Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Chris Ford on Compliance and Cloud Computing [Podcast]
    Post By: Adam Turteltaub

    While organizations have increasingly embraced cloud computing as a solution to their data management and other needs, they do so in an environment of heightened risks. Attacks on cloud providers are increasing, which makes it ever more important to ensure that the rewards outweigh the risks, including from a compliance perspective.

    Chris Ford, Vice President Product, Threat Stack, advises organizations look to cloud service providers that have taken the step of becoming certified against standards such as ISO 27001 or SOC 2. He also recommends not stopping there and looking to certifications that align with specific risk areas such as IPAA, GDPR, CCPA or PCI.

    That’s still not enough, though, he cautions in this podcast. Meet with the security team to discuss the organization’s practices and how it manages third party vendor risk. If their practices aren’t secure or the team is unwilling to meet with you that should be a very large red flag. So, too, is the approach to compliance:  stay away from vendors who take a check-the-box approach.

    Other pieces of advice he offers:

    * Ask if they scan code in the build pipeline
    * Determine if they do runtime monitoring of the infrastructure
    * Find out what tools they use to ensure your date is secure
    * Make sure they are constantly scanning for vulnerabilities

    Finally, security is a “team sport” he notes. It’s important to maintain trust on an ongoing basis and look at this as a journey together. Be sure to learn from the failures of others, and, of course, make sure that you are just as vigilant of your internal IT security as you are of your vendor’s.
    14 min
  • Tyler Shultz on Compliance Lessons from Theranos [Podcast]
    Post By: Adam Turteltaub
    With the Theranos trial in the news, we thought we would repost this podcast with former Theranos employee and whistleblower Tyler Shultz.
    Tyler Shultz, like many others, was entranced by the vision of Theranos and its charismatic founder Elizabeth Holmes. He would not remain so for long, ultimately sharing his concerns with her, his grandfather (a member of the board), and then becoming a source for a Wall Street Journal reporter, and a whistleblower, reporting to New York state’s public-health lab his concerns that the company’s proficiency tests had been manipulated.

    On March 30, 2020 he will be sharing his experiences and insights at the 2020 Compliance Institute, and he was also kind enough to talk with us for the Compliance Perspectives podcast.

    In a very frank discussion, he tells us how the culture of Theranos discouraged people from coming forward and raising issues. In fact, there were severe disincentives for doing so ranging from potential loss of a visa to litigation.

    We also discuss what drew him to the company and why it was so hard to face the dark reality behind the enticing façade.

    Finally, he addresses signs that compliance professionals should watch out for that could be symptomatic of a very dysfunctional culture, if not outright wrongdoing.

    Listen in to hear what he has to say and then plan on hearing much more at the 2020 Compliance Institute.
    13 min
  • Peter Baumann on Dark Data [Podcast]
    Post By: Adam Turteltaub

    “Dark data” sounds ominous, and as Peter Bauman (LinkedIn), Founder and CEO of ActiveNav explains in this podcast, it can lead to great risks for organizations.

    Dard data is essentially data which organizations collect as a part of their business processes but don’t necessarily have a plan to use. It is also data that rarely gets thrown out, instead residing indefinitely on devices and services. It includes weblogs, tracking data, surveillance footage, email correspondence, chatroom conversations, presentations and old spreadsheets.

    This data is typically unstructured, and often it is very opaque.

    It also carries significant risks including the need to access it during litigation, and it even may create privacy issues.

    How can you get a handle on this data? Shine a light on it. Determine where it is in your organization and start building a data inventory that classifies the data.

    Next determine what is worth keeping and what needs to be destroyed. And, for the data worth keeping, take the trouble to classify it.

    Most of all, treat this as an ongoing issue to manage. Data tends to collect itself, in many ways, and organizations need to be aware of what it has and what it’s for. That requires the creation of better policies for collecting and managing data.

    Those policies need to be pragmatic, reflecting both business needs and the inevitable collection of ever more amounts of data.

    Listen in to learn more about dark data and how you can start bringing it into the light.
    12 min
  • Jannica Houben and Katarzyna Golonka on Complex Investigations [Podcast]
    Post By: Adam Turteltaub

    You’re about to begin a complex investigation. What should you be thinking about? What should your first steps be?  And what tricks of the trade are there?

    To find out we spoke with Tech Data’s Jannica Houben (LinkedIn), Vice President Global Legal Transformation and Katarzyna Golonka (LinkedIn), Vice President Global Compliance. The two of them will be leading the virtual session “Advanced Investigations in Multi-National Companies” at the 2021 SCCE Compliance & Ethics institute, which takes place September 19-22, 2021.

    A good investigation, they explain, needs to be properly scoped and be staffed with qualified personnel. In thinking who those people would be for your organization, they advise remembering to consider both the obvious and the subtle issues such as the languages you need on the team. And, of course, be sure your interviewers are well trained, not just eager.

    Other things to think about right at the start:

    * The legal expertise needed to understand reporting obligations, privacy and labor laws
    * How enforcement authorities operate
    * Whether there will be a need for IT and forensic resources
    * Sector-specific knowledge
    * Other expertise required such as in finance, sales, operations even SAP

    One of the biggest decisions to make early is whether this is an investigation that is best handled using an internal or external team. Each has its own plusses and minuses. As they note in the podcast, an external team can bring in skillsets that you don’t have, including the often expensive and complex forensic resources. But, since an external team likely doesn’t know your culture as well as you do, they may miss the small things that an inside team wouldn’t.

    They also discuss here the report that will come at the conclusion of an investigation. Documenting the steps you have taken is key, so much so that they believe if it isn’t documented it’s as if it never happened. It’s a part of demonstrating that the company took the issue serious and investigated thoroughly.

    Make sure the report language is as concise and to the point as possible. The findings need to be reported objectively and accurately and, of course, state whether they allegations were substantiated or not.

    Listen in to learn more and don’t miss their virtual session at the 2021 SCCE Compliance & Ethics institute.
    14 min
  • Kortney Nordrum on the Ongoing and Evolving Risk of Social Media [Podcast]
    Post By: Adam Turteltaub

    Social media has now become a permanent fixture of our lives, but that doesn’t mean we’re altogether comfortable with it.  And for compliance professionals, there is  a constant and changing range of risks, reports Kortney Nordrum, Regulatory Counsel & Chief Compliance Officer for Deluxe.  She will be leading the session “Social Media:  Old Platforms, New Risks” at the 2021 SCCE Compliance & Ethics Institute.

    To understand the risks, in this podcast we take a look at several different types, starting with the organization’s own social media activities.  She advises that, despite the informality of social media, companies need to think through their communications like they would advertising or PR: professionally.  That means using appropriate language, checking the hashtags to make sure that they aren’t being used elsewhere online where the meaning may be inappropriate, and having someone responsible for the activity.  It also means having a defined objective and a method for measuring if the social media is achieving what it is supposed to.

    Organizations should also engage in what she calls “social listening”:  seeing what others are saying about you online.  Visit sites such as Facebook, Twitter, LinkedIn, Glassdoor, Yelp, Amazon and Google reviews.  Use them to understand how people are interacting with your organization and their experiences.

    When it comes to looking at what employees are doing online, she cautions that the National Labor Relations Act covers a wide range of employee activities and protects them.  Generally speaking, the National Labor Relations Board has found that employees have the right to complain online about compensation and work conditions.

    Also, exercise caution when reacting to that bikini-clad photo on Facebook.  There’s probably nothing you can or should do about it.

    Be cautious, too, about the new platforms that have emerged.  Their data practices may be cause for concern.

    Finally, she recommends using social media as a means for compliance teams to connect with the business people.  It provides opportunity to engage with them both in a formal professional way, as well as informally.

    Listen in to learn more, and be sure to catch her session “Social Media:  Old Platforms, New Risks” at the 2021 SCCE Compliance & Ethics Institute.
    13 min
  • Hooper, Kearney and Macklin on Cutting Edge Topics in the False Claims Act [Podcast]
    Post By: Adam Turteltaub

    While the pandemic put many things on hold, it did not do the same for the False Claims Act (FCA). To find out what is happening in FCA activity we spoke with Patrick Hooper, Jordan Kearney and Alicia Macklin, partners at the law firm Hooper, Lundy & Bookman, PC and authors of the chapter Cutting Edge Topics in the FCA for the new HCCA book False Claims In Healthcare.

    In this podcast they share that the opioid pandemic will still receive enforcement focus, particularly in areas such as treatment fraud. That’s likely to happen because of the increased number of people receiving medical coverage and the resurgence of the opioid epidemic during the pandemic.

    They point to recent press releases and public comments by the FDA. The government also signaled it is looking at fraud related to electronic health records, which oven overlaps with opioid-related fraud.

    We also discuss the now confusing area of subregulatory guidance. With the US Supreme Court decision in Azar v. Allina Health Services requiring more formal processes, and with a subsequent decision regarding local coverage decisions, many are wondering what to do.

    Listen in to learn what to consider as you navigate these thorny, cutting edge FCA issues. And be sure to check out False Claims in Healthcare.
    16 min
  • Ashley Coselli and Daniel Wendt on Difficult Anti-Corruption Due Diligence Projects [Podcast]
    Post By: Adam Turteltaub

    Third party anti-corruption due diligence didn’t stop during the pandemic, but it was different.  And, as the world begins to, hopefully, emerge from the pandemic Ashley Coselli, Senior Ethics and Compliance Counsel, Total American Services and Daniel Wendt, Member, Miller & Chevalier suggest in this podcast that companies should now go back to their files and see where there are holes

    The two of them will be leading the session Managing the Most Difficult and Most Important Anti-Corruption Due Diligence Projects at the 2021 SCCE Compliance & Ethics Institute, which will be taking place September 19-22.

    As you look through the due diligence files you are likely to find that one of the more important pieces missing is the face-to-face interaction that can be so important when gauging the risks posed by a third party. Once travel becomes safe and practical again, it’s important to get those relationship going, especially with high-risk relationships such as those with sales agents and joint venture partners.

    Next, determine how effective their compliance programs are, and begin to triage based on the greatest risks. But, they advise, don’t try to do everything all at once. It can just be too much.

    Also, invest the time to fill in the knowledge gaps about ownership structure to determine if anyone from the government, a former government official, or even a close family member of one has a stake in the organization.

    As you fill in the blanks, make sure to document what you are doing and have done, including the business justification for using a third party. It can be dreadfully difficult during a government investigation five years from now answering why the company decided it needed a third party, how it made the selection and why there were gaps in the due diligence. But, if you have been documenting your actions all along, the challenge is much less significant.

    One issue to consider that doesn’t involve the pandemic: Stop periodically to assess your current relationships. Sometimes a third party is brought on to handle one issue, and then over time the relationship expands greatly. Be sure to periodically ask: Is there the necessary due diligence for all the entity is doing, or just what it was initially hired to do?

    Listen in to learn more about this very thorny risk area, and then join us virtually or in person at the 2021 SCCE Compliance & Ethics Institute.
    15 min
  • Adam Balfour on Helpline Call Intake [Podcast]
    Post By: Adam Turteltaub

    When the helpline rings, it’s a make or break opportunity. Get it right, and you could find out about potential wrongdoing and useful details. Get it wrong, and the caller may decide it’s not worth it, give perfunctory information, or, at worst, hang up.

    Adam Balfour (LinkedIn), Vice President and General Counsel for Corporate Compliance and Latin America at Bridgestone Americas, Inc. strongly advocates in this podcast starting by asking yourself a question: Who is this helpline really meant to help? Is it simply there to collect information about issues or is it there to help employees? If an organization wants a speak-up culture, then the intake process can’t be an unpleasant, rote one. That will discourage employees from calling in.

    Instead, he argues, it is better to embrace a process in which the organization demonstrates to callers that it hears them. That includes using a more empathetic approach, using language such as, “I’m sorry to hear that and it sounds like it was upsetting to you.” This can help encourage the employee to open up and share more.

    Leading by addressing emotions can help open up people to sharing more facts, he has found.

    To guide the conversation, a script is helpful, but it should not get in the way of the conversation. More important is to keep in mind the goal of getting information.

    So, what do you do when setting up (or revising) the helpline with your vendor? He recommends laying out what processes and experiences you want for your workforce. Then, take a look at how they incentivize employees. If their goals are designed to get callers off the phone as quickly as possible, that could be sending exactly the wrong message.

    Listen in to learn more about listening up.
    14 min
  • Elaine Ong, Kalpana Kothari and Caveni Wong on Consistent, Global Disciplinary Guidelines [Podcast]
    Post By: Adam Turteltaub

    Consistent discipline is difficult for organizations, especially when high performers are involved. It’s even more difficult for large organizations operating in dozens of countries around the world, navigating multiple cultures.

    Yet, Dentsu International was not afraid to take on the challenge. In this podcast, and at their session at the 2021 SCCE Compliance & Ethics Institute, three Regional Ethics & Compliance Directors from the company -- Elaine Ong (APAC), Kalpana Kothari (EMEA) and Caveni Wong (Americas) – share what it took to put together consistent global disciplinary guidelines in a decentralized organization.

    The goal of the project was to impose consequence and improve accountability around the globe. A first draft was created and reviewed by the regional compliance directors, legal, HR and internal audit. Then, approval was obtained from the Global CEO and Chairman before being presented to the board. The entire process took ten months.

    And that was just the starting point. After that came the task of rolling it out.

    Critical to the next phase was the support of senior management, the board, HR and business leaders. With their support the compliance team worked with local businesses to ensure that they understood the guidelines and how to apply them. Compliance also let the business know that it would not be alone. Compliance would be supporting them along the way.

    Some of the other keys to success:

    * Develop a simplified framework that is easy to understand
    * Create case-based training to provide opportunities to practice decision making
    * Develop supporting collateral
    * Review employee feedback

    Listen in to learn more, and then plan on attending their virtual session at the 2021 SCCE Compliance & Ethics Institute
    13 min
  • Ted Lasso Executive Producer Bill Wrubel on Culture and Ethics [Podcast]
    Post By: Adam Turteltaub

    Ted Lasso has been a pandemic streaming success story. The show stars Jason Sudeikis as an American college football coach hired to lead a troubled English soccer (football) club.

    Unlike the typically-portrayed coach, barking out orders and all about winning, Ted is an empathetic person, who wears his heart on his sleeve, looks for the best in people, and does his best to bring it out of everyone. That’s not always easy given the personalities that surround him. The team’s owner is engaged in a personal vendetta. One star player is self-obsessed, another is arguably the angriest person in the world.

    The show has been a runaway success, with the public, critics and the press. It has earned 20 Emmy nominations, including Outstanding Comedy Series, Outstanding Lead Actor in a Comedy Series, and two nominations for Outstanding Writing for a Comedy Series.

    For those of us working in compliance and ethics, the show is a great watch, not just for its entertainment value. It contains several lessons on creating the right organizational culture, and how to engage people in discussions of right and wrong.

    In this podcast I sit down with Bill Wrubel, Executive Producer of the series who, not surprisingly for a show about working as a team, gives the credit to others including Brendan Hunt, Joe Kelly, Bill Lawrence, and, of course, Jason Sudeikis, who wanted the show to have meaning and be something beyond laughter. Fittingly, when Bill interviewed for the job, Sudeikis asked him if he had any mentors in his career and to tell him about them.

    Sudeikis drew heavily from his own experiences in the entertainment industry, Bill shares. From his years working in improv he learned that success is the product of team work. You are as dependent upon what others are doing as what you are doing. From writing for SNL, under Tina Fey’s leadership, he had learned from her habit of listening to all the voices in the room, not just the loud ones, and to recognize that everyone had a contribution to make.

    You can see that in the show, when Coach Lasso encourages the players to speak their mind, and also, notably, when he chooses to listen, not escalate confrontations, and be forgiving.

    What may surprise many is that the writers regularly talked about and read books on leadership. They saw that not everything flows from the top and that great leadership comes from openness. “Be curious not judgmental” is an oft-quoted line from the show.

    Listen in to the podcast, and then enjoy Ted Lasso. Then watch it one more time (if you haven’t watched it already) for the lessons about how to create a culture that encourages growth and openness. The setting is an English football club, but the lessons can apply to compliance and ethics program everywhere.
    20 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners