
Sign up to save your podcasts
Or


The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent SEC pre-taliation enforcement action involving DE Shaw.
The recent $10 million settlement by financial services firm De Shaw over a retaliation case has sparked a significant conversation about whistleblower policies. This case, the largest of its kind, centered around employment agreements that prohibited employees from speaking to governmental agencies without company authorization, a practice that has been illegal since 2011 under the Dodd Frank Act. Matt views this as a significant issue, emphasizing the need for clear processes and alignment between policies and employment templates. He also expresses surprise at the rarity of instances where pretaliation clauses actually deter whistleblowers, suggesting that the problem lies in the language used in employment agreements.
Tom sees this as a problem of process. He believes that companies need to have a clear process in place to ensure that changes in employment policies are reflected throughout all relevant documents and agreements. He criticizes companies like De Shaw for updating their policies but failing to update their employment templates, which led to the inclusion of language that prevented whistleblowers from coming forward. Join Tom Fox and Matt Kelly as they delve deeper into this topic on the Compliance into the Weeds podcast.
Key Highlights:
Resources:
Matt in LinkedIn
Tom
Threads
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent OFAC enforcement action involving 3M.
3 3M, found itself in hot water after violating Iran sanctions, leading to a hefty fine of $9,618,477 from the Treasury Department and OFAC. This violation, involving a subsidiary selling goods to a German reseller who then sold them directly to Iran, including to a sanctioned entity.
Tom points out the significant failures in controls and monitoring within the company that led to the violation. He emphasizes the importance of end user statements and monitoring in compliance functions to prevent such violations. On the other hand, Matt acknowledges that while 3M made an effort to comply with the Iran nuclear deal, changes in the arrangement that were not properly communicated or approved led to a violation of the sanctions agreement. He also underscores the importance of monitoring and obtaining end user statements to ensure compliance with export control laws.
Join Tom Fox and Matt Kelly as they delve deeper into this topic in the latest episode of the Compliance into the Weeds podcast.
Key Highlights
· Sanctions Compliance and Ongoing Monitoring
· Challenges and Consequences of Sanctions Compliance
· Sanctions Settlement for Selling Goods to Iran
· Anticipated Impact of Recent Events on 3M
Resources
Matt in LinkedIn
Matt on Radical Compliance
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent MGM Reports data breach and what it may mean for CCOs and Danny Ocean.
The MGM Grand data breach, a significant cyber-attack that disrupted MGM Resorts' operations across the U.S., has raised serious concerns about cybersecurity and regulatory requirements. Tom and Matt discuss the potential financial impact and regulatory investigations that may arise from the breach, emphasizes the severity of the situation and the potential consequences for MGM.
They also question MGM's disaster recovery and business continuity plans and raises concerns about the network design vulnerabilities that allowed the attack to have such a widespread impact. He also discusses the implications of the breach in relation to new SEC rules mandating the disclosure of material cybersecurity events by public companies. Join Tom Fox and Matt Kelly as they delve deeper into these issues in this episode of the Compliance into the Weeds podcast.
Key Highlights
· MGM Grand Cyber Attack Disrupts Operations
· Understanding the Impact of Qualitatively Material Cybersecurity Incidents
· Navigating Material Cybersecurity Event Disclosure Requirements
· Inadequate backup plans leading to operational disruptions
· MGM's Ransomware Attack and Business Continuity
Resources
Matt in LinkedIn
Matt on Radical Compliance
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent DOJ enforcement action involving Verizon Business Network Services for failure to have an effective cyber security compliance program.
The recent case of Verizon's non-compliance with cybersecurity standards and subsequent remediation efforts has sparked a significant conversation in the realm of cyber compliance. Tom views this case as a roadmap for companies to enhance their cybersecurity programs, emphasizing the importance of gap analysis and pressure testing. He draws parallels between cybersecurity compliance and the Foreign Corrupt Practices Act (FCPA) compliance, suggesting that Verizon's case could serve as an example for other companies.
Matt applauds Verizon's voluntary self-disclosure and extensive remediation efforts. He underscores the importance of disclosure, cooperation, and remediation in both cybersecurity and corruption cases, viewing Verizon's actions as a positive example for other companies. Join Tom Fox and Matt Kelly as they delve deeper into this topic in the latest episode of the Compliance into the Weeds podcast.
Key Highlights
· Verizon's Cybersecurity Program Failures
· Enhancing Cybersecurity Compliance through Remediation Measures
· Automating Compliance Efforts with GRC Tools
· Potential Penalties for Non-Disclosure of Cybersecurity Issues
Resources
Matt in LinkedIn
Matt on Radical Compliance
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent pronouncements from the SEC regarding risk assessments together with control environments and all this played out in the Plug Power enforcement action.
The importance of risk assessments and a strong control environment in companies cannot be overstated. These elements are crucial for effective internal controls and proper financial reporting, as emphasized by the SEC's chief accountant, Paul Munter. In this episode Tom and Matt underscore the need for thorough evaluation of potential pitfalls in risk assessments, citing insufficient personnel, changes in board or management composition, and hasty adoption of new strategies or technologies as potential triggers for flawed assessments.
They highlight the significance of small control failures and entity-level failures, such as weaknesses in IT controls, as indicators of a weak control environment.. Join Tom Fox and Matt Kelly as they delve deeper into the topic of risk assessment in the latest episode of the Compliance into the Weeds podcast.
Key Highlights
· Munter’s statement
· Enhancing Control Environment through Risk Assessments
· The Importance of Risk Assessments and Controls
· Attracting and Retaining Competent Individuals
· Flaws in Risk Assessment Beyond Insufficient Personnel
· Lessons Learned
Resources
Matt in LinkedIn
Matt blogged twice on these issues. A report on Munter’s statements here and on the Plug Power enforcement action here
