activities, internal investigations, and responses to auditor inquiries. By providing auditors with well-documented information, companies can help auditors assess whether any potential illegal acts are isolated incidents or indicative of broader compliance concerns. Such documentation facilitates the audit process and demonstrates to regulators a serious commitment to compliance.

  • Prioritize High-Risk Areas with Targeted Monitoring

Auditors focus on high-risk areas in their evaluations, such as transactions or activities with greater potential for legal violations. Compliance professionals should proactively monitor these high-risk areas to detect and mitigate issues before they escalate. For instance, compliance in industries with high regulatory scrutiny should ensure that the organization adheres to all industry-specific legal requirements. Regularly evaluating high-risk areas through targeted monitoring helps create a solid foundation for internal and external financial statement audits, reducing the chance of undetected illegal acts.

  • Be Prepared to Act on Auditor Findings Promptly

When auditors identify potential illegal acts, it is essential for compliance to respond swiftly and decisively. This involves conducting a thorough internal investigation and determining any required disclosures or corrective actions. From there, you should perform a Root Cause Analysis and then proactively address any concerns from auditors to help the organization maintain transparency and avoid further regulatory scrutiny. A prompt response strengthens the relationship between the compliance and audit functions and demonstrates to auditors and regulators a proactive approach to managing and mitigating compliance risks.

  • Strengthen Leadership’s Commitment to Compliance

The PCAOB emphasizes the importance of a “tone at the top” in its guidance, noting that auditors consider a company’s commitment to compliance when assessing potential illegal acts. Compliance teams should work with executive leadership to promote a strong culture of ethics and compliance, as this can significantly impact employee behavior and organizational practices. A commitment to compliance at the leadership level signals to employees that ethical conduct is a priority, supporting the organization’s overall compliance efforts. When leadership promotes compliance, employees are more likely to report concerns, and auditors can rely on the company’s internal controls and integrity.

  • Prepare for Potential Notification

If auditors discover a material illegal act and management fails to take appropriate action, the auditor may be required to notify the SEC or DOJ. For compliance professionals, this highlights the importance of swift and transparent responses to any findings of illegal activity. Working closely with auditors to address material findings and avoid potential SEC/DOJ notification is crucial. When the compliance function demonstrates a proactive approach to addressing auditor findings, it helps maintain the organization’s reputation, strengthens auditor relationships, and reduces the likelihood of regulatory intervention.

  • Regularly Review and Update Compliance Training

Auditors also assess a company’s internal compliance functions, including how well employees understand and adhere to compliance obligations. Regular compliance training ensures that employees are informed about identifying and reporting illegal acts, understand whistleblower protections, and know the resources available to them. Compliance professionals should review and update training programs frequently to address any changes in laws or regulations and any emerging risks specific to the company’s industry. Effective training reinforces employees’ commitment to ethical behavior and supports the company’s internal controls, bolstering the compliance-audit relationship.

  • Emphasize Materiality Assessments in Compliance Evaluations

When auditors evaluate the impact of illegal acts, they consider both quantitative and qualitative materiality. Compliance teams should adopt a similar approach when assessing potential violations. For instance, even a small illegal payment could be material if it raises ethical concerns or results in contingent liabilities. By considering potential violations’ financial and reputational implications, compliance teams can better assess the materiality of issues and take appropriate corrective action. This approach aligns with auditor standards and helps create a thorough and effective compliance environment.

Strengthening Compliance and Audit Collaboration

The PCAOB’s guidance reminds compliance professionals that a proactive approach to detecting, evaluating, and addressing potential illegal acts is essential. By understanding the auditor’s role and aligning compliance practices with PCAOB and SEC standards, compliance teams can effectively support auditors and contribute to a thorough evaluation of the organization’s adherence to laws and regulations.

A corporate compliance function plays a crucial role in creating a transparent, accountable organization where employees feel empowered to raise concerns and management responds promptly to address potential issues. Strong compliance-audit collaboration enables companies to build trust with regulators and stakeholders, demonstrating a commitment to ethical business practices. By implementing these takeaways and fostering a culture of compliance, companies can better navigate regulatory requirements and mitigate the risk of material misstatements or regulatory penalties, upholding the integrity of their financial statements and safeguarding their reputation in an increasingly scrutinized environment.

Categories
Great Women in Compliance

Great Women in Compliance – Joy Hayes and Gitanjali Sakhuja on Expats and Repats: Working Abroad & Reentry to the US

Welcome to the Great Women in Compliance podcast with Hemma Lomax and Lisa Fine, sponsored by Corporate Compliance Insights. Have you considered being an Expat and what it’s like to return after being abroad? This #GWIC episode explores what you need to know on both legs of the journey and the rich personal and professional growth that comes from immersing yourself in another culture and country.

Our expat guests, Joy Hayes, who has just moved to Geneva, Switzerland, and Gitanjali Sakhuja, who has worked in seven different countries and is now back in the U.S., share their journey, tips, and practical advice. Their insights range from when you decide to work in another country to when you return home – and some great experiences (and challenges). Ellen Hunt leads this roundtable discussion with our guests, who share their personal experiences and professional insights on becoming an expat and repat, including balancing expectations, the importance of language proficiency, and the challenges of tax and visa regulations. They also delve into the emotional aspects of adjusting to life abroad and the reentry process, offering practical tips and anecdotes. 

Thanks, as always, to our sponsor, Corporate Compliance Insights, and our wonderful #GWIC community.  You can join the Great Women in Compliance community on LinkedIn here.

Categories
10 For 10

10 For 10: Top Compliance Stories For the Week Ending November 16, 2024

Welcome to 10 For 10, the podcast that brings you the week’s Top 10 compliance stories in one podcast each week. Tom Fox, the Voice of Compliance, brings you the compliance professional and the compliance stories you need to know to end your busy week. Sit back, and in 10 minutes, hear the stories every compliance professional should know from the prior week. Every Saturday, 10 For 10 highlights the most important news, insights, and analysis for the compliance professional, all curated by the Voice of Compliance, Tom Fox. Get your weekly filling of compliance stories with 10 for 10, a podcast produced by the Compliance Podcast Network.

  • Meta fined $840MM in EU for anti-trust violations. (NYT)
  • SBF LT. Builds fraud detection tool for DOJ. (Reuters)
  • Shell wins appeal in landmark climate case. (NYT)
  • ADM CCO steps down amid probe.  (Bloomberg)
  • End of ESG and crypt initiatives at SEC. (WSJ)
  • What science reveals about corruption. (El Pais)
  • Telefónica Venezuela settles FCPA action. (WSJ)
  • Handling a difficult employee with health issues. (NYT)
  • Hidden cost of textile and apparel non-compliance. (Homeland Security Today)
  • NetEase execs arrested for bribery and money laundering.  (biz)

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

You can check out the Daily Compliance News for four curated compliance and ethics-related stories each day here.

Check out the full 3-book series, The Compliance Kids, on Amazon.com.

Connect with Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn