Compliance into the Weeds

Compliance into the Weeds

Download on the App Store

Compliance into the Weeds episodes

  • DE Shaw Enforcement Action for Pre-taliation

    The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent SEC pre-taliation enforcement action involving DE Shaw.

    The recent $10 million settlement by financial services firm De Shaw over a retaliation case has sparked a significant conversation about whistleblower policies. This case, the largest of its kind, centered around employment agreements that prohibited employees from speaking to governmental agencies without company authorization, a practice that has been illegal since 2011 under the Dodd Frank Act. Matt views this as a significant issue, emphasizing the need for clear processes and alignment between policies and employment templates. He also expresses surprise at the rarity of instances where pretaliation clauses actually deter whistleblowers, suggesting that the problem lies in the language used in employment agreements.

    Tom sees this as a problem of process. He believes that companies need to have a clear process in place to ensure that changes in employment policies are reflected throughout all relevant documents and agreements. He criticizes companies like De Shaw for updating their policies but failing to update their employment templates, which led to the inclusion of language that prevented whistleblowers from coming forward. Join Tom Fox and Matt Kelly as they delve deeper into this topic on the Compliance into the Weeds podcast.

     

     Key Highlights:

    • Largest pre-taliation settlement in financial services
    • Persistent Non-Compliance Issues with Dodd Frank
    • The Rise of Multimillion-Dollar Penalties

    • Resources:

      Matt in LinkedIn

      Tom 

      Threads

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn


      Learn more about your ad choices. Visit megaphone.fm/adchoices

      18 min
    • 3M OFAC Enforcement Action

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent OFAC enforcement action involving 3M.

      3 3M, found itself in hot water after violating Iran sanctions, leading to a hefty fine of $9,618,477 from the Treasury Department and OFAC. This violation, involving a subsidiary selling goods to a German reseller who then sold them directly to Iran, including to a sanctioned entity. 

      Tom points out the significant failures in controls and monitoring within the company that led to the violation. He emphasizes the importance of end user statements and monitoring in compliance functions to prevent such violations. On the other hand, Matt acknowledges that while 3M made an effort to comply with the Iran nuclear deal, changes in the arrangement that were not properly communicated or approved led to a violation of the sanctions agreement. He also underscores the importance of monitoring and obtaining end user statements to ensure compliance with export control laws. 

      Join Tom Fox and Matt Kelly as they delve deeper into this topic in the latest episode of the Compliance into the Weeds podcast.

       Key Highlights

      ·      Sanctions Compliance and Ongoing Monitoring

      ·      Challenges and Consequences of Sanctions Compliance

      ·      Sanctions Settlement for Selling Goods to Iran

      ·      Anticipated Impact of Recent Events on 3M

       Resources

      Matt in LinkedIn

      Matt on Radical Compliance


      Tom  

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn


      Learn more about your ad choices. Visit megaphone.fm/adchoices

      22 min
    • MGM Grand Data Breach

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent MGM Reports data breach and what it may mean for CCOs and Danny Ocean.

      The MGM Grand data breach, a significant cyber-attack that disrupted MGM Resorts' operations across the U.S., has raised serious concerns about cybersecurity and regulatory requirements. Tom and Matt discuss the potential financial impact and regulatory investigations that may arise from the breach, emphasizes the severity of the situation and the potential consequences for MGM. 

      They also question MGM's disaster recovery and business continuity plans and raises concerns about the network design vulnerabilities that allowed the attack to have such a widespread impact. He also discusses the implications of the breach in relation to new SEC rules mandating the disclosure of material cybersecurity events by public companies. Join Tom Fox and Matt Kelly as they delve deeper into these issues in this episode of the Compliance into the Weeds podcast.

       Key Highlights

      ·      MGM Grand Cyber Attack Disrupts Operations

      ·      Understanding the Impact of Qualitatively Material Cybersecurity Incidents

      ·      Navigating Material Cybersecurity Event Disclosure Requirements

      ·      Inadequate backup plans leading to operational disruptions

      ·      MGM's Ransomware Attack and Business Continuity

       Resources

      Matt in LinkedIn

      Matt on Radical Compliance


      Tom  

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn


      Learn more about your ad choices. Visit megaphone.fm/adchoices

      28 min
    • Failure to Have Effective Compliance Program

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent DOJ enforcement action involving Verizon Business Network Services for failure to have an effective cyber security compliance program.

      The recent case of Verizon's non-compliance with cybersecurity standards and subsequent remediation efforts has sparked a significant conversation in the realm of cyber compliance. Tom views this case as a roadmap for companies to enhance their cybersecurity programs, emphasizing the importance of gap analysis and pressure testing. He draws parallels between cybersecurity compliance and the Foreign Corrupt Practices Act (FCPA) compliance, suggesting that Verizon's case could serve as an example for other companies. 

      Matt applauds Verizon's voluntary self-disclosure and extensive remediation efforts. He underscores the importance of disclosure, cooperation, and remediation in both cybersecurity and corruption cases, viewing Verizon's actions as a positive example for other companies. Join Tom Fox and Matt Kelly as they delve deeper into this topic in the latest episode of the Compliance into the Weeds podcast. 

      Key Highlights

      ·      Verizon's Cybersecurity Program Failures

      ·      Enhancing Cybersecurity Compliance through Remediation Measures

      ·      Automating Compliance Efforts with GRC Tools

      ·      Potential Penalties for Non-Disclosure of Cybersecurity Issues

       Resources

      Matt in LinkedIn

      Matt on Radical Compliance

      Tom  

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn


      Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min
    • Risk Assessments, Control Environments and Plug Power

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent pronouncements from the SEC regarding risk assessments together with control environments and all this played out in the Plug Power enforcement action.

      The importance of risk assessments and a strong control environment in companies cannot be overstated. These elements are crucial for effective internal controls and proper financial reporting, as emphasized by the SEC's chief accountant, Paul Munter. In this episode Tom and Matt underscore the need for thorough evaluation of potential pitfalls in risk assessments, citing insufficient personnel, changes in board or management composition, and hasty adoption of new strategies or technologies as potential triggers for flawed assessments. 

      They highlight the significance of small control failures and entity-level failures, such as weaknesses in IT controls, as indicators of a weak control environment.. Join Tom Fox and Matt Kelly as they delve deeper into the topic of risk assessment in the latest episode of the Compliance into the Weeds podcast.

       Key Highlights

      ·      Munter’s statement

      ·      Enhancing Control Environment through Risk Assessments

      ·      The Importance of Risk Assessments and Controls

      ·      Attracting and Retaining Competent Individuals

      ·      Flaws in Risk Assessment Beyond Insufficient Personnel

      ·      Lessons Learned

       Resources

      Matt in LinkedIn

      Matt blogged twice on these issues. A report on Munter’s statements here and on the Plug Power enforcement action here

      Tom  

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn


      Learn more about your ad choices. Visit megaphone.fm/adchoices

      23 min
    • 3M FCPA Enforcement Action

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent FCPA enforcement action involving the Chinese business unit of 3M.

      The importance of post-event documentation and monitoring in preventing fraud and corruption cannot be overstated, as highlighted by the recent FCPA incident involving 3M China. Tom believes that while training and control environment adjustments are crucial, they may not be enough to prevent misconduct if individuals are determined to commit such acts. He emphasizes the need for hard evidence, such as post-event documentation, and recommends looking to the heavily regulated pharmaceutical sector for guidance.

      Matt stresses the importance of rigorous post-event documentation to ensure the legitimacy of business activities. Both Fox and Kelly gained these insights from their extensive experience in the field of compliance and their analysis of various fraud cases. To learn more about their unique perspectives on post-event documentation and monitoring, join them on this episode of the Compliance into the Weeds podcast. 

      Key Highlights

      ·      Background facts

      ·      GTE in FCPA enforcement actions

      ·      What happens when conduct is done secretly

      ·      Concerns over the use of messaging apps

      ·      Lessons Learned

       Resources

      Matt in LinkedIn

      Tom -blog post on the FCPA Compliance and Ethics Blog

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      20 min
    • Messaging App Enforcement and Internal Controls

      The award-winning, Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent SEC and CFTC enforcement actions around messaging app non-compliance.

      Join Tom and Matt as they take a deep dive into the enforcement actions and then consider how such claims would impact non-regulated industries. Regulated industries, particularly broker-dealer firms like Wells Fargo and Morgan Stanley, are facing enforcement actions and hefty fines for their employees' use of messaging apps like WhatsApp and Snapchat that allow record preservation to be disabled. The involvement of senior managers in these misconducts has prompted the SEC to require an independent compliance consultant in settlements.

      The conversation between Tom and Matt emphasizes the importance of messaging policies and procedures in regulated industries and the need for stricter compliance measures. They also discuss the complexities and potential consequences of record-keeping obligations and the regulatory concerns over the use of messaging apps. The conversation briefly touches on the future of AI chatbots in customer service, with differing perspectives on their ethical implications. Overall, the conversation highlights the significance of messaging policies, enforcement, and compliance in regulated industries.

      Key Highlights

      ·      Enforcement Actions Against Regulated Industries

      ·      Enforcement actions and messaging policies

      ·      Record-keeping obligations for broker dealers and other industries

      ·      Regulatory concerns over the use of messaging apps

      ·      Internal Controls and non-regulated industries

       Resources

      Matt 

      LinkedIn

      Blog Post in Radical Compliance

      No Smoke and No Fire: The Rise of Internal Controls Absent Anti-Bribery Violations in FCPA Enforcement by Karen Woody in Cardoza Law Review

      Tom 

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min
    • Responses to PCAOB Proposal On Audits

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the PCAOB proposal for fraud and compliance audits.

      In this episode, we dive into the heated debate surrounding the proposed rule on auditors and fraud risk audits in this episode of Compliance into the Weeds. Compliance professionals and the audit community have contrasting perspectives on the PCAOB proposal to require audit firms to look more aggressively for compliance and legal violations at their client companies, and then report any such violations more promptly to the company’s board of directors. Discover the stipulations compliance professionals want to include, such as meeting with the chief ethics and compliance officer and reviewing the state of the compliance program. On the other hand, hear why the audit community, represented by the PCAOB, opposes the rule, arguing that auditors lack the necessary expertise and that fees would skyrocket without significant benefits. Gain insights into the complexities and challenges of asking auditors to take on compliance responsibilities. Tune in to understand the potential implications of the proposed rule on audit firms, compliance professionals, and investors.

       Key Highlights

      ·       The PCAOB proposal implications for auditors, with a focus on effects on fraud risk audits.

      ·       The difference in how compliance professionals and auditors perceive the impending rule.

      ·       The practical difficulties auditors face when tasked with compliance roles.

      ·       What are the potential cost and liability hikes for auditors, heralded by the enforcement of the rule?

      ·       The uncertainties enveloping the approval and implementation process for the proposed rule.

       Resources

      Matt 

      LinkedIn

      Blog Post in Radical Compliance

      Tom 

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn


      Learn more about your ad choices. Visit megaphone.fm/adchoices

      25 min
    • SEC Rules for Cyber Breach Disclosure

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt take a deep dive into the recently released SEC rules on cyber breach disclosures. 

      This new era of cyber security calls for increased accountability and transparency from companies to protect investors and citizens from cyber threats. The U.S. Securities and Exchange Commission (SEC) recently adopted new cyber disclosure rules requiring companies to disclose material cybersecurity incidents and risks in their annual reports. This policy change will require companies to analyze and disclose the impacts of any material cybersecurity incidents, as well as any potential exemptions from disclosure that companies may seek. 

       Key Highlights 

      ·      New Cyber Breach Disclosure Rules

      ·      Material Breaches

      ·      Role of the Board

       Resources

      Matt 

      LinkedIn

      Blog Post in Radical Compliance

      Tom 

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      25 min
    • Auditing AI For Compliance

      The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the current difficulties for auditors to perform an audit on AI.

      The use of AI in the tech world has brought with it a new concern: implicit bias. Auditing AI code is necessary to ensure that AI applications are free from bias and secure from cyber threats. This complex process involves examining the code of AI programs to ensure that they are functioning as intended and are not producing biased or unethical outcomes. In addition to auditing code, employers must also audit the outcomes of AI tools, and consider ethical considerations when defining the data that the AI is looking at. As AI hiring audits become increasingly necessary, it is more important than ever to ensure that AI applications are free from bias and secure from cyber threats.

       Key Highlights

      ·      AI Implicit Bias

      ·      Auditing AI Code

      ·      AI Hiring Audits

       Resources

      Matt 

      LinkedIn

      Blog Post in Radical Compliance

      Tom 

      Instagram

      Facebook

      YouTube

      Twitter

      LinkedIn

      Learn more about your ad choices. Visit megaphone.fm/adchoices

      24 min

    About Compliance into the Weeds

    From the publisher's feed

    What happens when two compliance aficionados get together to talk all things compliance, risk management and ERM? You get Tom Fox, the Voice of Compliance and Matt Kelly, the Coolest Guy in…

    More shows like Compliance into the Weeds

    The Daily by The New York Times

    The Daily

    111,766 Listeners

    Corruption Crime & Compliance by Michael Volkov

    Corruption Crime & Compliance

    42 Listeners

    Great Women in Compliance by Lisa Fine and Hemma Lomax

    Great Women in Compliance

    56 Listeners

    The Intelligence from The Economist by The Economist

    The Intelligence from The Economist

    2,543 Listeners

    Talking Feds by Harry Litman

    Talking Feds

    4,601 Listeners

    Daily Compliance News by Tom Fox

    Daily Compliance News

    7 Listeners

    Hard Fork by The New York Times

    Hard Fork

    5,561 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,872 Listeners

    #SistersInLaw by Politicon

    #SistersInLaw

    10,414 Listeners

    The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

    The AI Daily Brief: Artificial Intelligence News and Analysis

    680 Listeners

    2 Gurus Talk Compliance by Thomas Fox

    2 Gurus Talk Compliance

    5 Listeners