Categories
Compliance Into the Weeds

Compliance into the Weeds: Compliance Implications of DOJ’s New Fraud Division and McDonald Memo

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them in greater depth and uncover hard-hitting insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the DOJ’s “McDonald Memo.”

This DOJ Memo outlines a new Trump administration fraud division that broadly claims jurisdiction over “all types of fraud,” potentially reshaping DOJ enforcement and creating uncertainty about overlapping authority with existing divisions (e.g., antitrust). They review five priority areas: a. public trust/financial integrity fraud (procurement, bid rigging, grants, social welfare), b. healthcare fraud, c. internal revenue fraud, d. global trade and commerce fraud (tariffs/customs), and e. an undefined “corporate misconduct” category. From a compliance perspective, they urge companies to reassess risk areas (healthcare, importers, and government contractors), strengthen third-party oversight and documentation, and “pressure test” compliance programs with transparency and recordkeeping. They also warn that politicized enforcement and unclear guidance—such as on cartel-related liability—complicate compliance strategy and may tempt leaders to treat settlements as a cost of doing business.

Key highlights:

  • McDonald Memo Overview
  • Fraud Division Scope and Uncertainty
  • Five Fraud Categories Explained
  • Corporate Misconduct Questions
  • Compliance Program Impacts
  • Documentation as Defense
  • Mexico Cartels and Strict Liability

Resources

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. 

Categories
Blog

Ted Lasso Week: Part 1 – Ted Lasso: Ethical Leadership, Psychological Safety, and the Limits of Good Intentions

Season 4 of Ted Lasso has begun dropping (a new episode releases each Wednesday). Matt Kelly reposted a blog he wrote during the original run of the series, and he and I did a deeper dive into the show and its popularity for compliance professionals in an episode of Compliance into the Weeds. I decided to take a deep dive into five characters from the show and use them to explore compliance topics. Over the next 5 blog posts, I will consider team owner Rebecca Welton, Assistant Manager Nate Shelley, player and later coach Roy Kent, and social media influencer Keeley Jones. Today in Part 1, we begin with compliance lessons through the character of Ted Lasso.

Ted Lasso arrives at AFC Richmond with no meaningful knowledge of English football, a skeptical locker room, a hostile press, and an owner who secretly hired him to fail. On paper, he is an obvious control failure. In practice, he becomes the architect of Richmond’s cultural transformation.

For compliance professionals, that transformation is the point. Ted demonstrates how a leader can create trust, encourage candor, and turn values into daily behavior. He also demonstrates the limits of values-led leadership. Good intentions do not investigate misconduct. Empathy does not test a control. Forgiveness does not remediate a root cause.

The compliance lesson from Ted is not simply to “believe.” It is to build a culture in which accountability, information, controls, and oversight support belief.

Culture Is What the Leader Does

Ted’s first contribution is not tactical. It is behavioral. He learns names, asks questions, listens to people with little formal authority, and treats the kit man, Nate Shelley, as a colleague whose observations matter. In “Trent Crimm: The Independent” (Season 1, Episode 3), Ted recognizes that Jamie Tartt and other players are humiliating Nate. Rather than deliver a speech about respect and move on, Ted engages Roy Kent, the informal leader whose intervention can change locker-room conduct.

That is tone at the top connected to conduct in the middle. The DOJ Evaluation of Corporate Compliance Programs (ECCP) asks how senior leaders and managers have encouraged compliance through their words and actions. It states in part, “Beyond compliance structures, policies, and procedures, it is important for a company to create and foster a culture of ethics and compliance with the law at all levels of the company. The effectiveness of a compliance program requires a high-level commitment by company leadership to implement a culture of compliance from the middle and the top.”

The Principles of Federal Prosecution of Business Organizations (Justice Manual) likewise directs prosecutors to examine culture at all levels, including discipline, treatment of complaints, and incentives. 9.28.300 states in part that prosecutors shall consider “the pervasiveness of wrongdoing within the corporation, including the complicity in, or the condoning of, the wrongdoing by individuals in corporate management”. In Section 9-28.800, it directs the DOJ to review a “company’s culture of compliance”.

Ted understands instinctively that culture does not travel through posters. It travels through managers, peer leaders, everyday decisions, and the behavior an organization tolerates. A chief compliance officer can publish a code. Only operational leaders can make that code real during the meeting, on the sales call, and inside the locker room.

Psychological Safety Requires a Response System

Ted creates space for people to speak before they have status. He accepts tactical input from Nate, invites dissent from Coach Beard, and builds the Diamond Dogs as an informal forum for candid discussion. By “La Locker Room Aux Folles” (Season 3, Episode 9), Richmond can confront Colin Hughes’s sexuality and Isaac McAdoo’s reaction with empathy. Ted initially hears the team’s claim that Colin’s identity makes no difference, then corrects the underlying message: the team should care because Colin’s experience matters.

This is psychological safety in practice. Employees must be able to raise a concern, disclose vulnerability, or challenge a decision without humiliation or retaliation. Yet a compliance program needs more than an approachable leader. Equally importantly, a culture of Speak Up must be paired with a culture of Listen Up.

Richmond relies heavily on Ted’s availability and temperament. That is a strength while Ted is present and a key-person risk when he is absent. A mature speak-up program requires intake standards, anti-retaliation controls, escalation criteria, case tracking, trend analysis, and board reporting. An open door is valuable. It is not an operating system.

Accountability Must Apply to Stars and Friends

Ted’s strongest accountability moment comes in “Tan Lines” (Season 1, Episode 5), when he benches Jamie after the star player refuses to follow the team’s approach. Ted chooses collective standards over short-term performance. That is exactly the decision many organizations avoid when the employee at issue is a top salesperson, rainmaker, founder, or executive.

He is less decisive when loyalty clouds his judgment. In “All Apologies” (Season 1, Episode 9), Beard and Nate press Ted to confront Roy’s declining performance. Ted initially resists, even though the competitive risk is visible. He eventually has the necessary conversation and gives Roy a dignified path to support the team from the bench.

The contrast matters. DOJ asks whether discipline is applied consistently and whether the company tolerates misconduct by high performers. Compliance credibility collapses when consequences depend on revenue, rank, or personal affection. Ethical leadership is not the absence of hard decisions. It is the willingness to make them fair and explain the standard.

Forgiveness Is Not Remediation

Rebecca’s confession in “All Apologies” presents Ted’s greatest strength and clearest compliance blind spot. She admits that she hired him to fail, manipulated club decisions, and used people as instruments in her campaign against Rupert. Ted forgives her immediately.

At a human level, the scene is powerful. At an organizational level, forgiveness cannot close the matter. Richmond would still need to establish what happened, preserve evidence, identify affected decisions, assess financial and stakeholder harm, determine whether others participated, evaluate disclosure obligations, and strengthen governance.

The US Sentencing Guidelines require organizations to respond appropriately after misconduct and take steps to prevent recurrence. DOJ similarly focuses on root-cause analysis, remediation, and whether control improvements are tested. Ted offers grace, which can support rehabilitation. He does not create a record showing that the organization learned from the failure.

This distinction should matter to every CCO: mercy concerns the person; remediation concerns the institution. A company may do both. It cannot substitute one for the other.

Vulnerability Can Strengthen the Control Environment

Ted’s panic attacks show the cost of a culture in which even a supportive leader believes he must appear invulnerable. His attack during karaoke in “Make Rebecca Great Again” (Season 1, Episode 7) remains largely private. In “Headspace” and “Man City” (Season 2, Episodes 7 and 8), he finally engages with Dr. Sharon Fieldstone and begins addressing the trauma connected to his father’s suicide. After Nate leaks his panic attack to the press, Ted speaks honestly to the team and the public in “Inverting the Pyramid of Success” (Season 2, Episode 12).

Leaders retain legitimate medical privacy. The compliance point is not compelled disclosure. Organizations need trusted support channels, succession and contingency plans, and an environment where asking for help is not treated as weakness. Ted’s eventual candor reduces stigma. His earlier concealment creates an information vacuum that Nate weaponizes.

Within the COSO Internal Control Framework, Ted materially improves the control environment and information and communication. Richmond’s weakness is monitoring. Warning signs involving Nate, including humiliation of subordinates, resentment, and escalating hostility, do not reach a reliable response process before he leaks Ted’s health information and leaves for West Ham.

The Final Test Is Whether Culture Outlasts the Leader

By Season 3, Ted increasingly shifts from hero to system builder. “Sunflowers” and “The Strings That Bind Us” (Season 3, Episodes 6 and 7) show Richmond developing Total Football through shared learning, role flexibility, and trust. In “So Long, Farewell” (Season 3, Episode 12), Ted leaves, but Roy, Beard, Rebecca, Higgins, and the players can carry the culture forward.

That is the institutional test. A compliance program that depends on one charismatic executive is not sustainable. Caremark oversight principles require boards to make a good-faith effort to establish and monitor information and reporting systems, particularly around mission-critical risks, as the Delaware Supreme Court emphasized in Marchand v. Barnhill (the Bluebell Ice Cream case). Ted changes Richmond’s values. Governance must ensure that those values become repeatable processes, reliable information, and accountable decisions.

Practical Takeaways for CCOs 

Ted Lasso offers five questions for a CCO and compliance team:

  1. Do employees trust leaders, and can the organization demonstrate that concerns receive a consistent response?
  2. Are high performers held to the same behavioral standards as everyone else?
  3. When misconduct occurs, does forgiveness follow investigation and remediation rather than replace them?
  4. Are managers trained and monitored as culture carriers, especially after promotion?
  5. Would the speak-up culture and compliance program remain effective if a trusted leader departed tomorrow?

Ted’s enduring lesson is that ethical culture begins with human connection. Effective compliance begins there as well, but it cannot end there. Richmond becomes stronger when curiosity replaces judgment, candor replaces silence, and team standards replace individual entitlement. The next step for any real organization is to convert those behaviors into controls that can be tested, monitored, reported, and sustained.

Join us tomorrow in Part 2, as we turn to Rebecca Welton, whose decision to use AFC Richmond as an instrument of personal revenge reveals the risks created when concentrated authority operates without independent challenge. We will examine executive conflicts, institutional remediation, and Rebecca’s transformation from conflicted owner to accountable steward by requiring governance that can hold power to account.

Categories
Compliance Into the Weeds

Compliance into the Weeds – Two Cyber Security Cases for the Compliance Professional

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss recent enforcement actions under the False Claims Act (FCA) related to cybersecurity failures by government contractors.

They analyze two significant cases: Illumina, a medical device maker, and Aero Turbine, a contractor for the US Air Force. The conversation highlights the importance of ‘security by design’ in product development and the growing scrutiny on compliance practices, especially for smaller companies. The discussion emphasizes the need for robust cybersecurity measures and the challenges faced by organizations in meeting regulatory requirements.

Key highlights:

  • False Claims Act Cases Overview
  • Illumina Case Analysis
  • Aero Turbine Case Insights
  • Compliance Challenges for Smaller Companies

Resources:

Matt Kelly in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Awards for podcast excellence.

Categories
Blog

Top Compliance Leadership Skills for the Wild Wild West that is Coming – Part 2, Curiosity

This week, Donald Trump was inaugurated as the 47th President of the United States. I can only say with complete certainty that the world of compliance will never be the same. Trump not only promises tariffs and sanctions against America’s enemies and competitors but also promises them against America’s friends. His views on the Foreign Corrupt Practices Act (FCPA) are well known (‘a horrible law’), and so are his views on bribery.

He may well be the first President to employ the FCPA as a tactical weapon against companies from countries that are not only the US’s enemies and competitors but also our allies. This is nothing to say about how he will direct the Department of Justice to use the Foreign Extortion Prevention Act (FEPA) against our enemies, competitors, and allies. So prepare for the Wild West of corporate compliance for the next four years.

As compliance professionals face this miasma in 2025, compliance leadership skills will be more critical than ever. With these new, renewed, and mounting regulatory pressures, declining employee engagement, and intensifying demand for ethical corporate governance, the role of compliance leaders has never been more pivotal or challenging.

This week, I am looking at three leadership skills for the Chief Compliance Officer (CCO), compliance professional, or compliance practitioner to focus on for this sea change in compliance. One faces outward, one faces inward, and the third relates to your attitude. They are (1) fairness, (2) curiosity, and (3) a sense of humor. These three skills will enhance your team’s effectiveness and strengthen your organization’s overall compliance posture. Yesterday, we considered fairness. Today, we look at the curiosity of the compliance professional.

Curiosity: Your Secret Weapon for Compliance Growth 

From my experience, curiosity is a game-changer in compliance. Indeed, in the initial Radical Compliance podcast, Matt Kelly interviewed Hui Chen about the original (2017) Evaluation of Corporate Compliance Programs; she said it was designed to get compliance professionals and CCOs to ask questions about their compliance programs.

Besides the Trump Administration, in 2025, compliance programs will face emerging challenges such as AI ethics, ESG requirements, and new data privacy laws. Curiosity enables compliance leaders to stay ahead of these trends, fostering innovation and adaptability in their programs. Curious leaders break free from silos, seek new knowledge, and inspire their teams to think creatively. This mindset is critical for identifying risks and opportunities in an unpredictable regulatory environment.

Curiosity drives innovation, sharpens problem-solving skills, and helps compliance officers identify risks and opportunities others may overlook. But how can compliance professionals actively cultivate curiosity in themselves and their teams? Here’s a roadmap to help you stay informed, ask better questions, and fill critical knowledge gaps.

Stay Informed on Industry Trends 

Regulatory landscapes are shifting faster than ever, with new challenges arising in artificial intelligence (AI), environmental, social, and governance (ESG) standards, and data privacy. Compliance professionals must proactively stay informed about these trends to keep their programs agile and relevant. Indeed, every Deferred Prosecution (DPA) includes language mandating awareness of other businesses in their industry and any compliance developments.

What are some of the action steps a compliance professional or CCO can take? If you are reading this blog post, it is an excellent first step. You can listen to one or more of the 50 podcasts on the Compliance Podcast Network. Both steps will put you on the cutting edge of the nuts and bolts of compliance. For topical compliance news and analysis, you can read well-known commentators such as Matt Kelly on Radical Compliance. You can read industry publications like Compliance Week or law firm or consulting firm newsletters on topical compliance issues. Focus on emerging areas like AI ethics, ESG enforcement actions, and updates to GDPR or other privacy frameworks.

Attending webinars and conferences are excellent opportunities to hear from industry leaders, regulators, and peers. These conferences include Ethisphere and Compliance Week in the spring and SCCE and ACI in the fall. These events provide real-time insights and practical strategies for addressing emerging risks. When you attend such events, you can often garner as much information by networking with your peers. You can also join professional organizations, such as SEEC, ACFE, ECI, and others, which often have online forums to exchange knowledge and share best practices with other compliance professionals.

By staying informed, you can anticipate changes before they disrupt your organization and position yourself as a forward-thinking compliance leader.

Ask Better Questions 

Compliance professionals are often tasked with identifying risks and making decisions under uncertainty. The quality of the questions you ask determines the depth of your understanding and the effectiveness of your solutions. Traditional compliance questions like “What’s the risk here?” are essential but can be limiting. To foster curiosity, you need to dig deeper and challenge assumptions.

What are some examples of better questions you can ask? Start with such basics as “What assumptions are we making, and how can we test them?” This question helps uncover blind spots in risk assessments or compliance strategies. Follow up with questions like “How does this risk evolve?” Understanding the lifecycle of a risk can help you develop proactive mitigation strategies. Always add this query to your repertoire: “What can we learn from other industries?” Exploring how different sectors handle similar challenges can inspire innovative solutions in your company.

You should work to apply all of this in your everyday compliance work. Start by encouraging your team to approach problems from multiple angles. Take your risk assessment, where you can consider not just the likelihood and impact of a risk but also the assumptions underlying those ratings. This mindset shift leads to more robust and effective compliance strategies.

 Fill Knowledge Gaps 

In the compliance field, the more you know, the more you realize how much you still need to learn. Recognizing and addressing knowledge gaps is a critical skill for any compliance professional. Think about compliance issues in some of the following ways: Reflect on your recent projects or decisions. Consider if there were times when you felt unsure or relied heavily on external experts. Keep track of emerging topics where you only have surface-level knowledge, such as ESG reporting requirements or AI regulations. Finally, do not be afraid to ask your team for feedback. They may identify areas where additional expertise could strengthen the program.

Encourage Curiosity in Your Team

Curiosity is not simply a personal trait but a cultural value that compliance leaders can cultivate within their teams. A curious team is more likely to challenge assumptions, identify risks early, and propose creative solutions. You do not have to send your team to conferences to foster curiosity. You can do that yourself by creating opportunities for cross-functional in-house learning. Invite experts from other departments, such as cybersecurity, ESG, or finance, to share insights during compliance meetings. This not only broadens your team’s knowledge but also strengthens cross-departmental collaboration.

Encourage “What If” scenarios by asking your team to imagine hypothetical scenarios and explore how they would address them. Such as, “What if we faced a cyber breach tomorrow?” or “What if a supplier violated ESG standards?” It can be a perfect starting point for you and your entire team. Finally, celebrate curiosity by recognizing and rewarding team members who ask insightful questions, propose innovative ideas, or learn about emerging risks. By embedding curiosity into your team’s culture, you empower them to think critically and proactively, enhancing the overall effectiveness of your compliance program.

Curiosity is a powerful tool that enhances professional growth and strengthens compliance programs’ resilience and adaptability. In 2025 and beyond, compliance leaders who embrace curiosity will be best positioned to navigate uncertainty, address emerging risks, and lead their organizations confidently.

Join us tomorrow as we explain why having a sense of humor may be the most important skill for surviving the new administration’s inevitable chaos.

Categories
Blog

Addressing Pre-taliation

One of the most talked about subjects in corporate compliance is the issue of pre-taliation—an increasingly common enforcement target by the U.S. Securities and Exchange Commission (SEC). Matt Kelly and I did a recent podcast on the topic, and you can check out the recent episode of Compliance Into the Weeds for an audio discussion of the topic. Matt has blogged on the topic of Radical Compliance. This post will deeply dive into this issue and show why pre-taliation clauses in contracts, which inhibit whistleblowers from claiming financial rewards, are illegal and how compliance officers can effectively address this recurring problem.

What Is Pre-Taliation?

Pre-taliation refers to contract provisions that prevent or discourage employees from reporting potential misconduct to regulators. Typically, these clauses claim an employee forfeits the right to financial rewards associated with whistleblowing. While companies cannot directly prohibit employees from reporting wrongdoing, they attempt to introduce barriers that dissuade individuals from taking the financial risk of blowing the whistle. These clauses have a “chilling effect” on potential whistleblowers and are, quite simply, illegal under SEC rules.

The SEC’s recent enforcement actions against several corporations show that despite being a known violation, many businesses continue to use these clauses in their employment contracts. The fines may be relatively small, but the impact of these enforcement actions is clear: companies must remove pre-taliation language from all contracts, or they will face the consequences.

Recent SEC Enforcement Actions on Pre-Taliation

Last week, the SEC sanctioned seven companies for including pre-taliation language in their employment contracts. One major violator, Acadia Healthcare Corporation, was fined $1.4 million, while others, including TransUnion and IDEX Corporation, paid penalties ranging from $19,000 to $690,000. While these fines may seem minor compared to other enforcement actions, the real issue lies in the recurring use of these illegal clauses.

For the compliance professional, the key is that these contracts stated that employees were free to report potential violations to regulators. Still, they included an additional clause that employees had to forfeit any right to claim whistleblower rewards. This approach violates SEC whistleblower provisions designed to incentivize whistleblowers with financial rewards for bringing misconduct to light.

Why Do Companies Use Pre-Taliation Clauses?

Companies continue to use such clauses to prevent them from going to the SEC or other regulators. Including pre-taliation language is an intentional tactic designed to scare employees into silence. These clauses are legally dubious, but they can effectively discourage employees from whistleblowing if they are unaware of their legal rights. The logic is simple: why risk your career and financial livelihood to report misconduct without potential financial reward?

In some cases, these companies may also be testing the boundaries of the law if regulators do not prioritize enforcement. However, as the SEC’s actions have shown, this is a serious miscalculation, as it is clear that using such clauses is intentionally trying to prevent employees from exercising their federal rights.

Addressing Pre-Taliation: A Compliance Officer’s Roadmap

How can compliance officers avoid falling into the same trap as Acadia Healthcare and others? Here’s a practical roadmap for compliance professionals tasked with eliminating pre-taliation clauses from their companies’ contracts:

  • Conduct a Contract Review

The first step is to conduct a comprehensive review of all employment contracts, both current and historical. This is easier said than done, particularly for large organizations with decentralized operations. As Matt Kelly pointed out, the challenge lies in the sheer volume of contracts and the number of people involved in drafting and approving them. Contracts may come from various teams—HR, legal, commercial, and even procurement—so identifying all instances of pre-taliation language requires a coordinated effort across multiple departments.

  • Establish Clear Contract Policies

The next step is establishing clear and enforceable policies about what can and cannot be included in contracts. This policy should be enterprise-wide and include specific language that prohibits the inclusion of pre-taliation clauses. Not only does this create a standard for new contracts, but it also sets a clear precedent for remediating older contracts that may still contain illegal language.

This policy should also include specific guidelines for all contracts, not just employment agreements, as pre-taliation clauses can sometimes slip into customer contracts, vendor agreements, and third-party relationships. For instance, earlier this year,  J.P. Morgan was penalized for including pre-taliation language in its customer contracts, which stipulated that customers had to notify the company before reporting misconduct to regulators.

  • Collaborate with Legal and HR Teams

A cross-functional approach is critical to solving this issue. Compliance officers must work closely with the legal and HR teams to implement contract policies correctly. HR plays a key role in drafting employment contracts, while the legal department ensures the language complies with regulatory standards. Without close collaboration, tracking down all the contracts that need to be updated or ensuring that future contracts are compliant will be nearly impossible. The idea that there is a magical person in the company who can fix this problem is a myth. Addressing pre-taliation requires a team effort involving multiple functions and a strong commitment to enterprise-wide remediation.