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent FCPA enforcement action involving the Chinese business unit of 3M.
The importance of post-event documentation and monitoring in preventing fraud and corruption cannot be overstated, as highlighted by the recent FCPA incident involving 3M China. Tom believes that while training and control environment adjustments are crucial, they may not be enough to prevent misconduct if individuals are determined to commit such acts. He emphasizes the need for hard evidence, such as post-event documentation, and recommends looking to the heavily regulated pharmaceutical sector for guidance.
Matt stresses the importance of rigorous post-event documentation to ensure the legitimacy of business activities. Both Fox and Kelly gained these insights from their extensive experience in the field of compliance and their analysis of various fraud cases. To learn more about their unique perspectives on post-event documentation and monitoring, join them on this episode of the Compliance into the Weeds podcast.
Key Highlights
· Background facts
· GTE in FCPA enforcement actions
· What happens when conduct is done secretly
· Concerns over the use of messaging apps
· Lessons Learned
Resources
Matt in LinkedIn
Tom -blog post on the FCPA Compliance and Ethics Blog
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award-winning, Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the recent SEC and CFTC enforcement actions around messaging app non-compliance.
Join Tom and Matt as they take a deep dive into the enforcement actions and then consider how such claims would impact non-regulated industries. Regulated industries, particularly broker-dealer firms like Wells Fargo and Morgan Stanley, are facing enforcement actions and hefty fines for their employees' use of messaging apps like WhatsApp and Snapchat that allow record preservation to be disabled. The involvement of senior managers in these misconducts has prompted the SEC to require an independent compliance consultant in settlements.
The conversation between Tom and Matt emphasizes the importance of messaging policies and procedures in regulated industries and the need for stricter compliance measures. They also discuss the complexities and potential consequences of record-keeping obligations and the regulatory concerns over the use of messaging apps. The conversation briefly touches on the future of AI chatbots in customer service, with differing perspectives on their ethical implications. Overall, the conversation highlights the significance of messaging policies, enforcement, and compliance in regulated industries.
Key Highlights
· Enforcement Actions Against Regulated Industries
· Enforcement actions and messaging policies
· Record-keeping obligations for broker dealers and other industries
· Regulatory concerns over the use of messaging apps
· Internal Controls and non-regulated industries
Resources
Matt
Blog Post in Radical Compliance
No Smoke and No Fire: The Rise of Internal Controls Absent Anti-Bribery Violations in FCPA Enforcement by Karen Woody in Cardoza Law Review
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the PCAOB proposal for fraud and compliance audits.
In this episode, we dive into the heated debate surrounding the proposed rule on auditors and fraud risk audits in this episode of Compliance into the Weeds. Compliance professionals and the audit community have contrasting perspectives on the PCAOB proposal to require audit firms to look more aggressively for compliance and legal violations at their client companies, and then report any such violations more promptly to the company’s board of directors. Discover the stipulations compliance professionals want to include, such as meeting with the chief ethics and compliance officer and reviewing the state of the compliance program. On the other hand, hear why the audit community, represented by the PCAOB, opposes the rule, arguing that auditors lack the necessary expertise and that fees would skyrocket without significant benefits. Gain insights into the complexities and challenges of asking auditors to take on compliance responsibilities. Tune in to understand the potential implications of the proposed rule on audit firms, compliance professionals, and investors.
Key Highlights
· The PCAOB proposal implications for auditors, with a focus on effects on fraud risk audits.
· The difference in how compliance professionals and auditors perceive the impending rule.
· The practical difficulties auditors face when tasked with compliance roles.
· What are the potential cost and liability hikes for auditors, heralded by the enforcement of the rule?
· The uncertainties enveloping the approval and implementation process for the proposed rule.
Resources
Matt
Blog Post in Radical Compliance
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt take a deep dive into the recently released SEC rules on cyber breach disclosures.
This new era of cyber security calls for increased accountability and transparency from companies to protect investors and citizens from cyber threats. The U.S. Securities and Exchange Commission (SEC) recently adopted new cyber disclosure rules requiring companies to disclose material cybersecurity incidents and risks in their annual reports. This policy change will require companies to analyze and disclose the impacts of any material cybersecurity incidents, as well as any potential exemptions from disclosure that companies may seek.
Key Highlights
· New Cyber Breach Disclosure Rules
· Material Breaches
· Role of the Board
Resources
Matt
Blog Post in Radical Compliance
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on sanctions compliance? Look no further than Compliance into the Weeds! In this episode, Tom and Matt consider the current difficulties for auditors to perform an audit on AI.
The use of AI in the tech world has brought with it a new concern: implicit bias. Auditing AI code is necessary to ensure that AI applications are free from bias and secure from cyber threats. This complex process involves examining the code of AI programs to ensure that they are functioning as intended and are not producing biased or unethical outcomes. In addition to auditing code, employers must also audit the outcomes of AI tools, and consider ethical considerations when defining the data that the AI is looking at. As AI hiring audits become increasingly necessary, it is more important than ever to ensure that AI applications are free from bias and secure from cyber threats.
Key Highlights
· AI Implicit Bias
· Auditing AI Code
· AI Hiring Audits
Resources
Matt
Blog Post in Radical Compliance
Tom
YouTube
Learn more about your ad choices. Visit megaphone.fm/adchoices
From the publisher's feed

111,766 Listeners

42 Listeners

56 Listeners

2,543 Listeners

4,601 Listeners

7 Listeners

5,561 Listeners

15,872 Listeners

10,414 Listeners

680 Listeners

5 Listeners