Tom Fox is the Compliance Evangelist and is universally recognized as one of the top experts in corruption compliance, literally across the globe. In this daily podcast series, he explains how to design, create and implement a best practices compliance program. Each month, he tackles a different area of compliance. From Internal Controls, to the Role of the Board of Directors, to Communication, to the Role of HR in Compliance, Investigations, 3rd Parties and Business Ventures. Listen in each day and get one tip you can implement at little or no cost to enhance your compliance program.
31 Days to a More Effective Compliance Program
31 Days to a More Effective Compliance Program: Day 9 - Continuous Monitoring and Continuous Improvement
Continuous monitoring and continuous improvement are two of the most important phrases for any compliance program. These twin concepts were further enshrined in the 2023 Update to the Evaluation of Corporate Compliance Programs (2023 ECCP). In 2023, all companies’ risks changed as we moved from Wo...
Read moreContinuous monitoring and continuous improvement are two of the most important phrases for any compliance program. These twin concepts were further enshrined in the 2023 Update to the Evaluation of Corporate Compliance Programs (2023 ECCP). In 2023, all companies’ risks changed as we moved from Working From Home to Return To Office and, now, a hybrid model. In addition to this straight-forward change in risk due to working locations, new risks in the form of geopolitical, supply chain, and export control, as well as increased risk due to social media, continue to impact compliance programs. Your compliance program must be ready to respond to whatever those risks might be going forward.
Continuous improvement runs the gamut in a best practices compliance program, from risk assessments to policies and procedures to periodic testing and review.
Three key takeaways:
1. How have your company’s risks changed over the past year, and how will they change in 2024?
2. What is your process for continuous monitoring and improvement?
3. What sources of information do you use that come from outside your organization?
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessDay 8 - Building Effective Compliance Through Payroll
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6–8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
Operationalizing a compliance program through payroll is a vital component of a company’s risk management strategy, serving as both a control mechanism and a crucial link to the broader compliance function. Payroll is instrumental in identifying potential red flags, such as offshore payments, which require meticulous documentation and enhanced internal controls to prevent compliance violations. Tom Fox, a noted expert in compliance, underscores the significant role payroll plays in fortifying compliance programs by aligning with FCPA requirements and preventing fraudulent activities. He advocates for implementing demonstrable controls like Approval Certification processes, segregation of duties, and regular review procedures to mitigate compliance risks effectively. According to Tom, by embedding robust controls within payroll operations, companies deter potential violations and ensure compliance is woven into the organizational fabric, thus operationalizing their compliance programs seamlessly.
Key highlights:
- Payroll should be on the front lines of any attempt to prevent, detect, and remediate anti-corruption compliance.
- Key compliance program components for payroll.
- Watch for offshore payments.
Resources:
Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less31 Days to a More Effective Compliance Program: Day 8 - Operationalizing Compliance Through Payroll
One of the areas articulated in the 2023 ECCP was around payments and payroll. For both the compliance professional and the corporate payroll function, there is a significant role to play in the operationalization of a corporate compliance program. The 2023 ECCP was replete with references to paymen...
Read moreOne of the areas articulated in the 2023 ECCP was around payments and payroll. For both the compliance professional and the corporate payroll function, there is a significant role to play in the operationalization of a corporate compliance program. The 2023 ECCP was replete with references to payment and its critical nature to any best practices compliance program. This includes references to payments to foreign officials, payments to third parties, and hiding bribes in payments to distributors. The 2023 ECCP begins with an admonition to stop wasting time on low-hanging fruit when there are much higher risks in your business operations.
The role of payroll in compliance is not often considered in operationalizing your compliance program, yet the monies to fund bribes must come from somewhere. Unfortunately, one of those places is out of payroll. All CCOs need to sit down with their head of payroll, have them explain the role of payroll, and then review the internal controls in place to see how they facilitate compliance goals. From that review, you can then determine how to use payroll to help operationalize your compliance program.
The DOJ has now provided its clearest statement on how it expects a company to actually comply going forward. Long gone are the days where the DOJ simply considered the inputs of a written program as sufficient to protect companies from compliance violations. Yet the mandate to operationalize a corporate compliance program drives home the concept that compliance is a business process that should be administered by the appropriate business unit with the requisite SME. When it comes to following the money, payroll is the most well-suited corporate discipline to provide this first level of oversight and control.