  • Provide Employee Education

Another important step is to educate employees about their rights under whistleblower laws. Pre-taliation language works best when employees do not understand that these clauses are illegal. By informing employees of their rights, compliance officers can undermine the chilling effect these clauses are designed to create. Employees should know they are legally entitled to report misconduct to regulators and cannot be penalized.

  • Establish a Remediation Plan for Older Contracts

Once all pre-taliation clauses have been identified, the next step is to establish a remediation plan. This may involve contacting former employees who signed contracts with illegal language and current employees who must be informed that their contracts have been updated. While this can be a complex process, it is essential for maintaining the integrity of the company’s compliance program.

  • Monitor for Future Violations

Finally, compliance officers should establish ongoing monitoring to ensure that pre-taliation language doesn’t slip into future contracts. This can be done by including contract reviews as part of regular compliance audits or by implementing automated tools to flag problematic language. By proactively monitoring contract language, compliance officers can prevent future violations and ensure that their company complies with SEC regulations.

A Simple Fix but a Complex Process

Addressing pre-taliation clauses may seem straightforward, but as Matt Kelly pointed out, it can be highly complex. With multiple stakeholders involved and various contracts to review, it truly takes a coordinated, enterprise-wide effort to eliminate these illegal provisions.

For compliance officers, the message is clear: do not wait for the SEC to come knocking. Review contracts, establish clear policies, and educate employees about their rights. By taking these steps, compliance officers can ensure that their companies are compliant and foster a culture where whistleblowers feel empowered to come forward. With the new DOJ Whistleblower Financial Incentive Program, it is only a matter of time before the DOJ comes knocking.

Categories
Blog

Bank of America Enforcement Action and Using Data Analytics

Data analytics has become an essential tool in the field of compliance and risk management. It allows compliance officers to assess the effectiveness of their programs and identify potential risks before they escalate into major issues. In a recent episode of the podcast “Compliance into the Weeds,” Tom Fox and Matt Kelly, discussed not only the importance of having data analytics in a compliance program but actually using the data in a risk management strategy.

The Consumer Financial Protection Bureau (CFPB) recently fined Bank of America $12 million for mishandling data analytics, specifically around accurate data about home mortgage applications. The bank had all the necessary data to assess its compliance risks, but it failed to maintain continuous monitoring, leading to compliance issues. This case serves as a reminder of the need for ongoing data analysis for proactive risk management.

The CFPB found that Bank of America violated the Home Mortgage Disclosure Act, a law on the around since the time I graduated from High School, that being 1975. The law itself requires mortgage lenders to collect demographic data about home loan applicants and report that data to various federal agencies. Bank of America settled the matter without admitting nor denying the allegation and agreed to the aforementioned $12 million fine.

As Matt noted in his Radical Compliance blog post, “Dig into the details of the settlement order, and you can see how data analytics, auditing, and monitoring all play a crucial role in assuring compliance with a regulation like this. Given that so many other business sectors have similar obligations to collect and report lots of data to regulators, maybe this case isn’t so obscure after all.”

The enforcement action drives home the clear lesson that data analytics is not a one-time tool to determine violations or identify risks. It should be used as a monitoring device that runs continuously to provide early warnings when risks enter the red zone. Bank of America’s mistake was treating data analytics as a one-time solution to a problem, rather than a long-term monitoring tool. They implemented analytics in 2013, found the error, introduced a control to correct it, and then switched it off when the problem seemed to be solved. However, the problem recurred, leading to the CFPB penalty.

As noted, is the high level of importance around surveillance and monitoring in the banking and financial services industry. These sectors have extensive monitoring and surveillance practices, recording every email and phone call to prevent improper messaging and manage risk. While this level of monitoring may seem draconian to other industries, it has proven effective in ensuring compliance and preventing fraud in those arenas.

The Bank of America case demonstrates that compliance officers often already have the necessary data for analysis; they just need to identify which information to study. In this case, the bank had all the data it needed to assess the compliance risk of information not provided in home loan applications. They implemented a monthly report to crack down on the abuse, resulting in a significant drop in the information not provided group. However, when they ceased the report in 2016, the rate started to increase again, ultimately leading to the violation and penalty.

The use of data analytics to monitor the effectiveness of controls was also a key lesson from the enforcement action. When Bank of America instituted monitoring to determine who was filling out the reports, they obtained significant information and saw a drop in the information not provided group. This strategy raises the stakes around the question of whether being watched or monitored can influence individuals to follow controls and do the right thing.

Data analytics should not only be used to analyze the effectiveness of compliance programs but also to analyze overall activity within an organization to identify compliance risks. Compliance officers should strive for analytics that run continuously, providing insights into the state of affairs over the long term. This approach allows for early detection of risks and enables business units to manage their own risks effectively.

The Bank of America case serves as a valuable lesson for compliance officers in any industry. It highlights the importance of ongoing data analysis, continuous monitoring, and the need to consider data analytics as a long-term risk management tool. By leveraging data analytics effectively, organizations can proactively identify and mitigate compliance risks, ultimately avoiding costly penalties and reputational damage.

Data analytics plays a crucial role in compliance and risk management. It enables compliance officers to assess program effectiveness, identify potential risks, and monitor activities for early warnings. The Bank of America case underscores the importance of continuous data analysis and monitoring in proactive risk management. By embracing data analytics as a long-term risk management tool, organizations can enhance their compliance efforts and safeguard against potential violations.

Categories
Blog

The Importance of Trust, Accountability, and Ethics in the Workplace

Trust, accountability, and ethics are fundamental pillars of a healthy and successful workplace. They form the foundation upon which organizations build strong relationships with their employees, customers, and stakeholders. In the most recent episode of the podcast “Compliance into the Weeds,” Tom Fox and Matt Kelly discussed the importance of these factors in light of a wrongful termination lawsuit filed against Citibank by a former employee.

The importance of trust, accountability, and ethics in the workplace cannot be overstated. These elements are the bedrock of a healthy corporate culture and are crucial for maintaining a positive and productive work environment. I believe that a broader conversation about these topics is necessary within corporations, with a need for employees to understand the importance of trust, accountability, and adherence to policies and procedures. While there is great cynicism that exists among the public and the workforce regarding ethical enforcement particularly when banks which have paid literally billions of dollars in fines are involved, it is up to each employee to commit to doing the right thing, even when it is difficult.

As Matt noted in a Radical Compliance blog post, “Our tale, first reported by the Financial Times, involves one Szabolcs Fekete, who had been an analyst with Citibank’s London offices since 2015. In July 2022 Fekete had to take a three-day business trip to Amsterdam. He took along his romantic partner for the trip, and while there he billed a coffee and sandwich for his partner to his corporate expense account. Except, Fekete tried to cover it up by submitting a receipt for two sandwiches and two coffees, all for him.” He was subsequently fired for dishonesty on an expense report and lying to his supervisor and investigators when questioned about his submitted expenses. While the amount in question may seem trivial, (less than €100) the case highlights the potential consequences of dishonesty, even in seemingly minor matters.

One of the key takeaways from this case is the significance of trust in the workplace. Trust is the cornerstone of any successful organization. It is the belief that individuals can rely on each other to act with integrity, honesty, and transparency. When trust is compromised, it can have far-reaching implications for the overall culture and effectiveness of the organization.

The case also underscores the importance of accountability. Accountability means taking responsibility for one’s actions and being answerable for the outcomes. In this case, Fekete’s dishonesty led to a breach of trust, and he was held accountable for his actions. Organizations must have clear corporate values, policies, and training programs in place to prevent unethical behavior and promote accountability among employees.

Ethics, too, play a crucial role in the workplace. Ethics refers to the moral principles that guide individuals’ behavior and decision-making. It is about doing the right thing, even when it may be difficult or inconvenient. The case of Fekete highlights the need for employees to have a genuine commitment to ethical conduct, even in situations where it may be tempting to cut corners or bend the rules.

Balancing these factors can be challenging. On one hand, organizations must establish a culture of trust and accountability, where employees feel empowered to act ethically and take responsibility for their actions. On the other hand, organizations must also have systems in place to detect and address unethical behavior, ensuring that trust is not misplaced.

The episode also raises the question of the impact of these factors on decision-making. When faced with ethical dilemmas, individuals and organizations must consider the potential consequences of their actions. One thing we have learned from Enron going forward, if someone is willing to break ethical rules at a minor level, it raises concerns about their integrity and the potential for more significant breaches in the future.

Yet there is another, more troubling aspect to this matter that compliance and ethics professionals must consider. Pilita Clark, also writing in the FT noted, “Except the response to this story has been anything but straightforward. Most striking of all is the level of derision directed not at Fekete but at Citi. At the time of writing, more than 500 people had digitally applauded one FT reader who wrote in response to the story: “You can’t lie in a bank, unless it’s a really big lie.”

Clearly folks are still not happy that large financial institutions paid billions in fines without seemingly missing a beat. Clark went on to write, “Some of the largest costs related to the 2007-2008 financial crisis, but big sums arose in more recent years, including $402mn in 2018 to settle the bank’s role in a conspiracy to manipulate foreign exchange markets. Citi was among 20 large banks that collectively paid more than £377bn in such costs between 2008 and 2018, as a result of mis-selling, money-laundering, market abuse and other” misdemeanors.

In conclusion, the importance of trust, accountability, and ethics in the workplace cannot be overstated. These factors form the bedrock of a healthy and ethical organizational culture. The case discussed in the podcast episode serves as a reminder of the potential consequences of dishonesty and the need for clear corporate values, policies, and training programs. It also emphasizes the importance of individual responsibility in maintaining an ethical workplace. By prioritizing trust, accountability, and ethics, organizations can create an environment where employees feel empowered to act with integrity and make ethical decisions, ultimately leading to long-term success.

Categories
Blog

Messaging App Compliance in Regulated Industries: Lessons from Recent Enforcement Actions

In recent years, regulated industries, particularly broker-dealer firms like Wells Fargo and Morgan Stanley, have faced increased scrutiny from regulatory bodies due to their lack of compliance in policing messaging apps. The Securities and Exchange Commission (SEC) recently announced charges against 10 firms in their capacity as broker-dealers and one dually registered broker-dealer and investment adviser for widespread and longstanding failures by the firms and their employees to maintain and preserve electronic communications. The firms admitted the facts outlined in their respective SEC orders. These firms collectively “agreed to pay combined penalties of $289 million and have begun implementing improvements to their compliance policies and procedures to address these violations.” Additionally, the Commodity Futures Trading Commission (CFTC) ordered four financial institutions to pay $260 million for recordkeeping and supervision failures due to the widespread use of unapproved communication methods.

Even more troubling is the involvement of senior managers in these misconducts, leading the SEC to require an independent compliance consultant in multiple settlements. This highlights the significance of overall corporate culture and the need for stricter compliance measures. Matt Kelly and I recently explored these enforcement actions, the reforms that companies must implement, the role of consultants in reviewing these reforms, and the potential risks and consequences of using messaging apps for business purposes in a Compliance into the Weeds podcast.

Reforms in regulated industries focus on policies and procedures, messaging policies, and employee training. Companies must establish clear messaging policies that outline the acceptable use of communication channels and the importance of recordkeeping obligations. Training employees on these policies and ensuring their understanding is equally vital. Additionally, companies must track training records and allegations of policy violations, making them readily available for review. Next, both ongoing monitoring and continuous improvement must be utilized. Finally, do not forget the need for disciplinary frameworks, with repeat offenders and senior employees potentially facing more severe discipline.

