Categories
Blog

The McKinsey $650 Million Settlement: Compliance Lessons from the Opioid Crisis

Last week, McKinsey & Company resolved civil and criminal matters with the Department of Justice (DOJ). This settlement represents a seismic shift in corporate accountability. For the first time, a management consulting firm has been held criminally liable for advice that contributed to a client’s commission of a crime. This $650 million resolution with the DOJ offers profound lessons for industry compliance professionals. This should be coupled with the previous Foreign Corrupt Practices Act (FCPA) resolution for $122 million with the DOJ over the company’s bribery and corruption in South Africa. From failures in risk management to the imperative of ethical decision-making, McKinsey’s cases are a masterclass in how compliance missteps can lead to devastating consequences.

A Timeline of Ethical Erosion  

Between 2004 and 2019, McKinsey worked on 75 engagements with Purdue Pharma, a key player in the opioid epidemic. In 2013, McKinsey spearheaded a project to “turbocharge” OxyContin sales despite growing awareness of the drug’s role in the crisis. This “Evolve to Excellence” initiative targeted high-prescribing physicians, some already under scrutiny for unsafe practices. Despite Purdue’s 2007 guilty plea for misbranding OxyContin, McKinsey continued advising the company, prioritizing profits over public health.

The fallout included a criminal charge for obstruction of justice against a former senior partner, allegations of advising on fraudulent claims to federal healthcare programs, and revelations of conflicts of interest in dealings with the FDA. The penalties include a $231 million fine, $93 million in forfeitures, and $323 million under the False Claims Act. McKinsey also agreed to a Deferred Prosecution Agreement (DPA), mandating significant compliance reforms.

Key Compliance Takeaways  

1. Risk Assessment and Client Selection: The First Line of Defense

McKinsey’s failure to assess its work’s reputational and legal risks with Purdue underscores the importance of robust risk evaluation processes. Like any organization, consulting firms must consider client histories and engagement scopes. Purdue’s 2007 plea and ongoing controversies should have triggered heightened scrutiny, yet McKinsey continued its relationship unabated. One key lesson is to establish a formalized client diligence framework. Identify high-risk clients and engagements, factoring in legal histories, industry regulations, and reputational implications.

2. The Ethical Perils of Aggressive Strategy

The directive to “turbocharge” OxyContin sales illustrates the ethical blind spots that arise when profit-driven goals overshadow public welfare. McKinsey’s PowerPoint presentations and marketing strategies directly influenced Purdue’s ability to sustain OxyContin sales, exacerbating the opioid crisis. Every organization must build ethics into strategic decision-making. Compliance officers should collaborate with business units to ensure strategies align with ethical standards and regulatory requirements.

3. Document Retention and the Dangers of Obstruction

The case against former senior partner Martin Elling reveals how internal actions can escalate legal risks. Elling’s directive to “eliminate all our documents and emails” and his subsequent obstruction charge illustrates the severe consequences of tampering with evidence during investigations. Every company must develop and enforce strict document retention policies. Provide training to employees on legal holds and the dangers of obstructing investigations.

4. Conflict of Interest Management

McKinsey’s simultaneous work with Purdue and the FDA highlights a blatant disregard for conflict-of-interest policies. Misleading the FDA undermined trust and compounded McKinsey’s liability. Your organization must institute robust conflict-of-interest protocols. Regularly audit engagements to identify overlapping or competing interests and disclose conflicts proactively.

5. Deferred Prosecution Agreements: A Path to Reform

As part of the DPA, McKinsey committed to implementing significant compliance reforms, including a risk evaluation process, quality review programs, and new document retention procedures. These measures are designed to prevent a repeat of past mistakes. Indeed, no company wants to be under a DPA, but the conduct of McKinsey, both in this case and in its FCPA matter in South Africa, were both so egregious that the company should view its DPA as an opportunity for transformation. Compliance leaders should use such agreements to rebuild trust, enhance internal controls, and foster a culture of accountability.

Culture as a Compliance Imperative  

The most striking lesson from the McKinsey case is the absence of a culture of accountability. McKinsey’s actions were not the result of one rogue employee; they reflected systemic failings within the organization. From top executives to client teams, the firm consistently prioritized financial gain over ethical responsibility.

Building an ethical culture requires multiple steps. It all begins with Tone from the Top—a commitment from top leadership to demonstrate an unwavering commitment to compliance and ethics. A company must empower its corporate compliance functions with the authority and resources to challenge decisions that pose ethical risks. Through training, communication, and employee awareness, there must be awareness throughout the organization of this commitment to business ethically and in compliance. Organizations must regularly train employees on ethical decision-making, risk identification, and reporting mechanisms.

Looking Ahead: The Compliance Professional’s Role  

The McKinsey settlements are a wake-up call for compliance professionals. They challenge us to rethink our roles as rule enforcers and stewards of ethical integrity. This case underscores the importance of proactive measures to identify risks, implement controls, and foster a culture where doing the right thing is non-negotiable.

The DOJ’s message is clear: no entity is above the law. Consulting firms, financial advisors, and other service providers must now grapple with the reality that their advice carries legal and ethical implications. For compliance officers, this means doubling down on preventive measures, promoting transparency, and ensuring accountability at every level.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Potpourri of Compliance Issues

The award-winning, Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode, Tom Fox and Matt Kelly dive into a potpourri of issues, including Paul Atkins’s appointment to chair the SEC, a massaging of DOJ and the Corporate Enforcement Policy, and McKinsey’s FCPA resolution.

Tom and Matt discuss various compliance issues, focusing on the implications of Paul Atkins’ appointment as SEC chairman, the challenges of enforcement and corporate penalties, the role of whistleblowers, and recent FCPA enforcement actions, including the McKinsey settlement. They explore how Atkins’ conservative views may shape SEC policies and the potential impact on compliance officers and corporate governance.

Key highlights:

  • Paul Atkins and the SEC
  • Enforcement Challenges and Corporate Penalties
  • Whistleblower Protections and Compliance Officers
  • FCPA Enforcement and McKinsey Settlement

Resources:

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

AI in Compliance: Part 2, Leveraging AI for Third-Party Risk Management

We continue our week-long look at the use of AI in compliance. Today, we consider third parties. Third-party relationships remain one of the most significant areas of risk for corporate compliance programs. From supply chain partners to distributors and everything in between, third parties act as the face of your organization in many jurisdictions, making their actions, and any misconduct, your problem. To mitigate these risks, companies traditionally relied on periodic due diligence and reactive responses. But in today’s fast-moving and increasingly interconnected world, such approaches fall short.

This is where artificial intelligence (AI) can revolutionize third-party risk management. With AI tools, compliance teams can shift from static, checklist-driven processes to dynamic, continuous monitoring systems. In this post, we’ll explore how AI enhances third-party risk management by screening, monitoring, and evaluating third parties in real time and how it helps meet the DOJ’s 2024 Evaluation of Corporate Compliance Programs (2024 ECCP) expectations for robust, data-driven compliance practices.

The DOJ’s 2024 ECCP places a strong emphasis on using data analytics and continuous monitoring to strengthen compliance programs. These expectations are included with the requirements of a proactive risk management and data-driven compliance. AI allows compliance teams to manage a large volume of third-party relationships efficiently and effectively. To fully align with DOJ expectations, companies should document their use of AI tools, including how they support risk assessments and monitoring activities. Regular audits of AI systems can ensure they remain effective and compliant with legal standards.

AI: The Compliance Professional’s New Ally

The compliance risks tied to third parties are well-documented:  bribery and corruption, reputational damage, and legal and regulatory violations. AI excels at handling exactly the complexity of third-party management entails. It can process vast amounts of data from multiple sources, identify patterns, and provide actionable insights in real-time. Let’s break down how AI can be used at each stage of the third-party lifecycle.

  • Initial Screening.

Traditional screening processes rely on questionnaires and public database checks—important but limited in scope. AI-powered tools enhance this step in a variety of ways. By aggregating diverse data sources, AI systems can pull information from public records, news outlets, litigation databases, social media platforms, and proprietary sources. Through the use of natural language processing (NLP) algorithms, you can detect hidden risks through the analysis of news articles, blogs, or social media posts to uncover potential red flags, such as allegations of fraud, regulatory violations, or ethical misconduct. Finally, with scored risk profiles, AI models assess the likelihood of misconduct based on factors such as geographic risk, industry norms, and historical behavior. This risk scoring allows compliance teams to prioritize their efforts.

  • Onboarding Due Diligence

The onboarding phase is critical for setting the tone of the relationship and understanding the potential risks. AI can assist you in a variety of ways. With automated document review, AI tools can process contracts, certifications, and policies submitted by third parties, flagging inconsistencies or missing information. One area that continues to bedevil due diligence is the identification of Beneficial Ownership. By cross-referencing corporate records, AI can reveal ultimate beneficial owners, including individuals who might otherwise remain hidden. Machine learning (ML) models trained on historical compliance data can predict the likelihood of future misconduct, enabling proactive risk mitigation strategies through predictive insights. The bottom line is that by ensuring a thorough onboarding process, AI helps organizations comply with DOJ guidance, which emphasizes the importance of understanding third-party relationships.

  • Continuous Monitoring

A one-time due diligence exercise is no longer sufficient. The 2024 ECCP made clear the need for ongoing monitoring to ensure that third-party relationships remain compliant. AI facilitates this mandate by offering real-time alerts, where AI-driven systems can monitor news feeds, regulatory databases, and other sources 24/7, sending alerts when a third party is implicated in a legal issue, sanctions violation, or reputational scandal. One of the more challenging areas for compliance professionals has in around transaction monitoring. Here, AI can analyze financial transactions involving third parties, flagging anomalies that might indicate fraud or corruption. Finally, in the area of behavioral analytics, AI tools can track changes in a third party’s behavior, such as a sudden increase in high-risk transactions or shifts in geographic focus. These patterns often signal emerging risks. The bottom line is that with continuous monitoring, companies can address potential problems before they escalate into full-blown compliance failures.

  • Periodic Risk Re-Evaluation

AI ensures that risk assessments are dynamic, reflecting changes in the external environment and the third party’s circumstances. As far back as 2020, the DOJ told compliance professionals that risk assessments should be performed with your organization’s risk change, so a periodic risk re-evaluation directly aligns with the DOJ’s expectations. Key AI capabilities in this area include geopolitical risk analysis, using AI to evaluate the impact of geopolitical events, such as sanctions, trade disputes, or political instability, on third-party relationships. Your industry trends are something the DOJ has been talking about for at least 10 years, and AI systems can monitor regulatory developments and industry trends, helping organizations anticipate new compliance risks. Perhaps most excitedly are the customizable risk models you can create with AI. This would allow compliance teams to adjust risk assessment models based on evolving business needs, ensuring that evaluations remain relevant and actionable.

Overcoming Challenges in AI Implementation

While the benefits of AI are clear, implementing these tools effectively requires careful planning and preparation in several areas. First is your data quality. The old adage of GIGO (Garbage In, Garbage Out) has been replaced by BIBO (Best Input, Best Output). Here, AI is only as effective as the data it analyzes. Organizations must invest in robust data governance practices to ensure accuracy, completeness, and consistency.

Transparency is a key issue for compliance in using AI, and it was directly addressed in the 2024 ECCP. The black-box nature of AI decision-making can be a concern. Compliance teams should work with internal teams and vendors to ensure algorithms are interpretable and results are explainable. AI tools must integrate seamlessly with existing compliance systems to avoid creating silos or inefficiencies. While the US is far behind the rest of the world in data privacy laws, GDPR and others still apply to any internationally facing organization. This means companies must deploy AI responsibly, respecting privacy laws and ensuring that monitoring does not cross ethical boundaries.

The Future of Third-Party Compliance

AI is transforming third-party risk management from a reactive, one-size-fits-all process into a dynamic, data-driven discipline. By leveraging AI tools for screening, onboarding, monitoring, and reassessment, compliance professionals can manage third-party risks with unprecedented precision and agility. However, as with any powerful tool, AI must be used thoughtfully. By focusing on data quality, transparency, and ethical considerations, organizations can harness the full potential of AI while maintaining trust and accountability.  At the end of the day, a best practices compliance program is not simply about checking the box; rather, it is about creating a system that evolves with the risks it manages. AI is that system’s next evolution.

Categories
10 For 10

10 For 10: Top Compliance Stories For the Week Ending December 7, 2024

Welcome to 10 For 10, the podcast that brings you the week’s Top 10 compliance stories in one podcast each week. Tom Fox, the Voice of Compliance, brings you the compliance professional and the compliance stories you need to know to end your busy week. Sit back, and in 10 minutes, hear the stories every compliance professional should know from the prior week. Every Saturday, 10 For 10 highlights the most important news, insights, and analysis for the compliance professional, all curated by the Voice of Compliance, Tom Fox. Get your weekly filling of compliance stories with 10 for 10, a podcast produced by the Compliance Podcast Network.

  • McKinsey agrees to FCPA settlement for corruption in South Africa. (DOJ Press Release)
  • Judge rejects DOJ/Boeing settlement.  (WSJ)
  • Defense in Trafigura case can’t knock out star prosecution witness. (FT)
  • Was it corruption or a smart (or dumb) business deal? (TNR)
  • Tesla lost the case on the 2nd Musk pay package. (WSJ)
  • Was it fraud or worse? (NYT)
  • Paul Atkins was selected to head SEC. (FT)
  • Trump-appointed Texas judge enjoins CTA nationally. (Bloomberg)
  • OIG looks to hold nursing care execs responsible. (McKnight’s Long-Term Care News)
  • Buying/Selling homes and compliance.  (Mortgage News Daily)

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

You can check out the Daily Compliance News for four curated compliance and ethics-related stories each day here.

Check out the entire 3-book series, The Compliance Kids, on Amazon.com.

Connect with Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Daily Compliance News

Daily Compliance News: December 6, 2024 – The Boeing Settlement Bounced Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News—all from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

  • He forgot what the Compliance Committee did. (FT)
  • Colombia’s Finance Minister was replaced. (Reuters)
  • McKinsey agrees to FCPA settlement for corruption in South Africa. (DOJ Press Release)
  • Judge rejects DOJ/Boeing settlement.  (WSJ)

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

Check out the entire 3-book series, The Compliance Kids, on Amazon.com.

