Categories
Great Women in Compliance

A Non-Linear Compliance Life with Amy Landry

Welcome to the Great Women in Compliance Podcast, co-hosted by Lisa Fine and Mary Shirley.

In today’s episode, Lisa talks to Amy Landry, who is one of the original GWICs, and a part of the podcast community since Day 1.  Amy is an External Oversight and Risk Analyst for Vaya Health, and has experience in ethics, compliance and privacy.  She is also someone who has a non-linear career.

Amy spent a lot of her career working with E&C vendors, and when her job was impacted during COVID, she decided that she wanted to move to the in-house side.  She shares how she made that decision, and what steps she took to grow her knowledge base.

Amy is also known for how she has built a great network, and she  has a great network and she talks about how she built and grew it by starting a blog when she was looking for her in-house role and about her experience looking for a job during the pandemic.

We also discuss the intersection of DEI and ethics and compliance, and Amy provides some of the insight she gained as part of the University of South Florida DEI certification program.

The Great Women in Compliance Podcast is on the Compliance Podcast Network with a selection of other Compliance related offerings to listen in to.  If you are enjoying this episode, please rate it on your preferred podcast player to help other likeminded Ethics and Compliance professionals find it.  You can also find the GWIC podcast on Corporate Compliance Insights where Lisa and Mary have a landing page with additional information about them and the story of the podcast.  Corporate Compliance Insights is a much appreciated sponsor and supporter of GWIC, including affiliate organization CCI Press publishing the related book; “Sending the Elevator Back Down, What We’ve Learned from Great Women in Compliance” (CCI Press, 2020).

You can subscribe to the Great Women in Compliance podcast on any podcast player by searching for it and we welcome new subscribers to our podcast.

Join the Great Women in Compliance community on LinkedIn here.

Categories
Blog

Compliance Lessons from a Fraudulent Unicorn

With a name like HeadSpin Inc., you would probably expect nothing less than what has transpired over the past few months with the former Silicon Valley darling and unicorn. According to a Securities and Exchange Commission (SEC) Press Release, in August 2021, the SEC sued Manish Lachwani, the company’s former Chief Executive Officer (CEO), stating he “engaged in a fraudulent scheme to propel HeadSpin’s valuation to over $1 billion by falsely inflating the company’s key financial metrics and doctoring its internal sales records.” Lachwani, “controlled all important aspects of HeadSpin’s financials and sales operations, significantly inflated the value of numerous customer deals and fraudulently treated potential deal amounts that he had discussed with customers as if they were guaranteed future payments.” He created fake invoices and altered genuine invoices to make it appear as though customers had been billed higher amounts.
Lesson No. 1 – (with a nod to Elizabeth Holmes) Don’t Be a Fraudulent Unicorn
All of this was done so Lachwani could garner additional investor monies through Series B and Series C funding rounds which would eventually drive the company’s value over the $1 billion mark so it could obtain magical unicorn status. Lachwani is alleged to have enriched himself by selling $2.5 million of his HeadSpin shares in a fundraising round during which he made misrepresentations to an existing HeadSpin investor. All of this brought the attention of the SEC.
Lesson No. 2 – The Most Important Internal Control is Segregation of Duties
 How could Lachwani get away with such shenanigans in an entity allegedly worth over $1 billion? In addition to lying, cheating, creating fraudulent invoices and other forms of creative financing, he abrogated one of the most basic internal controls in compliance (and finance) – segregation of duties (SODs). According to the SEC Complaint (Lachwani Complaint), “Lachwani was able to carry out his fraudulent scheme for years because he controlled and managed all the key aspects of HeadSpin’s financials and sales operations, and he kept HeadSpin employees in those different departments isolated from each other. For instance, virtually all the information provided to HeadSpin’s bookkeeper, including the supporting documentation for claimed revenue amounts, flowed through Lachwani.”
The Lachwani Complaint specifically noted, “Lachwani dictated the inflated revenue numbers each quarter to HeadSpin’s bookkeeper, who recorded those numbers in the company’s financial statements. He frequently sent the numbers without supporting documentation (like contracts and invoices) notwithstanding the bookkeeper’s regular requests for such backup, and he sometimes sent her fake or altered invoices that he had created, including the three fictional invoices related to Customer 2 and a doctored invoice related to Customer 1.”
Lesson No. 3 – Returning the Money to Those Harmed is Very Significant
 All of this played out last week when Lachwani’s former employer HeadSpin settled a SEC enforcement action via a Complaint (HeadSpin Compliant). What relief did the SEC receive? (It is awaiting Court approval.) The SEC asked for “an order permanently enjoining Defendant from directly or indirectly violating Section 10(b) of the Exchange Act”. There was no request for monetary fine, penalty or profit disgorgement. How did HeadSpin achieve this notable goal? Through its remediation efforts.
The two critical remedial steps were to get rid of the corrupt (now former) CEO Lachwani and to repay investors from the Series B and Series C funding rounds. The HeadSpin Complaint stated, “HeadSpin revised its valuation from approximately $1.1 billion down to approximately $300 million. The company also returned approximately 70% of principal to investors in the Series B and C funding rounds through a recapitalization process. The company further offered to return the remaining funds in the form of promissory notes with one percent interest. Approximately 31 investors chose to retain their HeadSpin stock instead of exchanging for promissory notes.”
This is obviously a step more than profit disgorgement. Here the money was returned to those who invested based upon the fraudulent misrepresentations. Additionally, HeadSpin offered to return money to additional investors beyond the Series B and Series C investors.
Lesson No. 4 – Structural Remedial Measures are Critical
Another set of remedial steps were generally described in the SEC Press Release announcing the HeadSpin resolution. The Press Release note, “HeadSpin’s remedial actions also included hiring new senior management, expanding its board, and instituting processes and procedures designed to ensure transparency and accuracy of deal reporting and associated revenues.” This was phrased slightly differently by HeadSpin, who said in their Press Release, “Upon learning of the alleged actions approximately two years ago, the Company immediately replaced its CEO, strengthened its leadership team, appointed an external auditor and implemented numerous financial and internal controls and corporate governance practices.”
What remediation did HeadSpin engage in which persuaded the SEC not to ask for financial penalties? There are several key actions every compliance professional should study.

