Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Meiran Galis on Data Security, SOC 2 and ISO 27001 [Podcast]
    By Adam Turteltaub

    Improving data security at your organization doesn’t just protect you, it can also increase your business, explain Meiran Galis, Chief Executive Officer of Scytale. Customers increasingly want to know that their business partners’ systems are secure and that critical data will not get stolen or held hostage in a ransomware attack.

    To ensure that they are meeting data security standards and can provide their customers the assurance that they seek, many organizations pursue SOC 2 or ISO 27001 certification. As Meiran explains, there are key differences between the two.

    * SOC 2, he reports, has become the new gold standard for SaaS applications. It is generally considered of greater value in the US and is not technically a certification. An attestation report is made and independently certified.
    * ISO 27001 is a traditional certification and is focused on information security management. It is more popular outside the US, especially in Europe.

    So, should your organization pursue SOC 2 or ISO 27001? That depends on where your current and potential customers are and what they require. Ask sales if prospects and customers are already wanting a certification from your organization.

    Once you decide on which certification to pursue, or if both make sense, don’t expect it to be a fast process. For small organizations it may take 250 hours of work.  For larger companies, it may take 1000 hours or more.

    Once you earn the certifications, have a plan in place to continuously monitor and periodically audit your efforts.

    Listen in to learn more about whether SOC 2, ISO 27001 or both are necessary to protect and grow your organization.
    15 min
  • Ty Francis and Eric Morehead on Assessing Your Compliance Program [Podcast]
    By Adam Turteltaub

    The writing on the wall is pretty clear: regulators expect compliance programs to be custom designed for the organization and kept up to date. That means compliance teams need to stop periodically and reassess their program to ensure it is effective in practice and not just on paper.

    In this podcast, LRN’s Ty Francis MBE, Chief Advisory Officer and Eric Morehead, Director, Advisory Solutions explain that regulators want to know if organizations are targeting their compliance resources to the risks that they are facing.

    To allocate efforts successfully, it is essential to look at the data to see if your program is effective.

    Yet, they point out, it’s not just a numbers game in which more spending leads to more results. If, for example, there is an issue with employees not speaking up and living in fear of retaliation, paying for more training is not going to be enough. Instead, compliance teams need to look holistically at the situation and address the underlying cultural issues. That includes demonstrating to employees that a manager who retaliates will face discipline.

    So how do you conduct an effective assessment? First, they recommend budgeting enough time. The process tends to take longer than people think given the number of people you will need to interview and the time at the front end to gain support from leadership.

    Next, make the effort to talk to people from the top of the organization to the bottom. Do so in person, or via surveys if necessary. As you do, be sure to learn how they feel about the compliance programs, the culture of the organization, violations they may be seeing and the ability to speak up without fear.

    Finally, they advise looking outward. Benchmark your efforts against your peers. This can provide context and expose you to ideas and solutions you may not have been aware of.

    Listen in to learn more, and then spend some time assessing your assessment program.
    16 min
  • George Tziahanas on New International Privacy Laws [Podcast]
    By Adam Turteltaub

    GDPR, CCPA and HIPAA all pose daunting privacy challenges for organizations.  But, George Tziahanas (LinkedIn), Managing Director of Breakwater explains that there are many more national laws to consider. In this  podcast he takes us through five countries with laws and regulations that global compliance and privacy teams needs to consider.

    The People’s Republic of China
    China’s law, he reports is very focused on the company’s national interest and a belief that preserving data, particularly critical data on firms and infrastructure, needs to stay in the country. The law affects whether data can be transferred outside China and under what circumstances. It also has limits on what information can shared with foreign law enforcement.

    France
    The US Cloud Act triggered concerns in many jurisdictions around the world. The French National Security Agency established a certification program that now requires French nationals to run cloud-based services in France and limits the ownership levels of foreigners. It affects broad sectors of the economy.

    Germany
    The largest economy in Europe is embarking on efforts similar to those in France, which is having the effect of creating digital borders in the EU. They have created a sovereign cloud, in partnership with the private sector, that affects government agencies, vital services and critical sectors of the economy.

    The Kingdom of Saudi Arabia
    Saudi Arabia has classified certain data as needing to stay within the country. This has led to partnerships with cloud vendors to bring their infrastructure into the country.

    Dubai
    The UAE, he reports, has long had limits on encrypted voice channels and VOIP. To gain access to cloud technology they, too, are slated to introduce new data and cybersecurity rules that are anticipated to be similar to Saudi Arabia’s.

    In sum, organizations are now increasingly facing a world in which data transfers will be more complex and where data is housed will be closely scrutinized and limited. Listen in.
    14 min
  • Cindy Morrison on Trust and Speak-Up Cultures [Podcast]
    By Adam Turteltaub

    Getting employees to come forward and raise issue can be difficult. There is often genuine fear of retaliation, and many don’t trust that the company will do anything. It’s a topic that Cindy Morrison CCEP (LinkedIn), Director, Global Ethics and Compliance, Post Holdings, Inc. will be addressing at the 2022 SCCE Compliance & Ethics Institute and tackles in the latest Compliance Perspectives podcast.

    Her own journey of discovery in this area was jolted by an assessment revealing that employees did not think the company had a speak-up culture. The key to creating one, she realized, is encouraging respectful dialogue. A true, two-way discussion is necessary to help build the trust that is so essential. Employees want to be heard, and if the company isn’t listening to them, they are never going to feel safe.

    Showing that the organization is listening begins with making the effort to know the employees, a difficult challenge in this remote-working world where employees tend to change jobs frequently. Still, it must be done and managers need to practice active listening and adapting communications style to the listener.

    It also means demonstrating that when employees speak up, actions are taken: bad actors get disciplined or fired, policies are changed or publicly reinforced.

    In addition, it is essential to remember that each facility may have its own distinct culture. That may stem from the history of the facility and who has worked there, or the ethnic makeup of the employees. It’s also important to remember that not all facilities in the same country will share a common culture. As she notes, their operation in Minnesota is 70% Somali.

    Finally, she underscores the importance of constant education. Make sure the workforce knows all the ways it can raise issues and what to do if they feel they are being retaliated against.

    Listen in to learn more, and then join us at the 2022 SCCE Compliance & Ethics Institute.
    13 min
  • Vin Lacovara and Corey Parker on Risk Assessment Frameworks [Podcast]
    By Adam Turteltaub

    What’s a risk assessment framework? How can it help?

    Vin Lacovara, Institutional Compliance Leader, George Mason University and Corey Parker, Director, Baker Tilly, explain that the framework is a document that should be tailored to the organization’s needs and starts with an inventory of applicable laws and regulations. Next, the responsible personnel and controls that are in place should be added, followed by a preliminary prioritization of risk areas. Then, more details can be added, looking on the more granular level.

    All in all, the process should take about a month. The harder, longer work comes next and involves filling out all the efforts that need to be put in place.

    How often should the framework be reassessed? That depends on the organization’s priorities and how high a given risk is. Any high risk area that threatens to literally or figuratively shut the institution down should be looked at more frequently to see where the institution’s risk mitigation efforts stand.

    To ensure that the framework is properly tailored to your organization, they recommend investing time in developing relationships with stakeholders to make sure their needs are met.

    The most important thing is to start somewhere, don’t let yourself get bogged down, and look for the process to develop and improve over time. Perfection out of the gate is not likely.

    Listen in to learn more about how to create a proper risk assessment framework.
    15 min
  • Rich Hale on Data Security and Privacy [Podcast]
    By Adam Turteltaub

    The challenge of complying with data protection laws is growing more complex, with US states increasingly having their own laws or considering adopting them. This had led many to call for one national data privacy law for the US.

    Rich Hale, Chief Technology Officer, ActiveNav hopes that a national law emerges that identifies and normalizes the common threads in the various state requirements. Until then compliance needs to draw out those threads, itself, and provide clear advice on core requirements.

    Compliance teams, he advises, also need to resist the temptation to boil the ocean and try to solve all the challenges at once. Instead, as elsewhere, it is better to identify and prioritize the risks. Then, work in partnership with operations to implement effective mitigation plans.

    One key area to focus on is identifying what data the organization has and the justification for holding it, including understanding where the data is being used. That is often easier said than done, since many organizations do not have a full appreciation of all the uses of the data. Finding that information, he reports, is both a top-down and bottom-up exercise.

    Here, too, prioritization is critical. You need to determine where the data is used most actively, including the unstructured data.

    Listen in to learn more about how to get a better handle on your data in the face of regulatory complexity.
    13 min
  • Marsha Ershaghi Hames on The Board’s Role in Corporate Culture [Podcast]
    By Adam Turteltaub

    Corporate culture, tone at the top, proper governance and the relationship between the board and compliance have all been frequent subjects of conversations of late. In this podcast, Marsha Ershaghi Hames, partner at Tapestry Networks, shares recent research into governing boards and their role in shaping corporate culture.

    The report, Assessing Corporate Culture:  A Practical Guide to Improving Board Oversight, and the research leading up to it, revealed that culture Is most definitely a focus of directors, and there is a strong need for board alignment on what the culture should be.

    Turning that vision into a reality requires building bridges and a partnership between the board and the management team. It also requires data to measure where an organization is and to track progress about where it is going.

    That is not all, though. Directors who formerly held compliance roles were quick to point out that there is a need to think beyond the numbers and balance quantitative, qualitative and anecdotal evidence. All these measures are essential to developing a holistic view.

    The report, which was developed after interviews with 40 directors from 65 publicly traded companies, revealed five keys to success:

    * Prioritize culture on the agenda
    * The board has to challenge its own culture
    * Monitor and measure, but also create blended data sources
    * Ensure that the culture is articulated and simplified enough that it can be measured
    * Calibrate the board and management structure to optimize the information flow

    The last step means enabling managers, including compliance, to communicate directly with the board as needed to give it a fuller picture of the organization.

    Listen in to learn more about how to help the board lead in shaping corporate culture.
    12 min
  • Chris Audet on Helpline Usage, Or Lack Thereof [Podcast]
    By Adam Turteltaub

    The 2022 Risk & Compliance Hotline & Incident Management Report from NAVEX included data that showed that helpline calls, while increasing, were not back to pre-pandemic levels.

    New research from Gartner confirms that data, reports Chris Audet, Gartner’s Senior Director, Research. It also provides new insights into reporting and where organizations continue to struggle to win over their workforces.

    The drop in observed misconduct reported likely reflects, he explains, a decline in actual misconduct – a reflection of less opportunity for it – and a significant change in the landscape: the type of misconduct is changing. Bullying, intimidation, unwanted behavior and misuse of time and resources are going up.

    So what should organizations do with employees calling the helpline not as often? He recommends relying less on reporting and more on embedded controls, as was discussed in his previous podcast. In addition, many are seeking technologies that support narrow risk areas such as insider trading.

    Gartner is also seeing an increase, he reports, in questions about wider views into risk through GRC and other third-party risk tools.

    But, even with all that, the helpline is critically important to compliance programs. To increase its usage, the research suggests revisiting the value proposition about reporting. Expectations have change for the employer/employee relationship over the last few years. Feeling safe from retaliation is not the driver that it was thought to be. Their data suggest that there are other levers to pull.

    Listen in to learn about what those levers are and how to use them most effectively.
    14 min
  • Melanie Sponholz and Nick & Gio Gallo on Compliance Budgets [Podcast]
    By Adam Turteltaub

    Melanie Sponholz, Chief Compliance Officer, WCP Healthcare, Nick Gallo, Chief Servant and Co-CEO of ComplianceLine, and Gio Gallo, Co-CEO and CTO of ComplianceLine have a simple message for compliance officers:  don’t be embarrassed about asking for the budget you need.

    Historically, they report, compliance budget proposals have not been strong, and some programs have even lacked a formal budget, which is consistent with the historical perception that compliance is a cost center.

    Changing that dynamic, they argue in this podcast, means taking a more positive approach and discarding any apologetic tones to the budget request. Instead, they counsel going in knowing the worth of the program and feeling empowered to create a budget based on the resources the program needs, just as other department do.

    Let management know what your goals are, what it will take to achieve them, and how much of an investment is required now, they say. Also, don’t worry about the data you don’t have. Instead, focus on what you have and know, and use it to support your argument.

    When presenting the budget, they offer three additional pieces of advice:

    * When facing feedback and hard questions, don’t freak out. It’s a normal part of the process.
    * Anticipate objections and concerns, and be prepared to address them.
    * Be honest.

    If you can approach the budget meeting calmly and feeling prepared, you will be far better off.

    Listen in to learn more, including what poker players can teach you about getting the right budget for your compliance program.
    15 min
  • Amii Barnard-Bahn on Delivering Bad News [Podcast]
    Post by Adam Turteltaub

    No one likes to be the bearer of bad news, but if you sign up for a job in compliance, you are inevitably going to be one. The challenge is doing so in a way that is most productive.

    Long-time compliance veteran and executive coach Amii Barnard-Bahn has invested a great deal of time in studying this challenge. She reports in this podcast that social science has discovered that bad events impact us five times more than positive ones. We are programmed not to want bad news. Worse, messengers of unwelcome information tend to be deemed unlikeable and less competent. There is even some malevolence towards them, believing, usually wrongly, that the person got some pleasure from sharing the unpleasant news.

    So how do we overcome it? She developed a six-step process:

    * Psychologically prepare your audience
    * Rehearse confident delivery
    * Be present and fully focused
    * Convey benevolent, proactive intent
    * Explain without justifying
    * Add a sense of urgency

    Psychological preparation of the audience, she explained, is often overlooked. When people are surprised it can slow down their thinking and increase negative emotions. So, it is best to prepare people for what is coming. Then let them know what the cost will be, time involved and what needs to change.

    Conveying benevolent, proactive intent is about overcoming the gut perception that somehow you were involved, wanted the incident to happen or are to blame. Chances are you were not the one at fault and you need to help people see it. When you did make a mistake, take the blame, accept responsibility and then show a path forward.

    Listen in and learn more about how to make delivering bad news better.
    12 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners