Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program with Boards – Board Governance and Risk Oversight

One of the ongoing questions from members of the Board of Directors is how to resolve the tension between oversight and management. I recently had the opportunity to visit with Joe Howell, former Executive Vice President (EVP) of Workiva, Inc., on this subject. Howell has worked on and with Boards of Directors at various companies, and I wanted to garner his understanding of the role of a Board, senior management, and a Chief Compliance Officer (CCO). Howell’s short response was an excellent starting point for understanding the role; put sand in management’s shoes.

The key to such a metaphor succeeding is that a Board of Directors, “by continuing to challenge management on these scenarios that management has considered and the stories management is telling itself about what could go wrong,” can “help get management out of its comfort zone by and large executive teams begin to believe themselves when they talk about how well they’re doing. The independent challenge that the board can offer is putting a little bit of sand in the shoe to make sure you’re thinking about things carefully can cause you to step back and focus your resources where they’re needed.”

Howell noted that the role of the Board is not management but oversight, focusing on governance. To do so, an effective Board should challenge senior management not only on what they have planned for but what they may not have considered or may not even know about. He said, “One perfect example is the reputation of those stakeholders involved in the company, and that can be the management team itself, the employees, and the board members themselves.” This is because reputational damage hurts everyone. Howell stated, “It’s essential as we go through some ways the Board can help management in that role. I think the things that make a difference to management is when the Board can be an effective devil’s advocate. Not managing management but helping them in their governing role by helping management to step back and think critically of their underlying assumptions and biases.”

A Board is more than just there to be a rubber stamp for senior management. It must exercise independent judgment, action, and oversight. Further, it is the Board’s role to ask hard, difficult, and probing questions to ensure management is doing its job and has considered other risk possibilities.

Three Key Takeaways:

  1. Boards should force management to open up the company to itself.
  2. Boards should be a grain of sand in the shoe of management.
  3. Boards should ensure senior management is aware of and planning for known and unknown risks.
Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program with Boards – The Board as an Internal Control

James Doty, former Commissioner of the Public Company Accounting Oversight Board (PCAOB) was once asked if the Board or its sub-committee which handles audits was a part of a company’s internal financial controls. He answered that yes, he believed that was one of the roles of an Audit Committee or full Board. I had never thought of the Board as an internal control but the more I thought about it, the more I realized it was an important insight for any Chief Compliance Officer or compliance practitioner as it also applies to compliance internal control.
In the FCPA Resource Guide, 2nd edition, in the Hallmarks of an Effective Compliance Program, there are two specific references to the obligations of a Board. The first is in Hallmark No. 1, which states, “Within a business organization, compliance begins with the board of directors and senior executives setting the proper tone for the rest of the company.” The second is found under Hallmark No. 3, entitled “Oversight, Autonomy and Resources”, where it discusses that the CCO should have “direct access to an organization’s governing authority, such as the board of directors and committees of the board of directors (e.g., the audit committee).” Further, under the US Sentencing Guidelines, the Board must exercise reasonable oversight of the effectiveness of a company’s compliance program. The Department of Justice’s (DOJ) Prosecution Standards posed the following queries: (1) Do the Directors exercise independent review of a company’s compliance program? and (2) Are Directors provided information sufficient to enable the exercise of independent judgment? Doty’s remarks drove home to me the absolute requirement for Board participation in any best practices or even effective anti-corruption compliance program.

A Board’s oversight is part of effective compliance controls, then the failure to do so may result in something far worse than bad governance. Such inattention could directly lead to a FCPA violation and could even form the basis of an independent SOX violation as to the Board.
Three Key Takeaways

  1. A Board must engage in active oversight.
  2. A Board should review the design of internal controls on a regular basis.
  3. Failure to do so could form the basis for an independent legal violation under SOX.
Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program with Boards – Boards Inquiring Up and Down

Where does “tone at the top” start? It is with public and most private U.S. companies at the Board of Directors. But what is the role of a company’s Board in compliance? First, a Board should not engage in management but oversee a CEO and senior management. The Board asks hard questions, risk assessment, and identification.

These factors can be easily adapted to compliance and ethics risk management oversight. Initially, it must be necessary that the Board receive direct access to such information on a company’s policies on this issue. The Board must have quarterly or semi-annual reports from a company’s CCO to either the Audit Committee or the Compliance Committee. Every Board should create a Compliance Committee to deal with compliance issues, as an Audit Committee may more appropriately deal with financial audit issues. A Board Compliance Committee can devote itself exclusively to non-financial compliance. The Board’s oversight role should be to receive regular reports on the company’s compliance program’s structure, actions, and self-evaluations. From this information, the Board can oversee any modifications to managing FCPA risk that should be implemented.

Three key takeaways:

  1. A Board Compliance Committee should provide oversight, not management.
  2. A CCO should use multiple reports to communicate with the Board Compliance Committee.
  3. Board Compliance Committee oversight makes companies more efficient and profitable.
Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance – Once A Con, Always A Con

What happens when two top compliance commentators get together? They talk compliance of course. Join Tom Fox and Kristy Grant-Hart in their podcast, 2 Gurus Talk Compliance, as they dive into hot compliance topics. In this episode, they cover the Elizabeth Holmes goes to prison, the current office imbroglios, a record whistleblower award, the perils of using ChatGPT, cyber breach reporting, Gartner and trust and lightening and compliance. With their unique insights and engaging storytelling, this podcast is a must-listen for anyone in the compliance field. Don’t miss the latest episode of 2 Gurus Talk Compliance and stay ahead of the curve!

Highlights Include

·      Racial Justice at the Board

·      Gartner FCPA enforcement action

·      Cyber Incident Reporting

·      AI and Corporate Governance

·      Once a con, always a con

·      Record whistleblower award

·      WFH, RTW and Hybrid-Work

·      CCO Comp

·      Using ChatGPT

·      Penalties low, benefits high

 Resources 

  1. Racial Justice Initiative
  2. Gartner FCPA enforcement action
  3. FSB Report on Cyber Incident Reporting
  4. AI and Corporate Governance
  5. What the Hell Happened Here?.
  6. Record $279 Million Whistleblower Award
  7. Thank Goodness We Didn’t Get Struck by Lightening
  8. 3 Tips for Adapting to the Post-Pandemic Culture Shock at Work
  9. CCO Compensation Up 8%
  10. Here’s What Happens when Your Lawyer Uses ChatGPT

Connect with Kristy Grant-Hart on LinkedIn

Spark Consulting

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program with Boards – Compliance Expertise on the Board

Every Board of Directors needs a true compliance expert sitting at the table. Almost every Board has a former CFO, former head of Internal Audit, or persons with a similar background, and often these are also the Audit Committee members of the Board. Such a background brings a level of sophistication, training, and SME that can help all companies with their financial reporting and other finance-based issues. So why is there, not such compliance SME at the Board level?

This requirement was set out in 2017 in the FCPA Corporate Enforcement Policy, where one of the criteria to be evaluated in a compliance program is “the availability of compliance expertise to the board.” Finally, the 2020 Update to the Evaluation of Corporate Compliance Programs, under the section entitled Oversight, posed the following questions What compliance expertise has been available on the Board of Directors?

The DOJ and Securities and Exchange Commission introduced this concept to the FCPA Resource Guide, 2nd edition. It means that when your company is evaluated by the DOJ, under the factors set out in the 2020 Update and the FCPA Corporate Enforcement Policy, to retrospectively determine if your company had a best practices compliance program in place at the time of any violation, you need to have not only the structure of the Board-level Compliance Committee but also the specific SME on the Board and on that committee.

Three key takeaways:

  1. Boards must have compliance expertise.
  2. Government regulators and shareholder groups have both called for greater compliance expertise on the Board.
  3. Compliance expertise at the Board works up and down as such expertise can be a resource to both the CCO and Compliance Department.

For more information check out The Compliance Handbook, 3rd edition, available from LexisNexis here.

Categories
Great Women in Compliance

Great Women in Compliance – Carolyn Renzin on Compliance at FanDuel

Welcome to the Great Women in Compliance Podcast, hosted by Mary Shirley and Lisa Fine.

Over the past few years, it seems like fantasy sports and online gaming have a higher profile than ever, and they are part of a rapidly growing industry. Today’s guest, Carolyn Renzin, is the Chief Legal and Compliance Officer at FanDuel, which is one of the leaders in that space. In a wide-ranging discussion, Carolyn and Lisa discuss building a compliance function at the same time an industry framework is being built, and how she has grown her team. She also talks about FanDuel’s commitment to integrity – both as an organization and for professional sports in general.

Her analogy between sports and her role is one we can all keep in mind – “you play offense, we play defense, and we need each other.”

You can find the Great Women in Compliance Podcast on the Compliance Podcast Network where you can find several other resources and podcasts to keep you up to date in the Ethics and Compliance world. You can also find the GWIC podcast on Corporate Compliance Insights where you can learn more about the podcast, stream prior episodes and catch up on Mary’s monthly column “Living Your Best Compliance Life.”

Corporate Compliance Insights is a much-appreciated sponsor and supporter of GWIC, including affiliate organization CCI Press publishing the related book; “Sending the Elevator Back Down, What We’ve Learned from Great Women in Compliance” (CCI Press, 2020). If you enjoyed the book, the GWIC team would be very grateful if you would consider rating it on Goodreads and Amazon and leaving a short review.  Don’t forget to send the elevator back down by passing on your copy to someone who you think might enjoy reading it when you’re done, or if you can’t bear parting with your copy, consider it as a holiday or appreciation gift for someone in Compliance who deserves a treat.

If you enjoyed the book, the GWIC team would be very grateful if you would consider rating it on Goodreads and Amazon and leaving a short review.  Don’t forget to send the elevator back down by passing on your copy to someone who you think might enjoy reading it when you’re done, or if you can’t bear parting with your copy, consider it as a holiday or appreciation gift for someone in Compliance who deserves a treat.

You can subscribe to the Great Women in Compliance podcast on any podcast player by searching for it and we welcome new subscribers to our podcast.

Join the Great Women in Compliance community on LinkedIn here.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Compliance and Middle Managers

The award-winning, Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, going into the weeds to explore a subject more fully and looking for some hard-hitting insights on sanctions compliance. Look no further than Compliance into the Weeds!

Join Tom and Matt as they delve into middle managers’ crucial role in fostering a culture of ethics and compliance within organizations. In this episode, the hosts discuss compliance officers’ challenges in working with middle managers and share some practical tips on building alliances, teaching soft skills, and developing personal relationships. They also examine the use of incentives and consequence management in promoting compliance and highlight the need for positive incentives for middle managers. Take advantage of this insightful and thought-provoking discussion on enforcing internal controls in a compliance program and learn more about the different ways to ensure compliance in gift travel and entertainment expenses. Tune in now to stay ahead in the world of compliance!

Key Highlights:

  • The Role of Middle Managers in Compliance
  • Training Middle Managers on Ethical Leadership
  • Investing in middle managers for ethical conduct
  • Compliance: Incentives and Consequence Management

 Notable Quotes:

“Compliance officers need to think about because you live and die in the success of your corporate culture, and the middle managers are the custodians of that culture.”

“Compliance officers should think about how do I help middle managers. How do I coach them on how to be good leaders?”

“Nothing is as significant as that personal touch point.”

“If the middle manager either turned a blind eye to the unethical practice or should have known about it but was just so aimless about it and didn’t care, should that middle manager suffer consequences along with the frontline employees who committed the offense? And the answer was generally yes.”

 Resources

Matt 

LinkedIn

Blog Post in Radical Compliance

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Compliance Into the Weeds

Compliance into the Weeds: A Compliance Response on Messaging Apps

The award-winning, Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, going into the weeds to explore a subject more fully and looking for some hard-hitting insights on sanctions compliance. Look no further than Compliance into the Weeds!

Join Tom Fox and Matt Kelly on “Compliance into the Weeds” as they delve into the recent SEC crackdown on messaging apps and improper employee use. The hosts explore the challenges of regulating messaging app use and provide solutions emphasizing the importance of corporate culture and risk management strategies. Hear from experts like the DOJ representative who spoke at Compliance Week 2023 and a defense contractor who offers tech solutions to monitor messaging apps on employees’ phones. With GDPR and FINRA regulations to consider, the podcast presents a comprehensive plan for compliance officers that focuses on effective controls, processes, and consequences for policy infractions. Don’t miss out on this informative podcast highlighting the importance of cultivating relationships with internal audit teams, IT teams, and other control departments to ensure proper compliance measures.

