Categories
Greetings and Felicitations

Winnie the Pooh Explains Compliance: Part 2 – Kanga, Roo and the Compliance Ombudsman

This week I am exploring a five-part series on compliance as seen through the lens of Winnie the Pooh and the characters who live in the Hundred Acre Woods: Pooh, Eeyore, Tigger, Kanga & Roo, and Piglet. Winnie-the-Pooh, also called Pooh Bear and Pooh was created by English author A. A. Milne. Yesterday, we introduced Tigger and the sales function’s role in compliance. In this episode, we focus on Kanga and her son, Roo, and the Corporate Ombudsman’s role in compliance.

Kanga is a female kangaroo and the doting mother of Roo. They live near the Sandy Pit in the northwestern part of the Hundred Acre Wood. Kanga is the only female character to appear in the books. Kanga is kind-hearted, calm, patient, sensible and down to earth. She likes to keep things clean and organized and offers motherly advice and food to anyone who asks her. She is protective over Roo and treats him with kind words and gentle discipline. She also has a sense of humor, as revealed in chapter seven of Winnie-the-Pooh when Rabbit connives to kidnap Roo, leaving Piglet in his place; Kanga pretends not to notice that Piglet is not Roo and proceeds to give him Roo’s usual bath, much to Piglet’s dismay.

Roo is Kanga’s cheerful, playful, energetic son, who moved to the Hundred Acre Wood with her. His best friends are Tigger and a young Heffalump named Lumpy, who loves to play with him. Roo is the youngest of the main characters. When Kanga and Roo first come to the Hundred Acre Wood, everyone thinks Kanga is a fierce animal, but discover this untrue and become friends with her. In the book, when Tigger comes to the forest, she welcomes him into her home, attempts to find him food he likes and allows him to live with her and Roo. After this, Kanga treats him like she does her son. I want to use Kanga and Roo to consider another role in compliance. It is the creation of an ombudsman for employees to help facilitate compliance.

Kanga is the most trusted soul in the Hundred Acre Woods. She would be an ideal ombudsman and an example that the “success of these programs depends partly on getting the right person for the role. A good ombudsman is a superb listener who establishes trust in people at all levels.” They need to have the skills to think through solutions to problems. Kanga certainly has such skills. A great example is the arrival of Tigger in the Hundred Acre Woods. While Tigger claims to like everything to eat for breakfast, it is quickly proven he does not like honey, acorns, thistles, or most of the contents of Kanga’s larder. However, he discovers what Tigger likes best is the extract of malt, which Kanga has on hand because she gives it to Roo as “strengthening medicine”. This is another key trait of an ombudsman; the person must also respect senior executives and be comfortable taking issues to the Chief Executive Officer (CEO) or the Board if necessary. Understanding the corporate culture and who has influence is also important – which is why many capable people in this role are promoted from inside the company. The same can be said for Kanga in the Hundred Acre Wood.

Join me tomorrow when I consider Eeyore and the role of corporate legal in compliance.

Categories
Innovation in Compliance

The Accelerated Transformation of Compliance with Samantha Regan

 

Accenture provides top-notch services in strategy & consulting, and operations for its clients. Samantha Regan is Managing Director and Global Lead for the Regulatory Remediation & Compliance Transformation group within Accenture’s Finance & Risk practice. Tom Fox welcomes her to this week’s show to talk about the Accenture Compliance Risk Study Report. 

 

 

Accenture’s Compliance Risk Study

Tom asks Samantha about the origin of the report. Samantha responds that each year, the team at Accenture gets together to observe and record what’s happening in the world of compliance. They seek to discover the key issues and concerns for compliance officers across various organizations. Developing a framework, conducting a survey and collating the data are the next steps. This is followed by “synthesizing those results and looking for the insights from the information that’s been provided and then developing the report off the back of that,” Samantha tells Tom. 

 

Primary Compliance Risks In 2022 

Tom asks Samantha to discuss the primary risks that they identified through the study. She replies that the biggest area of focus for compliance folk in 2022 is cybersecurity, ESG, and privacy. Tom asks her to identify some challenges compliance professionals face when responding to and managing these risks. New pressures are constantly being placed on compliance professionals, Samantha explains. “Compliance functions continue to evolve at a speed and scale and force the compliance function to change from being reactive to what was going on in the environment, to needing to be more proactive, building a function that is able to adapt.” She believes that by using data, compliance officers can “build a future-ready and risk-proof compliance function”. 

 

Looking Ahead

Tom asks Samantha how she thinks compliance professionals should respond to risks in 2025. Would the trends highlighted in the study be accelerated? “I think the warp speed at which companies are operating is going to require compliance functions to have accurate and complete visibility into risks and mitigating controls across the business,” she comments. Data from the study suggests that most of the issues compliance officials have can be attributed to the lack of data; there needs to be enough information available to assess risk exposure. She mentions that there is increasing concern surrounding third-party risk. Samantha believes that with the increasing speed and evolution of risks, “the compressed transformation of organizations and industries is just going to put increasing pressure on compliance functions to continue the transition.” 

 

Resources

Samantha Regan | LinkedIn

Accenture | Compliance Risk Study – 2022 

 

Categories
Greetings and Felicitations

Winnie the Pooh Explains Compliance: Part 1 – Tigger and Sales

This week I begin a five-part series on compliance as seen through the lens of Winnie the Pooh and the characters who live in the Hundred Acre Woods: Pooh, Eeyore, Tigger, Kanga & Roo, and Piglet. This episode begins with Tigger and the sales function’s role in compliance.

Tigger first appears in the House at Pooh Corner when he arrives at Pooh’s doorstep in the middle of the night. Tigger takes up residence with Kanga and Roo. He becomes great friends with Roo, and Kanga treats him like she does her son. Tigger seems to have boundless energy, often too much energy for some of the other denizens of the Hundred Acre Wood. Rabbit, who is constantly exasperated by Tigger’s constant bouncing; Eeyore, who is once bounced into the river by Tigger; and, finally, there is Pooh’s good friend Piglet, who always seems a little nervous about the new, large, bouncy animal in the Hundred Acre Wood.

Tigger seems like the epitome of a top salesperson. He is very confident, has quite an ego, and has a high opinion of himself. He always seems to have great energy and optimism, and though always well-meaning, he can also be mischievous, and his actions have sometimes led to chaos and trouble for himself and his friends. Tigger often undertakes tasks with gusto, only to realize they are not as easy as he had originally imagined. Tigger, unique as ever, refers to himself not as a tiger but as a “Tigger”, and when he introduces himself, he announces the proper way to spell his name, and that is “T-I-double-Guh-Er”, which spells “Tigger”.

Tigger seems like a great way to think about sales incentives from the compliance perspective. Much like Tigger, most sales folks have their hearts in the right place, even if their actions cause trouble for themselves and others.

At the end of the day, Tigger is good-hearted, even if his over-exuberance can sometimes lead to misadventures. If you properly incentivize your sales team, you will hopefully keep their over-exuberance into being simply good-hearted as well.

Join me tomorrow when I consider Kanga, Roo and the Compliance Ombudsman.

Categories
Popcorn and Compliance

Schindler’s List

In this edition of Popcorn and Compliance, Richard Lummis and Tom Fox review the Best Picture-winning movie Schindler’s List. Highlights include:

  • Movie Storyline
  • How did it make you feel?
  • Leadership Lessons
  • Ethical Lessons
  • Servant Leadership
  • Final Thoughts on the Banality of Evil
  • Shoah and Schindler’s list

Resources

10 Leadership Lessons from Schindler’s List

Oskar Schindler-a Sheep in Wolf’s Clothing

Evaluating Ethics and Leadership in Schindler’s List

Ethics on Film: A Discussion of Schindler’s List

Categories
Corruption, Crime and Compliance

Episode 240 – The CCO’s Role in an Effective Compliance Program

I have been — and continue to be– hyper-focused on the proper role and responsibilities of Chief Compliance Officers. Not that I see any cause for alarm, but it is easy to lose focus in the sea of so-called hot issues — ESG, Diversity, Climate Change, Threats to Democracy, Cybersecurity and Data Privacy, each of which is an important component and focus for organizations. All of these issues intersect, are interdependent and should be addressed through organizational commitment. But I want to take a step back and return to an issue of importance — the proper role of CCOs. To do so, we need to remind everyone about basic requirements, lessons learned and ways forward to meet the fast-changing times. CCOs have to maintain and then advance their positions. In my view, given the interdependence of all the important issues mentioned above, the role of the CCO has become even more critical. In this episode, Michael Volkov reviews the standards applicable to the CCOs function in an effective compliance program.

Categories
Creativity and Compliance

Is It OK to Laugh at Work?

Where does creativity fit into compliance? In more places than you think. Problem-solving, accountability, communication, and connection – they all take creativity. Join Tom Fox and Ronnie Feldman on Creativity and Compliance, part of the award-winning Compliance Podcast Network. In this episode, Tom and Ronnie continue their shorts series on provocative statements on compliance training and communications, followed by discussion. In this episode, Ronnie riffs on the question is it OK to laugh at work? Highlights include:

o   Common excuses for not doing things creatively.
§  we’re a conservative company
§  we take the issues very seriously
§  it doesn’t fit our culture
§  my boss doesn’t have a sense of humor
§  we’re global
o   How to build a business case because entertainment and learning is more effective.
§  emotional connections
§  memory and recall
§  stands out in a noisy environment
§  It open people up
§  It helps increase airtime and exposure
o   The Fun Theory
o   Other examples in life

Resources:

Ronnie Feldman (LinkedIn)
Learnings & Entertainments (LinkedIn)
Ronnie Feldman (Twitter)

Learnings & Entertainments (Website)

60-Second Communication & Awareness Shorts – A variety of short, customizable, quick-hitter “commercials” including songs & jingles, video shorts, newsletter graphics & Gifs, and more. Promote integrity, compliance, the Code, the helpline and the E&C team as helpful advisors and coaches.

Workplace Tonight Show! Micro-learning – a library of 1-10-minute trainings and communications wrapped in the style of a late-night variety show, that explains corporate risk topics and why employees should care.

Custom Live & Digital Programing – We’ll develop programming that fits your culture and balances the seriousness of the subject matter with a more engaging delivery.

Tales from the Hotline – check out some samples.

Categories
Great Women in Compliance

Archana Shastri-Isn’t She Lovely

Welcome to the Great Women in Compliance Podcast, co-hosted by Lisa Fine and Mary Shirley.

Mary met Archana Shastri on her first day of work as Legal and Compliance Counsel at Tata Communications in Singapore in 2010.  The two were peers and became fast friends, bonding quickly as two of the quieter colleagues and, in fact, the only two Compliance colleagues in the Singapore headquarters.

 Archana, though now a Singaporean citizen, originally hails from India, and Mary asked Archana about some of the country’s cultural characteristics that might be of interest to Compliance Officers.  Archana also generally shares an update on the Asia Pacific region and comments on levels of activity from some of the local Compliance regulators and authorities.

 Mary asked Archana what she would like European and US-headquartered companies to know about the Asia Pacific region – Mary wholeheartedly stands behind Archana’s points on this one!

 Archana also details what it was like to study for her Master’s Degree in Anti-Corruption studies, a course based in Vienna.

 Archana wraps up the episode with some general commentary on the state and development of data privacy law in the Asia Pacific region.

 Are you planning on heading to the SCCE CEI in Phoenix in October?  Check out Lisa and Mary’s speaking sessions on the agenda and sign up!  We invite you to say hello and introduce yourself during the conference – it’s going to be a great time.

The Great Women in Compliance Podcast is on the Compliance Podcast Network with a selection of other Compliance-related offerings to listen to.  If you enjoy this episode, please rate it on your preferred podcast player to help other like-minded Ethics and Compliance professionals find it.  You can also find the GWIC podcast on Corporate Compliance Insights, where Lisa and Mary have a landing page with additional information about them and the podcast’s story.  Corporate Compliance Insights is a much-appreciated sponsor and supporter of GWIC, including affiliate organization CCI Press publishing the related book, “Sending the Elevator Back Down, What We’ve Learned from Great Women in Compliance” (CCI Press, 2020).

You can subscribe to the Great Women in Compliance podcast on any podcast player by searching for it, and we welcome new subscribers to our podcast.

Join the Great Women in Compliance community on LinkedIn here.

Categories
The Compliance Life

Joe Burke-Looking Down the Road for Compliance

The Compliance Life details the journey to and in the role of a Chief Compliance Officer. How does one come to sit in the CCO chair? What are some of the skills a CCO needs to success navigate the compliance waters in any company? What are some of the top challenges CCOs have faced and how did they meet them? These questions and many others will be explored in this new podcast series. Over four episodes each month on The Compliance Life, I visit with one current or former CCO to explore their journey to the CCO chair. This month, my guest is Joe Burke, most recently the Chief Ethics & Compliance Officer and Employment Counsel, Quest Software Inc.

