Categories
FCPA Compliance Report

FCPA Compliance Report – Virna Di Palma on The Evolution of Third-Party Risk Management and the Role of AI

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom Fox welcomes Virna di Palma, Head of Global Content and Brand at Ethixbase360.

Virna offers insights into her extensive background in third-party risk management, with a focus on FCPA compliance and the evolution of due diligence. They discuss the ongoing importance of third-party risk management, recent shifts in FCPA enforcement, and the growing impact of new regulations on corporate compliance. Virna highlights the transformative role of automation and AI in enhancing compliance programs while emphasizing the need for human analysis. The conversation also addresses emerging issues, such as modern slavery and sustainability, and explores how organizations can optimize investments in risk management to drive business growth and resilience.

Key highlights:

  • Importance of Third-Party Risk Management
  • Impact of FCPA Enforcement Pause
  • Technological Advancements in Compliance
  • Human Rights and Modern Slavery
  • Future of Third-Party Risk Management

Resources:

Virna Di Palma on LinkedIn

Ethixbase360

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
ACI FCPA Conference 2025

ACI-FCPA Conference Speaker Preview Series – Ricardo Wagner de Araujo on Potential Trouble in your (Latin American) Supply Chain

In this episode of the ACI-FCPA and Global Anti-Corruption Conference Speaker Podcasts series, Ricardo Wagner de Araujo discusses his panel at the event, “Managing New Risks in Latin America: A Look at the Biggest Ways Cartels/TCOs Are Infiltrating Businesses and Supply Chains, and How Companies Are Responding.”

Some of the issues the panel will discuss are:

    • The changing risks in Latin America.
    • How TCOs and cartels exploit 3rd party relationships.
    • Tips for adapting your compliance programs in Latin America.

I hope you can join me at the ACI–FCPA Conference. This year’s event will take place on December 3-4 at the Gaylord National Resort & Convention Center in National Harbor, Maryland, near Washington, D.C. The lineup of this year’s event is simply first-rate, featuring some of the top FCPA professionals, white-collar attorneys, and compliance practitioners in the field.

The 2025 program is being completely redesigned to help your organization stay agile, responsive, and ahead of the curve. Expect a dynamic agenda shaped by real-world priorities, practical takeaways, and the most cutting-edge thinking in compliance—led by a faculty of global practitioners with boots on the ground, encountering the very risks that come across your desk.

Please join me at the event. For information on the event, click here. Listeners of this podcast will receive a discount by using the code D10-999-CPN26.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Final Thoughts on Pre-Acquisition Due Diligence in M&A

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we conclude our week-long series on pre-acquisition due diligence in M&A from the anti-bribery/anti-corruption perspective.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing Your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
Blog

Failure to Prevent Fraud Mastery: Enhancing Due Diligence, Training, and Improvement

We conclude our deep dive into the Economic Crime and Corporate Transparency Act 2023, which has elevated the expectations for senior leadership and boards across large organizations. Our guide in this journey has been the UK government, which has put out a document entitled “Economic Crime and Corporate Transparency Act 2023: Guidance to organisations on the offence of failure to prevent fraud.” (The Guidance) Today, we conclude with the final three sections on Due Diligence, Training, Ongoing Monitoring, and Continuous Improvement.

As compliance professionals prepare diligently for the upcoming implementation of the Failure to Prevent Fraud (FTPF) offense, it becomes imperative to understand and apply comprehensive fraud prevention measures effectively. Central to a robust anti-fraud framework are due diligence, training, monitoring, and review processes. Each of these areas must be executed diligently, proportionately, and tailored specifically to address the unique risks faced by an organization.

Due Diligence: Building Trust Through Vigilance

Due diligence is a cornerstone of an effective fraud prevention strategy. Organizations must apply meticulous and proportionate due diligence procedures to mitigate fraud risks associated with individuals or entities performing services on their behalf.

For organizations facing heightened fraud risks, standard due diligence might not suffice. Comprehensive screening, including the use of technology-driven third-party risk management tools and vetting checks, becomes vital. Contracts should explicitly state compliance obligations and consequences of non-compliance, while mergers and acquisitions must include rigorous assessments of criminal, regulatory, and tax backgrounds.

Moreover, ongoing due diligence is essential; periodic reviews and updates ensure that an organization remains alert to emerging risks or changes in the status of associated persons. Continuous monitoring can detect potential red flags that may arise post-engagement, such as sudden changes in financial stability, reputation issues, or new regulatory concerns. Additionally, organizations should ensure transparency in their due diligence processes, clearly documenting their methods and findings. This not only enhances accountability but also ensures readiness in demonstrating compliance to regulatory bodies or stakeholders during audits or investigations.

Organizations might also consider collaboration with external experts or industry peers to refine their due diligence methodologies, leveraging collective insights to strengthen their anti-fraud defenses. Regular training and awareness sessions about due diligence expectations can further embed vigilance into organizational culture, ensuring that all stakeholders understand and uphold their roles in fraud prevention.

Five Key Takeaways on Due Diligence:

  1. Leverage Technology: Use advanced screening tools and third-party risk management platforms to enhance due diligence effectiveness.
  2. Contract Clarity: Clearly articulate compliance obligations and termination clauses for fraud breaches within contracts.
  3. Monitor Employee Well-being: Regular monitoring to identify stressors or workload issues that might increase susceptibility to fraud.
  4. Mergers and Acquisitions Scrutiny: Conduct thorough fraud prevention assessments during acquisitions, integrating robust prevention measures post-acquisition.
  5. Dynamic Review: Keep due diligence processes proportionate, up-to-date, and responsive to evolving risks.

Training: Empowering Prevention Through Knowledge

Training is critical to embedding an anti-fraud culture within an organization. A clear and regular communication strategy ensures all associated persons fully understand and internalize the organization’s fraud prevention policies and procedures.

Proportionate training tailored to the specific risks of roles within the organization, especially high-risk positions, is essential. Training must detail the nature of the FTPF offense, the particular procedures required, and the clear protocols for whistleblowing. Continuous evaluation and updates ensure training remains practical and relevant, particularly as personnel change. Effective training should also encompass interactive and engaging methods such as workshops, simulations, and scenario-based exercises, which help employees understand the real-world implications of fraud and the critical importance of adhering to procedures.

Incorporating case studies of relevant fraud incidents can significantly enhance learning by illustrating practical examples and reinforcing key lessons. Organizations should also regularly evaluate the impact of training through assessments, quizzes, and feedback surveys, ensuring that employees retain the information and can effectively apply it in their roles. Integrating fraud prevention messages into routine communications, such as team meetings and newsletters, can further reinforce an anti-fraud mindset. Ultimately, a robust training program not only builds awareness but also empowers employees to identify and address potential fraud risks proactively.

Five Key Takeaways on Training:

  1. Risk-Based Training: Deliver bespoke training programs specifically targeted at roles identified as high risk.
  2. Integration with Existing Programs: Leverage and integrate fraud prevention messages into broader financial crime training initiatives.
  3. Effective Communication: Communicate internal policies, the importance of whistleblowing, and the procedures to follow.
  4. Regular Updates: Keep training modules current with evolving fraud risks, regulatory updates, and personnel changes.
  5. Monitoring Effectiveness: Regularly assess and monitor training efficacy through feedback and performance evaluations.

Monitoring and Review: Continuous Improvement and Adaptation

Monitoring and review constitute the continuous feedback loop critical to fraud prevention. Organizations must regularly assess and refine fraud detection systems and response protocols based on real-world performance and evolving risks.

Monitoring involves detecting fraud, conducting robust investigations, and assessing the effectiveness of preventative measures. Organizations should ensure that sophisticated data analytics and AI-driven detection tools are employed effectively. Investigations must be independent, well-resourced, fair, and transparent, with results communicated to stakeholders.

Review processes ensure organizations adapt and improve continuously. Regularly scheduled reviews, supplemented by event-driven assessments in response to incidents or significant changes in risk, underpin an agile and resilient fraud prevention strategy. Utilizing external feedback and industry-wide insights, organizations can benchmark their strategies and implement best practices.

Five Key Takeaways on Monitoring and Review:

  1. Regular and Responsive Reviews: Schedule regular evaluations, complemented by prompt reviews triggered by specific fraud incidents or risk changes.
  2. Data-Driven Detection: Invest in advanced data analytics and AI tools to proactively detect fraud and fraud attempts.
  3. Independent Investigations: Ensure fraud investigations are conducted independently and transparently, with clearly documented processes and outcomes.
  4. Continuous Adaptation: Maintain flexibility in fraud prevention measures, promptly adapting strategies based on review outcomes and industry developments.
  5. Sectoral Benchmarking: Collaborate and engage with external entities and industry peers to adopt best practices and maintain practical fraud prevention standards.

Concluding Thoughts

As the countdown to the FTPF offense go-live continues, compliance professionals are tasked with a critical responsibility: to ensure their organization’s preparedness through meticulous due diligence, targeted training, and robust monitoring and review practices. Each component is integral to creating an effective, proportionate, and responsive fraud prevention strategy. By embedding these practices into the organizational fabric, compliance professionals not only safeguard their organizations but also reinforce ethical standards, protecting both reputation and long-term sustainability.

Categories
Daily Compliance News

Daily Compliance News: July 22, 2025, The I-9 Hell Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings to you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • What is the cost of culture of silence at NASA? (WSJ)
  • Corruption tainting Milan skyline. (Bloomberg)
  • Companies stuck in ‘I-9 hell’ of paperwork. (FT)
  • Credit Suisse flagged Sanjeev Gupta for corruption, but the bank ignored it. (Bloomberg)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief here.

Categories
All Things Investigations

All Things Investigation – Due Diligence and Drama: A Deep Dive into Art World with Daniel Weiner

Welcome to the Hughes Hubbard Anti-Corruption & Internal Investigations Practice Group’s podcast, All Things Investigation. In this podcast, host Tom Fox is joined by Daniel Weiner to discuss a complex legal case involving a valuable Picasso painting.

Weiner is the Chair of Hughes Hubbard & Reed’s Litigation Department, Chair of the Complex Business Disputes practice, and a partner in the International & Domestic Arbitration and Intellectual Property Disputes groups. Daniel and Tom take a deep dive into the intricate details of how a series of fraudulent transactions led to a multimillion-dollar dispute over Picasso’s ‘Le Peintre. The podcast highlights the importance of thorough due diligence in the art world and examines the legal complexities involved in resolving such cases. As they unravel the story, they highlight the crucial role of investigations in preventing art fraud and safeguarding ownership rights.

Key highlights:

  • The Fascinating Picasso Case
  • The Fraud Unveiled
  • Legal Issues and Investigations
  • Discovery Disputes and Court Proceedings
  • Consulting and Due Diligence in Art Law

Resources:

Daniel Weiner

Hughes Hubbard & Reed website

HHR Client Alert: Firm Obtains Discovery Win in Dispute Over Sale of Pablo Picasso Painting

Categories
FCPA Compliance Report

Amanda Carty on a Due Diligence and Risk Management

In this episode of the Diligent Compliance Week 2025 Speaker Preview Podcasts series, Amanda Carty discusses her presentation at Compliance Week 2025, “Going Beyond Due Diligence in Risk Management.”

Some of the issues she will discuss:

  • Demonstrate measurable and quantifiable ROI
  • Build psychological safety that drives ethical decision-making and engagement.
  • Navigate matrix environments to expand the influence.
  • Use data to tell compelling compliance success stories
  • Partner with the C-suite to help them navigate disruptive changes, including deregulation and major economic geopolitical shifts.

I hope you can join us at Compliance Week’s 20th Anniversary National Conference. This year’s event will be held April 28-30 at The Mayflower Hotel, Autograph Collection, Washington, D.C. The lineup is first-rate, with some top ethics and compliance practitioners around.

Drop by the Diligent booth for some Compliance Podcast Network coffee to gain insights and make connections at the industry’s premier cross-industry national compliance event, offering knowledge-packed, accredited sessions and take-home advice from the most influential leaders in the compliance community. Back for its 20th year, compliance, ethics, legal, and audit professionals will gather safely face-to-face to benchmark best practices and gain the latest tactics and strategies to enhance their compliance programs.

Categories
Blog

The Bre-X Mining Scandal: Part 5 – A Guide for the 2024 Compliance Professional (Part 1)

As we close out this series on the Bre-X mining scandal, the lessons from this notorious case continue to resonate, especially for today’s compliance professionals. The fraud that led to the downfall of Bre-X and the ensuing financial catastrophe for countless investors serves as a stark reminder of the pivotal role compliance plays in maintaining the integrity of any business. This two-part conclusion will explore the critical takeaways for compliance professionals in 2024. In Part 1, I focus on due diligence, transparency, corporate governance, conflict of interest, and regulatory compliance.

The Importance of Rigorous Due Diligence

If Bre-X taught us anything, it is the value of relentless due diligence. In today’s fast-paced business environment, where misinformation can spread like wildfire and trust is fragile, compliance professionals must maintain an unwavering commitment to fact-checking and independent verification.

Verification of Claims. Compliance officers are the gatekeepers of corporate integrity. The Bre-X scandal is a textbook case of what happens when claims are accepted at face value without proper scrutiny. In 2024, ensuring that all claims—whether they pertain to financial projections, resource estimates, or technological capabilities—are rigorously verified by qualified third parties is more crucial than ever. This due diligence must extend beyond simple paper trails; it requires thorough, boots-on-the-ground verification.

Third-Party Validation. One of the core failures in the Bre-X case was the reliance on internal data, which went unchecked. Today’s compliance landscape demands an external layer of assurance. Relying solely on the company’s self-reported information can be perilous. Independent third-party audits, validation, and assessments are no longer optional; they prevent corporate fraud. External experts often see red flags insiders miss due to oversight or willful blindness.

Transparency and Accurate Reporting

Transparency is the lifeblood of compliance, and the Bre-X scandal illustrates what happens when companies stray from this fundamental principle. The fine line between optimism and misleading information can be blurry, but compliance officers must ensure this line is never crossed.

Clear and Honest Disclosure. Today’s compliance professionals must act as the arbiter of clear and accurate corporate disclosure. More is needed to provide minimal information that technically complies with regulations; companies must fully disclose material facts related to their performance, risks, and operational realities. Bre-X misled investors with rosy projections based on fraudulent data. Modern compliance teams must guard against the temptation to oversell the company’s prospects or downplay significant risks.

Avoiding Misleading Information. The Bre-X debacle warns about the dangers of making exaggerated or false claims to investors and stakeholders. In 2024, compliance professionals must adopt a zero-tolerance stance toward misleading information. This requires close collaboration with all departments, ensuring financial reports, press releases, and investor communications are fact-checked, realistic, and grounded in verifiable data. The role of compliance in safeguarding against exaggeration or outright deception cannot be overstated.

Strengthening Corporate Governance

One of the critical failures in the Bre-X case was weak corporate governance. As companies grow in complexity, ensuring robust oversight from the boardroom down is essential.

Effective Oversight. Boards of directors must not only be present; they must be actively engaged in the business. The Bre-X scandal exposed how passive oversight can contribute to unchecked fraud. Compliance professionals should ensure that board members, especially independent ones, are empowered to ask tough questions and hold management accountable. In 2024, compliance officers should push for regular, thorough reviews of corporate governance practices, ensuring that the board remains active in safeguarding the company’s integrity.

Separation of Duties. Another key lesson from Bre-X is the need for a clear separation of duties. The concentration of power in a few individuals, especially in processes like reporting geological results, led to unchecked manipulation. Modern compliance frameworks must ensure no single person holds too much sway over critical processes. In areas such as financial reporting or resource assessments, compliance professionals must establish checks and balances that prevent conflicts of interest and reduce the risk of fraud.

Understanding and Mitigating Conflict of Interest

Bre-X was rife with conflicts of interest that, had they been addressed, might have mitigated the extent of the damage. In 2024, compliance professionals must be vigilant in identifying and managing potential conflicts at all levels of the organization.

Identifying Conflicts. Conflicts of interest can undermine the integrity of any organization through personal financial gain, favoritism, or unaddressed personal relationships. Compliance officers must develop robust mechanisms for identifying and addressing conflicts before they escalate. In the Bre-X case, certain individuals stood to personally gain from inflated stock prices directly conflicting with their fiduciary duties. Modern-day compliance professionals must establish clear conflict-of-interest policies and ensure these are consistently enforced.

Establishing Clear Policies. It is not enough to identify conflicts; companies must have clear policies and procedures to manage them. This includes mandatory disclosures, regular audits, and a strong ethical culture encouraging employees to report potential conflicts. Employees should be trained to recognize conflicts of interest and be empowered to raise concerns without fear of retaliation. The Bre-X scandal reminds us that an unaddressed conflict of interest can lead to catastrophic outcomes for all stakeholders.

Enhanced Focus on Regulatory Compliance

Finally, the Bre-X scandal illustrates the importance of adhering to industry standards and anticipating regulatory changes. In the wake of Bre-X, Canada introduced NI 43-101, a set of strict guidelines for reporting mineral resources. The lesson here is that compliance professionals must stay current with regulations and be proactive in their approach.

Adhering to Industry Standards. In 2024, industry standards are constantly evolving. Whether environmental regulations, data privacy laws, or sector-specific standards like NI 43-101, compliance professionals must ensure that their organizations are always fully compliant. This requires staying informed about changes in the regulatory landscape and ensuring that the company’s internal practices are aligned with the latest requirements.

Proactive Compliance. Compliance officers should take a proactive approach rather than waiting for regulations to change. This includes monitoring industry trends, participating in industry working groups, and maintaining open lines of communication with regulators. Proactive compliance can prevent costly legal battles and protect the company’s reputation.

The Bre-X mining scandal remains a cautionary tale for compliance professionals, and the lessons learned from this case are more relevant than ever in 2024. By emphasizing rigorous due diligence, transparency, corporate governance, conflict of interest management, and proactive regulatory compliance, compliance officers can help safeguard their organizations against fraud and mismanagement that led to Bre-X’s downfall.

In Part 2 of this series, we will conclude this blog post by diving deeper into the evolving role of technology and how it has transformed the compliance landscape, offering new tools and challenges for today’s compliance professionals. Join us tomorrow.

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance – Episode 23 — The Sustainability Edition

What happens when two top compliance commentators get together? They talk about compliance, of course. Join Tom Fox and Kristy Grant-Hart in 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode! In this episode, Tom and Kristy take on a wide variety of compliance related topics.

In the ever-evolving world of regulatory compliance and risk management, challenges are constant, and strategies must be dynamic. Tom highlights the focus on the Tesla Board, celebrates the OECD at 25, bemoans New Zealand’s drop in the TI-CPI, reviews the HP acquisition of Autonomy and looks at the differences in Binance and FTX enforcement.  Kristy highlights the slave labor allegations, EU sustainability law, the ease of whistleblower restrictions, the EU and AI, and checks in on Florida Woman. Join Tom Fox and Kristy Grant-Hart as they delve deeper into these issues in this episode of the 2 Gurus Talk Compliance podcast.

Topics Discussed:

1.     Chinese Slave Labor Allegations Hold Up VW’s Audi, Porsche, and Bentley Vehicles in U.S. Ports (MotorTrend)

2.     EU Corporate Sustainability Due Diligence Law Most Likely Dead, For Now (Forbes)

3.     US Supreme Court’s UBS case makes it easier for whistleblowers to win suits (Reuters)

4.     How EU AI Act May Accelerate Compliance Regime for U.S. Enterprises (WSJ)

5.     The Tesla Board Chair is under scrutiny for oversight of the company.  (NYT)

6.     A tale of 2 corps: Binance and FTX. (Reuters)

7.     OECD at 25.  (The Hill)

8.     No DD, no problem as HP seeks $4bn from Mike Lynch.  (Bloomberg)

9.     New Zealand drops to No. 3 on TI-CPI. (The Conversation)

10.  Woman swipes $1.5 million and splurges on flights, Carnival cruises, Florida cops say (Yahoo)

Resources 

Kristy Grant-Hart on LinkedIn

Spark Consulting

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance – Episode 10 – Ethical Remote Workers Edition

What happens when two top compliance commentators get together? They talk compliance of course. Join Tom Fox and Kristy Grant-Hart in 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Tom and Kristy consider the possibility of an international anti-bribery court, challenges in enforcing judgments against countries without strong anti-corruption laws, and the United States’ unlikely participation. The European Commission issued an adequacy decision regarding data transfers between the US and EU, resolving a long-standing issue, but privacy advocate Max Schrems plans to challenge its validity. The importance of on-site due diligence, and the value of on-site audits and cybersecurity disclosure were also explored. The benefits of remote work, global anti-corruption efforts, AI safeguards, and the dangers of zero tolerance policies were covered as well. The conversation provided insights into various compliance-related topics.

Highlights Include

·      World ABC Court

·      No DOJ control on Cognizant investigation.

·      SEC adopts Cyber disclosure rules.

·      Fight against corruption in Ukraine.

·      Goldilocks Compliance.

·      Data Privacy Framework Program Launches New Website Enabling U.S. Companies to Participate in Cross-Border Data Transfers

·      Site Visits: Sometimes the Best Due Diligence is Done on Foot

·      New Data Reveals that Remote Workers are Likely More Ethical than their Office Counterparts.

·      White House Says Amazon, Google, Meta, Microsoft Agree to AI Safeguards

·      Man Steals Vehicle, Crashes it into Building during Search for WiFi Connection

 Resources 

  1. WSJ Risk and Compliance Journal
  2. FCPA Blog
  3. Radical Compliance
  4. Dept. Of Commerce Press Release
  5. WSJ
  6. Conflicts of Interest Blog
  7. GAB
  8. Fast Company
  9. Fox 35 Orlando

Connect with Kristy Grant-Hart on LinkedIn

Spark Consulting

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn