Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Eddie Green on Electronic Messaging [Podcast]
    By Adam Turteltaub
    It used to be that tracking email usage was considered tough. These days the workforce is also communicating via text, WeChat, Slack and countless other channels both internally and externally. That can be a total nightmare since prosecutors want access to all those conversations.
    What makes things harder is that employees may be resistant, feeling that the communications they have on their phone, especially in organizations with a Bring Your Own Device (BYOD) policy, is private. The employee owns the phone, not the company.
    Eddie Green (LinkedIn), CEO of SnippetSentry advises companies get their heads around this problem. Digital compliance is broadening out from the investment community to pharma and elsewhere.
    To manage the issue, some companies are now scrapping BYOD policies and making it clear that all work communications need to go on work-owned devices. They are also looking for solutions which enable employees to communicate in familiar ways, but with the tracking that logs all those communications.
    Listen in to understand the challenge and how to approach it more effectively.
    8 min
  • Professor Todd Haugh on the Southern District of New York’s Whistleblower Pilot Program [Podcast]
    By Adam Turteltaub
    In January 2024 the US Attorney’s Office for the Southern District of New York (SDNY) set a shockwave through the business world by announcing a new whistleblower pilot program. To understand what the policy says and what it likely means for compliance programs, we spoke with Todd Haugh (LinkedIn), Associate Professor of Business Law and Ethics, Arthur M. Weimer Faculty Fellow in Business Law at the Kelley School of Business at Indiana University.
    Under the policy, he explains, individuals who have participated in a fraud may be eligible for a non-prosecution agreement, if the individual meets three key criteria:
    They provide information that is not previously known to prosecutors and is produced voluntarily, not subsequent, say, to an arrest.
    The information is full, substantial and truthful.
    The individual is not otherwise disqualified, such as serving as a government official or the CEO or CFO of the company.
    Given the incentives already in place for companies to self-report wrongdoing, this is in many ways an extension of what already exists.
    However, it’s impact should not be underplayed. The SDNY is a leader in white collar prosecutions and other US Attorney’s offices are likely to follow suit. At least one already has.
    Second, while the SEC has encouraged whistleblowing at publicly traded policies, the SDNY policy is open to public, private and even non-profit organizations.
    The new policy also may create situations in which employees and their employers find themselves in a race to disclose first.
    This, in turn, means that organizations need to significantly increase their efforts to create a culture that encourages internal whistleblowing. That includes creating easy paths to follow for potential whistleblowers and prompt investigations.
    Listen in to learn more about the policy and how your compliance program may need to evolve as a result of it.
    16 min
  • David Schumacher on the HHS OIG’s General Compliance Program Guidance [Podcast]
    By Adam Turteltaub
    In late 2023, The Office of Inspector General (OIG) at the Department of Health and Human Services issued its new General Compliance Program Guidance. In this podcast, David Schumacher, Partner and Co-Chair of the Fraud & Abuse Practice at Hooper Lundy & Bookman explains that this document is both evolutionary and revolutionary.
    For years the OIG’s office had been offering guidance through the Federal Register. To make that information more accessible it moved it online, consolidated the information, added interactive features and created a much richer resource which makes it both easier for compliance teams to understand the OIG’s expectations and more difficult for some to claim that they were unaware of the rules.
    The changes, though, are more than just the media used to communicate OIG expectations. The document demonstrates both the ongoing expectations by OIG for robust compliance programs and communicates changes in focus. For one, it reveals an enhanced emphasis on quality issues in healthcare and patient safety.
    It also reflects the OIG’s efforts to ensure effective compliance program in new entrants into healthcare, such as private equity and technology firms. Both may well discover that practices that are permissible elsewhere are not in healthcare.
    The guidance also encourages incentivizing compliance.
    Another gem in the guidance is the clear message to carefully scrutinize arrangements with third parties. Due diligence at the outset is important, but it is also necessary on an ongoing basis to determine if the relationship is necessary and the price tag is fair market value.
    Listen in to learn more, and be sure to check out the General Compliance Program Guidance.
    15 min
  • Dana McMahon on Embedding the Compliance Team in the Business [Podcast]
    By Adam Turteltaub
    Tired of being last to the party and then perceived as a party pooper?
    There’s a solution to that problem embraced by Dana McMahon, Global Chief Compliance Officer, Head, Privacy & Enterprise Risk at Stryker. She works to have her team embedded in the business unit.
    It’s a process that begins with getting a seat at the table and being intentional about conversations. From there the relationship evolves into being a consultant on sticky issues and then on to being integrated into decision making and proving yourselves indispensable.
    The key to the process, she explains, is to show up with a problem-solving mindset. Throughout, the compliance team has to be aware of the needs of the business and its challenges.
    To solidify compliance’s place takes three things:
    Adopt a problem-solving approach
    Tailor your efforts to the most pressing issues
    Timing: anticipate what the business needs to move forward
    Listen in to learn more and gain other tips for fully embedding compliance into the business process.
    9 min
  • Greg Garcia on Healthcare Cybersecurity Risk [Podcast]
    By Adam Turteltaub
    At the center of managing cyber risk in healthcare sits the Health Sector Coordinating Council Cybersecurity Working Group (LinkedIn). In this podcast, Executive Director Greg Garcia explains that healthcare has been designated as a part of the critical infrastructure, and the council has as its mission to: “identify systemic cybersecurity threats to critical healthcare infrastructure; collaborate on guidance and policies for mitigating those risks; and promote threat preparedness and incident response awareness and activities.”
    It’s a needed mission. The number of data breaches have soared, and ransomware has emerged as a top threat, crippling the ability of healthcare providers to care for patients.
    The Council recently released its Health Industry Cybersecurity – Strategic Plan. A five-year plan, it identifies trends, goals and objectives for securing healthcare technology infrastructure.
    One key goal, in the words of the plan, recognizes that, “A trusted healthcare delivery ecosystem is sustained with active partnership and representation between critical and significant technology partners and suppliers, including non-traditional health and life science entities”  It sets four objectives under that goal:
    Simplify access to resources and implementation approaches related to the adoption of controls and practices aligned with regulatory and sector standards for securing devices, services, and data
    Increase new partnerships with public/private entities on the front edge of evaluating and responding to emerging technology issues to enable safe, secure, and faster adoption of emerging technologies
    Enhance health sector senior leadership and board knowledge of cybersecurity and their accountability to create a culture of security within their organizations
    Develop meaningful cross-sector third-party risk management strategies for evaluating, monitoring, and responding to supply chain and third-party provider cybersecurity risks
    Listen in to learn more about the document, the council and how the healthcare sector is working together to stem cyberthreats.
    12 min
  • Markus Funk on FCPA Enforcement and Compliance [Podcast]
    By Adam Turteltaub
    The FCPA sure isn’t what it used to be, or is it?
    While the headline grabbing Foreign Corrupt Practices Act cases are much less frequent than they once were, there is still substantial risk both for individuals and companies, as recent dispositions have shown.
    To understand where things are we sat down with Markus Funk, partner at Perkins Coie and author of the chapter “Anti-Bribery and Corruption Compliance Programs” in The Complete Compliance and Ethics Manual 2024.
    He explains that just because there aren’t cases in the news, doesn’t mean all is quiet. There may remain a steady stream of companies self-reporting violations and reaching less-formal agreements with the DOJ.
    Whatever the trend may be, third parties remain the greatest risk, and the prescription stays the same. You need to know who the third party is and hire them for the right reason: their expertise and track record for success in the right way. Hiring a government official’s cousin to help get the deal remains a very bad idea.
    Another bad idea:  assuming your people are not a risk area. They are. Be sure to be sensitive to internal risks. Train the workforce and work with the finance team to help them serve as an extra sets of eyes when it comes to spotting misconduct.
    Above all, stay alert and be prepared to investigate possible incidents. Prosecutors still expect companies to bear the brunt of the investigative burden.
    10 min
  • Krista Muszak on Project Management and Process Improvement [Podcast]
    By Adam Turteltaub
    Krista Muszak is organized. More importantly, the longtime compliance professional and Senior Manager, Regional Process & Optimization Lead for Pfizer knows how to keep others organized as well.
    She will be sharing some of this wisdom in Nashville at the 2024 HCCA Compliance Institute in the session “Muda, Mura, Muri to Veni Vidi Vici: Applying Project Management and Process Improvement to Your Compliance Program.”  She also shares a bit of it here in the latest Compliance Perspectives podcast.
    First, she explains that the title comes from terms used by Toyota to improve the process flow at their plants and eliminate waste.
    Muda is about eliminating waste and activities that don’t add value.
    Mura speaks to addressing variability in operations to increase stability and reduce unnecessary variations.
    Mudi addresses not overloading people and the business with too many asks, such as releasing a round of training at the same time as year-end activities.
    Embracing these concepts can increase efficiency and effectiveness. At the same time adopting a project management approach helps build guardrails around your efforts. Use it to identify who is responsible, who is accountable, who needs to be informed and who needs to consulted. This brings clarity into who the key players are and their responsibilities.
    With the right people on board, a project charter can be extremely effective, identifying what the project goals are, and what they aren’t. From there it is time, she explains, to move on to measure, analyze, improve and establish controls for your initiative.
    Listen in to learn more about how to bring greater effectiveness and efficiency for your compliance efforts.
    15 min
  • Parth Chanda on Using Technology to Improve Your Compliance Program [Podcast]
    By Adam Turteltaub
    When it comes to compliance technology, there are two challenges. First is finding the right solutions to increase your programs effectiveness. Second is securing the resources to acquire and deploy the technology.
    Parth Chanda, Founder and CEO of Lextegrity, covers both topics in this podcast.
    When it comes to tech, he explains, you want tools that give you the confidence that your program is effective in practice and not just on paper. You also need to prioritize based on risk, and your organization’s own experience with technology. If the history is short or non-existent, start with something relatively simple such as training or policy management.  Tools that can make it easier for employees to report wrongdoing are also invaluable.
    To secure the resources you need, he advises making the business case by focusing on the ROI, for example, by showing that investigations can be completed in less time and with less staff.
    But, as you look at technology, be realistic and recognize that technology will not remove human judgement. It can expose gaps and gray areas, but then the compliance team will need to step in to understand the nuances and the appropriate solution.
    15 min
  • Jenna Wells on Leaning In on AI [Podcast]
    By Adam Turteltaub
    Imagine you are at a large company with thousands of suppliers. As a part of the compliance team you need to understand the risk of working with each and every one of them. To do that you may need to understand the ownership structure, where they source materials, where and how they manufacture, and a host of other data about each and every one of them.
    That’s a daunting task. It’s also one that Jenna Wells, Chief Customer and Product Officer at Supply Wisdom believes is ideally suited for AI. With human supervision it can help with such a large, seemingly impossible undertaking.
    AI, she argues, can be an effective tool for enabling compliance programs to better understand the risks they face and then focus on the most important ones.
    To get there, compliance teams need to get a handle on the data that they have that is normally siloed. Look to external sources for regulatory data and emerging legislation, she suggests.
    At the same time, though, it’s important to understand the limitations of AI. While it can handle the brute force exercises, such as combing through all the data on all those vendors, there is still a need for the human element.
    Listen in to learn more about putting the power of AI to work for your compliance efforts.
    16 min
  • Tanya Ganguli on the New Indian Criminal Laws [Podcast]
    By Adam Turteltaub
    Traditionally, explains, Tanya Ganguli (LinkedIn), Principal Associate, Law Offices of Panag & Babu, India’s criminal law framework revolved around the Indian Penal Code, The Code of Criminal Procedure and the Indian Evidence Act, two of which dated back to the 19th century. That changed with the passage of three new laws: the Bharatiya Nyaya (Second) Sanhita, 2023, the Bharatiya Nagarik Suraksha (Second) Sanhita, 2023 and the Bharatiya Sakshya (Second) Bill, 2023.
    Together they seek to bring criminal law into the 21st century and build off of long-established precedents. They are designed, she reports, to address loopholes, enhance efficiency and ensure justice.
    The laws are now more victim centric, but may not be too transformative, according to Tanya, for most compliance and ethics programs. Nonetheless, there are changes. New rules for searches and seizures will likely require updated training on dawn raids. Summons can now be delivered electronically. There is much greater need to digitize and consolidate records. Having the right tone at the top will be more important than ever.
    However, the change is likely to come relatively slowly with many aspects of the law expected to be implemented in stages.
    So keep your eye on the horizon in India, and be sure to listen to this discussion.
    Also, don’t miss the first ever SCCE Basic Compliance & Ethics Academy in India.
    14 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,492 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,359 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,717 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,249 Listeners

Pivot by New York Magazine

Pivot

9,616 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,447 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,244 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

801 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,882 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,446 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,254 Listeners