Categories
Blog

AI in Compliance Week: Part 2 – A Comprehensive Governance Approach

We continue our weeklong exploration of issues related to using Generative AI in compliance by examining some AI governance issues. In the rapidly evolving landscape of AI, the importance of robust governance frameworks cannot be overstated. The need for comprehensive governance structures to ensure compliance, ethical alignment, and trustworthiness has become paramount as AI systems become increasingly integrated into compliance. Today, we will consider the critical areas of compliance governance and ethics governance and present a holistic approach to mitigating the risks associated with these issues.

MIA AI Governance: The Problems

Missing compliance governance can have far-reaching consequences, undermining the integrity of an entire AI-driven initiative. Businesses must ensure alignment with enterprise-wide governance, compliance, and control (GRC) frameworks. This includes aligning with model risk management practices and embedding robust compliance checks throughout the AI model lifecycle. By promoting awareness of how the AI model works at your organization, you can minimize information asymmetries between development teams, users, and target audiences, fostering a culture of transparency and accountability.

The lack of ethical governance can lead to misalignment with an organization’s values, brand identity, or social responsibility. The answer is that companies should develop comprehensive AI ethics governance methods, including defining ethical principles, establishing an AI ethics review board, and creating a compliance program that addresses ethical concerns. Adopting frameworks like Ethically Aligned AI Design (EAAID) can help integrate ethical considerations into the design process while incorporating AI governance benchmarks beyond traditional measurements to encompass social and moral accountability.

Another outcome of the lack of trustworthy or responsible AI governance can result in unintentional and significant damage. To address this, compliance professionals should help develop accountable and trustworthy AI governance methods that augment enterprise-wide GRC structures. This can include establishing a committee such as an AI Advancement Council or similar structure in your company to oversee mission priorities and strategic AI advancement planning, collaborating with service line leaders and program offices to align with ethical AI guidelines and practices, and developing compliance programs to guide conformance with ethical AI principles and relevant legislation. Finally, implementing AI-independent verification and validation processes can help identify and manage unintentional outcomes.

The Solution

By addressing the critical areas of compliance governance and ethics governance through a more holistic approach, businesses can create a comprehensive framework that mitigates the risks associated with the absence of these crucial elements. This approach ensures that AI systems comply with relevant regulations and standards and align with your company’s values, ethical principles, and the pursuit of trustworthy and responsible AI. As the AI landscape evolves, this comprehensive governance framework will be essential in navigating the complexities and safeguarding the integrity of AI-driven initiatives.

Here are some key steps compliance professionals and businesses can think through to facilitate AI governance in your company:

  1. Establish a Centralized AI Governance Body:
    • Create an AI Governance Council that oversees your organization’s AI strategy, policies, and practices.
    • Ensure the council includes representatives from various stakeholder groups, such as legal, compliance, ethics, risk management, IT, and other subject matter experts.
    • Empower the council to develop and enforce AI governance frameworks, guidelines, and processes.
  2. Conduct AI Risk Assessments:
    • Identify and assess the risks associated with the organization’s AI initiatives, including compliance, ethical, and other compliance-related risks.
    • Prioritize the risks based on their potential impact and likelihood of occurrence.
    • Develop mitigation strategies and action plans to address the identified risks.
  3. Align AI Governance with Enterprise-wide Frameworks:
    • Ensure the AI governance framework is integrated with the organization’s existing GRC and Risk Management processes.
    • Establish clear lines of accountability and responsibility for AI-related activities across the organization.
    • Integrate AI governance into the organization’s broader risk management and compliance programs.
  4. Implement Compliance Governance Processes:
    • Develop and enforce AI-specific compliance controls, policies, and procedures.
    • Embed compliance checks throughout the AI model lifecycle, from development to deployment and monitoring.
    • Provide training and awareness programs to educate employees on AI compliance requirements.
  5. Establish Ethics Governance Mechanisms:
    • Define the organization’s AI ethics principles, values, and code of conduct.
    • Create an AI Ethics Review Board to assess and monitor the ethical implications of AI initiatives.
    • Implement processes for ethical AI design, such as the Ethically Aligned AI Design methodology.
    • Incorporate ethical AI benchmarks and accountability measures into the organization’s performance management and reporting processes.
  6. Implement Reliance-Related Governance:
    • Develop responsible and trustworthy AI governance practices that align with the organization’s enterprise-wide GRC frameworks.
    • Establish an AI Advancement Council to oversee strategic AI planning and alignment with ethical guidelines.
    • Implement AI-independent verification and validation processes to identify and manage unintended outcomes.
    • Provide comprehensive training and awareness programs on AI risk management for employees, contractors, and other stakeholders.
  7. Foster a Culture of AI Governance:
    • Promote a culture of accountability, transparency, and continuous improvement around AI governance.
    • Encourage cross-functional collaboration and communication to address AI-related challenges and opportunities.
    • Review and update the AI governance framework regularly to adapt to evolving regulatory requirements, technological advancements, and organizational needs.

By following these steps, organizations can implement a comprehensive governance framework that addresses compliance, ethics, and reliance-related governance. This framework enables organizations to harness the power of AI while mitigating the associated risks. 

AI Governance Resources

There are several notable resources the compliance professional can tap into around this issue of AI governance practices. The Partnership on AI Partnership on AI is a multi-stakeholder coalition of leading technology companies, academic institutions, and nonprofit organizations. It has been at the forefront of developing best practices and guidelines for the responsible development and deployment of AI systems. It has published influential reports and frameworks, such as the Tenets of Responsible AI and the Model Cards for Model Reporting, which have been widely adopted across the industry.

The Algorithmic Justice League (ALJ) is a nonprofit organization dedicated to raising awareness about AI’s social implications and advocating algorithmic justice. It has developed initiatives such as the Algorithmic Bias Bounty Program, encouraging researchers and developers to identify and report biases in AI systems. The AJL has highlighted the importance of addressing algorithmic bias and discrimination in AI.

IEEE Global Initiative on Ethics of Autonomous and Intelligent Systems is a multidisciplinary effort to develop standards, guidelines, and best practices for the ethical design, development, and deployment of autonomous and intelligent systems. It has produced key documents and reports, such as the Ethically Aligned Design framework, which guides the incorporation of ethical considerations into AI development.

The AI Ethics & Governance Roundtable is an initiative led by the University of Cambridge’s Leverhulme Centre for the Future of Intelligence. It brings together industry, academia, and policymaking experts to discuss emerging issues, share best practices, and develop collaborative solutions for AI governance. The roundtable’s insights and recommendations have influenced AI governance frameworks and policies at the organizational and regulatory levels.

These examples demonstrate the power of industry collaboration in advancing AI governance practices. By pooling resources, expertise, and diverse perspectives, these initiatives have developed comprehensive frameworks, guidelines, and standards being adopted across the AI ecosystem. Compliance professionals should avail themselves of these resources to prepare your company to take the next brave steps in the intersection of compliance, governance, and AI.

Categories
Compliance Tip of the Day

Compliance Tip of the Day: How AI is Transforming Risk Management

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

In today’s episode, we begin a week-long look at some of the ways Generative AI is changing compliance and Risk Management.

For more information on the Ethico ROI Calculator and a free White Paper on the ROI of Compliance, click here.

Categories
FCPA Compliance Report

FCPA Compliance Report: Evie Wentink on Making Compliance Training Practical

Welcome to the award-winning FCPA Compliance Report, the longest running podcast in compliance.

In this edition of the FCPA Compliance Report,  Tom Fox has a fascinating visit with Iveta (Evie) Wentink, a 15-year compliance veteran. Evie has worked in the public and private sectors and has expertise in compliance training, hotlines, government contract compliance, data privacy, reporting, & due diligence.

Evie has one of the most unique opening lines for hotline training, which is ‘Do You Know Your Hotline Number?” This simple yet incredibly important question encapsulates Evie’s approach to compliance training: make it simple, direct, and practical for the listeners. (Or, as Carsten Tams would say, ‘It’s all about the UX’).

Our conversation focuses on the critical role of hotline numbers in corporate compliance programs, emphasizing the need for employees to know and trust the hotline. Evie shares insights from her career, highlights the significance of marketing compliance hotlines effectively, and discusses the broader culture of compliance and non-retaliation in organizations. She shares practical tips for improving hotline awareness and usage, making this episode a valuable resource for compliance professionals and organizations alike.

Highlights in this Episode:

  • Enhancing Trust through Active Compliance Reporting
  • Promoting Reporting Culture Through Creative Marketing
  • Ethical Culture: Encouraging Compliance Reporting Safely
  • Enhancing Compliance Programs Through Anonymous Hotlines

Resources:

Evie Wentink on LinkedIn

Evie’s Top 10 Compliance Back to Basics

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

 

For more information on the Ethico ROI Calculator and a free White Paper on the ROI of Compliance, click here.

Categories
Blog

AI in Compliance Week: Part 1 – Transforming Risk Management

Compliance professionals face increasing pressures to adapt and innovate in today’s rapidly evolving landscape. On a recent episode of Innovation in Compliance, I visited with Matt Lowe, the Chief Strategy Officer at MasterControl. We discussed how AI is revolutionizing quality management in the life sciences industry. With a background in engineering and extensive experience at MasterControl, Matt offered a unique perspective on integrating AI into compliance processes. We deeply explored how AI is poised to transform the compliance field.

Generative AI is being utilized to create comprehension-based testing automatically. This innovation significantly reduces the time required for compliance-focused training, transforming a process that once took hours into a task completed in minutes. This approach resonates with the broader compliance community, where efficiency and accuracy are paramount. By automating the generation of training materials, AI can help ensure that employees are adequately trained on your internal policies and procedures, helping your organization maintain compliance with regulatory standards.

Perhaps one of AI’s most exciting promises is the shift from reactive to predictive and preventative compliance. Traditionally, risk management has focused on identifying and correcting issues after they occur. However, AI offers the potential to predict and prevent problems before they arise. By analyzing vast amounts of data, AI can identify patterns and anomalies, allowing organizations to address potential issues proactively.

This predictive capability is precious in the life sciences industry, where the stakes are high. Ensuring the highest quality products can directly impact patient safety and regulatory compliance. Leveraging AI to predict and prevent quality issues represents a transformative shift in managing compliance.

When implementing AI in compliance, you should take a risk-based approach. This involves starting with low-risk AI applications to gain confidence in the technology before moving on to more critical areas. For instance, generating training exams is a low-risk application that can still deliver significant benefits. As organizations become more comfortable with AI, they can explore its use in more complex and higher-risk areas.

This cautious approach aligns with the principles of compliance, where assessing and managing risk is a fundamental aspect of the profession. By gradually incorporating AI, organizations can mitigate potential risks while harnessing the technology’s power to enhance compliance processes.

While AI offers tremendous potential, we both stressed the importance of the “Human in the Loop” approach. AI can provide valuable insights and automate processes, but human oversight remains crucial. This is particularly important in life sciences, where the consequences of errors can be severe. Ensuring that humans review and validate AI-generated outputs helps maintain the accuracy and reliability of compliance efforts. This “Human in the Loop” reflects a balanced approach to AI integration. By combining the strengths of AI with human expertise, organizations can achieve a more robust and effective compliance framework.

Lowe shared his vision for the future of AI in compliance. He envisions a world where AI becomes integral to software applications, transforming how professionals interact with technology. Instead of navigating complex interfaces, users will engage with AI-driven chatbots that provide instant answers and guidance. This shift will enable compliance professionals to access the information they need more efficiently and effectively. AI has the potential to identify gaps in compliance frameworks and suggest appropriate controls. This capability can significantly enhance the effectiveness of compliance programs by ensuring that organizations are always prepared for audits and regulatory scrutiny.

As AI continues to evolve, collaboration within the industry will be essential. Lowe mentioned initiatives like the Convention for Healthcare AI, where industry players and regulators discuss the ethical implications and best practices for AI use. Such collaborations are vital to ensure that AI is leveraged responsibly and ethically, particularly in industries like life sciences, where the impact on human health is significant.

AI has transformative potential for compliance. By automating routine tasks, shifting from reactive to predictive compliance, and adopting a risk-based approach, AI can significantly enhance the efficiency and effectiveness of compliance programs. However, the human element remains crucial to ensure accuracy and reliability. As the industry continues to explore and embrace AI, collaboration and ethical considerations will play a vital role in shaping the future of compliance. By harnessing the power of AI, organizations can stay ahead of regulatory requirements, improve product quality, and ultimately protect patient safety. The journey towards AI-driven compliance is just beginning, and the possibilities are exciting and profound.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 8 – Risk Management Lessons from Miri

In this episode of Trekking Through Compliance, we consider the episode Miri, which aired on October 27, 1966, with a Star Date of 2713.5.

Episode Summary

A disfigured man attacks a landing party who dies after Kirk strikes him. They discover a preadolescent, Miri, who ran away from them because “grups” kill and maim children before dying. She and her friends are “onlies,” the only ones left. The distress call is traced to an automated signal. The landing party, except for Spock, notices purple lesions on their bodies; Miri tells them that these are the first signs of the disease, and they will soon become like the other adults. When the disease begins, its victims have seven days to live. Although Spock is immune, he considers himself a carrier who could infect the Enterprise if he returns.

Back on the Enterprise, after vaccinating everyone and leaving the children in the care of a medical team, Kirk sends for teachers and advisers to help the children improve their lives.

Commentary

In this episode of Trekking Through Compliance, host Tom Fox explores the Star Trek original series episode ‘Miri.’ Responding to a distress signal, the Enterprise crew discovers a planet that is a duplicate of Earth, inhabited only by children due to a disease that kills anyone who has reached puberty. The episode delves into themes of disaster preparedness, environmental and public health compliance, data governance, supply chain management, and employee welfare. The episode offers crucial compliance and risk management lessons relevant to modern organizations through these themes.

Key Highlights

  • Plot Summary of ‘Miri’
  • Behind the Scenes and Fun Facts
  • Risk Management Lessons from ‘Miri’

Resources

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

Categories
Compliance Tip of the Day

Compliance Tip of the Day: Compliance Lessons from The Gunvor FCPA Enforcement Action

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

In today’s episode, we consider Gunvor FCPA’s enforcement action, which  presents numerous lessons learned. Today we unpack the key compliance takeaways.

For more information on the Ethico ROI Calculator and a free White Paper on the ROI of Compliance, click here.

Categories
The Corruption Files

The Corruption Files: Tyco, Dennis Kozlowski and The Era of Excess

What is stranger than fiction? The stories of worldwide corruption. In this podcast series, co-hosts Tom Fox, the Voice of Compliance and Mike DeBernardis, partner at Hughes Hubbard, discuss some of the most audacious corruption cases in anti-corruption enforcement. More importantly, they will discuss the lessons learned on what your organization can do to prevent running afoul of international anti-bribery laws.

In this episode of Season 2, Tom and Mike take a deep dive into the historical case of Tyco, a quintessential example of dot-com era excess.

Tom and Mike discuss Tyco’s journey from a small semiconductor company to a corporate giant under CEO Dennis Kozlowski. Kozlowski’s aggressive growth strategies and extreme personal expenditures, such as a $6,000 shower curtain, became infamous. The discussion covers fraudulent activities, including unauthorized bonuses and misuse of loan programs, ultimately leading to Kozlowski and CFO Mark Swartz’s convictions.

The episode also examines the implications for corporate governance and the sweeping changes in third-party risk management prompted by the scandal.

Key Highlights:

  • The Rise of Tyco
  • Dennis Kozlowski’s Leadership and Excesses
  • Uncovering the Fraud
  • The Loan Programs and Misconduct
  • The Trial and Conviction
  • Compliance Lessons from Tyco
  • Board Oversight and Final Thoughts

 Resources:

Mike DeBernardis on LinkedIn

HughesHubbardReed

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Mentioned in Podcast

Taking Down the Lion by Catherine Neal

How Compliance Saved Tyco by Joe Mont

Categories
Blog

The Intersection of Creativity and Compliance: Lessons from Improv

In the most recent episode of the Creativity and Compliance podcast, Tom Fox and Ronnie Feldman delved into the fascinating intersection of improvisation and compliance with our special guest, Marla Caceres, an expert in applied improvisation. We explored how the skills and philosophies of improv can significantly enhance communication and leadership within the ethics and compliance community.

Marla introduced improvisation as the theatrical art of making it up on the spot. While it may seem spontaneous, successful improvisation relies heavily on technique, training, and practice. Like a basketball team practices fundamentals to be ready for any game, improvisers hone their skills to perform seamlessly as a team. This ensemble-based approach fosters a collaborative environment where each member supports the other, creating a space where innovation and quick thinking thrive.

Improvisation is not confined to the theater; its principles apply to various business practices, particularly in ethics and compliance. Marla explains that many students are drawn to improv not to pursue comedy but to improve their communication and leadership skills. Improv teaches others-focused communication, essential for building effective teams and fostering a positive organizational culture.

Communication that is others-focused is at the heart of improvisation. This concept involves shifting your focus from your agenda to genuinely listening and responding to others. In an improv scene, success depends on fully accepting and building on your partner’s input. This active listening and validation level creates a supportive environment where creativity and collaboration flourish. Marla highlighted that this approach can transform everyday interactions, making them more productive and meaningful. It also plays directly into the skills needed by a compliance professional.

Psychological safety is paramount for ethics and compliance professionals. Psychological safety refers to an environment where individuals feel safe speaking up without fear of retribution. Improv provides a low-stakes, fun way to practice the skills necessary to foster this environment. By focusing on deep listening and the “Yes” principle, compliance professionals can build trust and encourage open communication.

The “Yes, and” principle is fundamental in improv. It involves accepting your partner’s idea (Yes) and building on it (and). This technique fosters creativity and promotes a nonjudgmental and inclusive atmosphere. For compliance professionals, applying “Yes and” can shift their perception of their role from rule enforcers to supportive advisors. This change in approach can make employees more willing to engage with compliance, seeing it as a collaborative effort rather than a hindrance.

Marla and Ronnie discussed several practical techniques derived from improv that can benefit compliance professionals. One such exercise is the “Should vs. Could” activity. Participants pair up and share a problem, with one offering advice using “You should” statements and then “You could” statements. The difference in reception is profound, with “You could” fostering a more collaborative and empowering dialogue. This simple shift in language can significantly impact how compliance professionals communicate, making their advice feel more supportive and less authoritative.

Improvisation also teaches the importance of building trust and reducing fear in communication. By practicing techniques emphasizing validation and support, compliance professionals can create an environment where employees feel safe to raise concerns and seek guidance. This trust is crucial for effective compliance, as it encourages proactive problem-solving and early reporting of potential issues.

The principles of improv can be applied in various settings within the compliance field. For instance, compliance training sessions can incorporate improv exercises to make learning more engaging and memorable. Additionally, compliance professionals can use these techniques in their day-to-day interactions to build stronger relationships with employees and leadership.

Marla emphasized that organizational culture and communication nuances trickle down from the top. Leaders play a critical role in modeling the behavior and communication styles they want to see throughout the organization. By incorporating improv techniques, leaders can demonstrate openness, active listening, and collaborative problem-solving, setting a positive example for their teams.

Improvisation offers a unique and practical approach to enhancing communication and leadership within the ethics and compliance community. By practicing others-focused communication, fostering psychological safety, and embracing the “Yes, and” principle, compliance professionals can transform their interactions and build a more supportive and proactive organizational culture. If you want to explore how improv can benefit your compliance efforts, consider incorporating these techniques into your training and daily practices. As Marla and Ronnie have shown, a little creativity can go a long way in making compliance a collaborative and engaging endeavor.

Categories
Trekking Through Compliance

Trekking Through Compliance – Episode 4 – Ethical Lessons from The Naked Time

In this episode of Trekking Through Compliance, we consider The Naked Time, which aired on September 29, 1966, Star Date 1704.2.

Story

A landing party from the Enterprise beams aboard Psi 2000, an ancient planet about to break up. They find all six of the station’s crew dead. However, the circumstances are bizarre since the life support systems have been switched off, and everything in the station is frozen solid.

As Psi 2000 shows a shift in a magnetic field (and mass!), the Enterprise begins a close orbit requiring constant vigilance. Meanwhile, Sulu abandons his post for a jaunt at the gym, believing himself to be a rapier-brandishing French cavalier. Riley takes over the engine room and declares himself Captain. He demands ice cream for the entire crew and begins a ship-wide broadcast of his rendition of classic Irish ballads (his favorite being “Kathleen”).

While all this is happening, Nurse Chapel infects Spock and professes to love him. This is extremely difficult for Spock, especially since the infection is causing him to become excessively emotional. Spock then passes the infection on to Kirk, who begins exhibiting paranoia and a loss of ability to command. Bones finds the antidote just in time, and Riley is dislodged before his wrenching ballads permanently damage the audience’s ears.

After mixing matter and antimatter at a colder-than-recommended temperature according to an untested intermix formula, the Enterprise is thrown into a time warp, which causes the chronometer to run backward. This allows the Enterprise to escape the planet’s breakup, returning it 71 hours into the past and, therefore, before any events.

Commentary

In this episode, the focal points are the bizarre events that occur when a landing party from the Enterprise encounters a deadly contagion, leading to erratic behavior among the crew. The analysis draws nine key ethical lessons relevant to the compliance profession: self-control, accountability, transparency, respect for others, moral leadership, decision-making under pressure, understanding human vulnerabilities, the consequences of ethical lapses, and a commitment to ethical standards. The episode highlights how Star Trek can serve as a rich source of moral and compliance insights through vivid descriptions and character evaluations.

Key Highlights

  • Episode Summary: The Naked Time
  • Key Moments and Character Highlights
  • Ethical Lessons from ‘The Naked Time’
  • Conclusion and Final Thoughts

Resources

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Great Women in Compliance

Great Women in Compliance: Beth Colling – Common Sense and Compliance

Welcome to the Great Women in Compliance podcast on the Compliance Podcast Network, sponsored by Corporate Compliance Insights.

In this episode, Lisa speaks with Beth Colling, Senior Vice President and Chief Compliance Officer at CDM Smith. Beth joined organizations after they had to address a significant regulatory change or investigation, and she worked to operationalize and then maintain a compliance program. Lisa and Beth specifically talk about how, as issues inevitably arise, compliance officers will get the resources they need to make and implement changes, but over time, memories fade, and the attention and resources may diminish. Beth provides her insight on this.

Beth uniquely evaluates her work and program by “firing herself” on Friday and re-hiring herself on Monday to examine it with new eyes. After the past several years, with the pandemic and hybrid work, this review became even more relevant. This leads to a discussion of “common sense,” not just within a compliance program but also in terms of personal responsibility and how employees rationalize bad behavior.

One of Beth’s (and Lisa’s) childhood heroes was “Wonder Woman,” and Beth may be Wonder Woman. Outside her work, she coaches young adults to enjoy running, and by the end of 2024, she will have completed 5 of the 6 “World Marathon Majors.”

You can join the LinkedIn podcast community.
Join the Great Women in Compliance podcast community here.