Categories
Compliance Tip of the Day

Compliance Tip of the Day: Bank of America, Culture and Internal Controls

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements.

Whether you’re a seasoned compliance professional or just starting your journey, our aim is to provide you with bite-sized, actionable tips to help you stay on top of your compliance game.

Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law.

Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today we look at the recent report from the WSJ on Bank of America managers instructing junior employees to lie about the hours they work to avoid the 80-hour limit.

For more information on the Ethico ROI Calculator and a free White Paper on the ROI of Compliance, click here.

To check out The Compliance Handbook, 5th edition, click here.

Categories
Blog

Internal Control Lessons from Star Trek: The Doomsday Machine

Last month, I wrote a blog post on the tone at the top, exemplified in the Star Trek, the Original Series episode, Devil in the Dark. Based on the response, some passionate Star Trek fans are out there. I decided to write a series of blog posts exploring Star Trek: The Original Series episodes as guides to the Hallmarks of an Effective Compliance program set out in the FCPA Resources Guide, 2nd edition. Today, I will begin a two-week series looking at the following 10 hallmarks of an effective compliance program laid out by the Department of Justice (DOJ) and Securities and Exchange Commission (SEC) in the FCPA Resources Guide, 2nd edition.

Today, I wanted to watch one of my favorite and iconic episodes, The Doomsday Machine. I believe it offers more than just gripping sci-fi action; it provides valuable insights into internal control principles. For compliance professionals and business managers, the narrative unfolds a series of challenges and solutions that mirror real-world scenarios where robust internal controls are crucial. Let us deeply dive into the internal control lessons we can learn from this episode.

In The Doomsday Machine, the USS Enterprise encounters the wreckage of the USS Constellation and a giant, automated weapon of mass destruction known as the “doomsday machine.” Commodore Matt Decker, the sole survivor from the Constellation, is found traumatized and determined to destroy the machine, even at the risk of the Enterprise’s safety. As Captain Kirk and his crew navigate the threat, they must also deal with Decker’s erratic command decisions, ultimately working to regain control and neutralize the menace.

Lesson 1: The Importance of a Clear Chain of Command

When Commodore Decker assumes command of the Enterprise, the established chain of command disruption illustrates the chaos that can ensue when authority is not clearly defined or respected. Decker’s actions, driven by personal trauma and a lack of understanding of the Enterprise’s capabilities, lead to several risky decisions. The internal control lesson is that a transparent chain of command is essential to ensure that decision-making processes are streamlined and effective. Internal controls should clearly define roles and responsibilities, ensuring authority is delegated appropriately. This allows for clarity and mitigates the risk of individuals making decisions beyond their scope of knowledge or capability. 

Lesson 2: Risk Assessment and Management

The Enterprise crew must quickly assess the threat posed by the doomsday machine. Understanding the machine’s power and behavior is critical to formulating an effective response strategy. Kirk and Spock’s ability to analyze the situation and adapt their plans underscores the importance of risk assessment. The internal control lesson is that companies must continuously identify and assess potential risks to their operations. Implementing internal controls involves establishing procedures for risk assessment, including regular evaluations and updates to risk management strategies. This ensures that businesses remain agile and responsive to emerging threats.

Lesson 3: Crisis Management and Decision-Making

As the situation escalates, the Enterprise crew must make rapid decisions to avert disaster. Decker’s emotional state and inability to make rational decisions highlight the need for effective crisis management protocols. The lesson is that effective crisis management is integral to internal controls. Organizations should develop comprehensive crisis management plans that include clear guidelines for decision-making under pressure. Training and simulations can prepare employees to handle crises calmly and efficiently, minimizing the impact on operations.

Lesson 4: Operational Controls and Communication

The interactions between Kirk, Spock, and the rest of the crew emphasize the necessity of clear communication and cooperation. Spock’s adherence to logical reasoning and Kirk’s ability to inspire teamwork highlight how effective communication is crucial to executing complex operations. The internal control lesson is that operational controls rely heavily on clear communication channels within an organization. Ensuring that information flows freely and accurately between departments helps maintain efficiency and reduces the likelihood of errors. Internal controls should establish standardized communication protocols to support coordination and collaboration.

Lesson 5: Monitoring and Adaptability

Throughout the encounter with the doomsday machine, the crew continuously monitors the situation and adapts their strategies. Kirk and Spock’s ability to adjust their tactics based on real-time information is vital to their success. The internal control lesson is that continuous monitoring and adaptability are key to effective internal controls. Businesses should implement systems that allow for ongoing evaluation of processes and outcomes. This enables them to detect issues promptly and adjust strategies to maintain operational integrity.