  1. The Board convened a special committee of independent directors to lead an investigation.
  2. The Board (through its investigation) identified the CEO as the person responsible for the illegal conduct and terminated his employment.
  3. Additionally, the Board removed key senior management, here the Chief Operating Officer (COO), General Counsel (GC) and Controller who, although not responsible for or a part of the illegal conduct, failed to carry out their responsibilities to prevent such wrongdoing.
  4. After this clean sweep, the Board brought in a new management team and retained subject-matter experts to correct prior deficiencies.
  5. The Board added new board members with appropriate subject-matter expertise.
  6. HeadSpin implemented new internal controls and policies and procedures.

Lesson No. 5 – Creative Lawyerin’ in Remediation Can Pay Big Results
There is one more strand that should be considered from the HeadSpin matter. After the Lisa Monaco speech in October, SEC Chair Gary Gensler announced her remarks are “broadly consistent” with his own view of how to deal with corporate offenders. The HeadSpin enforcement action may offer guidance of how the SEC may implement Gensler’s remarks, through providing creative remedial measures, such as repaying those injured directly. The bottom line is that creative lawyerin’ in the form of aggressive remediation, may get you significant cooperation credit leading to a no fine or penalty resolution.
 

Categories
FCPA Compliance Report

Mike DeBernardis on Compliance Developments from Q4 2021


In this episode of the FCPA Compliance Report, I am joined by fan favorite Mike DeBernardis, partner at Hughes Hubbard. In this episode we look at compliance and temporal timeline developments from Q4 2021. Highlights of this podcast include:

  1. A deep dive into the Lisa Monaco speech, how it impacted the compliance temporal timeline whether it was a change or recalibration.
  2. Anti-Trust developments.
  3. The Biden Administration Strategy on Countering Corruption?
  4. Compliance in 2022 and moving forward.

Resources
Mike DeBernardis on HughesHubbard website.

Categories
Great Women in Compliance

Leaving a Lasting Impression with Wendy Wysong

Welcome to the Great Women in Compliance Podcast, co-hosted by Lisa Fine and Mary Shirley.

