Categories
Compliance Into the Weeds

CCO Certification of Compliance Programs

Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. This week, Matt and Tom take at the recent remarks by DOJ Assistant Attorney General Kenneth Polite on CCO certifications of compliance programs after the conclusion of a DPA. Highlights include:

·      Where did this issue come from?

·      Is its implementation looming?

·      What are the implications for individual CCO liability?

·       What about CEO liability for recidivism?

·      What are the corporate governance implications?
Resources 
Text of Kenneth Polite speech

Categories
Blog

Attributes of a Toxic Corporate Culture

Corporate culture is finally being acknowledged as a key ingredient in a successful business, particularly one which operates ethically and in compliance. The Department of Justice (DOJ) formally recognized the need to assess corporate culture in the speech by Deputy Attorney General Lisa Monaco to the ABA White Collar Conference in October 2021. But what are some indicia of good culture and more importantly what are some indicia of a toxic culture? A recent article in the MIT Sloan Management Review provided some guidance. In Why Every Leader Needs to Worry About Toxic Culture, Donald Sull, Charles Sull, William Cipolli and Caio Brighenti posited that by pinpointing the elements of toxic culture in a company, its leaders focus on addressing the issues that lead employees to disengage and quit. These ideas have significant importance for the compliance function as it navigates corporate culture, both in assessing and improving it.
Moreover, the Chief Compliance Officer (CCO) and corporate compliance function were identified in the 2020 Update to the Evaluation of Corporate Compliance Programs as the keepers of institutional justice and institutional fairness. This mean recognizing and then preventing a toxic culture from spreading and infecting your entire organization is squarely in the compliance wheelhouse. The article lays out key red flags for every CCO and compliance professional to look for in assessing culture. Finally, for any company with a toxic culture, the chances are much greater to be defrauded by its own employees or to defraud others through bribery and corruption by violating such laws as the Foreign Corrupt Practices Act (FCPA).
The authors identify behaviors that they call “the Toxic Five attributes”, being “disrespectful, noninclusive, unethical, cutthroat, and abusive – poison corporate culture in the eyes of employees. While organizational culture can disappoint employees in many ways, these five elements have by far the largest negative impact on how employees rate their corporate culture and have contributed most to employee attrition throughout the Great Resignation.” As a CCO or compliance professional you need to be on the watch for them and take steps to remedy them if you see or hear about them.
Non-inclusive Behavior
This is about whether your employees are “treated fairly, made to feel welcome, and included in key decisions.” It is “the most powerful predictor of whether employees view their organization’s culture as toxic. It applies to all demographic groups; “gender, race, sexual identity and orientation, disability, and age.” It can be outright discrimination to the equally invidious but more subtle conflicts of interests of nepotism and playing favorites. The topic of non-inclusiveness includes “terms like “cliques,” “clubby,” or “in crowd” that indicate that some employees are being excluded without specifying why.”
Disrespectful Behavior
The authors found that “feeling disrespected at work has the largest negative impact on an employee’s overall rating of their corporate culture of any single topic.” Lack of respect can occur in many areas. The most obvious is the lack of a speak up culture where employees understand it is useless to raise issues to management; whether serious matters such as FCPA violations to more straight-forward ideas such as process improvement. It can also be something as simple as whether or not to return to the office on a fulltime basis and whether management listens to employees about their desires to continue working from home or utilize some type of hybrid working arrangement. The authors noted, “whether you analyze culture at the level of the individual employee or aggregate to the organization as a whole, respect toward employees rises to the top of the list of cultural elements that matter most.”
Ethical Behavior
The authors believe that ethics “is a fundamental aspect of culture that matters at both the organizational and individual levels.” Interestingly, there are several different aspects to ‘ethics’ that every CCO needs to consider. Unethical behavior is “about integrity and ethics within an organization.” It also includes dishonesty, which “employees described dishonest behavior in many ways”, from outright lying to making false promises to shading the truth to simply “sugarcoating.” Under regulatory compliance employees talked about failure to comply with applicable regulations, including failure around safety standards.
Cutthroat Behavior
I found this category fascinating as it included both uncooperative co-workers and the lack of harmonization across organizational silos. This was not simply “friction in coordination” but situations where “employees talked about colleagues actively undermining one another.” It included what the authors termed as a “vivid lexicon to describe their workplace, including “dog-eat-dog” and “Darwinian” and talked about coworkers who “throw one another under the bus,” “stab each other in the back,” or “sabotage one another.””
Abusive Behavior
Having worked in law firms long ago, I understand abusive behavior. The authors called it “sustained hostile behavior toward employees” including such actions as “bullying, yelling, or shouting at employees, belittling or demeaning subordinates, verbally abusing people, and condescending or talking down to employees.” While one would hope such behaviors do not exist in the 21st century, they apparently still do. 0.8% of the employees surveyed for the article described their manager as abusive, however, when employees did mention abusive managers, it significantly depressed a corporate culture.
What CCOs and compliance professionals should try to drive forward is a “culture that is inclusive, respectful, ethical, collaborative, and free from abuse by those in positions of power.” But the authors caution that these are really the “baseline elements of a healthy corporate culture.” Employees want more than the basics and other stakeholders in an organization want companies to have strong official core values. In an interview with LRN’s Susan Divers, she called it the ‘value in values’. From the compliance professional’s perspective in means values like integrity, collaboration, respectful, and DEI.

Categories
FCPA Compliance Report

Susan Divers on the LRN Ethics & Compliance Program Effectiveness Report


In this episode of the FCPA Compliance Report, I am joined Susan Divers, Director of Thought Leadership at LRN. We discuss recently released LRN Ethics & Compliance Program Effectiveness Report. Highlights in include:

  • What is the LRN Ethics & Compliance Program Effectiveness Report?
  • What does it measure?
  • How is it generated?
  • Why is culture so critical?
  • What are the values in values?
  • What is LRN’s High Performance Premium?
  • What are the roles of managers and leaders?
  • What are the keys to effective training?
  • What will the new normal for compliance programs look like going forward?
  • The issue of culture and values down the road into 2025 and beyond.

Resources
Susan Divers
LRN Ethics & Compliance Program Effectiveness Report

Categories
This Week in FCPA

Episode 296 – the Seeing Green edition


The SEC releases regulations around climate change as Tom take a solo turn to look at some of the week’s top compliance and ethics stories in the Seeing Green edition.

Stories

1.     SEC comes out with climate change regs. Andrew Ross Sorkin in NYTimes Dealbook. Matt Kelly in Radical Compliance. Tom and Matt in Compliance into the Weeds.
2.     SFO spanked again. Andrew Crowley in MLex.
3.     Getting rid of old data critical. Debevoise lawyers in Compliance and Enforcement.
4.     The ‘S’ in ESG. Mike Volkov in Corruption Crime and Compliance.
5.     FINRA and CCO liability. Matt Kelly in Radical Compliance.
6.     IDB debars construction company. Harry Cassin in the FCPA Blog.
7.     First ZTE monitorship ends. Jaclyn Jaeger in Compliance Week (sub req’d)
8.     DOJ raises stakes. Todd Fishman, Noah Brumfield, Eun Woo Jhang and Elaine Johnston in CCI.
9.     Top 6 ESG issues for 2022. Giles Newman in Risk and Compliance Matters.
10.  A Privacy Shield replacement on the horizon? Neil Hodge in Compliance Week. (sub req’d) 

Podcasts and More

11.  In March on The Compliance Life, I visit with Audrey Harris, Managing Director at AMI, formerly CCO at BHP. In Part 1, she discussed her academic background and early professional career. In Episode 2, Audrey moved to the CCO chair at BHP. In Episode 3, she moved back to private practice. In Episode 4, she moves to AMI.
12.  Tom has a two part series with Aly McDevitt on her recent Ransomware case study, on Greetings and Felicitations,  Part 1 and Part 2.
13.  Why should you attend Compliance Week 2022? Find out on this episode of From the Editor’s Desk. Listeners get a $200 discount to CW 2022 with the code Fox200. More here.
14.  Tom visits with Pop Hair Art Salon founder, Michele Van Fossen on The Hill Country Podcast.
15.  An undergrad degree focusing on ESG? Jules Oringel explains on the ESG Compliance Podcast.
Tom Fox is the Voice of Compliance and can be reached at tfox@tfoxlaw.com. Jay Rosen is Mr. Monitor and can be reached at jrosen@affiliatedmonitors.com.

Categories
Blog

Sales incentives and Compliance

Sales incentives continue to be an area where Chief Compliance Officers (CCOs) and compliance professionals work refine their compliance regimes. In the 2020 Update to the Evaluation of Corporate Compliance Programs (Update), Incentives and Disciplinary Measures, the Department of Justice (DOJ) stated:

Incentive System — Has the company considered the implications of its incentives and rewards on compliance? How does the company incentivize compliance and ethical behavior? Have there been specific examples of actions taken (e.g., promotions or awards denied) as a result of compliance and ethics considerations? Who determines the compensation, including bonuses, as well as discipline and promotion of compliance personnel?

When considering how a company could use incentives to further a compliance program, and the role of HR in this process, we should also consider how incentives might lead to the converse, as they did in the now-infamous Wells Fargo fraudulent-accounts scandal. When you misalign these two concepts with a faulty sales strategy it can lead to a catastrophic failure, literally costing the company millions of dollars in fines, loss of business, and depreciation of shareholder value.

The sales incentives under which Wells Fargo came to such grief is a simple, and even benign, story of the cross-selling of products. After all, large banks cross-sell their clients all the time, and nobody seems to blink an eye at the cross-selling McDonalds engages in every time you buy a Big Mac when the representative asks if you would like fries with it. Yet there are other reasons for engaging in this type of business practice. Each and every time a company has a touchpoint, particularly a commercial touchpoint, with a business, it strengthens the relationship.

At Wells Fargo, however, what started off as a legitimate, legal and beneficial business strategy became not only high-risk, but illegal because of the manner in which Wells Fargo administered its approach to cross-selling. As with any sales initiative, if a company wants to push cross-selling, it will set up incentives for encouraging the sales team to engage in such behavior. This can be done by increasing commissions around the service or product being emphasized, such as the bank’s products. Companies can also increase sales by making clear that you will be evaluated on how much you sell a product or service. In other words, whether you receive a bonus, pay raise or even keep your job will be evaluated, in some part, on how much you cross-sell.

You can even have a hybrid of the above, which may be the worst of all worlds. At Wells Fargo, employees were evaluated for continuing employment by supervisors on cross-selling. Yet the employees did not receive the same financial incentives as the supervisors to make such cross-selling. Branch managers and supervisors could receive bonuses of up to $10,000 per month for meeting cross-selling quotas, whereas employees who hit their monthly quotas received, in addition to continued employment, $25 gift cards.

What about variable compensation? That is compensation based on alterable factors such as total sales, sales relative to a region, product line or other group. Some of the questions you might ask are: What does your bonus program consist of? Is it corporate performance based? Is it group performance based? Personal as in “eat what you kill”? Or is it some combination of all of the above?

A variable system can also lead to ethics and compliance failures. One reason could be similar to Wells Fargo—very high goals but no direction for employees on how to get there, coupled with a lack of communication between management and line employees, meaning there was raw fear from employees to inform their immediate supervisor of bad news. Conversely, it could be the supervisors who do not want to hear such bad news—for example, if your company has singular focus on numbers, meaning that is the single judge of your worth as an employee. Answering some of these questions if they arise can help you to understand the design of incentive plans and allow monitoring of incentive plans to identify underlying links that may arise through compliance violations.

Whatever your incentive structure, there will be employees who try to game the system. Some will do it with the tacit or explicit approval of management. You, as the CCO, may be required to act.

Categories
Daily Compliance News

March 21, 2022 the CCO Liability Edition


In today’s edition of Daily Compliance News:

Categories
Blog

Using Agile for Compliance Innovation

Driving innovation in your compliance program is still seen as one of the most difficult challenges for every Chief Compliance Officer (CCO) or compliance professional. I was therefore intrigued by a recent article in the Harvard Business Review (HBR), entitled Purposeful Business the Agile Way by Darrell Rigby, Sarah Elk and Steve Berez, which discussed how business leaders can “transform a profit-maximizing system into a purpose-driven one without jeopardizing the future of their businesses and their own careers.”
Interestingly, the authors came to their approach due to the post pandemic great resignation, which they posit business leaders have no clue as to why there is such employee action and equally importantly how to adapt to it, stating, “For decades managers trusted influential economists who promised that if businesses maximized profits, an invisible hand would generate greater benefits for all society. That isn’t happening the way they said it would.” Yet business executives went overboard on creating value for shareholders as their only focus. The authors believe that such a myopic approach robs other “stakeholders of value.” That has certainly been the case for businesses treatment of employees. The authors conclude, “One recent manifestation: Record numbers of people are quitting their jobs, and others are hitting picket lines to demonstrate a growing conviction that life is too short to waste on demoralizing work. Concern about social inequities and environmental damage is escalating. The system is out of balance, and the situation is getting worse.”
Business executives stand at the turning point. They can continue down a destructive path or adapt. However, the problem is that most business leaders are afraid to change, afraid to create multiple stakeholders, as opposed to focusing solely on shareholders and do not want to listen to their employees. The authors believe, “agile ways of working can help, turning squishy debates about corporate purpose into real actions and results.” It provided to me numerous tangible ideas about how to drive innovation in the compliance arena. I have adapted the authors ideas for a corporate compliance program. The authors posit several concrete steps you can take, which every CCO and compliance professional should consider for their compliance regime.
Create a Microcosm
The authors suggest an approach not unlike Design Thinking. Here are some of their suggestions.

  • Assemble a multidisciplinary team, including experts outside your silo.
  • Develop deep empathy for users, exploring their goals and frustrations.
  • Examine the current system to identify the causes of those frustrations.
  • Envision a more purposeful system.
  • Describe changes that might improve the system.
  • Prioritize and sequence them.
  • Test potential improvements.
  • Adapt to unexpected effects and side effects.
  • Scale up solutions that enrich the lives of stakeholders affordably.

Every CCO should be comfortable with these suggestions and steps.
Continuous Monitoring Leading to Continuous Improvement
Compliance, like business purpose, should not be viewed as a mechanical watch. In 2008, I heard then Deputy Attorney General (DAG) Lanny Breuer say that a best practices compliance program needed to be nimble and agile. Obviously, continuous monitoring and continuous improvement are mandated parts of a best practices compliance program in 2022. Where the authors expand on this basic component for any compliance program is around five questions you should ask about your compliance innovation.
These include: Does your compliance initiative support your strategic objectives and create important benefits for the stakeholders who have the most impact on the success of your business? Will multiple stakeholders actively support your compliance initiative? Will your investment in this compliance initiative create greater value for a wide variety of stakeholders, more “than would simply writing a check to a more economical innovator?” Finally, your compliance initiative should “test specific hypotheses and mitigate adverse side effects before scaling up the project.”
Do the Right Thing
Setting financial targets is one way of goal setting. However, as the authors note, “Agile helps flip that approach, focusing first on creating value for stakeholders and then on earning adequate profits in the process. Instead of asking, How can we improve profitability without damaging customer and employee satisfaction? they ask, How can we enrich the lives” of various stakeholder’s and employees?
In the 2020 Update to the Evaluation of Corporate Compliance Programs, the Department of Justice (DOJ) made clear that CCOs and the corporate compliance functions were the holders of institutional justice and institutional fairness in a company. In other words, you already have the obligation. Therefore, doing the right thing for both employees and other stakeholders is not something new for compliance professionals.
Prioritize Collaboration
If there is one thing compliance must do it is collaborate. Compliance generally does not have a hammer it can bring down but must lead through influence and working with others. Moreover, engagement with a wide variety of stakeholders in your company is a much better way to get something down as those stakeholders involved will be invested in the outcome if the are involved in its creation.
In the world of agile, the authors report, “A central reason for the success of agile ways of working is that they prioritize teamwork over individual performance. Research by the Standish Group, which has studied the success of IT projects since 1994, shows that agile teams improve software innovation by more than 60%, on average, and by 100% when the innovation is large and complex. Two-thirds of agile teams across a wide range of business functions report better cross-functional alignment, and 60% register higher team morale, according to the State of Agile Report by Digital.ai, a company focused on digital transformations.”
The bottom line is that by embracing these agile concepts, a CCO has a much better chance of implementing innovative change in their compliance program.

Categories
Innovation in Compliance

Taxman: Tax and ESG


 
In this episode of Taxman, Tom Fox and Tracy Howell conclude the special series by discussing a topic that has yet to be explored by most: tax and ESG. 
 

 
How Tax and ESG Intersect
Tracy tells Tom, “There are external forces pulling tax into the ‘S’ and ‘G’ of ESG.” In the social sector, different jurisdictions have different tax rates and laws, and as companies begin to operate in a tax-efficient manner, their activities will gravitate towards lower tax regimes. Tracy adds, “You’ve got forces trying to push the concept of ‘fair share’ rather than compliance with tax laws of different jurisdictions.” Governance-wise, it’s becoming more common for companies to be required to talk about their compliance tax audits. 
 
The Role of Tax in a Company
With the growing pressures on ESG transparency, there’s a push to standardize reporting and scorecarding of companies based on their tax transparency. This would include things like the reporting of an organization’s effective tax rate. 
 
Tax and ESG in Multinational Organizations 
Institutional investors play a major role in impacting the activities of a multinational company. When making investment decisions, these entities heavily incorporate ESG scorecards with tax transparency, further emphasizing the need for a relationship between the two sectors. 
 
Resources
Tom Fox’s Email
Tracy Howell | Email | LinkedIn
 

Categories
Innovation in Compliance

Taxman: Tax and Supply Chain


 
As the Taxman five-part series nears the end, Tom Fox and Tracy Howell tackle an important topic that has become more prominent over the years: tax and supply chain. 
 

 
How Tax Can Help Supply Chain
Supply chain in a traditional sense focuses on the acquisition of goods, in particular the quality, cost, and delivery. There can be a substantial tax component in each of those steps to help companies attain goods at the lowest possible cost. Consequently, if supply chain does not have a relationship with tax, it can result in additional surprise costs being attached to goods. Data beyond the cost of goods, material, and service can be used to model and predict the additional tax burden so that better procurement decisions can be made. 

Mitigating the Risk of Mission Creep 
Establishing a connection between tax and supply chain in an organization is good, but the relationship needs to be kept fresh for a positive impact. In a company, people may be focused on so many different things that they forget to interact. Creative people tend to expand their roles and look for goods and services in different locations, which can be the cause of a mission creep. Hence, having constant close interaction between supply chain and tax allows for changes in functionality to be documented and implemented into the organizational framework.
 
Elements of a Tax-Efficient Supply Chain
Tom and Tracy discuss the elements of a tax-efficient supply chain. This includes:

  • Examination of the entire scope of what’s being manufactured and sold to allow the creation of tax opportunities to bring value based on special purpose entities. 
  • Coordination of transactions in a supply chain with transfer pricing. 
  • Compliance with tax laws and regulations. 
  • Documentation of the process. 

 
Resources
Tracy Howell | Email | LinkedIn 
 

Categories
Blog

Tax and Compliance: Tax and Supply Chain

What is the intersection of tax and compliance? Why does a Chief Compliance Officer (CCO) or compliance professional need to sit down with the corporate head of tax? How does a corporate tax function fit into a best practices compliance program? It turns out there is quite a bit a compliance professional can learn from a tax professional. Moreover, there are many aspects of tax which should be considered by a CCO and compliance professional from an overall risk management perspective. Unfortunately, these questions are rarely explored in the compliance community.
To explore these issues (and remedy this lack of awareness) I recently sat down with noted tax professional Tracy Howell to explore these and other questions. We tackled these issues and others in a five-part podcast series for Innovation in Compliance. Today, we consider the role of tax in the Supply Chain. We also expand that to compliance, because compliance also has a huge role in this area.

Obviously, this topic has become more prominent over the last couple of years during the pandemic. Over the past couple of weeks, with the Russia invasion of Ukraine, it has become even more hyper-critical. One of the things we saw in the pandemic was that many companies with long established Supply Chains, perhaps not single source suppliers, but close to single source suppliers, found themselves scrambling when huge swaths. With the Russian invasion of Ukraine, we have had the largest amount of economic sanctions delivered by any administration in the modern era. Companies are struggling with not only responding to the sanctions but responding to the business dislocation from Russia and Belarus to Ukraine and into eastern Europe.
Clearly Supply Chain is critical for an organization, especially an organization that manufactures and has any substantial delivery of materials and services. There is also the question of where the highest risk in your Supply Chain might be. Is it in the critical component(s) in the acquisition of goods? Is it in the delivery of services? Or is it simply in the manufacturing process itself? Moreover, if you think of Supply Chains as only having a traditional focus on the acquisition of goods, comprising both the quality of the goods and the cost of the goods, and concluding with the delivery of the goods for consumption or later sale; you are missing a key component. That key component is tax and as Howell stated, “there can be a substantial tax component in each one of those steps of acquisition costs. If you are buying goods in foreign jurisdictions that can be transaction taxes, such as GST or VAT.”
Howell provided the following example. “If a company’s buying raw materials in a third country, in the shipping terms, we’d normally say title transfers in international waters, that’s a good thing for the buyer. Because that means if I’m buying something and I take title in international waters, it should not trigger any transaction taxes. However, if you are not paying attention to where you acquire goods from and then you take title within the country of origin’s territory, guess what? That could trigger up to a VAT liability of 15 to 20%. This means that if your Supply Chain is not interacting or does not have a relationship with tax, and the taxes can add a 15% to 20% component to the cost of goods in a transaction, which dramatically impacts the company’s cost of goods sold (COGS).”
However, if there is a good relationship between tax and Supply Chain, there can also be additional benefits tax brought to the fore and such benefits are more critical in 2022 and beyond because they can help a company plan for disruptions in the supply chain. For instance, if Supply Chain looks for alternative suppliers, or a different geo-region for component parts, tax can step in and do an analysis that would at least give them an estimate of what the tax costs are going to be.
Howell said that tax can provide “Supply Chain with the data that is beyond the cost of good, or the cost of material, or the cost of service. A tax professional can do so by modeling out the liability that a multinational could incur, including up to five different possible sources for goods and materials. From there you can extend your model out to see what the additional tax burden would be in each one of those scenarios. From there you can check to see if there are any tax incentives that either exist or that your organization can go negotiate.”
But the risk management that tax can bring to Supply Chain does not end there; particularly once tax and Supply Chain have established a relationship and it is understood how tax can assist Supply Chain in the procurement of goods and services. Through a documented process, it creates and entire framework for the organization to use going forward because at any given time Supply Chain will be looking for goods and services in different locations. Howell said, “you can have a mission creep. It is important for tax to have that relationship with Supply Chain so as their functionality changes and your organization is acquiring new goods in different locations, you can document the changes, and update your framework as needed when new tax issues can come to play.”

Join us tomorrow for our concluding post when we consider the role of tax in a corporate ESG program. Check out the full podcast series Taxman: On the Intersection of Tax and Compliance on the Compliance Podcast Network. Check out Tracy Howell on LinkedIn.