The Doomsday Machine is a compelling narrative that underscores the importance of strong internal controls in navigating complex challenges. From maintaining a transparent chain of command to ensuring effective communication and crisis management, the lessons drawn from this episode apply to any organization striving for excellence in compliance and operational efficiency.

As business managers and compliance professionals, we can draw inspiration from Captain Kirk and his crew. We recognize that robust internal controls prevent failures and empower organizations to respond effectively to unexpected challenges. By applying these lessons, businesses can create resilient structures capable of withstanding even the most daunting threats.

Join us tomorrow as we consider the lessons on CCO authority, resources, and expertise from the Star Trek episode The Galileo 7.

Categories
FCPA Survival Guide

FCPA Survival Guide – Step 9 – Internal Controls

How can you survive an FCPA enforcement action? In this special podcast series, Tom Fox and Nick Gallo outline the Top 10 things you can do to reduce your overall fine and penalty, perhaps down to a complete declination. All of the actions you can take come from recent DOJ prosecutions under the FCPA and speeches from DOJ representatives. This podcast, sponsored by Ethico, is the companion series to the book The FCPA Survival Guide: Surviving and Thriving a Foreign Corrupt Practices Act Enforcement Action. Today, we discuss lesson number nine: internal controls.

Tom and Nick delve into the importance of internal controls in compliance, emphasizing the pivotal role they play in business operations. After studying the COSO Framework, Tom shares his transformation into a firm believer in internal controls, underscoring that robust financial controls can cover a significant portion of compliance requirements. They discuss real-world examples, including SAP’s lack of payment process controls and ABB’s successful avoidance of a monitor through proactive measures. The episode highlights the necessity of continuous improvement and collaboration between legal, financial, and business units to ensure the effectiveness of internal controls and the appropriate handling of overrides. The session concludes with a nod to the upcoming episode on speak-up, triage, and internal investigation.

Key Highlights and Issues

  • The Importance of Internal Controls
  • Financial Controls and Compliance
  • Continuous Improvement in Internal Controls
  • Effective Collaboration and Overrides

Resources:

Nick Gallo on LinkedIn

Ethico

The FCPA Survival Guide: Surviving and Thriving a Foreign Corrupt Practices Act Enforcement Action

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Compliance Into the Weeds

Compliance into the Weeds: Major Cybersecurity Incidents and Regulatory Challenges

The award-winning, Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to more fully explore a subject.

Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds!

In this episode, Tom Fox and Matt Kelly take a deep dive into the dismissal of the SEC’s enforcement action against Solar Winds and CrowdStrike cybersecurity failures.

Tom and Matt begin with UnitedHealth’s costly ransomware attack, a federal judge’s ruling against the SEC’s lawsuit over SolarWinds’ cybersecurity practices, and CrowdStrike’s flawed software update impacting global corporations.

The episode explores the regulatory challenges of enforcing effective cybersecurity controls and the implications for companies and their compliance programs. The discussion highlights the need for better IT general controls and the role of different stakeholders, including Congress, regulatory agencies, and audit firms, in addressing these cybersecurity risks.

Key Highlights:

  • UnitedHealth Ransomware Attack Breakdown
  • SolarWinds Cybersecurity Lawsuit
  • Regulatory Challenges and Implications
  • Operational Risk Management and IT Controls
  • Call to Action for Compliance and Audit Professionals

Resources:

Matt on Radical Compliance

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Everything Compliance

Everything Compliance: Episode 137, The Boeing Pleads Guilty Edition

Welcome to the only roundtable podcast in compliance as we celebrate our second century of shows.

In this episode, we welcome Karen Moore as a permanent panelist.

We have one topic for this episode, the Boeing guilty plea, which we slice and dice from a variety of perspectives. Karen is joined by Jonathan Marks, Jonathan Armstrong, and Matt Kelly as panelists, all hosted by Tom Fox.

  1. Karen Moore considers that there are multiple stakeholders involved with Boeing and will they be covered in the resolution? She shouts out to the UK for their seamless transition of power after the July 4 election and to the Men’s Football team for making the UEFA Cup Final.
  2. Matt Kelly asks multiple questions about the form of the guilty plea and what it may mean for compliance professionals going forward. He rants about Tractor Supply which ditched its DEI and sustainability efforts based on one Twitter campaign.
  3. Jonathan Armstrong takes a look at the Boeing plea deal from his uniquely British perspective, with 3 takeaways. He shouts out to the new British Prime Minister, Sir Keir Starmer.
  4. Jonathan Marks considers corporate governance and internal control failures. He rants about Board members who do not understand Board governance.
  5. Tom Fox shouts out to Pittsburgh rookie Paul Skenes for his great first season and being named the Starting Pitcher for the All-Star Game.

The members of the Everything Compliance are:

The host, producer, rantor (and sometimes panelist) of Everything Compliance is Tom Fox, the Voice of Compliance. He can be reached at tfox@tfoxlaw.com. Everything Compliance is a part of the award-winning Compliance Podcast Network.

Categories
Compliance Into the Weeds

Compliance into the Weeds: The Convergence of Cybersecurity and Internal Controls

The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance-related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds!

In this episode, Tom Fox and Matt Kelly take a deep dive into a recent SEC enforcement action involving RR Donnelley, where a cyber breach was characterized as an internal control

In this episode, we discuss how criminal activities in cyberspace are outpacing regulatory measures and the law’s ability to keep up. The conversation touches on the idea that access controls for valuable corporate assets, whether financial data or sensitive information, are becoming indistinguishable in the eyes of cybercriminals. The discussion includes a thought-provoking perspective on merging cybersecurity and anti-money laundering functions, as both deal with improper electronic transactions. The core concern is not just the breach itself, but also the prevention of data exfiltration.

Key Highlights:

  • Corporate Jewels: Money vs. Data
  • Cybersecurity and Anti-Money Laundering
  • Improper Electronic Transactions
  • Focus on Data Exfiltration
  • Conclusion: Preventing Data Theft

Resources:

Matt on Radical Compliance

Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

Navigating the New Frontier: SEC’s Enforcement Action on RR Donnelley and its Implications for Compliance

In the ever-evolving compliance landscape, the recent enforcement action by the Securities and Exchange Commission (SEC) against RR Donnelley is a significant case study. This incident underscores the importance of robust cybersecurity measures and highlights the SEC’s expanding reach into areas traditionally viewed outside its purview. As compliance professionals, understanding the intricacies of this case is crucial for adapting to the dynamic regulatory environment. Matt Kelly and I took a deep dive into the enforcement action in a recent Compliance into the Weeds episode.

RR Donnelley, a company historically known for its printing services and later for marketing services, faced an SEC enforcement action in November 2021 due to a cybersecurity breach. Hackers accessed and copied confidential corporate customer data, which was later posted on the dark web. The SEC’s main contention was that Donnelley failed to disclose this breach to investors promptly and had inadequate internal controls over its IT systems. Ultimately, the company was fined $2.1 million.

The SEC’s enforcement action was based on the premise that Donnelley’s cybersecurity measures were insufficient, leading to unauthorized access to its IT assets. Specifically, the SEC utilized provisions related to internal control over financial reporting to impose sanctions even though no direct accounting fraud or economic loss occurred. This approach represents a novel application of the SEC’s powers, using internal accounting control clauses to address cybersecurity issues.

Matt believes that the SEC’s enforcement hinged on the idea that poor cybersecurity equates to poor internal controls over assets. The SEC interpreted the Exchange Act to mean that access to a company’s assets, whether data or financial, should be controlled and authorized by management. Matt noted in his blog post that the statutory authority for that statement flows from the Exchange Act of 1934, which established the Securities and Exchange Commission and the anti-fraud securities laws we use today. The text of the Exchange Act states that companies must devise and maintain a system of internal accounting controls “sufficient to provide reasonable assurances” on four points:

  • Transactions executed according to management authorization;
  • Transactions are appropriately recorded;
  • Access to assets is permitted only according to management authorization;
  • Recorded accountability for assets is reconciled with existing assets.

The hackers’ ability to access Donnelley’s IT systems without authorization was viewed as a failure of these internal controls.

This interpretation broadens the scope of what compliance professionals must consider under the umbrella of internal controls. Traditionally, internal controls were seen in the context of financial reporting and safeguarding physical assets, most usually cash or cash equivalent. However, it is not simply cash as the only assets these requirements cover but all other corporate assets. Moreover, this case suggests that digital assets and the controls around them are equally critical.

Another critical aspect of the case was the failure to disclose the breach promptly. According to the SEC, Donnelley’s IT security team was aware of the breach but did not quickly escalate it to senior management. It took an external party’s notification for the CISO and senior executives to become fully aware and take action.

This scenario underscores the importance of having robust internal communication channels and protocols to ensure that significant cybersecurity incidents are promptly reported to senior management. Moreover, it highlights the need for transparency with investors regarding such breaches, aligning with the SEC’s mandate to protect investor interests.