In 2011, Mary attended a conference in Singapore and listened to a learned lawyer speak about the FCPA.  Her name is Wendy Wysong and though they did not speak, Mary remembered Wendy’s name and many years later, connected with her on LinkedIn and ten years later asked Wendy to be on the Great Women in Compliance podcast.  Such was the lasting impression Wendy left from her talk that day.  Wendy is an American based in Hong Kong and shares some of her experiences of what work and life has been like during the pandemic.

 The two GWIC discuss the lessened guidance coming from US regulators in 2021 vs 2020, making adaptions to investigations during the pandemic with less ability to travel and how data privacy requirements have changed the way Wendy thinks about doing business.  This episode is snappy and right to the point with astute observations from Wendy packed into a relatively short timeframe – it’s perfect for filling a spare 20 minutes of your time or to keep you company while decluttering your drawers or vacuuming (iPods an essential for listening in while doing housework!).

The Great Women in Compliance Podcast is on the Compliance Podcast Network with a selection of other Compliance related offerings to listen in to.  If you are enjoying this episode, please rate it on your preferred podcast player to help other likeminded Ethics and Compliance professionals find it.  You can also find the GWIC podcast on Corporate Compliance Insights where Lisa and Mary have a landing page with additional information about them and the story of the podcast.  Corporate Compliance Insights is a much appreciated sponsor and supporter of GWIC, including affiliate organization CCI Press publishing the related book; “Sending the Elevator Back Down, What We’ve Learned from Great Women in Compliance” (CCI Press, 2020).

You can subscribe to the Great Women in Compliance podcast on any podcast player by searching for it and we welcome new subscribers to our podcast.

Join the Great Women in Compliance community on LinkedIn here.

Categories
Blog

Compliance and a Human Rights Strategy: Part 2

Yesterday, I began a series considering how a Chief Compliance Officer (CCO) and corporate compliance function can help lead a company’s human rights initiatives against such scourges as human trafficking and modern slavery based upon a recent MIT Sloan Management Review article, entitled “Does Your Business Need a Human Rights Strategy?,by authors N. Craig Smith, Markus Scholz and Jane Williams. In this piece, they took a solid look at both the risk side of this equation as well developing a corporate strategy to deal with the issue. Yesterday we looked at a framework to assess the human rights issues your organization may face in doing business across the globe. Today, we consider how to use that assessment in crafting a human rights strategy.
Three Key Decisions
The authors believe there are three key decisions an organization must make to determine a strategy and then begin to execute on that strategy.
Decision 1: Exit, Voice, or Silence?
At the most basic level the initial decision a company must make is whether to get involved. The authors believe, “business leaders must decide whether the issue requires further attention and, possibly, action. Is it serious enough to warrant divesting operations and/or possibly leaving the country? If not, what other options are available?” The caution that this calculus is “not always straightforward, nor is flight always the most appropriate action: Pulling out of a country can not only seriously impact a business’s bottom line but also harm the communities in which it operates, such as by eliminating local jobs or ending prosocial initiatives the company has taken.” However, in the event that an organization “makes the choice to continue operating and to work to address systemic human rights abuses within its environment, it needs to develop a nuanced strategy and be very deliberate about how and with whom it interacts.”
Decision 2: A Collective or Individual Approach?
The authors believe that if a company “chooses to stay and take action, it must decide whether the issue is best addressed by the company individually or should be undertaken collectively with other organizations or stakeholders.” At times such an individual approach can be effective if the company is large enough to have influence and can act with expedience. Conversely, smaller organizations may team up with other companies or even other stakeholders.
For this latter situation, the authors pointed to “the reaction of companies in the garment sector after the 2012 Rana Plaza tragedy in Bangladesh offers an example of collective action… Companies in the sector worked together to introduce the Accord on Fire and Building Safety in Bangladesh, an independent, legally binding agreement formed among global brands, retailers, and trade unions. Since the accord’s creation, engineers have inspected more than 2,000 garment factories, addressed more than 150,000 safety hazards, and helped set up safety training programs that have educated more than 1.4 million workers in proper workplace safety practices.”
Decision 3: Which Actions and Tactics Should Be Chosen?
Next is the move into execution. Should an organization “take direct action to stop human rights violations or whether more can be done by indirectly influencing the institutional settings in which they operate.” In the Rani Plaza response, the indirect strategy proved effective but “if ready-made garment brands had become aware that a particular factory presented an extreme and urgent threat to life — they may have instead chosen to take direct action, such as putting pressure on politicians or legal enforcement agencies to close or force repairs to the building.”
Tactics
The next set of decisions is around tactics. Should they be direct or indirect? In the direct tactics camp, the authors provide three examples. (1) Companies can provide information about human rights abuses. (2) Organizations can decide whom to provide financial aid to in the fight for human rights. (3) Businesses can engage in certain activities or decline to participate in commercial events. Under indirect tactics the authors also list three examples, including: (a) Companies can work to strengthen and otherwise support NGO or other similar organizations fighting human rights abuses. (b) Businesses can sign up for international initiatives such the UN Compact on climate change or NGO efforts to fight human trafficking and modern slavery, such as put forward by the Global Fund to End Modern Slavery. (c) Organizations can work to develop, solely or in conjunction with others “new standards that supplement hard law. By acting collectively or alongside other multistakeholder initiatives, organizations can individually create rules of the game that define guardrails for corporate behavior.”
However sometimes, even with the most robust risk analysis and a defined strategy, a company makes the decision it must leave. As the authors noted, “There may be times when, in balancing the tension between the moral and business imperative, leaders feel that the best — or only — choice is for a company to leave, be it a problematic supply chain, a market where its products are implicated in human rights abuses, or even an entire country. The decision then will be whether to take the high road and exit with fanfare to publicly signal.” This happened with many energy companies and Venezuela in the last decade. Just last week, NPR reported, “Total Energies and Chevron, two of the world’s largest energy companies, said Friday they were stopping all operations in Myanmar, citing rampant human rights abuses and deteriorating rule of law since the country’s military overthrew the elected government in February.”
The bottom line is that doing nothing is no longer an option. As human trafficking and modern slavery become more publicized, international companies must work to assess their risks and manage those risks through a human rights strategy. The authors end by stating, “Companies are increasingly expected to assume political responsibilities. Doing nothing when there is an arsenal of options available might easily be interpreted as — at minimum — silent complicity with human rights violations.” Once again compliance needs to lead the way for every business on this issue.

Categories
The Compliance Life

Valerie Charles – CCOs and the Compliance Profession Down the Road


The Compliance Life details the journey to and in the role of a Chief Compliance Officer. How does one come to sit in the CCO chair? What are some of the skills a CCO needs to success navigate the compliance waters in any company? What are some of the top challenges CCOs have faced and how did they meet them? These questions and many others will be explored in this new podcast series. Over four episodes each month on The Compliance Life, I visit with one current or former CCO to explore their journey to the CCO chair. This month, my guest is Valerie Charles, partner at StoneTurn. We discuss Valerie’s journey to the CCO chair, then to a ComTech start up, to her current role at StoneTurn and look down the road at where ComTech and compliance will be in 2025 and beyond.
In this concluding episode, Valerie looks down the road at the compliance function. She believes there will be increased use of ComTech by compliance functions. Moreover, CCOs and compliance professionals will need learn how to use data and become more comfortable in leveraging data for insights to help prevent, detect and remediate corporate conduct. The corporate compliance function will become even more important in the corporate setting as it will bring together various corporate functions such as legal, HR and IT into collaborative actions.
Resources
Valerie Charles LinkedIn Profile
Valerie Charles at StoneTurn

Categories
Blog

Compliance and a Human Rights Strategy: Part 1

The compliance intersection with Environmental, Social, and Corporate Governance (ESG) continues to drive many initiatives in both the ESG realm as well as compliance. One of the key areas is in found in corporate Supply Chain, particularly around human rights, human trafficking and modern slavery. The Uyghur Forced Labor Prevention Act puts additional pressure on companies who do business with China to be able to affirmatively show no goods or services were produced through forced labor involving the Chinese Uyghur population, much to the consternation of the Chinese government. Most compliance professionals depend on language in supplier contracts which certify that no products are the result of slave labor. A New York Times (NYT) piece, entitled U.S. Effort to Combat Forced Labor Targets Corporate China Ties, reported, “One of the biggest hurdles for U.S. businesses is determining whether their products touched Xinjiang at any point in the supply chain. Many companies complain that beyond their direct suppliers, they lack the leverage to demand information from the Chinese firms that manufacture raw materials and parts.” However, that most basic approach is no longer adequate.
In a recent Sloan Management Review article, entitled “Does Your Business Need a Human Rights Strategy?,authors N. Craig Smith, Markus Scholz and Jane Williams took a solid look at both the risk side of this equation as well developing a corporate strategy to deal with the issue. Over the next couple of blog posts, I will be exploring the article in the context of the compliance professional and a corporate ESG strategy.
While the Chinese response may be painful, it will frankly pale next to the response from the US government and the buying public. With so much increased attention to human rights, the authors believe “businesses that turn a blind eye to violations that occur in their sphere of operations face the risk of being exposed as morally complicit as well as vulnerable to legal action and reputational harm. That’s why it’s critical for companies to have a human rights strategy and proactively consider when and how to take the action needed to fulfill their moral obligations; meet shareholder, customer, and employee expectations; and keep other stakeholders satisfied.”
Three Categories of Human Rights Violations
The authors believe there are three broad categories of human rights issues. They are:

  1. Abuse in the way a company’s products or services are made or delivered. This includes abuse by suppliers or contractors or within a company’s own operations. Although most western companies believe this is not a problem for them, a UK investigation found a slave labor operation within the country itself, which was supplying food products to such UK retailors as Tesco, Sainsbury’s and others.
  2. Abuse in the way a company’s products or services are used. This includes companies that find themselves complicit when customers employ their products or services to do so — if not legally complicit, then at least guilty in the court of public opinion. The obvious example here are the digital surveillance systems sold to Chinese security agencies and used to implement a mass surveillance program against minority groups while creating an overall surveillance state within the country.
  3. Abuse by regimes where the company operates. This may be one of the trickiest to navigate. Obviously working with governments is an important business component but even working with the US government can be trick as McKinsey found out when it contracted with Customs and Borders and “Media reports suggested that the consultancy had been redirected to assist in former President Donald Trump’s clampdown on illegal immigration and was responsible for money-saving recommendations that included cuts in funding for food, medical care, and the supervision of detainees.”

Obligations to Address Human Rights
 Both compliance and ESG have driven the discussion on the role of the corporation in dealing with this issue. The Business Roundtable’s Statement on the Purpose of a Corporation also pointed in this direction. Companies are now being called to engage as responsible corporate citizens in a wide variety of areas, including human rights. The authors see four reasons why a company should consider human rights a priority. (1) Moral reasons. The fight against human trafficking and slavery are moral duties that require not simply a call for action but real action. Inaction is no longer acceptable. (2) Legal considerations. Together with the US, multiple  countries have enacted laws that require organizations to act in ways that protect and promote human rights. (3) Soft laws. Standards may come into play, such as the United Nations’ Guiding Principles on Business and Human Rights, and are becoming more important. (4) Reputation. With social media, amplifying human trafficking and other human rights issues which may have been more inconspicuous in the past, it is making businesses increasingly vulnerable to being accused of complicity.
Corporate Exposure

The authors have developed an approach which identifies key factors driving ““corporate human rights strategies and used them to create an exposure” scale. This tool captures both the moral intensity and the potential influence of a company in a specific situation.” Understanding where your organization lies on such a scale can assist a Chief Compliance Officer (CCO) or compliance professional to not only lead a discussion but more importantly help to formulate a corporate response. The twin axis are moral intensity and influence. Moral intensity “captures the degree to which people see a situation as unethical and demanding of action.” Some of the questions you need to consider include what is the magnitude of consequences? The extent of the harm likely to result? What is the social consensus, the extent to which people agree on the moral rights and wrongs of an issue? What is the probability of effect and how likely is harm to happen? What is the “Temporal immediacy. How urgent is the issue? Is fast action required to prevent harm?” How near is your organization to the issue and what part of your stakeholder communities will be affected by the issue?
 
The authors believe that determining influence is even trickier. They believe a nuanced approach should be used when assessing an organization’s influence. Their approach includes reviewing institutional factors, then understand “What are the formal and informal rules and values that shape the environment, including willingness — or pressure — to conform?” Next look at some industry specifics to help understand  “How is influence affected by factors such as the complexity of supply chains, the geographic location of where vital products are sourced, or the degree of concentration or fragmentation of the industry?” From there review your resources to help understand “What can the organization bring to bear to influence the issue?” Such a review would look at both “tangible resources, such as funds, inventory, land, and buildings;” as well as “intangible ones, such as networks, skills, and knowledge.” Finally, consider embeddedness, which is “How closely and on how many levels is the company entangled with the perpetrators of abuse?”
Tomorrow we will look at how you can create a corporate human rights strategy for your corporate compliance regime or ESG program based upon the authors’ model.

Categories
FCPA Compliance Report

Andrew Neblett and Brian Beeghly Join Ethisphere

In this episode of the FCPA Compliance Report, I am joined by Andrew Neblett and Brian Beeghly, co-founders of Informed360 who recently joined forces with Ethisphere. Highlights of this podcast include:

  1. Tells us about Informed360 platform
  2. Why did you decide to join Ethisphere?
  3. How will the Informed360 solution be integrated into the Ethisphere offering(s)?
  4. As a combined company how will this improve compliance offerings?
  5. How will you be able to take data and provide insights for enhancement of compliance programs?
  6. Their roles at Ethisphere moving forward.

Resources

Check out the upcoming webinar Turning Ethics and Compliance Insights into Action. Register at Ethisphere.com/events

Categories
Daily Compliance News

January 24, 2022 the Burnout in Compliance Edition


In today’s edition of Daily Compliance News:

  • Trouble at Peleton. (WaPo)
  • Bank compliance professionals facing burnout. (WSJ)
  • Family trouble in the Magic Kingdom. (NYT)
  • Congress to probe role of BODs in energy cos misinformation campaigns. (Retuers)
Categories
This Week in FCPA

Episode 287 – the Activision Blizzard Sold edition


As both of their teams are unceremoniously knocked out of the playoffs, Tom and Jay are back looking at some of the week’s top compliance and ethics stories this week in the Activision Blizzard Sold edition.
Stories

  1. Activision Blizzard was sold to Microsoft. Check out articles on how the NYT happened, the parameters of the deal in the  WSJ, the compliance mess in Bloomberg, and legal issues in  Reuters.
  2. Did the pandemic undo corruption risk models? Dick Cassin explores in the FCPA Blog.
  3. KPMG spanked yet again in the UK. Jaclyn Jaeger in Compliance Week (sub req’d).
  4. Person of the Year in Compliance? ESG. Mike Volkov in Corruption Crime and Compliance.   
  5. Is Abby Normal next? Banks using behavioral science. Vera Cherepanova in FCPA Blog.
  6. Businesses and Strategy on Countering Corruption. Sara Paul, Andrea Gordon, and Dane Sowers in the CCI.  
  7. Climate change compliance. Jeff Kaplan in Conflicts of Interest Blog.
  8. Trust has its moment. Stewart Levine in Forbes.com
  9. Institutional investors on ESG voting. Lawrence Heim in PracticalESG.
  10. The virtual Board Room. Jeffrey Karpf and Fernando Martinez in Compliance and Enforcement

Podcasts and More

  1. Tom and Matt Kelly conclude a 2-part podcast series on issues they are following in 2022. On Compliance into the Weeds, Part 1 and Part 2
  2. In January on The Compliance Life, I visited Valerie Charles, a partner at StoneTurn. Val has one of the most interesting journeys in compliance. In Part 1, she discussed her academic background and early professional career. In Part 2, she discusses her move to ComTech. In Part 3, Valerie moves into the consulting world. 
  3. What is the intersection of Joel Coen’s Macbeth and organizational issues in compliance? Tom explores in a 4-part blog series on the FCPA Compliance and Ethics Blog
  4. CCI releases a new e-book from Tom, “FCPA 2021 Year in Review”. Available free from CCI.
  5. Trial of the Century-the Enron Trial. On Monday, January 4, Tom premiers a 5-part podcast series on the Enron Trial with Loren Steffy, who covered the trial for the Houston Chronicle. You can check out the preview here. It will be available on the Compliance Podcast Network, Megaphone, iTunes, and other top podcast platforms. 
  6. Check out 31 Days to a More Effective Compliance Program returns, which runs from January 1 to January 31. Available on the Compliance Podcast NetworkMegaphoneiTunes, and other top podcast platforms. 

 Tom Fox is the Voice of Compliance and can be reached at tfox@tfoxlaw.com. Jay Rosen is Mr. Monitor and can be reached at jrosen@affiliatedmonitors.com.