Categories
Blog

Making the Business Case for Data Driven Compliance

I recently had the opportunity to visit with Vince Walden, founder and CEO of KonaAI, for a podcast series on the uses of data driven compliance. KonaAI is the sponsor of those podcasts. This blog post series will flesh out the podcast show notes. Over the next five blog posts, we will discuss generative AI and ChatGPT in compliance, the profiles of corrupt payments, making the business case for data-driven compliance, what to ask for and how to ask for it, and some success stories. Part 3 will discuss making the business case for data-driven compliance.

Vince Walden, the CEO and founder of KonaAI, is here with me as always. Walden pointed out a dual aspect to this, bringing risk and financial perspectives into play. The risk perspective aligns with meeting expectations from the Department of Justice, SEC, or other regulatory bodies, which include culture alignment and prudent data handling. The financial end deals with a knock-on effect of compliance: a potential improvement in financial performance by curtailing revenue leakage through fraud and improper payments. This is what compliance professionals do every day. In regulated industries, however, it is not simply about convincing others of the necessity. It is also about aligning the company’s tools and methods to meet the expectations of external regulatory bodies. In an ideal world, a company’s compliance goals should align with its business goals. But achieving this balance is easier said than done.

While regulatory compliance is important, businesses are about generating revenue and turning a profit. Balancing compliance with profitability can often seem like a tightrope walk. But businesses need to realize that this balance is possible and beneficial in more ways than one. Compliance and profitability could coexist with the help of a business-savvy compliance tool. Compliance professionals need to distance themselves from a narrow focus on policies and enforcement. A broader perspective, including understanding the importance of data-driven metrics and business context, can position these professionals as valuable contributors to an organization’s bottom line. Yet Walden warned against complacency, saying that professionals who only focus on regulation and leave the business aspect by the wayside can find themselves marginalized.

Increasingly, companies realize the value of having multiple perspectives at the decision-making table. While finance and internal audit have always been pivotal, including compliance in these discussions provides a more rounded view. This broad-based approach can unlock novel insights into operational efficiency, risk mitigation, and more. The dialogue between compliance, finance, and procurement has been improving. Industries like telecommunications, oil and gas, technology, and pharmaceuticals are leading this change, recognizing the value of integrated discussions. Vince stresses the need for transparency in transactions that pose risks to the organization and sees compliance professionals playing a significant role in these discussions.

One of the greatest challenges of being a compliance professional is speaking the language of the CFO and financial stakeholders. Convincing them about the monetary benefits of compliance involves more than just throwing around regulation jargon – it requires the ability to present your case strategically. Compliance professionals understand their audience and tailor their discussions accordingly. He advises professionals to focus on how data-driven compliance can save money, improve efficiencies, and prevent improper payments. This is how to get the CFO and other financial stakeholders on board and win them over with the business case for compliance.

Walden emphasizes the importance of understanding the CFO’s financial language to argue for effectively implementing data-driven compliance. Compliance professionals must demonstrate the return on investment and the success of compliance and fraud risk management programs. Key performance indicators such as dollar recoveries and risks avoided can be used to measure the impact of data-driven compliance. Walden also highlighted the significance of finding hidden money and stopping improper payments before they occur. By utilizing data-driven metrics, compliance professionals can identify the riskiest transactions and prevent fraud, waste, and abuse. This not only aligns with the DOJ’s expectations but also improves the overall functioning of the business.

Also of significance is the role of compliance professionals in finance and procurement. More and more companies are recognizing the need to have compliance professionals at the table when making financial decisions. Compliance professionals must be able to speak the language of CFOs and help them understand the importance of compliance in reducing costs, eliminating waste, and preventing improper payments.

To make a compelling business case, compliance professionals should focus on the financial benefits of data-driven compliance. For example, if a company disburses hundreds of millions or billions of dollars in accounts payable payments to third parties, implementing a risk scoring system can help identify the top ten riskiest transactions at risk for fraud, waste, and abuse. The company can recover millions of dollars by investing a relatively small amount, such as $200,000, resulting in a significant return on investment.

It is also important for compliance professionals to collaborate with finance, procurement, and internal audit teams. The Association of Certified Fraud Examiners (ACFE) and COSO collaborated on writing the COSO Fraud Risk Management Guide, which offers useful advice for running a fraud risk management program. The principles outlined in this guide align with the DOJ’s guidance on effective compliance programs. Compliance professionals should take the initiative to engage with CFOs, heads of accounting, and heads of internal audit to foster collaboration and ensure compliance efforts are aligned with overall business objectives.

Compliance professionals play a vital role in data-driven risk management. By making a compelling business case for data-driven compliance, they can demonstrate the financial benefits, such as preventing fraud, improving cash flow, and uncovering hidden funds. Collaboration with CFOs and other key stakeholders is crucial to ensure compliance efforts are integrated into overall business strategies. Compliance professionals must continue to adapt and evolve their understanding of finance and procurement to effectively communicate the importance of data-driven compliance in mitigating risks and driving business success.

Finally, remember that data-driven compliance can improve financial performance and ROI. By harnessing the power of data to inform compliance activities, professionals in regulated industries can effectively navigate complex regulatory landscapes, minimize risks, and optimize business operations. The steps in making a business case for data-driven compliance lay the foundation for success, enabling professionals to leverage data insights, drive informed decision-making, and, ultimately, drive better business outcomes. Embrace data-driven compliance and unlock the potential for improved financial performance and ROI—within your reach.

 Resources:

Connect with Vince Walden on LinkedIn

Check out KonaAI

Connect with Tom Fox on LinkedIn

Categories
Blog

Profiles of Corrupt Payments

I recently had the opportunity to visit with Vince Walden, founder and CEO of KonaAI, for a podcast series on the uses of data driven compliance. KonaAI is the sponsor of those podcasts. This blog post series will flesh out the podcast show notes. Over the next five blog posts, we will discuss generative AI and ChatGPT in compliance, the profiles of corrupt payments, making the business case for data-driven compliance, what to ask for and how to ask for it, and some success stories. In Part 2, we will consider the profiles of a corrupt payment.

The episode highlighted research by MIT and KonaAI that examined $75 billion in payments from various companies to identify characteristics associated with high-risk payments. For businesses looking to identify and stop improper payments, the MIT and KonaAI research offered useful insights. Key attributes that were found to be associated with high-risk payments included payments made without purchase orders, payments flagged by anti-corruption keywords, and payments that significantly deviated from the norm. These attributes were often relevant in the data that humans tagged as high-risk.

One of the key takeaways from the research is the importance of investigating red flags in sales increases. A case study was presented in the episode, highlighting a suspicious sales increase in a Polish province. Contributions to a charitable organization came with increased sales, which raised questions about potential corruption or bribery. This case study emphasizes that compliance officers and risk professionals must monitor commissions, sales incentives, and margins to identify potential bribery and corruption issues.

Companies are encouraged to leverage data analysis tools like KonaAI to identify high-risk payments and prevent corporate corruption. These tools can help track and identify improper payments, providing transparency and easy access to financial accounting data for compliance professionals. By combining financial accounting data with data analysis capabilities, companies can gain insights into payment patterns and detect anomalies that may indicate potential corruption.

However, it is important to note that tradeoffs are involved in balancing different factors when identifying high-risk payments. Compliance officers and risk professionals must carefully consider the impact of their decisions on the business. The podcast episode highlighted the analogy of brakes on a car, emphasizing that the purpose of brakes is not to slow down but to enable the car to go fast and stop when necessary. Similarly, compliance efforts aim to facilitate business growth while ensuring ethical practices and preventing corruption.

The episode also discussed the challenges of identifying high-risk payments and preventing corporate corruption. One challenge is the need for collaboration among companies in an anonymous way to analyze the profiles of improper payments. The research conducted by MIT and KonaAI demonstrated the potential of such collaboration in identifying common risk triggers and profiles of high-risk payments. However, ensuring data privacy and confidentiality is crucial in such collaborative efforts.

In conclusion, identifying high-risk payments and preventing corporate corruption require a comprehensive approach that combines data analysis, collaboration, and a focus on business growth. The MIT and KonaAI research offers useful insights into the characteristics of high-risk payments. Compliance officers and risk professionals are urged to leverage data analysis tools and closely monitor payment patterns to detect and prevent improper payments. By balancing compliance efforts and business objectives, companies can mitigate corruption risks and foster a culture of transparency and integrity.

Examining data is like peering into a crystal ball that projects the inner workings of a business, but only if you know what to look for. One essential facet is sales performance. Even the tiniest irregularities can be a hint of greater issues at hand, such as improper payments. So, understanding and tracking sales data, be it a sudden sales surge in a particular area or an individual outperforming all expectations, is quite crucial.  Walden emphasized the importance of transparency in analyzing sales data. If figures shoot up in a specific region or uncannily exceptional sales are tied to a particular individual, Vince suggests investigating to find out more. The key here, he describes, is the ability to spot these oddities before they morph into a serious problem. Transparency in financial analysis, Vince implores us, can be a game-changer in tracking down and rectifying improper payments.

Third-party relationships can be as much a source of risk as any other part of a business. Keeping tabs on the financial activities of entities such as distributors, commission sales agents, and joint venture partners is therefore imperative. Monitoring these relationships to minimize the risks of improper payments. Walden suggests that the same strategies used to interpret company data for potential risks can also be utilized for third-party relationships. Compliance officers can pair financial analysis with tools like KonaAI to actively monitor anomalies or suspicious transactions. In this scenario, compliance officers can be armed with the right tools and data to monitor and, if required, mitigate any suspicious financial activities related to third-party relationships.

Extending data analysis to third parties is no longer nice; in today’s compliance and fraud-risk environment, it is a business necessity. Monitoring these outside relationships closely provides another layer of security and reduces the breeding ground for unethical activities like improper payments. By integrating financial data with tools like these, compliance officers can actively keep an eye out for anything unusual. This way, companies are not only ensuring that their internal affairs are in order but are also making sure that their external associations are clean and ethical. It’s an insight into how companies can use strategic data analysis to maintain regulatory compliance.

The bottom line is that compliance officers are the guardrails that keep a company on track. Their role is two-pronged – facilitate business growth and, at the same time, deter the business from veering off into unethical practices. Compliance officers ensure the company is always one step ahead in identifying and addressing compliance risks. A balance between growth enablement and ethical conduct is needed to steer the course towards success.

Finally, as compliance officers, you have the power to make a significant impact by preventing improper payments and preserving your organization’s reputation. By embracing the learnings from this podcast episode, you can confidently navigate the challenges of today’s complex business environment and ensure that your efforts contribute to a culture of transparency and ethical behavior. Together, we can create a stronger, more accountable business world.

Resources:

Connect with Vince Walden on LinkedIn

Check out KonaAI

Connect with Tom Fox on LinkedIn

Categories
31 Days to More Effective Compliance Programs

One Month to More Effective Written Standards: Day 6 – Operationalization of your Code of Conduct

How can you work to operationalize your Code of Conduct as articulated in the DOJ 2023 Evaluation of Corporate Compliance Programs (ECCP)? The 2023 ECCP focuses not on whether a company has a paper compliance program but whether a company is actually doing compliance. A company does compliance by moving it into the functional business units as a part of an overall business process. That is what makes a compliance program effective at the business level. There are several different parts of the 2023 ECCP that touch upon your Code of Conduct.
The Code of Conduct design and implementation process enshrine your company’s values. Those are set by senior management and their input and support for any code project, whether initial draft or update, is critical. This gets to the heart of operationalization and demonstrates how a Code of Conduct can work to meet the DOJ requirements. As an early part of your design and drafting process, you should assemble a cross-functional team. This is important for several reasons. First, diversity in your team will help produce a more well-rounded final product. But having such team diversity will also assist in your benchmarking effort, coupled with those who are going to help you out looking at designs and maybe helping forge the design of the code. Finally, you can use a group to help in the drafting, redrafting and editing process. This diversity will help you to answer all of the DOJ questions from the 2019 Guidance in a manner consistent to support operationalization.
All of these requirements point to getting out and making your Code of Conduct a part of the very fabric of your organization. By using some or all of these strategies, you will have a good starting point. But it is more than simply rollout and training. There must be ongoing communications as well.

Three key takeaways:

  1. What has been the role of senior management in the creation or update of your Code of Conduct?
  2. How have you worked with employees outside the compliance function to lay the groundwork for fully operationalizing your Code of Conduct?
  3. How have you measured the effectiveness of your Code of Conduct training?

For more information, check out The Compliance Handbook, 4th edition, here.

Categories
31 Days to More Effective Compliance Programs

One Month to More Effective Written Standards: Day 5 – Training on your Code of Conduct

What about the training on your finalized Code of Conduct? While there have been criticisms of code training, if you consider training as one source of your 360-degrees of compliance communications, the rollout of a new or updated code can be an opportunity. This rollout fits directly into the concept of 360-degrees of compliance communications as rollout is part of both communications and engagement. The delivery of a Code of Conduct is a key element of its effectiveness. By allowing your employees and other stakeholders to engage and interact with the code, through live or interactive training, the effectiveness can be better monitored and measured.
Beginning with the DOJ’s 2017 Evaluation and continuing into the 2023 ECCP, is the DOJ’s emphasis in the effectiveness of training. I think everyone would understand you do need to train but now the government’s talking to us about effective training. Begin with live training that can be held at the corporate headquarters with senior management and executive involvement. Many companies will videotape a message from the CEO to help celebrate the rollout. Then there is the opportunity for localized training that gives employees an opportunity to see, meet, and speak directly with a compliance officer, not an insignificant dynamic in the corporate environment. Such personal training also sends a strong message of commitment to the Code of Conduct. It gives employees the opportunity to interact with the compliance officer by asking questions which are relevant to markets and locations outside the corporate office, which can often provide employees with the opportunity to have confidential in-person discussions.
However, your Code of Conduct training should be an extension of the way you communicate compliance in your organization. If it is divorced from your 360-degrees of compliance communications style, you may well be missing an opportunity to drive better understanding of the code and denigrate the effectiveness of the training. Whatever approach is used, one of the critical factors is the length of time of the training session. Although lawyers and ethics and compliance professionals can (sometimes) sit through a multi-hour Code of Conduct lesson, it is almost impossible to keep the attention of business and operations employees for such a length of time. The presentation and number of PowerPoint slides must be kept to a manageable length before the attendee’s eyes start to glaze over.

 Three key takeaways:

  1. Consider a video message from your CEO to help roll out your Code of Conduct initiation or update.
  2. Tailor your Code of Conduct training to your workforce.
  3. Consider interactive and modular approaches to Code of Conduct training.

For more information, check out The Compliance Handbook, 4th edition, here.

Categories
Blog

Revolutionizing Compliance Monitoring with Generative AI and Chat GPT

I recently had the opportunity to visit with Vince Walden, founder and CEO of KonaAI, for a podcast series on the uses of data driven compliance. KonaAI is the sponsor of those podcasts. This blog post series will flesh out the podcast show notes. Over the next five blog posts, we will discuss generative AI and ChatGPT in compliance, the profiles of corrupt payments, making the business case for data-driven compliance, what to ask for and how to ask for it, and some success stories. In Part 1, we will consider using generative AI and ChatGPT for compliance.

My special guest is Vince Walden, a trailblazer spearheading transformative advancements in the compliance industry through the innovative use of data and data analytics. Vince’s grounding in generative AI and Chat GPT has enabled him to push the boundaries of traditional compliance monitoring. His knack for simplifying complex concepts has won him acclaim at numerous conferences, where he frequently shares his expertise. Vince’s novel strategies are revolutionary and rapidly becoming the new standard in the field.

Together with Walden, we will explore how compliance professionals can enhance their monitoring efficiency through generative AI and Chat GPT. Having worked extensively in the compliance and data arenas, Walden understands the challenges compliance professionals face in navigating the complex regulatory landscape. He shares his expertise and highlights practical use cases of Chat GPT in compliance monitoring, demonstrating how it can streamline the decision-making process. We will provide actionable strategies for improving compliance monitoring and addressing compliance professionals’ pain points.

You have probably heard of Generative AI. What is the hype about it? Generative AI does not just analyze data—it creates or “generates” responses or outputs based on the given data. Something like a brilliant virtual assistant! Walden discussed some of the uses. He mentioned how these AI chatbots can interact directly with a compliance dashboard. This means it is more than simply about reading data—it is about interpreting it and helping make navigating tons of data more accessible. It provides recommendations, insights, and options based on what it’s looking at. This could eliminate the need to click around on your dashboard.

AI is pretty good with data. But what about qualitative information? You might be wondering if you can leave everything entirely to AI. Walden adds a bit of a reality check here by reminding us of the importance of human intervention in checking the AI’s output. There is a downside to relying exclusively on AI’s output. A compliance professional must take results at face value. There is a need for validation and fact-checking to ensure we’re not accidentally spreading misinformation or making decisions based on false statements. It’s like that saying, “Trust but verify.”

One of the key challenges associated with generative AI and chatbots in compliance monitoring is striking the right balance between automation and human oversight. While chatbots can assist in navigating and analyzing data, human judgment and expertise are still crucial in interpreting the results and making informed decisions. Compliance professionals must ensure that the rules and algorithms used by the chatbots are accurate and aligned with regulatory requirements.

Another consideration is data privacy and security. Using generative AI and chatbots within a secure platform that protects sensitive information is essential. Compliance professionals should avoid sending data to third-party providers and ensure privacy regulations are followed.

Despite these challenges, generative AI and chatbots in compliance monitoring are promising. By leveraging these technologies, compliance teams can improve efficiency, reduce costs, and enhance the overall effectiveness of their monitoring processes. The ability to customize review strategies based on different risk thresholds and areas of concern further enhances the value of these tools.

The bottom line is that generative AI and chatbots are set to revolutionize compliance monitoring by providing professionals with more efficient and interactive ways to navigate data and identify potential compliance issues. While there are tradeoffs and challenges to consider, the benefits of these technologies in terms of efficiency and cost-effectiveness are significant. Compliance professionals must exercise caution, fact-check the output of generative AI, and maintain human oversight to ensure accuracy and compliance with regulations. As compliance monitoring continues to evolve, the integration of generative AI and chatbots will undoubtedly play a crucial role in shaping its future.

The steps outlined in the article – leveraging generative AI and Chat GPT for compliance monitoring – are pivotal in helping compliance professionals achieve improved monitoring efficiency. By using generative AI to analyze large volumes of data in real time, compliance professionals can detect anomalies and potential violations more efficiently than ever. Additionally, the automation of compliance checks through Chat GPT significantly reduces the burden of manual reviews and frees up valuable time for proactive monitoring activities. These technological advancements enhance monitoring accuracy and streamline the decision-making process, allowing compliance professionals to make informed and timely decisions. By adopting these innovative tools, compliance professionals can achieve improved compliance monitoring results and ensure organizational adherence to regulations.

 Resources:

Connect with Vince Walden on LinkedIn

Check out KonaAI

Connect with Tom Fox on LinkedIn

Categories
Blog

Navigating Transformational Changes: The Intersection of E&C and ESG

Today I would like to explore the intersection thought of ethics and compliance (E&C) and environmental, social, and governance (ESG) efforts. In a recent podcast on Report from IMPACT 2023, we explored the crucial role of ethics in guiding organizations through transformational changes. With data-driven insights and practical advice, considered the challenges, opportunities, and strategies for success in this evolving landscape.

In the face of rapid technological advancements, the importance of ethics cannot be understated. The need to build safeguards to prevent potential crashes or negative consequences. Much akin to car racing, this world has the need to moving forward with technology in a safe and responsible manner. Further and just like a skilled racer, organizations must navigate the track of progress while ensuring the ethical implications of their actions are considered. Finally always remember that brakes are not on a car to slow it down but so that you can drive fast.

As power dynamics shift and new technologies emerge, the establishment of checks and balances in this arena becomes paramount. This means that organizations need to distribute power internally both wisely and ensure ethical decision-making processes are in place. By doing so, they can safeguard against potential abuses and ensure that transformative changes are guided by integrity. I often use the visual of the billboard announcing the Eyes of Dr. T J Eckleburg from The Great Gatsby as the best way to think about having a second set of eyes on your process for process validation.

In a world undergoing rapid transformation, continuous education and expanding horizons are crucial for organizations and individuals alike. For Chief Compliance Officers (CCOs) and other compliance professionals, the importance of being adaptable and open to learning cannot be overstated. Our profession is changing as fast as any other corporate function and it is coupled with the needs of our customers changing. Who are the customers of a corporate compliance program? You can start with the multiple stakeholders identified by the Business Roundtable in their seminal Statement on the Purpose of a Corporation. It can be employees, shareholders, third-parties, vendors and business partners and those who may live in localities where your organization does business.  By embracing new perspectives and staying informed, CCOs, compliance professionals and corporate compliance functions can effectively navigate the challenges of a changing world.

A significant development highlighted in the podcast is the convergence of ESG and E&C. This integration presents a strategic risk and opportunity standpoint for organizations. By aligning environmental, social, and governance considerations with ethical and compliance practices, companies can create a holistic approach that benefits both their bottom line and society at large. Equally importantly is the mandate that the CCO and corporate compliance function should lead this effort. There is no other corporate function which has such a wide mandate, as set out by the regulators as the corporate compliance programs. One need only consider the 2019 Evaluation of Corporate Compliance Programs which led to the 2023 Evaluation of Corporate Compliance Programs to see that a corporate compliance function (and CCO) must have visibility literally across your entire corporate organization.

The demand for businesses to take positions on social issues is growing louder, both from employees and stakeholders. It well known within the compliance community and wider corporate world of the importance of both the CCO and compliance function not remaining silent on these matters. You may call this speaking truth to power but in the wider ESG world, businesses must recognize the power they hold to effect change and leverage it responsibly. By aligning their values with those of their workforce and society, they can build purpose-filled organizations that resonate with the younger generations.

I speak with many Human Resource (HR) and talent specialists and they all say that the acquisition and retention of talent will be the key market differentiator for business by mid-century. From Baby Boomers to through GenXers to Millennials and now Genders; the values and mindset of the current and upcoming workforce differ significantly from those of previous generations. To motivate and attract these individuals, organizations must listen to their ideas and incorporate them into the company’s values and purpose. By engaging with the younger generations and understanding their perspectives, board members can foster an environment that aligns with their aspirations. Businesses which try to enforce well-known and well-debunked tropes such as there is no such thing as climate change will be consigned to the dustbin of corporate failures.

Building transformative leadership and engaging forward-thinking board members pose challenges but are necessary for success. Just as talent acquisition and retention will be one of the most critical aspects of corporate survival, the importance of recruiting board members who understand current and future challenges and the need for an integrated approach will be equally critical. Critically this also means diversity on the Board. While seasoned experience is valuable, finding individuals who can bridge the gap between traditional values and the demands of a changing world is crucial. It also means new and different subject matter expertise will be critical. The Department of Justice (DOJ) has noted that a Board needs to have a compliance resource on it. The logical step is for a Board to have a Compliance Committee, chaired by a seasoned compliance professional.

It might even lead to a broader concept of a true risk management professional on the Board. Given the paradigm shift coming out of the Pandemic from disaster recovery to business resiliency to business as usually; a Board having the ability to have that strategic discussion  and lead through oversight will be a critical element as well.

Recognizing the pivotal role that ethics and compliance play in guiding organizations through transformational changes is something that is gaining traction in the corporate world. In a world that is evolving at an unprecedented pace, it is imperative to build ethical safeguards, establish checks and balances, provide appropriate oversight and adapt to the values and mindset of the younger generations. By embracing continuous education, converging ESG and E&C efforts, and taking a stand on social issues, organizations can navigate the inflection point we find ourselves in and thrive in the future.

Categories
Report from IMPACT 2023

Report from IMPACT 2023: Katie Smith on Unleashing the Power of Ethics and Compliance Community

ECI’s IMPACT 2023 was one of the leading compliance events in 2023. At this conference, Tom Fox, the Voice of Compliance, was able to visit with several of the speakers, exhibitors, participants and one group of ethically minded Girl Scout Troop. In this limited podcast series, Report from IMPACT 2023, Tom explores many of the most cutting-edge topics in ethics and compliance through short podcast episodes. Check out the full series of interviews. You will be enlightened, informed and come away with a fuller and more thorough understanding of the most cutting-edge topics in ethics and compliance. In this episode, Tom visits with Katie Smith is a distinguished ethics and compliance professional who has devoted her career to pioneering a new path for ESG and ethics in compliance.