Three key takeaways:
- Payroll can be a key to preventing and detecting control
- The 2020 Update specified the tie between the corporate compliance function and the corporate payroll function.
- Offshore payments remain a key indicator of a red flag.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessDay 7 - Argentieri on Clawbacks and Holdbacks
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
In this episode, we explore the critical insights from the DOJ Clawback Program for compliance professionals. It emphasizes integrating compliance into the compensation structure as an effective strategy to promote ethical behavior and prevent misconduct. We also delve into the significance of financial accountability, noting the DOJ’s practice of reducing fines for firms that reclaim compensation from responsible employees. Finally, the episode highlights the necessity of continuously evaluating and enhancing compliance-linked compensation systems, urging companies to regularly assess their effectiveness, gather feedback, and make necessary adjustments. This iterative process reinforces the idea that compliance programs must be dynamic and proactive rather than static operational checklists.
Key highlights:
- Integrating Compliance into Compensation
- Financial Accountability Emphasis
- DOJ’s Commitment to Individual Accountability
- Continuous Evaluation and Improvement
Resources:
Listeners to this podcast can receive a 20% discount on The Compliance Handbook, 5th edition, by clicking here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less31 Days to a More Effective Compliance Program: Day 7-Compliance Program Use of Data Analytics
Matt Galvin, Counsel, Compliance & Data Analytics at the DOJ and one of the experts leading the DOJ’s data analytics initiative, highlighted in another talk, the proactive use of data to generate cases related to the FCPA and emphasized that this is just the beginning. The DOJ expects comp...
Read moreMatt Galvin, Counsel, Compliance & Data Analytics at the DOJ and one of the experts leading the DOJ’s data analytics initiative, highlighted in another talk, the proactive use of data to generate cases related to the FCPA and emphasized that this is just the beginning. The DOJ expects companies to adopt a similar data-driven approach to compliance. In her speech, Argentieri speech she stated, “just as we are upping our game when it comes to data analytics, we expect companies to do the same.” This expectation extends beyond simply tracking trainings, policies, and investigations. The DOJ’s focus is on monitoring third parties throughout the lifespan of the relationship, not just during the onboarding process.
The DOJ’s increasing use of data analytics for proactive enforcement signifies a significant shift in their approach to combating white-collar crime. Companies must embrace this data-driven approach to compliance, continuously monitor high-risk transactions, and invest in the necessary resources and technology. By doing so, they can demonstrate effective compliance programs, uncover hidden financial irregularities, and improve overall efficiency.
Three key takeaways:
1. This also means that data analytics in the compliance function has moved from cutting edge to best practice. It soon may simply mean table stakes for compliance.
2. The DOJ is seeking to incentivize an acquiring company to timely disclose misconduct uncovered during the M&A process.
3. The DOJ has made clear that under this new Mergers & Acquisition Safe Harbor Policy organizations that do not perform effective due diligence or self-disclose misconduct at an acquired entity will be subject to full successor liability.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessOne Month to a More Effective Compliance Program Through Data Analytics: Day 7 - From Cutting Edge to Table Stakes
Compliance programs play a crucial role in ensuring that companies adhere to legal and ethical standards. In today’s digital age, where data is abundant and easily accessible, the importance of data-driven compliance programs cannot be overstated. This message was driven home very forcefully in a ...
Read moreCompliance programs play a crucial role in ensuring that companies adhere to legal and ethical standards. In today’s digital age, where data is abundant and easily accessible, the importance of data-driven compliance programs cannot be overstated. This message was driven home very forcefully in a speech in November by Nicole Argentieri, acting assistant attorney general for the Criminal Division.
Anselmo Guevara, manager at VMware, has emphasized the need for companies to have a compliance program that provides visibility into their data at their fingertips. It is no longer sufficient to simply collect data and have someone review and reconcile it. Compliance professionals must actively analyze the data for trends, anomalies, and potential compliance risks. This proactive approach allows companies to identify and address compliance issues before they escalate.
Data-driven compliance programs have moved from cutting-edge and are now seen as best practices. Soon they will simply be table stakes for companies to effectively manage compliance risks. By actively monitoring and analyzing data, companies can identify potential compliance issues, mitigate risks, and maintain their reputation and integrity. Collaboration between different departments and a formal risk assessment are key factors in establishing a robust compliance program. As technology continues to advance, the role of data analytics and AI in compliance monitoring is expected to become even more significant. Compliance professionals must stay informed, continuously learn, and adapt to the evolving landscape of data-driven compliance.
Three key takeaways:
1. Nicole Argentieri, acting assistant attorney general for the Criminal Division, said, “Let me be the first to tell you that we have proactively used data to generate FCPA cases, and we’ve only just gotten started.”
2. . Compliance professionals must actively analyze the data for trends, anomalies, and potential compliance risks.
3. Data-driven compliance programs have moved from cutting-edge and are now seen as best practices. Soon they will simply be table stakes for companies to effectively manage compliance risks.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessOne Month to a More Effective Compliance Program Through Culture: Day 7 - To Improve Culture, Engage More
One thing I have learned in working with Carsten Tams is that one of the very top keys to a successful compliance program is employee engagement. Tams and I explored this topic in the popular podcast series Design Thinking in Compliance. It also appears that attention can lead to excellent business...
Read moreOne thing I have learned in working with Carsten Tams is that one of the very top keys to a successful compliance program is employee engagement. Tams and I explored this topic in the popular podcast series Design Thinking in Compliance. It also appears that attention can lead to excellent business resiliency based upon an article entitled The Top 10 Findings on Resilience and Engagement, by Marcus Buckingham.
Not surprisingly, trust is the number 1 factor in engagement and resilience. Astoundingly, the author found that “employees who said they completely trust their team leader were 14 times more likely to be fully engaged.” Moreover, those employees who completely trusted their colleagues, team leader, and senior leaders “were 42 times more likely to be highly resilient.” The reason should seem obvious as it is undoubtedly “easier to engage in our best work when we don’t have to expend mental resources looking over our shoulders or protecting ourselves against dysfunctional workplace practices that erode trust, like bullying or micromanaging. When it comes to building engagement and resilience, trust is everything.”
Teamwork is also a key factor. Although this is not something I have experienced over the past 12 years of working alone, the author found, “Those who said they are on a team were 2.6 times more likely to be fully engaged and 2.7 times more likely to be highly resilient than those who didn’t identify as team members. For millennia, humans have experienced psychological well-being only when they feel connected to and supported by a small group of people around them.” When the pandemic hit, working from home was not new to me as I had been doing it since 2010, but even in the WFH or Hybrid Work era, most employees need to feel like they are part of a team.
Every CCO and compliance professional must work to lessen or dissolve the disconnect between senior leadership and front-line workers. Your front-line business folks will make or break your compliance program. Getting your senior management more engaged will create and establish the trust your employees will need to show resilience in the face of the following primary business location, whether a pandemic or military invasion.
Three key takeaways:
1. The concepts from Design Thinking can improve your culture.
2. A key factor in culture is engagement.
3. You can improve culture by dissolving the disconnect between senior leadership and front-line workers.
Check the free webinar on the new tool, The Culture Audit with Tom Fox and Sam Silverstein on Tuesday, November 20, 12 CT. For more information and registration, click here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessDay 6 - M&A Safe Harbor Policy
Welcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information ...
Read moreWelcome to a special podcast series on the Compliance Podcast Network, 31 Days to a More Effective Compliance Program. Over these 31 days of the series in January 2025, Tom Fox will post a key part of a best practices compliance program daily. By the end of January, you will have enough information to create, design, or enhance a compliance program. Each podcast will be short, at 6-8 minutes, and will include three key takeaways you can implement at little or no cost to help update your compliance program. I hope you will join us each day in January for this exploration of best practices in compliance.
This episode delves into the Department of Justice’s mergers and acquisitions (M&A) Safe Harbor Policy, as Deputy Attorney General Lisa Monaco explained. This policy encourages companies to voluntarily self-disclose criminal conduct discovered during acquisition. If a company promptly discloses such misconduct, cooperates with the ensuing investigation, and engages in appropriate remediation, restitution, and disgorgement, it can receive a presumption of a criminal declination. Key deadlines include disclosing misconduct within six months of the closing date and fully remediating within one year. The DOJ aims to incentivize acquiring companies to perform robust pre- and post-acquisition due diligence and self-disclosure to mitigate risks and de-risk transactions effectively.
Key highlights:
- New DOJ Mergers and Acquisitions Safe Harbor Policy
- Key Requirements and Deadlines
- Historical Context and Clarifications
Resources:
Click here to receive a 20% discount on The Compliance Handbook, 5th edition, for listeners to this podcast.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less31 Days to a More Effective Compliance Program: Day 6 - DOJ M&A Safe Harbor
In October 2023, Deputy Attorney General Lisa Monaco announced a new policy regarding M&A. It is a Mergers & Acquisitions Safe Harbor policy that encourages companies to self-disclose criminal misconduct discovered by an acquiring company during the acquisition of a target company. Under ...
Read moreIn October 2023, Deputy Attorney General Lisa Monaco announced a new policy regarding M&A. It is a Mergers & Acquisitions Safe Harbor policy that encourages companies to self-disclose criminal misconduct discovered by an acquiring company during the acquisition of a target company. Under the policy, the acquiring party will receive a presumption of criminal declination if it promptly and voluntarily discloses criminal misconduct, cooperates with any ensuing investigation, and engages in appropriate remediation, restitution and disgorgement.
Under this new Mergers & Acquisitions Safe Harbor, which applies across the Department of Justice, companies that promptly and voluntarily disclose criminal misconduct with the Safe Harbor period, and then cooperate with the resulting investigation, engage in timely and appropriate remediation and pay applicable restitution and disgorgement, will receive a presumption of a declination. Once again, the key deadlines are as follows:
- Companies must disclose misconduct discovered (whether pre-or post-acquisition) at the acquired entity within six (6) months from the date of closing.
- Companies will then have one year from the date of closing to fully remediate the misconduct.
The 6 month and one-year deadlines are subject to modification depending on the specific circumstances and complexity of the transaction. The acquired company can also qualify under the Mergers & Acquisition Safe Harbor Policy for voluntary self-disclosure benefits. Interestingly, DOJ clarified that any misconduct disclosed under the Safe Harbor Policy will not implicate or be counted in any future potential recidivist analysis.
Three key takeaways:
1. The DOJ Mergers & Acquisitions Safe Harbor policy encourages companies to self-disclose criminal misconduct discovered by an acquiring company during the acquisition of a target company.
2. The DOJ is seeking to incentivize an acquiring company to timely disclose misconduct uncovered during the M&A process.
3. The DOJ has made clear that under this new Mergers & Acquisition Safe Harbor Policy organizations that do not perform effective due diligence or self-disclose misconduct at an acquired entity will be subject to full successor liability.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read lessOne Month to a More Effective Compliance Program Through Data Analytics: Day 6 - Data Analytics and Business Decisions
In today’s rapidly evolving business landscape, compliance, enterprise performance management (EPM) systems, and data analytics play crucial roles in driving informed decision-making. Compliance program visibility and proper documentation are essential for managing data and ensuring regulatory...
Read moreIn today’s rapidly evolving business landscape, compliance, enterprise performance management (EPM) systems, and data analytics play crucial roles in driving informed decision-making. Compliance program visibility and proper documentation are essential for managing data and ensuring regulatory compliance across companies of all sizes. EPM systems, also known as Enterprise Resource Planning (ERP) systems, are vital tools for financial planning and analysis. These systems go beyond basic accounting functions and offer features such as budgeting, forecasting, and strategic long-range planning. By using EPM systems, organizations can operate at a higher level, enabling medium to long-range planning and supporting informed decision-making.
The importance of compliance, EPM systems, and data analytics in business decision-making cannot be overstated. Compliance program visibility and documentation are crucial for managing data and ensuring regulatory compliance. EPM systems provide the tools for financial planning and analysis, supporting strategic long-range planning and informed decision-making. Data analytics allows businesses to uncover patterns and gain insights, but overcoming data silos is necessary to maximize its potential. By adopting cloud-based solutions and integrating systems, organizations can make the most of their data and drive informed decision-making. Balancing different factors and considering the impact on decision-making processes is key to successfully leveraging compliance, EPM systems, and data analytics in business.
Three key takeaways:
1. Compliance program visibility and proper documentation are essential for managing data and ensuring regulatory compliance across companies of all sizes.
2. Having data is important, it is equally crucial to focus on how that data is being used.
3. Overcoming data silos is key to maximizing the potential of data analytics.
For more information on KonaAI, click here.
Learn more about your ad choices. Visit megaphone.fm/adchoices
Read less