The enforcement crackdown by the SEC and CFTC has already resulted in significant penalties, with fines totaling a staggering $550 million. J.P. Morgan was the first bank to face such a settlement decree, setting a precedent for other banks. This raises speculation about whether the misconduct will continue and if there will be additional enforcement actions. While some large securities firms have yet to be targeted, all regulated industries must take note and proactively address compliance issues.

As noted above, using improper messaging apps for business communication is a significant concern for regulators. Moreover, these violations of securities laws occurred due to employees using ephemeral messaging apps like WhatsApp and Snapchat, which turn off record preservation. Once again, the involvement of supervisory employees and managers in using these apps is even more alarming, further angering the regulators. The SEC’s requirement for an independent compliance consultant in multiple settlements indicates a focus on corporate culture and the need to address senior managers’ involvement.

While these enforcement actions focused on regulated industries, it raises an important question about whether non-regulated industries could also face similar exposure to the SEC. The Justice Department has emphasized taking messaging and communication app risks seriously for all companies. Therefore, even if a company operates outside the purview of specific regulations, it is crucial to consider the potential risks and consequences of using improper messaging apps for business purposes. In a Radical Compliance blog post, Kelly noted, “That is a terrible look for a company. It paints the picture of a management team not interested in good ethical conduct, and we all know how that goes over with the Justice Department when evaluating the state of your compliance program.”

We desired to shed some light on the recent enforcement actions against regulated industries for their lack of compliance in policing messaging apps. The fines and penalties imposed by the SEC and CFTC highlight the seriousness of these violations. Companies must implement reforms, establish robust policies and procedures, and prioritize employee training to ensure compliance. The conversation also underscores the potential risks and consequences of using improper messaging apps for business communication. All companies must prioritize compliance and take proactive measures to address these concerns regardless of industry. By doing so, companies can foster a culture of integrity and avoid the hefty fines and reputational damage associated with non-compliance.

Categories
Blog

Auditing AI

The recent kerfuffle over an AI tool misinterpreting instructions to make a woman look more professional as making her look Caucasian has raised important questions about how to audit AI code to avoid undesirable outcomes. AI instruments are behaving in a fundamentally different way than most other types of apps and systems, and auditing AI code for implicit bias is not yet feasible. Matt Kelly recently wrote a blog post on this topic on Radical Compliance. I thought it would make a great podcast so this week’s episode of Compliance into the Weeds is dedicated to it. I also thought it was so important that I should blog about it as well.

It started when MIT grad student Rona Wang tested an AI tool called Playground AI to modify a photo of herself wearing an MIT T-shirt to look ‘more professional’. Rather than replacing the T-shirt she was wearing with more professional business attire to achieve a more professional look, the AI tool interpreted the instruction to make her look more professional as making her look Caucasian. Wang posted a before and after comparison of her photo on Twitter, which caused a big kerfuffle in the AI world about how this happened. The CEO of Playground AI responded to Wang on Twitter saying “We’re quite displeased with this and hope to solve it”.

We began with a discussion of the implications of implicit bias in AI code. Matt suggested that the code in the AI app may have been influenced by the disproportionate number of white people on LinkedIn. It may not be the fault of the AI program, but rather a result of structural bias and racism in the world. Matt believes that at this point, it is impossible for a human to audit the code of AI programs like Chat GPT, which evaluates data according to 1.76 trillion different parameters. Unfortunately, it is not possible to eliminate implicit bias in AI code by simply correcting a few parameters. Matt compared it to the difficulty of eliminating implicit bias in AI code to the difficulty of eliminating racism in the human brain.

AI can handle 1.7 trillion parameters of data, but it is difficult to audit for an ethical outcome. AI can misinterpret structural racism and inequities that exist in the world. AI can be used to filter out images that are not representative of the population as a whole. Auditing AI is difficult because there are few people who know how to design and audit these programs. AI decisions may have life and death consequences, but there is no way to audit them yet.

Companies using AI in the hiring process must consider whether they will scrap the AI tool and use another, use human HR people and recruiters, or have auditors and coders sit down and try and figure out the problem. Additionally, there is a risk of implicit bias when someone must define the pool of data that the AI is looking at. New York City has a regulation requiring employers to audit AI tools used in the hiring process at least annually, but this is only a small step towards addressing the issue of implicit bias in AI.

Auditing AI code for implicit bias is a complex process. AI tools used in the hiring process can range from keyword matching to Chat GPT. While it is important for companies to audit their AI tools, it is also important to consider the data that is being used to train the AI. If the data is biased, the AI will be biased as well. To ensure that AI tools are not biased, companies should consider using a diverse set of data and conducting regular audits of the AI tools.

The Wang incident over an AI tool misinterpreting instructions to make a woman look more professional as making her look Caucasian is a reminder of the importance of auditing AI code to avoid undesirable outcomes. AI instruments are behaving in a fundamentally different way than most other types of apps and systems, and auditing AI code for implicit bias is not yet feasible. Companies using AI in the hiring process must consider whether they will scrap the AI tool and use another, use human HR people and recruiters, or have auditors and coders sit down and try and figure out the problem.

Finally, there is a risk of implicit bias when someone has to define the pool of data that the AI is looking at. New York City has a regulation requiring employers to audit AI tools used in the hiring process at least annually, but this is only a small step towards addressing the issue of implicit bias in AI. To ensure that AI tools are not biased, companies should consider using a diverse set of data and conducting regular audits of the AI tools.

For the complete discussion of this issue check out this week’s episode of Compliance into the Weeds.

Categories
Blog

Danske Bank: Part 5 – Final Thoughts

Over the past several blog posts, we have been exploring the Danske Bank A/S (Danske Bank), AML enforcement action in which Danske Bank pled guilty and agreed to forfeit $2 billion to resolve the US investigation into its fraud on US banks. Danske Bank also settled with the Securities and Exchange Commission (SEC) for misleading US investors about the bank’s anti-money laundering (AML) compliance program in its Estonian branch and failed to disclose the risks posed by the program’s significant deficiencies.

Banks Still Behaving Badly

According to Violation Tracker, the top 10 banks for fines and penalties for this century are as follows:

TOP 10 CURRENT PARENT COMPANIES TOTAL PENALTY $ NUMBER OF RECORDS
Bank of America $83,354,221,356 271
JPMorgan Chase $36,129,286,132 223
Citigroup $25,740,655,365 159
Wells Fargo $22,081,458,643 229
Deutsche Bank $18,541,562,802 79
UBS $17,082,743,334 106
Goldman Sachs $16,603,475,848 90
NatWest Group PLC $13,515,546,857 31
Credit Suisse $11,427,400,126 52
Morgan Stanley $10,167,765,234 190

In 2022, the top fines involving banks are:

  • Danske Bank: $2.4 billion
  • Bank of America: $225 million
  • Citigroup: $200 million
  • Goldman Sachs: $200 million
  • Morgan Stanley: $200 million
  • Credit Suisse: $200 million
  • Barclays: $200 million
  • Deutsche Bank: $200 million
  • Nomura: $100 million

For whatever reason, banks cannot seem to get it anything near right. Willie Sutton is alleged to have said the reason he robbed banks was because “that’s where the money was.” Now it seems the banks are the bad guys, and the regulators continually have to lay out what seems massive fines and penalties to banks. Yet banks seem oblivious to playing within the bounds of the law. Perhaps, and to broaden out Consumer Financial Protection Bureau (CFPB) head Rohit Chopra’s statement announcing the latest fine against a bank, Wells Fargo at $3.7 billion “Wells Fargo’s rinse-repeat cycle of violating the law” needs to be updated to banks “rinse-repeat cycle of violating the law.”

M&A Double Trouble

Purchasing a corrupt entity is certainly one thing but allowing it to stay corrupt is quite another. As I often say, if an acquisition target engaged in bribery and corruption, or indeed money-laundering, before you acquired them and continue to do so after said purchase; it is not them but you who are now breaking the law. When Danske Bank purchased the branch that became Danske Estonia, it was aware that a substantial portion of the Estonian branch’s customers were “non-residents of Estonia, a group of accounts known as the Non-Resident Portfolio or “NRP” and that many of the NRP customers were from Russia and other former Soviet-bloc countries. These NRP customers’ practices included well-known red flags for potential money laundering: for example, frequent use of offshore LLPs and nominee directors to obscure or conceal beneficial ownership information, use of unregulated intermediaries to carry out transactions on behalf of unknown clients, and ties to jurisdictions with enhanced money laundering risks. Some of these practices were known to Danske in 2007.”

But here is where Danske Bank sealed its fate. As detailed by Matt Kelly in Radical Compliance, calling it the “fatal mistake by bank leadership”; and as laid out in the Plea Agreement, “Danske Bank canceled the migration to the central technology system because the executive board, consisting of Danske Bank senior executives, concluded it would “simply be too expensive” and could cause irregularities.” This allowed Danske Estonia to “maintain its own antiquated IT systems, with no automated customer due diligence or transaction monitoring — simply because bringing the Estonia branch up to acceptable compliance standards would be too expensive. Danske leaders didn’t have the requisite commitment to effective compliance, and from there its AML troubles flowed.”

Money, Money, Money

Perhaps the biggest problem for Danske Bank was the one in the mirror and its addiction to the filthy lucre generated by its Estonia Branch. Both Danske Bank itself and the regulatory authorities made clear the actual AML failures which were ongoing. According to the SEC Order, in “February 2014, Danske hired an external, independent third party to conduct a limited review of Danske Estonia’s AML practices” who concluded into only two months that there were “numerous AML deficiencies that left Danske Estonia highly susceptible to money laundering, including 17 identified as “critical or significant” control deficiencies. Danske’s legal department recommended and retained a third party to conduct a comprehensive internal investigation of Danske Estonia’s customers and transactions and to investigate allegations of employee misconduct. However, Danske senior management canceled the contract and decided to conduct the investigation internally. An internal Danske working group conducted only limited additional investigation of Danske Estonia at that time.”

The regulators identified the illegal issues as well. The Estonia FSA conducted a series of examinations at Danske Estonia and provided a draft report to Danske Estonia which detailed extensive facts concerning willful violations of Estonian AML law by Danske Estonia employees. The report stated, “Danske systematically establishes business relationships with persons in whose activities it is possible to see the simplest and most common suspicious circumstances” and concluded that Danske Estonia systematically ignored Estonian AML law. Danske acknowledged the severity of the Estonian FSA’s findings in communications, including one in which a Danske manager stated, “It is a total and fundamental failure in doing what we should do and doing what we claim to do. This just even more underline[s] the need of full clean up now.” [Emphasis added.] Another manager stated, “The executive summary of the . . . letter is brutal to say the least and is as close to the worst I have ever read within the AML/CTF area. . . . [I]f just half of the executive summary is correct, then this is much more about shutting all non-domestic business down than it is about KYC procedures . . . .” Nonetheless, instead of terminating the NRP business, Danske management opted to continue it because of the profits it generated.” [emphasis in original]

So, we leave this sordid saga of the US DOJ and SEC bringing an AML enforcement action against a Danish bank. At least the US is willing to bring such an enforcement action.