Categories
FCPA Compliance Report

FCPA Compliance Report – Episode 737 – Navigating Compliance in a Trump Presidency: Insights and Concerns

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. This edition delves into the implications of Donald Trump’s presidency for corporate compliance and ethics.

We share some initial thoughts from compliance officers and industry experts, exploring the widespread concern over Trump’s controversial character and potential impact on businesses’ ethical cultures. Key discussion points include the existential angst among compliance professionals, the future of FCPA enforcement, and the role of influential figures like Elon Musk in the Trump administration. The episode underscores the importance of maintaining robust compliance programs despite political uncertainties and the potential for increased regulatory challenges and internal corporate risks.

Highlights in this episode:

  • Compliance in the Trump Era
  • Existential Angst in Compliance
  • FCPA Enforcement Under Trump
  • Elon Musk’s Role in the Administration
  • The Future of Compliance and Governance
  • Conclusion: The Risks of Relaxed Controls

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

Check out the full 3-book series, The Compliance Kids, on Amazon.com.

For an audio/video version of the Compliance Kids book, Speaking Up is AWESOME, contact Tom Fox.

Categories
10 For 10

10 For 10: Top Compliance Stories For the Week Ending November 23, 2024

Welcome to 10 For 10, the podcast that brings you the week’s Top 10 compliance stories in one podcast each week. Tom Fox, the Voice of Compliance, brings you the compliance professional and the compliance stories you need to know to end your busy week. Sit back, and in 10 minutes, hear the stories every compliance professional should know from the prior week. Every Saturday, 10 For 10 highlights the most important news, insights, and analysis for the compliance professional, all curated by the Voice of Compliance, Tom Fox. Get your weekly filling of compliance stories with 10 for 10, a podcast produced by the Compliance Podcast Network.

  • Is bribery how business is done in India? (NYT)
  • Adami Group charged with fraud, FCPA violations. (NYT)
  • Trafigura heads to trial in Switzerland. (Bloomberg)
  • A layer of crypto corruption. (TheBulwark)
  • Firings as layoffs without benefits. (FT)
  • KPMG rehabbed in the UK.  (FT)
  • Founder of Crypto mixer sentenced to 3 years in prison. (WSJ)
  • Bill Hwang gets 18 years. (NYT)
  • Gary Wang receives no prison time. (NYT)
  • Jay Clayton was picked to head SDNY. (FT)

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

You can check out the Daily Compliance News for four curated compliance and ethics-related stories each day here.

Check out the full 3-book series, The Compliance Kids, on Amazon.com.

Connect with Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Compliance and AI

Compliance and AI: Demystifying AI Integration in Compliance: Insights from the DOJ

What is the role of Artificial Intelligence in compliance? What about Machine Learning? Are you using ChatGPT? These questions are but three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, Tom reflects on recent DOJ speeches on AI and the 2024 ECCP revisions concerning AI and compliance.

Tom discusses Deputy Assistant Attorney General Nicole Argentieri’s September speech and the 2024 Evaluation of Corporate Compliance Programs (ECCP). He also unpacks how compliance professionals are expected to manage AI-related risks rigorously. He offers actionable steps, such as conducting comprehensive risk assessments, implementing robust compliance controls, and ensuring ongoing monitoring and employee training. This episode is essential listening for compliance professionals aiming to stay ahead of AI-related challenges and align with the DOJ’s latest expectations.

Key highlights:

  • DOJ’s New Approach to AI in Compliance
  • Steps to Align Compliance Programs with DOJ Expectations
  • 2024 ECCP: Key Questions for Compliance Professionals
  • Proactive Strategies for Managing AI Risks

Resources:

For additional information check out the FCPA Compliance and Ethics Blog.

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Daily Compliance News

Daily Compliance News: November 22, 2024 – The All NYT Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News—all from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Today’s stories:

  • Matt Gaetz withdraws from AG nomination. (NYT)
  • Is bribery how business is done in India? (NYT)
  • Bill Hwang gets 18 years. (NYT)
  • Gary Wang receives no prison time. (NYT)

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

Check out the full 3-book series, The Compliance Kids on Amazon.com.

Categories
Daily Compliance News

Daily Compliance News: November 21, 2024-the Adani Group Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance related stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest for the compliance professional.

For the first time ever, the Daily Compliance News focuses on one story, the massive civil and criminal set of charges brought against the Adani Group and its founder Gautam Adani. Articles featured in this edition include, the NYT, FT and WSJ.

For more information on the Ethico Toolkit for Middle Managers, available at no charge by clicking here.

Check out the full 3-book series, The Compliance Kids on Amazon.com.