31 Days to a More Effective Compliance Program

Tom Fox is the Compliance Evangelist and is universally recognized as one of the top experts in corruption compliance, literally across the globe. In this daily podcast series, he explains how to design, create and implement a best practices compliance program. Each month, he tackles a different area of compliance. From Internal Controls, to the Role of the Board of Directors, to Communication, to the Role of HR in Compliance, Investigations, 3rd Parties and Business Ventures. Listen in each day and get one tip you can implement at little or no cost to enhance your compliance program.

31 Days to a More Effective Compliance Program

100 Episodes Available
Episode 15

One Month to a More Effective Compliance Program Through Innovation: Day 15 – Leveraging AI in Compliance Investigations

6.03 min Aug 12, 2025

The 2023 ECCP provided clear-cut criteria regarding effective compliance investigations. Unfortunately, many compliance teams fail to promptly substantiate most of the reports they investigate, partly due to their inability to quickly and easily find the evidence they need, especially about harassme...

Read more

The 2023 ECCP provided clear-cut criteria regarding effective compliance investigations. Unfortunately, many compliance teams fail to promptly substantiate most of the reports they investigate, partly due to their inability to quickly and easily find the evidence they need, especially about harassment and misconduct cases. He stated, “This doesn’t just demonstrate a fundamental lack of effectiveness from the DOJ’s perspective, but a long-term organizational risk that goes well beyond any individual allegation of misconduct.” The reason is not simply legal but also operational. If substantive allegations are indeed violations, they could continue, exacerbating the problem(s) and lengthening the time of legal liability.

All of this is particularly significant in light of the industry research that shows many compliance investigations today are unsubstantiated and can take over 40 days from start to finish. The ability of AI to find and analyze data from the web and social media in this automated fashion will be able to overcome some of those challenges in terms of length of time and overall scope of the investigation. Finally, always remember data preservation. The regulators always want to know if you have the documents and data tied down. This allows a company to have confidence in its papers and, in turn, can make such representations to regulators and prosecutors that the documents are secure. In other words, Document, Document, and Document. 

Three key takeaways:

  1. AI is an appropriate tool for supplementing investigations.
  2. AI can look at large bodies of social media data.
  3. AI can help you decrease your investigation length.

For more information, check out The Compliance Handbook, 4th edition, here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 14

31 Days to a More Effective Compliance Program: Day 14 - Internal Controls

7.21 min Mar 1, 2024

What are internal controls? The best definition I have come across is from Jonathan Marks, partner at BDO, who defined internal controls as:
An internal control is an action or process of interlocking activities designed to support the policies and procedures detailing the specific preventative, det...

Read more

What are internal controls? The best definition I have come across is from Jonathan Marks, partner at BDO, who defined internal controls as:

An internal control is an action or process of interlocking activities designed to support the policies and procedures detailing the specific preventative, detective, corrective, directive, and corroborative actions required to achieve the desired process outcomes or objectives. This, along with continuous auditing, continuous monitoring, and training, reasonably assures:

• The achievement of the process objectives linked to the organization’s objectives;

• Operational effectiveness and efficiency;

• Reliable (complete and accurate) books and records (financial reporting);

• Compliance with laws, regulations and policies; and

• The reduction of risk fraud, waste, and abuse, which aids in the decline of process and policy variation, leading to more predictive outcomes.

The bottom line is that internal controls are just good financial controls. The internal controls that detail requirements for third-party representatives in the compliance context will help to detect fraud, which could well lead to bribery and corruption. As an exercise, map your existing internal controls to the Hallmarks of an Effective Compliance Program or some other well-known anti-corruption regime to see where gaps may exist. This will help you determine whether adequate internal compliance controls are present in your company. From there, you can move on to see if they are working in practice.

 

Three key takeaways:

1. Effective internal controls are required under the FCPA

2. Internal controls are a critical part of any best practices compliance program

3. There are four significant controls for the compliance practitioner to implement initially. (a) Delegation of authority (DOA); (b) Maintenance of the vendor master file; (c) Contracts with third parties; and (d) Movement of cash or currency

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 14

One Month to a More Effective Compliance Program Through Data Analytics: Day 14 - Continuous Converged Compliance

6 min Aug 12, 2025

How can you integrate compliance, risk management, and your security framework? Igor Volovich, Vice President, Compliance Strategy at Qmulos, introduced the innovative concept to this discussion: Converged Continuous Compliance. This approach aims to reunite compliance, security, and risk management...

Read more

How can you integrate compliance, risk management, and your security framework? Igor Volovich, Vice President, Compliance Strategy at Qmulos, introduced the innovative concept to this discussion: Converged Continuous Compliance. This approach aims to reunite compliance, security, and risk management, which have historically operated independently.

One of the key requirements impacting this new approach is the need to bridge the gap between these functions from both a data and human perspective. These concepts serve as a translator, helping organizations navigate the complex landscape of compliance, security, and risk management. By speaking the language of these three functions, Converged Continuous Compliance brings them together and facilitates collaboration.

Corporate compliance needs to promote new approaches to compliance and risk management by challenging misconceptions, reuniting compliance, security, and risk management, emphasizing data governance oversight, and advocating for automation. These approaches aim to enhance efficiency, increase trust in compliance reports, and ultimately drive a greater return on investment. As organizations navigate the ever-evolving landscape of compliance, it is crucial to consider the impact of new approaches and strike a balance between different factors to achieve effective compliance and risk management.

 Three key takeaways:

  1. The DOJ has stated that a chief compliance officer and a corporate compliance function must have visibility across all data sets in an organization. Converged Continuous Compliance aligns with this message.
  2. The bottom line is that we have accepted certain models of how compliance is done, what compliance means, what it delivers to the enterprise, and what it fails to deliver to the enterprise.
  3. It is crucial to consider the impact of new approaches and strike a balance between different factors to achieve effective compliance and risk management.

For more information on KonaAI, click here

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 14

One Month to a More Effective Compliance Program Through Culture: Day 14 - How Investigative Triage Can Drive Culture

5.85 min Aug 12, 2025

One area that organizations rarely consider impacting culture is the assessment and triage process in a hotline or speak up process. A proactive approach allows for increased response time and the ability to set realistic expectations for stakeholders, but this is a key component for improving corpo...

Read more

One area that organizations rarely consider impacting culture is the assessment and triage process in a hotline or speak up process. A proactive approach allows for increased response time and the ability to set realistic expectations for stakeholders, but this is a key component for improving corporate culture. One mechanism not thought of by compliance professionals is the setting of service level agreements (SLAs) to set response times based on the nature of the allegation. This concept, borrowed from customer service practices, ensures that employees who come forward with complaints or allegations are provided with a clear understanding of the expected timeline for response and communication. By setting these expectations, organizations can foster a culture of open communication and trust.

Obviously a triage process is particularly important for multinational companies that operate across different regions. With varying compliance programs and regulations in different countries, having a well-documented process becomes essential. It allows compliance departments to navigate the complexities of compliance programs and investigations, ensuring consistency and adherence to local laws.

The triage process and technology play a vital role in promoting a corporate culture and. By proactively assessing and triaging complaints and allegations, organizations can increase response time and set realistic expectations for stakeholders. It is important to consider the impact on employee rights and the need for thorough investigations when making decisions about the importance of triage process and technology in organizational compliance.

 Three key takeaways:

1. Think about how your triage process can be used to foster culture.

2. Set Service Level Agreements, make them public and adhere to them to engender trust in your organization.

3. However, it is important to recognize the tradeoffs involved in balancing different factors when implementing a triage process.

Do you want to improve your culture? How can you assess your culture and develop a strategy to improve it going forward? In this free webinar on the new tool, The Culture Audit with Tom

Fox and Sam Silverstein on Tuesday, November 28, 12 CT. For more information and registration, click here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 14

One Month to A More Effective Compliance Program Through Innovation: Day 14 – Creating an Inventory of Metrics

6.43 min Aug 12, 2025

The 2023 ECCP not only continued to emphasize the importance of monitoring and testing the effectiveness of a compliance program, but it spoke more about a Chief Compliance Officer (CCO) and compliance function utilizing data to engage in continuous monitoring and continuous improvement. For some ti...

Read more

The 2023 ECCP not only continued to emphasize the importance of monitoring and testing the effectiveness of a compliance program, but it spoke more about a Chief Compliance Officer (CCO) and compliance function utilizing data to engage in continuous monitoring and continuous improvement. For some time, the DOJ has stressed the importance of leveraging data to have objective evidence around whether or not a compliance program is working effectively. Yet, as many CCOs are legally trained, they are still determining what specific areas to consider in establishing quantifiable metrics to monitor for effectiveness.

A methodical review of the 2023 ECCP to identify the different areas where a company could establish and quantify metrics to assess effectiveness is the place to start. Many companies have what Edwards called “metrics on the basics” and noted they “have in place processes whereby their employees review the Code of Conduct and confirm they comply with it either when they first onboard with the company and then periodically on an annual basis, companies are doing just fine at reporting.” But it is now the barest minimum of what compliance professionals must do. For instance, they could consider Quote To Cash (QTC) lifecycles or Procure To Pay (P2P). The key starts with a documented process that can be audited and built from there.

Three key takeaways:

  1. Create an inventory of compliance metrics.
  2. Create your metrics based on the 2023 ECCP.
  3. Use these metrics for continuous monitoring and improvement.

For more information, check out The Compliance Handbook, 4th edition, here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 13

Day 13 - Policies and Procedures

7.06 min Dec 1, 2025

Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...

Read more

Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.

In this episode, we review the importance of having well-crafted compliance policies and procedures as the foundation of a robust compliance program. As highlighted by the 2024 ECCP and 2020 FCPA Resource Guide, such policies and procedures are crucial for addressing and mitigating risks identified during a company’s risk assessment. Regulators emphasize having articulated anti-bribery and anti-corruption policies regularly reviewed and updated to reflect evolving risks. We discuss the five general elements of a compliance policy and underscore the need for consistent implementation to maintain the credibility and effectiveness of the compliance program. Key takeaways include the necessity of written policies, expectations from the DOJ and SEC, and the critical role of institutional fairness.

Key highlights:

  • Importance of Compliance Policies
  • Key Elements of Compliance Policies
  • Assessment and Evolution of Policies

Resources:

Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 13

Day 31 to a More Effective Compliance Program: Day 13-Policies and Procedures

7.13 min Mar 1, 2024

There are numerous reasons to put some serious work into your compliance policies and procedures. They are certainly a first line of defense when the government comes knocking. The 2023 ECCP made clear that “Any well-designed compliance program entails policies and procedures that give both conten...

Read more

There are numerous reasons to put some serious work into your compliance policies and procedures. They are certainly a first line of defense when the government comes knocking. The 2023 ECCP made clear that “Any well-designed compliance program entails policies and procedures that give both content and effect to ethical norms and that address and aim to reduce risks identified by the company as part of its risk assessment process.” This statement made clear that the regulators will take a strong view against a company that does not have well thought out and articulated policies and procedures against bribery and corruption; all of which are systematically reviewed and updated. Moreover, having policies written out and signed by employees provides what some consider the most vital layer of communication and acts as an internal control. Together with a signed acknowledgement, these documents can serve as evidentiary support if a future issue arises. In other words, the “Document, Document, and Document” mantra applies just as strongly to policies and procedures in anti-corruption compliance.

 Three key takeaways:

1. Written compliance policies and procedures, together the Code of Conduct, with form the backbone of your compliance program.

2. The DOJ and SEC expect a well-thought out and articulated set of compliance policies and procedures and that they be adequately communicated throughout your organization.

3. Institutional fairness for the application of policies and procedures demands consistent application of your policies and procedures across the globe.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 13

One Month to a More Effective Compliance Program Through Data Analytics: Day 13 - Data Management Automation

6 min Aug 12, 2025

Data automation not only streamlines the compliance process but also provides transparency and visibility into the decision-making process. There is a clear importance to connecting people, data, process systems, and tools in one place. This eliminates the need for compliance officers to navigate mu...

Read more

Data automation not only streamlines the compliance process but also provides transparency and visibility into the decision-making process. There is a clear importance to connecting people, data, process systems, and tools in one place. This eliminates the need for compliance officers to navigate multiple systems and tools, allowing them to focus on risk-based due diligence. By having a clear understanding of the decision tree and the ability to adjust the automation process, organizations can trust the automation while maintaining control and oversight.

The importance of automation for data analysis in compliance programs cannot be overstated. Organizations need to have visibility into their data at their fingertips to ensure regulatory compliance and mitigate risks. Automation streamlines the compliance process, provides transparency, and allows for adaptability in the face of evolving regulations and risks. By leveraging data analysis, organizations can identify deviations, improve cycle times, enhance training effectiveness, and make informed decisions. Board-level involvement is crucial in overseeing the automation and data analysis process, recognizing its strategic value, and ensuring its effective implementation. With the advent of AI and intelligent approaches, organizations that do not embrace automation and data analysis may suffer in the long run. Trust but verify, and always prioritize visibility and transparency in compliance programs.

 Three key takeaways:

  1. Automation not only streamlines the compliance process but also provides transparency and visibility into the decision-making process.
  2. There is a need for board-level involvement in overseeing the automation and data analysis processes.
  3. Through analyzing deviations from the expected path, compliance officers can identify areas that require additional process controls or adjustments.

Check out KonaAI here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 13

One Month to a More Effective Compliance Program Through Innovation: Day 13 – Consistency as a Compliance Best Practice

6.47 min Aug 12, 2025

The 2023 ECCP emphasized the need for the corporate compliance function to ensure consistency and fairness in monitoring investigations and the resulting discipline. One of the ways the 2020 Update emphasized this was through tracking the investigations and the discipline that may come out of any in...

Read more

The 2023 ECCP emphasized the need for the corporate compliance function to ensure consistency and fairness in monitoring investigations and the resulting discipline. One of the ways the 2020 Update emphasized this was through tracking the investigations and the discipline that may come out of any investigation. Companies’ challenges are that facts and circumstances are always different in every investigation. This makes it sometimes difficult, but if companies treat employees of one country differently in terms of discipline, it does create potential gaps in a compliance program. This can give certain countries a feeling that they can do what they want without the risk of punishment from corporate headquarters. This is why the DOJ re-emphasized monitoring the investigations and ensuring consistent application of discipline as a critical factor in providing an effective compliance program.

The FCPA Resource Guide, 2nd edition, added a new hallmark to the previously titled 10 Hallmarks of an Effective Compliance Program (now it is simply the Hallmarks). The Hallmark added was one that has been around for some time: Root Cause Analysis (RCA). It is familiar because it was subtly considered in the original FCPA Resource Guide and explicitly discussed since at least the original formulation of the Evaluation of Corporate Compliance Programs in February 2017.

The focus on consistency is insightful and instructive as a key element of a best practices compliance program. Consistency forms the basis of both institutional justice and institutional fairness. That, in turn, facilitates a speak-up culture, which is the role of the compliance department to foster.

Three key takeaways:

  1. Consistency is a key part of any compliance program.
  2. Consistency forms the basis of both institutional justice and institutional fairness.
  3. Consistency facilitates a speak-up culture.

For more information, check out The Compliance Handbook, 4th edition, here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Episode 12

Day 14 - Internal Controls

7.06 min Dec 1, 2025

Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...

Read more

Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.

Today, the focus is on internal controls and their critical role in compliance frameworks. The episode provides a comprehensive definition of internal controls, emphasizing their importance for achieving operational efficiency, reliable financial reporting, compliance with laws and policies, and the reduction of risks such as fraud and waste. The discussion highlights the requirements outlined in the FCPA for internal controls, including the authorization and documentation of transactions and the protection and accountability of assets. Moreover, four significant internal controls for compliance practitioners are identified: delegation of authority, maintenance of the vendor master file, contracts with third parties, and management of cash and currency transfers. The episode underscores that effective internal controls are essential and mandated by the FCPA, forming a cornerstone of any robust compliance program.

Key highlights:

  • Defining Internal Controls
  • Key Components of Internal Controls
  • Internal Controls in Compliance Programs

Resources:

Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.

Learn more about your ad choices. Visit megaphone.fm/adchoices

Read less
Loading audio...
0:00 / 0:00
Link copied to clipboard!
Exit mobile version