Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Joshua Drew on Attachment C Compliance Guidance [Podcast]
    By Adam Turteltaub
    While most eyes have focused on the US Department of Justice’s document Evaluation of Corporate Compliance Programs when looking for guidance, it’s not the only DOJ source out there.
    Josh Drew (LinkedIn), Member, Miller & Chevalier explains that it would be wise to also look to Attachment C. What is it? It’s a document typically attached to Foreign Corrupt Practices Act (FCPA) resolutions. It specifies what the defendant company will need to do to establish and maintain an effective corporate compliance program. As a result, it, like the Evaluation document, provides very clear guidance as to what the DOJ’s thinking is when it comes to compliance.
    In August and September 2023 there were several changes to Attachment C. For one, it expanded the call for support from senior management down to include midlevel management as well. It specifically points to the importance of their tone and conduct:  “The Company will ensure that mid-level management throughout its organization reinforce leadership’s commitment to compliance policies and principles and encourage employees to abide by them.”
    In the realm of training, it calls for metrics to assess the effectiveness of the training, not just that it was given. That’s a theme consistent with other direction from the DOJ.
    Not surprising for an FCPA-related document, it also calls for documenting the business justification for engaging a third party and ensuring that contract terms are specific. Third parties should also be tracked after the initial engagement, which means ongoing due diligence.
    And, here, too, as elsewhere, the Department of Justice reinforces the importance of both incentives for good behavior and disincentives for bad.
    Listen in and then be sure to spend some time reading Attachment C.
    12 min
  • Nancy Roht on HIPAA Deep Dives [Podcast]
    By Adam Turteltaub
    At this point anyone in healthcare who doesn’t have a plan for managing HIPAA compliance risks is behind the eight ball and times. But, for those who do have a program in place, the question is: does it currently reflect your risk profile?
    Nancy Roht (LinkedIn), Managing Principal at Compliance Pro Consulting points out in this podcast that just because the HIPAA regulations don’t specify how often a HIPAA risk assessment should be done it’s best to do so annually, and perhaps even more frequently if something significant happens. Changes in leadership, organizational structure, goals, quality and major vendors can all call for a fundamental reexamination of your strategy.
    When conducting the assessment, don’t mistake it for a gap analysis. Make it a true assessment of risk and put together a work plan to address any deficiencies.
    When conducting the assessment, she recommends interviewing both leadership and staff to get a comprehensive picture. Take an inventory of the PHI you have, potential threats, vulnerabilities and security measures. Then, assign risk levels, prioritize and document your thinking. Years from now no one will remember what decisions were made and why, without the documentation.
    Be sure to look externally at your business associates, particularly those with evergreen agreements. They may have run out of date.
    Listen in to learn more about how to make your HIPAA risk assessment stronger.
    16 min
  • Steve Forman on Monitoring and Auditing [Podcast]
    By Adam Turteltaub
    Steve Forman (LinkedIn), Senior Vice President at Strategic Management Services, had an eye-opening experience years ago when interviewing for the job of Vice President of Audit and Compliance for New York Presbyterian Hospital. The chair of the board’s audit and compliance committee told him that his main role was not to find problems or weaknesses but to validate through the discipline of the audit processes what management suspected were problematic areas in terms of audit and coverage of risk areas.
    That insight had several implications. First, it underscored that operational managers will always know more about their risk areas than auditors will, which means they are in the best position to identify problems and weaknesses. Second, it was a good reminder that there are never going to be enough auditors to even address the high risk areas. Once again, we are dependent on managers.
    So what does that mean? It means that monitoring should help drive the audit plan and strategy. In addition, managers need to be listened to on a regular basis, and they should be charged with monitoring.
    In addition, he observes that the risk assessment must also not be treated as a static document. Risks can go up and down during the course of the year, and the risk mitigation strategy needs to be adjusted with it.
    Listen in to learn more about how to improve your monitoring and auditing, as well as the role of management in it.
    11 min
  • The FBI on Economic Espionage [Podcast]
    By Adam Turteltaub
    Economic espionage sounds more like the stuff of a spy thriller than a day-to-day concern for business. Not so, as it turns out. To learn more we sat down with the FBI’s Counterintelligence Division Unit Chief Matthew Charles and Cyber Division Supervisory Special Agent Michelle Liu.
    Economic espionage generally refers to stealing trade secrets for the benefit of an overseas competitor, often one aligned with a foreign government. An employee at your organization working on a sensitive project may be leveraged, frequently with the lure of cash and other payments.
    Typical targets include technology with potential military use and, of late, pharmaceuticals.
    To counter this threat, the FBI Cyber Division maintains partnerships with many private sector companies to identify nefarious conduct on their networks. Meantime the Counterintelligence Division looks upstream for actors coming into the US seeking access to US technology.
    So what should companies do? First, protect yourself. Encryption can be helpful along with limiting access to sensitive information only to key people. Make sure, too, to track who in your firm is accessing trade secrets.
    Also, be sensitive to unusual employee behaviors or changes in affluence levels. An employee suddenly downloading large files at night, emailing their personal email address sensitive information or whose debt problems have inexplicably disappeared could be engaged in economic espionage.  Just don’t jump to any conclusions.  There could be legitimate reasons for these actions.
    Second, the FBI advises reaching out to them when an incident occurs. The FBI can’t investigate without ongoing collaboration of the victim organization. They also advise that it is never too early to call them in, and if you do not want them there, they will pull out.
    Finally, take the time to leverage government resources. Be sure to familiarize yourself with the US Department of Justice’s Criminal Division’s Computer Crime and intellectual Property Section (CCIPS) website.
    You will find there information on reporting computer, internet-related or intellectual property crime.
    And, of course, listen in to the podcast to learn more about the risks of economic espionage and what you can do to mitigate it.
    13 min
  • Jason Meyer on Neurodiversity [Podcast]
    By Adam Turteltaub
    How do you understand “neurodiversity” or “neurodivergence”? It starts with the recognition that no two human are exactly alike and not two brains function exactly the same way. It then goes on to recognize that for people with ADHD, autisms, dyslexia, sensory integration and executive function issues, those differences can be substantial.
    Estimates are that about 20% of the workforce has some sort of neurodivergence.
    In this podcast, Jason Meyer (LinkedIn), President of LeadGood Education, explains that compliance teams need to recognize neurodivergence when communicating with the workforce. This means looking for more structured communications that make it easy for learners to see things step by step.
    Another technique to pursue is reducing cognitive loads and demands on working memory. A test at the end of a two-hour course may be too much for many people to be able to manage successfully.
    Some other tips include having visual cues to accompany text and offering an audio option. That way if someone is limited in one sense, they can rely on another.
    If you have someone neurodivergent on your team, start with watching your assumptions. If a person is person not making eye contact or responding to questions haltingly, don't assume they don't care. They may be neurodivergent.
    Above all, be empathetic and listen, and park your preconceived notions at the door.
    Listen in to learn more about the challenges and opportunities with neurodiversity.
    15 min
  • Vera Cherepanova on the EU Directive on Combatting Corruption [Podcast]
    By Adam Turteltaub
    Currently there is a patchwork of anticorruption laws across the EU. What has been lacking, though, is a EU-wide approach. That is likely to change soon, reports Vera Cherepanova, founding partner of Studio Etica.
    Change is afoot.  In May 2023 the EU issued a new proposal to combat corruption, including a new Directive of the European Parliament and the Council on combatting corruption by criminal law.
    The new directive, she explains, makes it clear that actions by senior executives can have significant consequences both for the individuals involved and their organizations. Companies could face fines of no less than 5% of worldwide turnover.
    Notably, like the US Foreign Corrupt Practices Act, the new EU directive has extraterritorial reach, which raises the prospect of more enforcement actions.
    The directive also includes incentives for compliance programs consistent with what is found in law elsewhere: “…where legal persons have implemented effective internal controls, ethics, and compliance programmes, it should be possible to consider these actions as a mitigating circumstance.”
    Meantime, across the English Channel, the UK Parliament is considering a new Economic Crime and Corporate Transparency Bill, which could be represent a hugely significant change in the enforcement landscape. It includes a crime of failure to prevent fraud. In addition, corporations can be held liable for acts of senior managers.
    Listen in to learn more about the upcoming changes and what they may mean for your compliance program.
    16 min
  • Kristine Coy-Foster on Goal Tracking [Podcast]
    By Adam Turteltaub
    Kristine Coy-Foster (LinkedIn), Senior Manager, Compliance & Employee Engagement at Vulcan, had a challenge many in compliance face: tracking all her to-dos, and then, once a to-do turned to done, tracking the accomplishment. It was important for her to be able to capture the challenges she faced, new ideas tested and processes developed.
    Trying to keep it all straight in Outlook or Excel spreadsheets wasn’t enough. To solve the problem she invested the time to learn Smartsheet, a platform that primarily is for managing projects and automating processes. In it, she created workstreams, alerts, dashboards and more.
    She also created categories for each of the functional areas she oversees and organized her to-dos accordingly.
    The solution has worked well for her, but, she cautions, it does take a strong commitment to keeping everything up to date.
    Listen in to learn more about how to put this tool to work for you, or, maybe, customize the tool you are already using to track your own compliance team’s progress.
    13 min
  • Evelyn Suarez and Thad McBride on the Uyghur Forced Labor Prevention Act [Podcast]
    By Adam Turteltaub
    Since the 1930s the United State has had import bans on forced and convict labor. But, the rules were tightened, explains Evelyn Suarez, Principal, The Suarez Firm and Thad McBride, Partner, Bass, Berry & Sims PLC, in 2021. That is when Congress passed the Uyghur Forced Labor Prevention Act (UFLPA). The act has a rebuttable presumption that goods made in whole or part with labor from the Xinjian region in China is made with forced labor.
    If US customs suspects that goods are made in this region, they can stop them until the importer can provide the necessary assurances. In addition, goods made in other regions are also being stopped because their supply chain includes labor from Xinjian.
    So, what should compliance teams do to help the business unit navigate the issue? For one, it’s key to go beyond the first line supplier, as is typical, and start looking deeply into the supply chain and start researching your supplier’s suppliers.
    Suppliers should be asked what connections they have to China. Mapping questionnaires should be developed and issued. Training needs to be given, and third-party vetting vendors will likely be needed.
    In addition, develop interdisciplinary teams to create a plan for responding should a shipment be held. Even before that, start developing a good relationship with customs and take advantage of their expertise.
    As is the case with so much else in compliance, keep good records that you can present to customs, maybe even on a proactive basis.
    Finally, keep your eyes open for customs ruling and court cases that may provide guidance on what to expect next.
    15 min
  • Stefani Sonzzini Navarro on When Employees Report on Themselves [Podcast]
    By Adam Turteltaub
    We spend a lot of time in compliance discussing how to encourage employees to come forward and report any wrongdoing they see around them. Considerably less time, though, is spent on how to handle employees who report their own wrongdoing.
    In this podcast, Stefani Sonzzini Navarro, LATAM Compliance Officer for Corteva Agrisciences balances the scales.
    Encouraging employees to come forward with their own questionable acts, she explains, begins with having the right culture. People need to be comfortable and feel safe to report.
    Getting there takes time and repetition, she explains, along with a strong anti-retaliation policy that covers self-report wrongdoing as well.
    When an employee first brings the potential issue to your attention, she advises letting them know that if they report something you are obligated to act on it, and that you have to do what is in the best interest of the company. Let them know you will protect their confidentiality as much as possible, but that you also will have to remediate.
    This will help build trust, but also let them know what is likely to happen.
    The subsequent investigation should be conducted as quickly as possible, in recognition of how anxious the subject likely is.
    Throughout, she advises, be open and make yourself available.  If you let the employee grow too anxious, there could be adverse behaviors and consequences.
    If the employee has in fact done something wrong, their willingness to report much be recognized.  Let them know that things would have been worse if they had not spoken to you.
    Listen in to learn more about how to encourage and support self-reports of wrongdoing.
    13 min
  • Maria Victoria Mota on Brazil’s AI Legislation [Podcast]
    By Adam Turteltaub
    While many of the world’s governments are struggling to determine what to do about AI, Brazil already has a track history in this area. As Maria Victoria Mota, Corporate Attorney at Viapol (a subsidiary of RPM), explains in this podcast, the roots of government action in Brazil go back to 2018 with data protection regulations that are similar to the European General Data Protection Regulation (GDPR).
    This initial legislation was followed by a second in 2020 created to develop the rules of how the government, companies and individuals may use AI. It was followed by more legislation, most recently in 2023.
    The latest came after a committee of jurists was created to help frame the bill. Working with scientists and experts in technology, they examined how AI should be used and AI laws of 31 different countries. The goal was to creation legislation specific for the needs of Brazil.
    Privacy is a central pillar of the bill, which is also based in human rights and sound data protection practices. It is designed to ensure accountability, and organizations seeking to comply need to follow eight steps, Maria explains:
    Create a multidisciplinary work group.
    Empower the group with knowledge so they can bring learning to company.
    Map AI in the company.  Understand what departments are using it and how much.
    Create a policy and procedures around AI and document them.
    Train employees on the policies and procedures created so they can understand how important they are.
    Apply the policy and procedures.
    Stay current with changing laws and regulations.
    Audit compliance regularly
    Listen in to learn more about both Brazilian AI law and what makes for effective internal controls around the use of AI.
    11 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,492 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,359 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,717 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,249 Listeners

Pivot by New York Magazine

Pivot

9,616 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,447 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,244 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

801 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,882 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,446 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,254 Listeners