Tom Fox is the Compliance Evangelist and is universally recognized as one of the top experts in corruption compliance, literally across the globe. In this daily podcast series, he explains how to design, create and implement a best practices compliance program. Each month, he tackles a different area of compliance. From Internal Controls, to the Role of the Board of Directors, to Communication, to the Role of HR in Compliance, Investigations, 3rd Parties and Business Ventures. Listen in each day and get one tip you can implement at little or no cost to enhance your compliance program.
31 Days to a More Effective Compliance Program
Day 21 - Managing 3rd Parties
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
On Day 21 of our series, we dive into the essential strategies for managing third-party relationships in a compliance program. We consider the significance of a structured and strategic approach in handling third parties to mitigate anti-corruption risks. As companies mature, the operationalization of compliance through third-party management becomes crucial. Key areas explored include the importance of dual and diversified sourcing, monitoring subcontractors, legal protections, and financial stability checks. Additionally, we cover the necessity of integrating performance-based compensation and regular auditing to uphold compliance standards. Join us tomorrow as we explore levels of due diligence on Day 22.
Key highlights:
- Strategic Approach to Third-Party Relationships
- Auditing and Ongoing Management
- Key Takeaways
Resources:
Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less31 Days to a More Effective Compliance Program: Day 21 - Managing Your Third Parties
The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and complia...
Read moreThe building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance programs, the issue of third-party management becomes more important. It is also the one where the rubber meets the road of operationalizing compliance. It is also an area the DOJ specifically articulated in the 2023 ECCP that companies need to consider.
Managing your third parties is where the rubber meets the road in your overall third-party risk manage program. You must execute on this task. Even if you successfully navigate the first four steps in your third-party risk management program, those are the easy steps. Managing the relationship is where the real work begins.
Three key takeaways:
1. Have a strategic approach to third-party risk management.
2. Rank third parties based upon a variety of factors including compliance and business performance, length of relationship, benchmarking metrics and KPIs for ongoing monitoring and auditing.
3. Managing the relationship is where the real work begins.
For more information on Ethico and a free White Paper on top compliance issues in 2024, click here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessDay 20 - Third-Party Risk Management Process
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
On Day 20, we delve into the third-party risk management process, a crucial aspect of corporate compliance under the FCPA. Third parties continue to pose the highest risk, necessitating an integrated and operational approach throughout the company. The episode outlines the five essential steps in the third-party risk management life cycle, as mandated by the DOJ in the 2020 FCPA Resource Guide. These steps include business justification, third-party questionnaires, due diligence, compliance terms and conditions, and post-contract management and oversight. Each step is explored in detail, emphasizing the importance of documenting business cases, performing thorough due diligence, and maintaining diligent oversight to mitigate potential FCPA violations. Key takeaways include the necessity of using the full five-step process, involving business development and ensuring all steps are operationalized with business unit representatives. Join us tomorrow for Day 21 to discuss managing your third parties.
Key highlights:
- Introduction to Third Party Risk Management
- The Five Steps of Third-Party Risk Management
- Key Takeaways
Resources:
Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less31 Days to a More Effective Compliance Program: Day 20 – The Third Party Risk Management Process
The DOJ expects an integrated approach that is operationalized throughout the company. This means you must have a process for the full life cycle of third-party risk management. There are five steps in the life cycle of third-party risk management that will fulfill the DOJ requirements as laid out i...
Read moreThe DOJ expects an integrated approach that is operationalized throughout the company. This means you must have a process for the full life cycle of third-party risk management. There are five steps in the life cycle of third-party risk management that will fulfill the DOJ requirements as laid out in the 2023 FCPA Resource Guide, 2nd edition, and in the Hallmarks of an Effective Compliance Program. The five steps in the lifecycle of third-party management are:
1. Business Justification by the Business Sponsor.
2. Questionnaire to Third-party.
3. Due Diligence on the Third Party.
4. Compliance Terms and Conditions, including payment terms.
5. Management and Oversight of Third Parties After Contract Signing.
Three key takeaways:
1. Use the full 5-step process for third-party management.
2. Make sure you have business development involvement and buy-in.
3. Operationalize all steps going forward by including business unit representatives.
For more information on Ethico and a free White Paper on top compliance issues in 2024, click here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessDay 19 - Evaluating Risk Assessments
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
In today’s episode, we review the critical process of evaluating and translating risk assessments into actionable risk profiles. The discussion highlights the importance of prioritizing risks based on their significance and likelihood using risk matrices and heat maps. Expert insights from Ben Locwin and Bill Anathas emphasize focusing resources on high-risk employees and maintaining a robust compliance program aligned with FCPA guidelines. The episode also covers the Treasury Department’s OFAC compliance framework and offers concrete steps for continuous risk monitoring and remediation. Key takeaways include the necessity of a well-reasoned approach to risk evaluation, thorough documentation, and the implementation of a dynamic risk matrix to guide compliance efforts.
Key highlights:
· Understanding Risk Profiles
· Evaluating Risk Management Processes
· Risk Matrix and Heat Maps
Resources:
Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less31 Days to a More Effective Compliance Program: Day 19 - Evaluating a Risk Assessment
One way to evaluate risks as determined by the company’s risk assessment is through a risk matrix. Once risks are identified, they are then rated according to their significance and likelihood of occurring and then plotted on a heat map to determine their priority. The most significant risks wi...
Read moreOne way to evaluate risks as determined by the company’s risk assessment is through a risk matrix. Once risks are identified, they are then rated according to their significance and likelihood of occurring and then plotted on a heat map to determine their priority. The most significant risks with the greatest likelihood of occurring are deemed the priority risks, which become the focus of your remedial efforts or for continuous auditing. A variety of solutions and tools can be used to manage these risks going forward, but the key step is to evaluate and rate these risks. All your actions should flow from the risk ranking.
The most significant risks with the greatest likelihood of occurring are deemed to be the priority risks. These become the focus of your most significant risk management efforts, coupled with audits and monitoring going forward. A variety of tools can be used to continuously monitor risk going forward. Consider providing employees with substantive training to guard against the most significant risks coming to pass and to keep the key messages fresh and top of mind. It is important to create a risk control summary that succinctly documents the nature of the risk and the actions taken to mitigate it. Finally, let this risk assessment and evaluation inform your compliance program, rather than letting the compliance program inform the risk assessment.
Three key takeaways:
1. Even after you complete your risk assessment, you must evaluate those risks for your company.
2. The DOJ and SEC are looking for a well-reasoned approach to how you evaluate your risk.
3. Create a risk matrix and rank your risks; then remediate and monitor as appropriate.
For more information on Ethico and a free White Paper on top compliance issues in 2024, click here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessDay 18 - Risk Assessments
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
In this episode, we discuss the essential role of risk assessments in anti-corruption compliance programs. A well-structured risk assessment forms the foundation of every corporate compliance program. We explore how organizations should identify, assess, and define their risk profiles, emphasizing the need for annual risk assessments whenever business risks change. The focus then shifts to geopolitical issues, supply chain dynamics, and evolving work environments and how these should be factored into compliance risk assessments. Historical perspectives from DOJ guidelines and the importance of a robust risk identification, analysis, and management methodology are also discussed. As highlighted, documenting these processes is crucial for developing an effective compliance strategy that evolves with the company’s risk landscape. Finally, the episode outlines the steps to create a comprehensive risk management strategy post-assessment, including policy development, training, monitoring, and updating protocols.
Key highlights:
- The Importance of Regular Risk Assessments
- Methodologies for Risk Assessment
- Steps in Conducting a Risk Assessment
Resources:
Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less31 Days to a More Effective Compliance Program - Day 18 - Risk Assessments
One cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based on a risk assessment, on an understanding of your organization’s business from a commercial perspective, on how your organization has i...
Read moreOne cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based on a risk assessment, on an understanding of your organization’s business from a commercial perspective, on how your organization has identified, assessed, and defined its risk profile, and, finally, on the degree to which the program devotes appropriate scrutiny and resources to this range of risks. The 2023 ECCP added a new emphasis on the cadence of Risk Assessments, mandating that risk assessments should be done not less than annually, but in reality, they should be done each time your risk changes. Over the past couple of years, every company’s risks have changed from going to Work From Home to Return to the Office to the Hybrid Work environments of 2024. What about geopolitical issues, the supply chain, or even potential compliance risks in the 2024 election cycle? Have you assessed each of these new paradigms for risks from a compliance perspective?
There are a number of ways you can slice and dice your basic inquiry. As with almost all FCPA compliance, it is important that your protocol be well thought out. If you use one, some, or all of the above as your basic inquiries for your risk analysis, it should be acceptable as your starting point.
Three key takeaways:
1. Since at least 1999, the DOJ has pointed to the risk assessment as the start of an effective compliance program.
2. The DOJ will now consider both your risk assessment methodology for identifying risks and the gathered evidence.
3. You should base your compliance program on your risk assessment.
For more information on Ethico and a free White Paper on top compliance issues in 2024, click here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessOne Month to a More Effective Compliance Program: Day 18-Strategic Considerations for Implementing AI in Compliance
What are the key factors that impact these strategic considerations for implementing AI in compliance, exploring the tradeoffs, challenges, and importance of considering the impact on decision-making.
Key Considerations
1. Understand the impact of AI on the company.
2. Maintain a...
What are the key factors that impact these strategic considerations for implementing AI in compliance, exploring the tradeoffs, challenges, and importance of considering the impact on decision-making.
Key Considerations
1. Understand the impact of AI on the company.
2. Maintain an inventory of all tools used.
3. Understand the tools for cost efficiency and risk avoidance.
4. Involve all business sectors in AI discussions.
5. Utilize AI for better data usage in compliance.
While implementing AI in compliance brings numerous benefits, there are tradeoffs and challenges to consider. One tradeoff is the need to balance exploration and innovation with rules and regulations. Another challenge is the selection of AI tools.
Implementing AI in compliance requires strategic considerations and decision-making. Understanding the impact of AI, maintaining an inventory of tools, considering cost efficiency and risk avoidance, involving all business sectors, and utilizing AI for better data usage are key factors to consider. Balancing exploration and rules, as well as selecting the right AI tools, are challenges that need to be addressed. By carefully navigating these considerations and challenges, companies can leverage AI to enhance their compliance programs and stay ahead in an ever-evolving regulatory landscape.
Three key takeaways:
1. What are the key factors that impact these strategic considerations for implementing AI in compliance?
2. Compliance professionals need to stay updated with the latest AI developments and trends, which requires continuous learning and keeping abreast of industry news and insights.
3. Understanding the impact of AI, maintaining an inventory of tools, considering cost efficiency and risk avoidance, involving all business sectors, and utilizing AI for better data usage are key factors to consider.
For More information on KonaAI, click here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessDay 17 - Podcasting for Compliance
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
In this episode, we explore the transformative potential of podcasting in compliance training and fostering corporate culture. Harnessing the power of imaginative communication methods, we discuss the effectiveness of delivering compliance messages and training through various podcast formats. We revisit the 2012 Morgan Stanley declination to underscore the impact of consistent compliance reminders and venture into how short ethics and compliance video clips and storytelling podcasts can enhance employee engagement and regulatory satisfaction.
These podcasts are standalone training tools and can be broadcast through social media, creating a larger reach and providing valuable feedback through listener engagement metrics. Additional formats discussed include a branded podcast series featuring longer episodes that humanize compliance topics through interviews and a daily compliance news show to keep employees informed and engaged. This episode emphasizes the importance of innovative storytelling in making compliance communications memorable and effective.
Key highlights:
· Podcast Storytelling: A New Approach
· Branded Podcast Series for Compliance
· The Benefits of Podcasting for Compliance
Resources:
Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less