Compliance professionals must now consider cybersecurity an integral part of internal control systems. Ensuring that IT systems are secure and that access to digital assets is tightly controlled should be a priority. This involves regular audits of cybersecurity measures, continuous monitoring of IT systems, and implementing robust access control mechanisms.

The case also highlights the necessity of clear and effective disclosure practices. Compliance teams should ensure that there are well-defined procedures for reporting cybersecurity incidents internally and disclosing them to investors when necessary. This might include setting up rapid response teams and informing senior management immediately of significant breaches.

Given the technical nature of cybersecurity, collaboration between compliance and IT departments is essential. Compliance officers should work closely with CISOs and IT security teams to understand potential risks and ensure appropriate controls are in place. This partnership is vital for creating a comprehensive compliance strategy that addresses traditional financial risks and emerging digital threats.

The SEC’s approach, in this case, signals that regulators are willing to use existing frameworks to address new types of risks. Compliance professionals should prepare for increased scrutiny and be proactive in ensuring their organizations meet regulatory expectations. This may involve regular training, staying updated with regulatory changes, and conducting thorough risk assessments.

The RR Donnelley case serves as a wake-up call for compliance professionals, emphasizing the need to adapt to an evolving regulatory landscape. By broadening the scope of internal controls to include cybersecurity and enhancing disclosure practices, compliance teams can better protect their organizations and meet regulatory expectations. Collaboration with IT and staying vigilant about regulatory trends will be vital to navigating this new frontier in compliance. Perhaps more ominously, Matt, in another blog post on the United Healthcare cyber-attack in Q1 2024, asked, ” If the SEC applied that theory of enforcement against Donnelley, shouldn’t that same theory now be applied against UnitedHealth? At this point, we should discuss exactly how UnitedHealth’s breach happened. Change Healthcare had not implemented multi-factor authentication on a critical computer server, which allowed attackers to use stolen employee credentials to gain access. In other words, UnitedHealth had allowed poor access control on a critical system.”

In other words, Watch This Space.

Categories
Blog

Design-Centric Internal Controls: The Foundation for Compliance Excellence

The dynamic world of compliance is continually evolving. New regulations, emerging technologies, and changing market conditions demand that organizations remain vigilant and proactive in their compliance efforts. One crucial aspect of this ongoing vigilance is the design and implementation of internal controls. Recently, I had the pleasure of discussing this topic with Adrienne Bellehumeur. In this blog post, we will explore the key insights from our conversation and delve into the importance of design-centric internal controls.

Adrienne is a chartered accountant and entrepreneur in Canada who has advocated for a design-first approach to internal controls for many years. Adrienne says design-centric internal controls are essential because they lay the foundation for effective compliance. She likens this approach to baking a cake: the design is the cake itself, while testing and other compliance activities are the icing. Without a solid foundation, no amount of testing can ensure the effectiveness of internal controls.

The necessity of robust internal controls has never been more critical. With the increasing complexity of regulatory requirements (on both sides of the border) and the rapid advancement of technology, organizations must continuously assess and improve their internal control systems. Adrienne points out that while internal controls have existed for over two decades, many organizations have become complacent. This complacency can lead to outdated processes that may not adequately address current risks and regulatory expectations.

Adrienne outlined five principles to improve and energize control design work:

  1. Think of Design as the Cake and Testing as the Icing: Focus on building solid and well-thought-out processes before jumping into testing. This approach ensures that the foundation is solid and can withstand scrutiny.
  2. Assess the Organization’s Level of Maturity: Tailor the internal control program to the organization’s stage of development. A one-size-fits-all approach is ineffective, as different organizations have varying needs and challenges.
  3. Focus on Habits, Not Theory: Practical, habitual practices are more effective than theoretical concepts. Encourage habits like regular access control reviews and inventory management to embed compliance into the organizational culture.
  4. Support Continuous Improvement: Internal controls should not be static. Regularly review and update controls to ensure they remain effective and relevant. Continuous improvement helps organizations stay ahead of emerging risks and regulatory changes.
  5. Keep It Interesting: Vary the techniques used in internal control assessments to maintain engagement and effectiveness. Workshops, interviews, and creative diagramming can provide fresh perspectives and uncover new insights.

One of the most intriguing aspects of Adrienne’s approach is her use of workshops to discuss and improve internal controls. These workshops involve stakeholders, including internal auditors, compliance officers, and business unit leaders. By fostering open dialogue and collaboration, these sessions can identify inefficiencies, propose improvements, and build stronger relationships between auditors and the internal team.

Adrienne emphasizes that these workshops should occur before external audits. This pre-audit preparation allows organizations to address issues internally, reducing the likelihood of negative findings during the audit. Moreover, involving the internal team in the design process helps build a sense of ownership and commitment to maintaining robust controls.

For the internal auditor, leveraging technology is crucial for adequate internal controls. Adrienne highlighted the decreasing reliance on transactional testing, thanks to automation and data analytics advancements. Modern internal controls must adapt to these changes by incorporating technology that enhances efficiency and accuracy.

AI and data analytics can provide deeper insights into organizational processes, helping identify potential risks and areas for improvement. By integrating these technologies into the internal control framework, organizations can achieve higher precision and responsiveness.

Adrienne’s expertise in documentation is particularly relevant to internal controls. I wholeheartedly agree that good documentation practices are the backbone of any effective compliance program and form the basis of information management. Clear, accurate, accessible documentation supports transparency, accountability, and continuous improvement.

Companies must establish simple rules for naming, classifying, and managing documents. This foundational step ensures that all relevant information is readily available for internal reviews, audits, and regulatory inspections.

The compliance landscape continually evolves, with new challenges like ESG and AI gaining prominence. Adrienne articulated that a back-to-basics approach can help organizations navigate these new areas. Organizations can build a solid foundation that supports emerging compliance requirements by focusing on fundamental principles of good information management and documentation.

For instance, effective ESG reporting relies on accurate and comprehensive data. Similarly, AI systems must be underpinned by robust data management practices to ensure transparency and accountability. By strengthening these foundational elements, organizations can more easily adapt to new regulatory expectations and technological advancements.

Adrienne and I also discussed the role of internal controls in supporting whistleblower programs. With the Department of Justice (DOJ) formulating new rules for financial incentives in whistleblower programs, organizations must ensure their internal controls can detect and address issues before they escalate. Adequate internal controls can help prevent whistleblower claims by identifying and mitigating risks early. For example, strong documentation practices provide a clear audit trail that can validate the organization’s actions and decisions. Additionally, fostering a culture of transparency and accountability encourages employees to report concerns internally, allowing the organization to address them proactively.

Design-centric internal controls are essential for building a robust and effective compliance program. By focusing on the principles outlined by Adrienne Bellehumeur, organizations can enhance their internal control frameworks, support continuous improvement, and stay ahead of emerging compliance challenges. A proactive approach to internal controls is crucial for long-term compliance success, whether through innovative workshops, leveraging technology, or strengthening documentation practices.

Categories
FCPA Compliance Report

FCPA Compliance Report: Adrienne Bellehumeur on Design – Centric Approaches to Internal Controls

Welcome to the award-winning FCPA Compliance Report, the longest running podcast in compliance.

In this edition of the FCPA Compliance Report, Tom Fox welcomes back Adrienne Bellehumeur, a chartered accountant and expert in internal controls and documentation.

Adrienne discusses her recent article on design-centric internal control and emphasizes the importance of focusing on design as the foundation for effective control programs. She outlines five key principles for improving control design and details her approach to challenging processes and governance systems. The conversation also touches on the necessity of continuously updating controls to adapt to evolving business and regulatory environments.

Adrienne shares tips on fostering better design through workshops, effective interviewing, and continuous improvement, while also addressing new developments such as AI and ESG. The episode finishes with insights into how internal controls can support whistleblower programs and the importance of back-to-basics documentation and information management.

Highlights in this Episode:

  • Professional Background
  • Design-Centric Approach to Internal Controls
  • Challenges and Importance of Good Design
  • Principles for Improving Control Design
  • Back to Basics: Adapting to New Business Developments
  • Whistleblower Programs and Internal Controls

 Resources:

Adrienne Bellehumeur on LinkedIn

Risk Oversight

New Approaches to Control Design

Tom Fox

Instagram

Facebook

YouTube

Categories
Compliance Into the Weeds

Compliance into the Weeds: Analyzing The Trump Conviction: Compliance Lessons from an Unprecedented Case

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to more fully explore a subject.

Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds!

In this episode of ‘Compliance Into the Weeds’, Tom and Matt take a deep dive into last week’s trial verdict against Donald Trump in NYC and lessons for the compliance professional.

We explore the importance of internal controls, consistent consequence management, and effective leadership. They also delve into how compliance officers can learn from the storytelling strategies used in the trial and emphasize the application of the rule of law.

Key Highlights:

  • Overview of Trump’s Criminal Conviction
  • Internal Controls and Compliance Lessons
  • Consequences Management and Consistent Enforcement
  • Ethical Leadership and Communication
  • Who is your audience? Storytelling in Compliance
  • Final Thoughts and Rule of Law

Resources:

Matt on Radical Compliance

 Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn