Categories
Blog

Levels of Due Diligence

Due diligence is generally recognized in three levels: Level I, Level II and Level III. Each level is appropriate for a different level of corruption risk. The key is to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward. Identifying key risk areas is essential to risk mitigation and the protection of your company’s reputation. Corporate and institutional investors need to know who they will be doing business with especially given heightening regulatory compliance actions by the US and other government agencies, and increasing geopolitical risk concerns.

The 2023 Evaluation of Corporate Compliance Programs (ECCP) stated, “A well-designed compliance program should apply risk-based due diligence to its third-party relationships. Although the need for, and degree of, appropriate due diligence may vary based on the size and nature of the company, transaction, and third party, prosecutors should assess the extent to which the company has an understanding of the qualifications and associations of third-party partners, including the agents, consultants, and distributors that are commonly used to conceal misconduct, such as the payment of bribes to foreign officials in international business transactions.”

The question becomes how you use the information you obtained in the business justification and the questionnaire to determine an appropriate level of due diligence for the next step in the five-step process of third-party management. A three-step approach of varying levels of due diligence is the appropriate analysis to take going forward.

A three-step approach was discussed in Opinion Release 10-02, in which the DOJ discussed the due diligence that the requesting entity performed:

First, it [the requestor] conducted an initial screening of six potential grant recipients by obtaining publicly available information and information from third-party sources … Second, the Eurasian Subsidiary undertook further due diligence on the remaining three potential grant recipients. This due diligence was designed to learn about each organization’s ownership, management structure and operations; it involved requesting and reviewing key operating and assessment documents for each organization, as well as conducting interviews with representatives of each MFI [microfinance institution] to ask questions about each organization’s relationships with the government and to elicit information about potential corruption risk. As a third round of due diligence, the Eurasian Subsidiary undertook targeted due diligence on the remaining potential grant recipient, the Local MFI. This diligence was designed to identify any ties to specific government officials, determine whether the organization had faced any criminal prosecutions or investigations, and assess the organization’s reputation for integrity.

This Opinion Release sets out a clear break that every compliance practitioner should use in considering an appropriate level of due diligence to engage with third-party risk management process or when considering the level of due diligence required on a potential business venture partner.

Further in October 2023 the DOJ announced the new Mergers and Acquisitions Safe Harbor Policy, which encourages companies to self-report corruption and criminal misconduct found during an acquisition. Companies that cooperate with federal regulators, investigate, and then remediate such misconduct may be eligible for criminal declination by the federal government. This process must be initiated within 6 months of the M&A transaction and is heavily dependent on effective due diligence.

Importantly, you can’t disclose what you don’t know. Understanding FCPA risks in foreign jurisdictions requires a deep level of due diligence based on local and regional intelligence.

Given the increasing sanctions and geopolitical risk environment it behooves a company to identify these risk factors. Due diligence investigations also help to identify national security risks ranging from corruption, and sanctions violations to terrorist financing. The stakes are increasingly serious for all companies working internationally and domestically within the US.

Due diligence investigations can reveal reputational risk, litigation issues, fraud and corruption risks, financial sanctions, criminal activity, supply chain risk, regulatory risk and environmental, social & governance (ESG) risks.

A very good description of the three levels of due diligence was presented by Candice Tal, Founder and CEO of Infortal Worldwide, in an article entitled, Deep Level Due Diligence: What You Need to Know.

Level I. First level due diligence typically consists of checking individual names and company names through over 1400 Global Watch lists comprised of AML, anti-bribery, sanctions lists, coupled with other financial corruption and criminal databases. These global lists create a useful first-level screening tool to detect potential red flags for corrupt activities. It is also a very inexpensive first step in compliance from an investigative viewpoint. Tal believes that this basic Level I due diligence is extremely important for companies to complement their compliance policies and procedures—demonstrating a broad intent to actively comply with international regulatory requirements.

Level I should also consider beneficial ownership records when they are available, and company tax information to assess whether the third party is financially sound and in compliance with tax payments as required within its primary country of business, plus a check of perceived business risks in that country. Additionally, the third party’s website should also be reviewed; it is unusual for a company not to have a website and this can be a preliminary flag that there are issues. Tal recommends verifying that the company address also exists; a non-verifiable address should be considered a potential red flag that would indicate the need for a deeper-level due diligence investigation.

Level I will reveal some of the key information needed to make preliminary risk exposure ranking decisions, especially for larger corporations who may have several hundred thousand vendors in their supply chains. However, Level I is very basic in scope and will not identify the majority of corruption risks; it should therefore only be considered a first step.

Level II. Level II due diligence encompasses a broader public records search and supplementing Global Watch lists with a negative keyword screening of international media, typically major newspapers and periodicals from all countries, plus detailed internet searches. Negative keywords are not the same as deep media/ OSINT searches as these focus on a smaller selection of keywords only. Such inquiries will often reveal other forms of corruption-related information and may expose undisclosed or hidden information about the company, the third-party’s key executives and associated parties.

Level II should also include everything found in Level I searches plus in-country database searches. Other types of information you should consider obtaining are country of domicile and international government records, use of in-country sources to provide assessments, a check for international derogatory electronic and physical media searches, which should be performed in both English and foreign-languages, in its country of domicile. Further, if you are in a specific industry, use technical specialists and obtain information from sector specific sources.

Level III. This level is a deep dive due diligence with a far more thorough investigation than the Level II scope, enabling a comprehensive assessment of corruption and business risks.

I agree with Tal that a Level III due diligence investigation is designed to supply your company “with a comprehensive analysis of all available public records data supplemented with detailed field intelligence plus a deep dive investigation of online records to identify known and more importantly unknown conditions. It will also require an in-country “boots-on-the-ground” investigation in the country involved. Seasoned investigators who know the local language and are familiar with local politics bring an extra layer of depth assessment to an in-country investigation.”    Further, Tal notes that:

Direction of the work and analyzing the resulting data is often critical to a successful outcome; and key to understanding the results both from a technical perspective and understanding what the results mean in plain English. Investigative reports should include actionable recommendations based on clearly defined assumptions or preferably well-developed factual data points. These are security-based recommendations designed to highlight issues and themes of information found across different investigative avenues. Without this understanding companies may miss critical information necessary to make informed risk and compliance decisions.

Significantly, thorough Level III due diligence can provide an additional level of fiduciary duty of care for the company’s board.

Level III should include deep web, accessible dark web, and historical Internet searches, also known as Open-Source Intelligence Investigations (OSINT). Although AI can be used for some of this work, it should be noted that AI without investigative analysis will yield less adverse information. AI can ignore  critical information that it cannot identify as missing, also there may be indicators inferring an outcome which is likely to be missed by AI currently. Investigative analysis looks at hidden and undisclosed information and searches for information that should have been found but was not. It is an integrated approach incorporating “boots on the ground”, intelligence gathering, and due diligence investigations. Relying on basic Google searches is a certain mistake as hidden and undisclosed information are unlikely to be discovered.

But more than simply an investigation of the company, including a site visit and coupled with onsite interviews, Tal says that some other things you should investigate include:

An in-depth background check of key executives or principal players. These are not routine employment-type background checks, which are simply designed to confirm existing information; but rather executive due diligence checks designed to investigate hidden, secret or undisclosed information about that individual.

Tal believes that an in-depth background check should also look for such “Reputational information, undisclosed involvement in other businesses, direct or indirect involvement in other lawsuits, history of litigious and other lifestyle behaviors which can adversely affect your business, and public perceptions of impropriety, should they be disclosed publicly.”

Further, you may need to engage a foreign law firm to investigate the third-party in its home country to determine their compliance with its home country’s laws, licensing requirements and regulations. Lastly, and perhaps most importantly, you should use a Level III to look the proposed third-party in the eye and get a firm idea of the third party’s cooperation and attitude towards compliance—as one of the most important inquiries is based on the response and cooperation of the third-party. More than simply trying to determine if the third party objected to any portion of the due diligence process or objected to the scope, coverage or purpose of the FCPA, you can use a Level III due diligence investigation to determine if the third party is willing to stand up with you under the FCPA and are you willing to partner with the third party?

There are many different approaches to the specifics of due diligence. By laying out some of the approaches, you can craft the relevant portions into your program. The Level I, II and III trichotomy appears to have the greatest favor and one that you should be able to implement in a straightforward manner. But the key is that you must assess your company’s risk and then manage that risk. If you need to perform additional due diligence to answer questions or clear red flags you should do so. And do not forget to “Document, Document, and Document” all your due diligence.