In this concluding episode, Burke looks down the road for compliance in the following areas. Data privacy and trade compliance take center stage. How the new ownership model provided by Private Equity provides challenges and opportunities. The long, slow march to ethics and tone.

How do we inspire through influence through the teaching of compliance?

Resources

Joe Burke LinkedIn Profile

Categories
Innovation in Compliance

Ethisphere’s The Sphere with Erica Salmon Byrne

 

Erica Salmon Byrne is the President of Ethisphere and Chair of the Business Ethics Leadership Alliance. Ethisphere is a company that believes that companies that focus on building a sustainable business will outperform their peers that do not. Tom Fox welcomes her to this week’s show to talk about Ethisphere’s innovative new service called The Sphere. 

 

 

What is The Sphere?

Tom asks Erica to describe The Sphere and why she is so excited about the launch. For more than 15 years, Ethisphere has been collecting data on the programmatic practices of the world’s most ethical companies through their questionnaire, called the Ethics Quotient, Erica explains. They realized a demand for solid benchmarking within the compliance space, and decided to democratize their data access. This was the birth of The Sphere – a subscription-based service that allows you to select the topic you are interested in getting data on and gain access to a multitude of resources. 

 

Peer Data: A Powerful Tool

Tom asks Erica what makes peer data so important and powerful for a CCO. Whenever you’re going to make a business proposition, she replies, the first question you will be asked is ‘What are other people doing?’. Businesses want to compare their practices and progress to their peers’. This is to avoid being dubbed “a weak antelope” – you don’t necessarily want to be ahead of the pack, you just want to ensure that you have a functioning practice compared to your competitors. So how to determine you’re in that comfortable middle position of the pack? The answer is data analysis. When you present the relevant data to your CFO or compliance team, they tend to believe in your leadership and vision more.

 

Resources

Erica Salmon Byrne | LinkedIn | Twitter

Ethisphere | The Sphere

 

Categories
Blog

Biotronik Anti-Kickback Enforcement Action: Bribery Schemes and Lessons Learned

Today we conclude our series on a Federal Anti-Kickback enforcement action which was announced last week, involving the Oregon based medical device manufacturer Biotronik Inc. (Biotronik). Today, I want to consider the corruption schemes and the lessons learned for the compliance professional. As stated in the Settlement Agreement, Biotronik “knowingly caused the submission of false claims for payment to federal healthcare programs by providing remuneration to physicians to induce them to use Biotronik’s CRM devices in violation of the Anti-Kickback Statute, 42 U.S.C. § 1320a-7b(b).”

I. The Bribery Schemes

 a. Abuse of Training Programs

The Settlement Agreement alleges “Biotronik knowingly paid excessive payments to physicians with a purpose of inducing and rewarding their use of Biotronik’s pacemakers, defibrillators, and other cardiac devices. One of ways the company did so was through “its new employee training program (“Training Program”) by knowingly paying some of its physician customers (“Training Physicians”) to provide excessive employee trainings.” Under this scheme, the Training Physicians were to be paid a fixed fee of approximately $400.00 each time a Biotronik employee trainee received training during one of the Training Physician’s CRM implant procedures. For instance, under the Training Program implant procedure, the “Training Physician was supposed to educate the employee trainee on Biotronik’s devices and teach how to assist a physician during an implant procedure.”

However, it was the sales team which set up these training programs. Biotronik’s compliance and training functions warned that “Biotronik’s salespeople had too much influence in the selection of Training Physicians, that the Training program and resulting payments were being over- utilized, and that the goal of educating Biotronik employees could be achieved without paying Training Physicians.” However, “Biotronik permitted trainees to attend an excessive number of training procedures for which Training Physicians received payment from Biotronik without first conducting an adequate assessment of the trainee’s need for additional training.”

To further line the pockets of the Training Physicians, “salespeople, including managers, intentionally prevented otherwise qualified trainees from successfully completing the Training Program, not because they needed additional training, but rather as a means of ensuring that the trainee could attend more trainings, thereby purportedly justifying additional payments to Training Physicians.” Biotronik also knowingly paid Training Physicians for some trainings that either never occurred or was of little or no value to trainees. This included paying one “Training Physician for certain trainings for which there was no trainee physically present to observe the implant procedure.”

b.  Lavish Entertainment

The Settlement Agreement also alleged that “Biotronik knowingly paid for lavish meals, entertainment, and travel for certain physicians who are known to Biotronik and the United States (hereinafter the “Subject Physicians”) with a purpose of inducing and rewarding their use of Biotronik’s pacemakers, defibrillators, and other cardiac devices.” The company “did not require sign in sheets for lavish meals with physicians and did not use adequate methods to verify the number or identity of attendees or to confirm whether the meals were for a legitimate business purpose.”

This led to  some Biotronik employees falsifying “receipts and participant lists, making it possible to exceed the company’s compliance spending limit per attendee.” These meals and outings often included little or no legitimate business discussion. There was also the amount of the entertainment expense, which included “winery tours, annual office holiday parties, and lavish meals with certain Subject Physicians and their guests at high-end restaurants.” Yet another example of spending far too much on entertainment was “one Subject Physician’s international business class airfare and honoraria in the thousands of dollars for a short, 30-minute talk at an international conference.”

II. Biotronik Remediation

No doubt one of the reasons Biotronik did receive the settlement amount was that, at some point, it recognized the issues and instituted remediation. With the training programs “beginning in 2017, Biotronik added new compliance measures and oversight of the Training Program, limited the number of Training Program events, and reduced payments made in connection with such Training Program events.” In April 2021, Biotronik hired a new Vice President of Compliance and was able to get the lavish entertainment under control by adding “new compliance measures related to the provision of meals and travel to healthcare providers which provided additional employee training, imposed new restrictions, and improved oversight to identify and prevent meal and travel policy violations.”

III. Lessons Learned

There are multiple lessons here for the compliance professional outside the laws under which Biotronik ran afoul. Perhaps the clearest and foremost is that compliance not only needs visibility into areas of risk about also some modicum of control. In the area of Physician Training, the Settlement Agreement specifically noted that the Biotronik compliance function “warned that Biotronik’s salespeople had too much influence in the selection of Training Physicians, that the Training program and resulting payments were being over-utilized, and that the goal of educating Biotronik employees could be achieved without paying Training Physicians.” Here a control should have been put in place which required compliance approval before payments and reimbursements were made for the training. This is similar to a compliance oversight and control of expenses paid or reimbursed to foreign government officials in a Foreign Corrupt Practices Act (FCPA) compliance program.

Interestingly, the Department of Justice (DOJ) also discussed a more nuanced approach to determining if the Physician’s Training is both initially warranted and then continues to be warranted. This is ongoing monitoring. Obviously for Biotronik, one of their risks was when the company paid for training provided by doctors who could also prescribe the company’s products and services. The risk to the company is similar to the risk of an internationally focused company doing business with foreign governments or state-owned enterprises, under the FCPA. If you are paying out monies for training and that puts you in a high-risk category, you need to make sure those receiving the training are required to receive it or even need it.

Under the lavish spending on entertainment and travel, the same type of analysis can apply. The key is both “reasonable spending and business purpose.” The amount spent must be reasonable for the time, locale and participants. There should also be an articulated business purpose for the dinner or other event.

Under the FCPA, there is no threshold that a Company can establish a value for business entertainment. However, I believe there are clear guidelines which should be incorporated into your business expenditure policy, which should include the following:

  • A reasonable balance must exist for bona fide business entertainment during an official business trip.
  • All business entertainment expenses must be reasonable.
  • The business entertainment expense must be commensurate with local custom and practice.
  • The business entertainment expense must avoid the appearance of impropriety.
  • The business entertainment expense must be supported by appropriate documentation and properly recorded on the company’s book and records.

The incorporation of these concepts into a compliance policy is a good first step towards preventing potential violations from arising, but it must be emphasized that they are only a first step. There must be procedures to implement these policies. At a minimum, you must require a business justification from the business representative requesting to provide the gift or business entertainment. Next it should be reviewed and approved by a front-line compliance professional. Then, depending on the amount and nature of the request, it may need Chief Compliance Officer (CCO) approval. Finally, if there is a Compliance Committee it should go to that Committee for a final check to make sure everything is in order.

These guidelines must be coupled with active training of all personnel, not only on a company’s compliance policy, but also on the corporate and individual consequences for violation of the policy. Lastly, it is imperative that all such business entertainment be properly recorded, as required by the books and records component of the FCPA.

And, as always, do not forget the gut check test.