 Key Highlights: 

  • Risk management of employee messaging app usage
  • Tech solution for monitoring employees’ messaging
  • Corporate Culture Approach to Compliance in Financial Firms
  • Compliance Challenges in Monitoring Employee Communications
  • Building Relationships for Effective Compliance Management

 Notable Quotes:

“Assess your risks, put a risk management strategy in place, execute that strategy, train your employees, monitor the effectiveness, and remediate as appropriate.”

“And the tech company CEO said it is in his mind, People the policies, procedures, people and processes a more culture compliance strategy could work, but you would need to convince employees.”

“If they are also violating the policy, that’s bad. And that shows you have a corporate culture problem.”

“If it’s corporate culture, how is this any different than any difficult issue we’ve seen in compliance over the past 15 years?”

Resources

Matt 

LinkedIn

Blog Post in Radical Compliance

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Great Women in Compliance

Great Women in Compliance – Nicole Di Schino – The Compliance Education Fanatic

Welcome to the Great Women in Compliance Podcast, hosted by Mary Shirley and Lisa Fine.

Most E&C professionals know that you can have the best practices and policies, but if they are not understood by your employees and teams, they cannot be effective. And some of us, like today’s guest, Nicole Di Schino, help us with that next step in our training programs. She calls herself the “Compliance Education Fanatic,” and you will understand why after hearing this episode. Nicole discusses the importance of having creative and interactive training, and also how using training with a choice of a “best” answer is better than letting people pick a clear right answer.

Nicole and Lisa also talk about how different ways to communicate with and provide training for those in different generations, particularly with Gen Z.

You can find the Great Women in Compliance Podcast on the Compliance Podcast Network where you can find several other resources and podcasts to keep you up to date in the Ethics and Compliance world. You can also find the GWIC podcast on Corporate Compliance Insights where you can learn more about the podcast, stream prior episodes, and catch up on Mary’s monthly column “Living Your Best Compliance Life.”

Corporate Compliance Insights is a much-appreciated sponsor and supporter of GWIC, including affiliate organization CCI Press publishing the related book; “Sending the Elevator Back Down, What We’ve Learned from Great Women in Compliance” (CCI Press, 2020). If you enjoyed the book, the GWIC team would be very grateful if you would consider rating it on Goodreads and Amazon and leaving a short review.  Don’t forget to send the elevator back down by passing on your copy to someone who you think might enjoy reading it when you’re done, or if you can’t bear parting with your copy, consider it as a holiday or appreciation gift for someone in Compliance who deserves a treat.

If you enjoyed the book, the GWIC team would be very grateful if you would consider rating it on Goodreads and Amazon and leaving a short review.  Don’t forget to send the elevator back down by passing on your copy to someone who you think might enjoy reading it when you’re done, or if you can’t bear parting with your copy, consider it as a holiday or appreciation gift for someone in Compliance who deserves a treat.

You can subscribe to the Great Women in Compliance podcast on any podcast player by searching for it and we welcome new subscribers to our podcast.

Join the Great Women in Compliance community on LinkedIn here.

Categories
31 Days to More Effective Compliance Programs

One Month to a More Effective Compliance Program in Training and Communications – 10 Compliance Training Program Design Objectives

Well-known compliance training guru Shawn Rogers has developed ten design objectives for establishing your compliance program training design objectives. It would be best if you considered doing the same for your organization. Your organization may value other objectives. What the government has told us since the original FCPA Resource Guide back in 2012 is that it expects a well throughout the approach. If you consider your design objectives early in the planning phase, it will not only meet this requirement but also become a roadmap for your program implementation easier. Finally, you can pivot more quickly in this new era as new compliance risks emerge.

Three key takeaways:

  1. What are your design objectives?
  2. They should be dynamic, not static.
  3. You should use them as touchpoints going forward.