As the Vice Chair on the Board of Directors of ECI, she has been instrumental in shaping the organization’s future role and mission. Katie’s unique perspective on “Charting a New Course: ESG and Ethics in Compliance” is that she views it as a chance for the ethics and compliance community to unite and make a positive impact on the world. She emphasizes that there are currently no established rules in this new societal inflection point, which presents a tremendous opportunity for the ethics and compliance community to shape the future of ESG and ethics in compliance. Her enthusiasm and optimism for the beginning of this new journey are palpable. Join Tom Fox and Katie Smith on this episode of the Report from Impact podcast as they delve deeper into this fascinating topic.

 Highlights Include 

·      Conference Themes

·      Re-invigoration by the Keynote Speakers

·      What are the rules of the road now.

 Resources 

Katie Smith on LinkedIn

Categories
Compliance Into the Weeds

Compliance into the Weeds: 3M FCPA Enforcement Action

The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent FCPA enforcement action involving the Chinese business unit of 3M.

The importance of post-event documentation and monitoring in preventing fraud and corruption cannot be overstated, as highlighted by the recent FCPA incident involving 3M China. Tom believes that while training and control environment adjustments are crucial, they may not be enough to prevent misconduct if individuals are determined to commit such acts. He emphasizes the need for hard evidence, such as post-event documentation, and recommends looking to the heavily regulated pharmaceutical sector for guidance.

Matt stresses the importance of rigorous post-event documentation to ensure the legitimacy of business activities. Both Fox and Kelly gained these insights from their extensive experience in the field of compliance and their analysis of various fraud cases. To learn more about their unique perspectives on post-event documentation and monitoring, join them on this episode of the Compliance into the Weeds podcast. 

Key Highlights

·      Background facts

·      GTE in FCPA enforcement actions

·      What happens when conduct is done secretly

·      Concerns over the use of messaging apps

·      Lessons Learned

 Resources

Matt in LinkedIn

Tom –blog post on the FCPA Compliance and Ethics Blog

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Innovation in Compliance

Innovation in Compliance – Oshri Cohen on the Role of a CTO in Compliance

The role of a Chief Technology Officer (CTO) in compliance and data governance is explored in this podcast episode between Tom Fox and Oshri Cohen. They discuss the varying responsibilities of a CTO based on company size, with larger organizations focusing on strategic planning while smaller organizations have the CTO as the head engineer. The importance of the CTO in managing risks, particularly in industries like healthcare and finance, is emphasized, along with the role of the board in providing oversight. The conversation also delves into the significance of data strategy, compliance, and data governance, emphasizing the need for collaboration between the CTO and the Chief Compliance Officer (CCO). Technical due diligence and the establishment of a data commission within organizations are suggested as strategies for effective data governance. Overall, the conversation highlights the crucial role of the CTO in ensuring compliance and protecting sensitive information.

  • The Role of a CTO in Compliance
  • Data Strategy and Compliance
  • Data Governance Challenges
  • Data Governance and Startups
  • Risks in System Audits

 Resources:

Oshri Cohen on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program: Day 14 – Hiring A CCO: Developing The Job Profile

What should a company do when it desires to hire a CCO? To do so, a company needs to fully understand and appreciate what it needs from such a position going forward. Unfortunately, many companies do not have this insight at the beginning of the recruitment process. The key company stakeholders need to understand the full hiring process. Obviously, this will include HR and others involved in the hiring process for a CCO for the company. It could include the CEO, COO, CFO, CISO, Head of IA and others. They may need to rethink their approach to focus on what they will ask the new hire to accomplish because typically there is a disconnect between what the company thinks it needs and what it really needs.

Tom highlights the importance of developing a comprehensive job profile. Maurice Gilbert provides insights on the topic, emphasizing the need for companies to understand their specific needs and risks when creating a job profile for the CCO position. The podcast also discusses the importance of involving key stakeholders, setting realistic expectations, and considering professional growth opportunities and an attractive package for potential candidates. By involving key stakeholders in defining the role of the CCO and seeking the assistance of a professional executive recruiter, companies can find the right fit for their compliance program’s success.

Three key takeaways:

  1. Bring in your key stakeholders to flesh out the job description.
  2. Consider the top four things you would like a new CCO to accomplish in the first year.
  3. For a new CCO to succeed, the company must have a realistic expectation developed before the process begins.

For more information, check out The Compliance Handbook, 4th edition here.