Categories
Sunday Book Review

Sunday Book Review: January 21, 2024 The Books on HR Edition

In the Sunday Book Review, I consider books that would interest the compliance professional, the business executive, or anyone who might be curious. It could be books about business, compliance, history, leadership, current events, or anything else that might interest me. Over the month of January, we will review some of the best books reported by People Managing People in various categories. In today’s edition of the Sunday Book Review, we look at four books on HR you should read in 2024.

  • The Essential HR Handbook by Sharon Armstrong and Barbara Mitchell
  • Irresistible: The 7 Secrets of the World’s Most Enduring, Employee-Focused Organizations by Josh Bersin
  • Built for People: Transform Your Employee Experience by Jessica Swaan
  • Remote Not Distant by Gastavo Ruzzetti

Resource:

28 Best HR Books You Should Read in 2024

For more information on Ethico and a free White Paper on top compliance issues in 2024, click here.

Categories
31 Days to More Effective Compliance Programs

31 Days to a More Effective Compliance Program – Day 17 – Podcasts for Compliance Training and Corporate Culture

One of the biggest benefits of podcasting is that it allows a compliance function to connect with their audience on a more personal level. Unlike traditional forms of advertising, which often come across as impersonal and sales-driven, podcasts enable businesses to build a loyal following by offering valuable and engaging content. This can include interviews with industry experts, behind-the-scenes glimpses of the business, and informative discussions on relevant topics.

Now take these same concepts of audience engagement and apply them internally to an organization. What do you potentially have? A mechanism to engage your employees, to engender trust, and to improve your overall corporate culture. Do you think this is a crazy way to improve culture? Think again about all the advantages podcasting has in place already.

A major US consumer product company started a podcast and had corporate executives on it. Who were the biggest fans of the podcast? It turned out it was the company employees, many of whom had never met their corporate executives. This allowed the executives to be humanized in a way no number of town hall meetings or other similar corporate events could ever achieve.

Since you are only limited by your imagination in compliance, why not use some of that imagination to be creative in your compliance training and communications?

Three key takeaways:

1. Using podcast storytelling to tell longer, more involved stories about compliance.

2. You can use compliance department-branded podcasts to have ongoing communications about compliance.

3. A Daily Compliance News show will drive engagement.

For more information on Ethico and a free White Paper on top compliance issues in 2024, click here.

Categories
Great Women in Compliance

Great Women in Compliance – Marlene Olsavsky and Kim White on Working with Stakeholders

Welcome to the Great Women in Compliance Podcast. Today Lisa Fine and Ellen Hunt visited Marlene Olsavsky and Kim White.

Kim White and Marlene Olsavsky are both seasoned professionals with extensive experience in the ethics, compliance, and business leadership fields. Kim, with over 20 years of experience in the ethics and compliance field, believes in promoting collaboration, compliance, and diversity through proactive communication and building strong relationships with business leaders. She emphasizes the importance of understanding the strategies and goals of business leaders and involving all parts of the team in driving them forward. Marlene, with 27 years of experience at Marlene Olsavsky’s Global Leadership, views compliance as essential for the success of a business. She emphasizes the importance of education, ownership, and accountability in promoting compliance within the organization and believes in setting expectations with leaders across the organization and acting on compliance issues with a sense of urgency and trust. Join Lisa Fine and Ellen Hunt as they delve deeper into these perspectives with Kim White and Marlene Olsavsky on this episode of Great Women in Compliance.

Key Highlights:

  • Kimberly White’s Leadership in Ethics and Compliance
  • Marlene Olsavsky’s Global Leadership at Pearson
  • The Crucial Partnership for Organizational Success
  • The Crucial Partnership Between Compliance and Business
  • Real-World Examples: A Tactical Approach to Compliance
  • Creating an Inclusive and Equitable Workplace
  • Embracing Growth Through Lifelong Learning

Resources:

Join the Great Women in Compliance community on LinkedIn here.

Categories
Innovation in Compliance

Innovation in Compliance – Steve Vincze on Building Trust: Overcoming Challenges as an Outsider

Innovation comes in many forms, and compliance professionals need to not only be ready for it but also embrace it. My guest in this episode is Steve Vincze, founder of Trestle Compliance.

Steve Vincze is a seasoned professional with a rich background as an in-house corporate commercial compliance lawyer, specializing in building trust and implementing compliance programs in businesses. His perspective on the subject is rooted in the belief that developing a human connection is key to building trust and implementing successful compliance programs. Drawing from his experience, including being recruited by Tap Pharmaceuticals to implement their first compliance program, he emphasizes the importance of modeling the behavior he wants from others and creating an environment where people feel comfortable sharing. He views compliance programs as tools to empower individuals rather than restrict them, and he strives to change the perception of compliance by demonstrating that it can be a tool for confidence and success. Join Tom Fox and Steve Vincze on this episode of the Innovation in Compliance podcast to learn more about his unique approach.

Key Highlights:

  • Establishing Trust through Human Connection
  • Experienced Professionals Providing Comprehensive Consulting Solutions
  • Expert Compliance Program Implementation Services
  • The Impact of Artificial Intelligence on Data Security

 Resources:

Steve Vincze on LinkedIn

Trestle Compliance

 Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

For more information on Ethico and a free White Paper on top compliance issues in 2024, click here.

Categories
Data Driven Compliance

Data Driven Compliance: The Journeys of Albemarle and ABB to Data – Driven Compliance

Are you struggling to keep up with the ever-changing compliance programs in your business? Look no further than the award-winning Data-Driven Compliance podcast, hosted by Tom Fox. This podcast features an in-depth conversation around the uses of data and data analytics in compliance programs. Data-Driven Compliance is back with another exciting episode. Today, I co-hosted with Vince Walden, CEO of KonaAI, to visit with our guests Andrew McBride, Chief Risk Officer at Albemarle, and Tapan Debnath, Head of Integrity, Regulatory Affairs, & Data Privacy—Process Automation at ABB, on their respective companies’ journeys to data-driven compliance.

We consider the importance of integrating due diligence systems with business conduct and anticipate 2024 to be a breakthrough year for data-driven compliance. McBride, recognized by the Department of Justice for his work in data-driven compliance, believes in the critical role of data in identifying and responding to risks, testing the effectiveness of compliance programs, and reporting to internal stakeholders. Debnath stressed the need for visibility and alignment with senior business stakeholders during investigations and the use of data analytics platforms to measure integrity and key performance indicators. Join Tom Fox, Vince Walden, Andrew McBride, and Tapan Debnath on this episode of the Data Driven Compliance podcast as they delve deeper into the challenges and importance of data-driven ethics and compliance programs.

Key Highlights:

  • Using data analytics to assess program effectiveness
  • Proactive risk management through continuous monitoring
  • Leveraging due diligence for proactive risk management
  • Data transparency and collaboration for compliance success
  • Transitioning from external dependencies to internal capabilities

Resources:

Vince Walden on LinkedIn

KonaAI

Tom Fox 

Connect with me on the following sites:

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Great Women in Compliance

Great Women in Compliance – Hayley Tozeski – From Big Law to Big Compliance

Welcome to the Great Women in Compliance Podcast. Today Hemma visits with Hayley Tozeski on her career in compliance.

Hayley Tozeski is a seasoned professional in strategic compliance and risk management in business conduct, with a rich background in big law and financial crime enforcement. Hayley’s perspective on the subject is that it is vital to prioritize and allocate resources effectively, advising companies on strategic investments of money, time, and resources in managing risks. She believes that a clear strategy is essential for the company and its stakeholders to understand the timeline and pace of development in managing ethics and compliance risks. Additionally, Hayley emphasizes the importance of addressing underlying business processes and building a solid foundation before implementing an ethics and compliance program, viewing strategy as the key to connecting different pieces of the program and ensuring that they are aligned and effective. Join Hemma Lomax and Hayley Tozeski on this episode of Great Women in Compliance to delve deeper into these insights.

Key Highlights:

  • Strategic Resource Allocation in Compliance Management
  • Building Strong Ethics and Compliance Programs
  • Effective Risk Management through Data Analytics
  • Strategic Risk Management for Ethical Business Conduct
  • Driving integrity through values, leaders, and champions
  • Supporting Youth Transitioning from Foster Care
  • Connecting and Learning Through Mentoring

Resources:

Join the Great Women in Compliance community on LinkedIn here.

Categories
Adventures in Compliance

The Memoirs of Sherlock Holmes – The Final Problem

Welcome to a review of all the Sherlock Holmes stories that are collected in the work “The Memoirs of Sherlock Holmes.” They appeared in Strand Magazine from December 1892 to December 1893. Over the past 12 episodes, I have reviewed each story and mined them for leadership, compliance, and ethical lessons.  In this, we begin a two-part series looking at the last story from The Memoirs of Sherlock Holmes.

The intriguing concept of applying Sherlock Holmes’ methods to the work of compliance professionals is the focus of our discussion today. Tom Fox, a seasoned compliance professional, believes that the principles embodied by the iconic detective, such as ethical behavior, problem-solving abilities, continuous learning, and persistence, can greatly enhance the effectiveness of compliance professionals. Fox’s perspective is shaped by his extensive experience in the field, where he has seen the value of attention to detail, deductive reasoning, thorough research, collaboration, risk assessment, and discretion. Join Tom Fox in this episode of the Adventures in Compliance podcast as he delves deeper into how the methods of Sherlock Holmes can be applied to uphold ethical and legal standards in the world of compliance.

Key Highlights:

  • The Story
  • Reichenbach Falls Showdown
  • Lessons for Compliance Professionals

Resources:

The New Annotated Sherlock Holmes

Connect with Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Innovation in Compliance

Innovation in Compliance – Ed Parcaut – From Phone Sales to Global Connections

Innovation comes in many forms, and compliance professionals need to not only be ready for it but also embrace it. One of those areas is telehealth and telemedicine. My guest in this episode is Ed Parcaut, CEO and founder of Lending for Living.

Ed Parcaut, a dynamic individual who transitioned from phone sales to a successful real estate radio show host, has a unique perspective on his journey. Parcaut discovered his knack for connecting with people through his voice during his 18-year tenure in phone sales. When presented with the opportunity to host a local talk radio show, he initially questioned the relevance of radio in the digital age but soon recognized its enduring popularity.

He launched his radio show, “Real Estate Jerky,” which began as a platform for real estate and mortgage discussions but later expanded to include community topics. Parcaut also recognized the potential of podcasting and began uploading his radio show as a podcast to reach a wider audience. He firmly believes in the power of audio platforms in promote businesses and foster connections. Join Tom Fox and Ed Parcaut as they delve deeper into this topic on the next episode of the Innovation in Compliance podcast.

Key Highlights:

  • Ed’s Voice-Driven Journey to Global Connections
  • Promoting Homeownership and Community Engagement
  • Ed’s Expertise in Real Estate Market Profitability
  • Insights into Housing Affordability and Trends
  • The Power of Repurposing Content for Podcasting
  • California’s Property Tax Protection Law

 Resources:

Ed Parcaut on LinkedIn

Lending for Living

 

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program Through Data Analytics: Day 14 – Continuous Converged Compliance

How can you integrate compliance, risk management, and your security framework? Igor Volovich, Vice President, Compliance Strategy at Qmulos, introduced the innovative concept to this discussion: Converged Continuous Compliance. This approach aims to reunite compliance, security, and risk management, which have historically operated independently.

One of the key requirements impacting this new approach is the need to bridge the gap between these functions from both a data and human perspective. These concepts serve as a translator, helping organizations navigate the complex landscape of compliance, security, and risk management. By speaking the language of these three functions, Converged Continuous Compliance brings them together and facilitates collaboration.

Corporate compliance needs to promote new approaches to compliance and risk management by challenging misconceptions, reuniting compliance, security, and risk management, emphasizing data governance oversight, and advocating for automation. These approaches aim to enhance efficiency, increase trust in compliance reports, and ultimately drive a greater return on investment. As organizations navigate the ever-evolving landscape of compliance, it is crucial to consider the impact of new approaches and strike a balance between different factors to achieve effective compliance and risk management.

Three key takeaways:

  1. The DOJ has stated that a chief compliance officer and a corporate compliance function must have visibility across all data sets in an organization. Converged Continuous Compliance aligns with this message.
  2. The bottom line is that we have accepted certain models of how compliance is done, what compliance means, what it delivers to the enterprise, and what it fails to deliver to the enterprise.
  3. It is crucial to consider the impact of new approaches and strike a balance between different factors to achieve effective compliance and risk management.

For more information on KonaAI, click here.