Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Ronnie Kann and Trent Sandifur on Third-Party Monitoring [Podcast]
    Post By: Adam Turteltaub

    So much attention is paid to vetting third parties, it’s easy to forget that it is just the start of the process. Monitoring needs to be done on an ongoing basis as well.

    Ronnie Kann, head of Global Ethics & Compliance at Energizer Holdings and Trent Sandifur, partner at Taft Law will be addressing that topic in their virtual session “What Does Third-Party Compliance Monitoring Look Like in Real Life?” at the 2021 SCCE Compliance & Ethics Institute.  In this podcast they caution that it’s advisable to think of monitoring not as something separate but as a part of a larger third-party due diligence program.

    That program includes:

    * Keeping an eye on what’s going on with the third party
    * Understanding what the risks are
    * Thinking about how to monitor
    * Making any improvements necessary to ensure the risk is effectively managed

    How do you get the vendor on board for the monitoring process? They recommend beginning by ensuring that monitoring is included in the initial agreement. That helps both set and manage expectations. Also, work with the vendor to make sure that while getting the information you need you are not unnecessarily burdening them.

    Be sure also to avoid overburdening your own business people, but, at the same, time, it’s essential that they recognize that they own the risk. This can help create a spirit of partnership that will help protect your organization and make the process go smoother.

    Finally, they close the podcast with a discussion of what to think about as the pandemic ends and business starts catching up on all the due diligence that was done only partially when the pandemic made travel impossible. They recommend taking a risk-based approach to what you were unable to do.

    Listen in to learn more, and be sure to join their session session “What Does Third-Party Compliance Monitoring Look Like in Real Life?” at the 2021 SCCE Compliance & Ethics Institute.
    12 min
  • Andy Powell on Creating an Integrated Scorecard [Podcast]
    Post By: Adam Turteltaub

    Andy Powell is Chief Ethics & Compliance Officer, Senior Vice President and Deputy General Counsel at Flex, a global technology manufacturing company with approximately 160,000 employees in over 100 manufacturing and services sites spread out over 30 countries.

    When he entered the compliance role there he realized that, realistically, the compliance team couldn’t be everywhere all the time.

    He also sought to enhance the compliance and ethics culture.  To do so, he embarked on a strategy of normalizing compliance, making it a part of every manager’s job.  That, he knew, would require making managers both responsible and accountable.

    His solution: create an integrated scorecard that leaders could manage against and would provide valuable insights to the compliance team.  As he explains in this podcast, you can’t expect managers to be accountable unless you can show them how they are doing.

    The scorecard provides the hard numbers managers need.  To create it, he worked cross-functionally to gather data points from across the organization, including employee engagement surveys, helpline data, and even external benchmarking data.  The information is represented graphically along with insights from the compliance team.  Some of the data is macro.  Some give insights as finite as production lines.

    How powerful is this tool?  Day to day it helps identify hot spots and generate improvements.  As importantly, the CEO typically asks each manager to show it to her whenever she travels around the company.

    Listen is to learn more about the benefits from creating an integrated scorecard.
    15 min
  • Andy Dunbar and Nick Morgan on What the SEC Expects from Your Internal Investigation [Podcast]
    Post By: Adam Turteltaub

    What does the SEC expect from an internal investigation?  It’s a topic that Nick Morgan, partner, Paul Hastings and Andy Dunbar, Chief Compliance Officer, Herbalife Nutrition tackle in this podcast and will be addressing at the 2021 SCCE Compliance & Ethics Institute.

    So what makes for a good internal investigation?  It starts before the investigation even begins with a robust whistleblower program, speak-up culture and easily accessible reporting opportunities.

    It also includes a disciplined investigation process.  That means someone need to be monitoring it to ensure that matters don’t fall through the cracks, that they get assigned efficiently, and that all investigations are moving forward.  In addition, someone has to be designated to review the final outcome of the investigations and determine if the right people were spoken to and the right documents examined.

    And while the emphasis and effort will be placed on those tips that seem to have merit, It’s important to remember that the vast majority of them will not.  Yet, even for those that are unsubstantiated, take the time to document what was done and how conclusions were reached.

    No matter if a claim does or doesn’t have merit, they advise ensuring that an adequate program is in place to protect whistleblowers from retaliation.  That includes a documented anti-retaliation policy and processes available for both employees to turn to and regulators to see.  Be sure also to let whistleblowers know that the same channels they used to report wrongdoing can be used to report retaliation as well.

    It is also advisable for the compliance team to stay in contact with the whistleblower, even checking in a couple of months after an investigation concludes to make sure he/she is doing okay.  That can be very reassuring to the whistleblower and demonstrate that the compliance program is trustworthy.

    Finally, they address what the compliance team can do, should the matter escalate to the point that the organization self-report, or if the SEC or DOJ comes knocking.  These include:

    * Reviewing hotline data to see if there were any early indications of the problem
    * Amassing the data to demonstrate the effectiveness of the compliance program
    * Preparing a plan to remediate

    Listen in to learn more, and be sure to attend their session What the SEC Expects from Your Internal Investigation:  Former SEC Enforcement Attorneys Share Their Insights at the 2021 SCCE Compliance & Ethics Institute.
    21 min
  • Courtney Blau on Section 1135 HIPAA Waivers [Podcast]
    Post By: Adam Turteltaub

    HIPAA Section 1135 waivers are a tricky area, explains Courtney Blau (LinkedIn), Attorney, Risk Management and Compliance, Norman Regional Health System.

    As she explains, Section 1135 Subsection B in the Social Security Act provides express authority to the HHS Secretary to waive a number of requirements, including the HIPAA privacy rule. In response to the pandemic, the Secretary was given additional authority to make amendments to HIPAA by program instruction or otherwise. These are no longer subject to public hearing or comment period.

    However, a waiver is only effective for three days after implementation. As a results she advises not to adjust your organization’s processes. Instead continue to maintain normal operations.

    In addition, compliance teams need to remember that many states have laws that are even stricter HIPAA. As a result, the waiver may not be applicable to providers in those states.

    Listen in to learn more about this complex topic.
    10 min
  • Fernanda Beraldi and Ed Broecker on Compliance’s Role in M&A’s [Podcast]
    Post By: Adam Turteltaub

    Mergers and acquisitions can be filled with landmines.  To find out what compliance teams can do to help manage the risk, and help ensure a successful transaction for the business unit, we spoke on this podcast with Fernanda Beraldi, Senior Director, Ethics and Compliance at Cummins Inc. and Ed Broecker, Partner, Foster Brown Todd.  The two of them will be leading the session Compliance Diligence in M&A:  Best Practices from LOI to Integration at the 2021 SCCE Compliance & Ethics Institute, which will be taking place in-person and virtually September 19-22, 2021.

    Since the earlier compliance is brought into the M&A process the better, they advise developing a close relationship with the business. The goal is to have compliance involved starting with the initial discussions, even before there is a letter of intent.

    When doing a compliance assessment, they recommend conducting a risk-based approach, to a point. Looking at legal and regulatory risk areas are important, but as important is looking at the corporate culture. Get a handle on whether the compliance program simply exists on paper or is woven into the way the company does business. Take the time to interview the compliance team at the target company and ask specific questions about culture, training, and receptiveness to compliance.

    Be alert also to one red flag that is often missed: the absence of helpline calls and cases.  While it is hard not to miss the red flag of a lot of calls from a facility or a large number of investigations, it can be easy not to notice when there are far too few calls, or none at all. That may be the very troubling sign of a culture that makes it difficult, if not impossible, for employees to raise their hands when they see something wrong.

    After the acquisition, they advocate for the creation of a compliance champions or ambassadors program. Having people in other departments who can be the eyes, ears, arms and legs for the compliance program can be invaluable both for what is happening and for communicating compliance messages.

    Listen in to learn more, and to gain even more of their expertise, be sure to join us in Las Vegas at the 2021 SCCE Compliance & Ethics Institute.
    14 min
  • Ronnie Feldman on Encouraging People to Speak Up [Podcast]
    Post By: Adam Turteltaub

    How do you get people to come forward and report issues? Ronnie Feldman (LinkedIn), President and Founder of Learnings & Entertainment, has an unconventional suggestion:  Learn from improv groups.

    As he explains in this Compliance Perspectives podcast, improv performances only work because the members of the cast know that they have unconditional support from their castmates. They embrace the concept of “yes and”, looking to embellish what each other did and move it forward.  That gives them the ability to take risks.

    Improv artists also practice their listening skills to make sure that they understand what each other is saying.

    This creates a psychologically safe environment where people can bring ideas forward without fear. Harvard Professor Amy Edmondson, argues that the best organizations do the same thing, he explains.

    How does an organization get to that place of psychological safety where people can feel come forward and say what’s on their mind safely? By constantly reminding people that it is okay to point out what is wrong. And a good compliance program, he explains, is one that creates this environment.

    How can a program get there? For one, he argues that compliance training needs to be improved. Taking the trouble to do it right both engages employees and shows the company is committed. Stories of incidents that happened at the organization can be particularly impactful.

    Then think more like an advertising agency and seek to get the message in front of people as many times as possible and as creatively as possible. And, as you do so, be entertaining and interesting. He argues that this will help put compliance in a more positive light.

    Listen in to hear more provocative ideas for encouraging more employees to come forward.
    16 min
  • Marjorie Doyle and Art Weiss on Polishing Your Corporate Values [Podcast]
    Post By: Adam Turteltaub

    What do the current times and the times to come mean for corporate values?

    To answer that question we turn in this podcast to Marjorie Doyle, Principal, Marjorie Doyle & Associates, and Art Weiss, Principal, Strategic Compliance and Ethics Advisors, SCCE & HCCA President and Chief Compliance and Ethics officer at TAMKO Building Products. These two compliance veterans, and members of the SCCE Basic Compliance & Ethics Academies faculty, will be addressing the topic in their session “Polish Your Brand! Make Your Values Apply to Current Issues” on September 19th at the 2021 SCCE Compliance & Ethics Institute.

    When faced with such monumental changes as we are today they advise sticking to your values but looking to see if it is time to evolve the definitions. As an example they point to the value of safety, which now should likely reflect not just preventing injuries from things such as falls, but also from COVID-19.

    Likewise, they argue that with remote work values remain just as important, but organizations need to recognize that the application of those values is different. Studies have long shown that company values tend to be stronger for employees in the corporate headquarters than they are for those farther away. With so many workers no longer in the office, organizations will need to work harder to keep their values front and center and a driver of corporate culture.

    And how can organizations bridge the very different experiences of workers who come into the office and those who don’t? They advise regular communications from leadership filled with examples that reinforce the organizational culture. Those communications, and others, should also explain how the organization’s values are being applied to meet the changing environment.

    Listen in to learn more, and be sure to join us at the 2021 SCCE Compliance & Ethics Institute.
    12 min
  • Mark Lanterman on Brute Force Attacks and Corporate Cyber Defenses [Podcast]
    Post By: Adam Turteltaub

    On July 1, 2021 the US National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), FBI, and UK National Cyber Security Centre (NCSC) released an advisory reporting on “malicious cyber activities by Russian military intelligence against U.S. and global organizations…”

    The advisory shared that “brute force” is being used to “penetrate government and private sector victim networks.”

    To understand what this means for organizations and what they should do we talked with Mark Lanterman (LinkedIn), Chief Technology Officer at ComputerForensic Services. He explains in this podcast that it’s not just the brute force attacks that should cause concerns. It is these efforts combined with the use of “known vulnerabilities” to access data undetected.

    What should organizations do to protect themselves? He advises following the recommendations in the advisory. For one adopt multi-factor authentication along with time out and lockout features. Other steps to take include network segmentation and closely monitoring access controls.

    He also suggests that organizations review existing protocols to ensure that they are actually being followed. Just because a policy is documented, he warns, doesn’t mean it is being applied.

    If your organization is using a cloud provider, he recommends take the time to revisit its value as a tool, what protections are in place, what data is stored and where it is stored. Ask your cloud provider about the infrastructure it uses, how it is protected, and what are the backup and protection policies. Trusting any third party with your data, including a cloud provider, is not something that should be done lightly.

    Inside your organization, he argues for rethinking the approach to data security, changing it from something you train on once a year to an entire culture. There can’t be a set it and forget it mentality. A much more dynamic approach is required.

    Listen in to learn more about how you can better protect your organization against brute force and more subtle attacks.
    13 min
  • Jenny Radcliffe on People Hacking [Podcast]
    Post By: Adam Turteltaub

    Liverpool-based Jenny Radcliffe, who leads Human Factor Security, is not your typical hacker, clad in a black hoodie and working out of basement. Rather than spending her time hunched over a keyboard, she seeks to hack people.

    What does that mean? As she explains in this podcast, she uses persuasion, psychology and influence methods to make her way into systems, and even into physical premises. She is often hired to break alarms and see if she can talk her way into a building.

    She does it by capitalizing on the all-too-human aspects of our personalities, and from her experiences she has learned how phishing emails and other techniques also capitalize on human weaknesses to enable hackers to breach computer systems.

    What’s both terrifying and fascinating, is how hackers take advantage of our weaknesses, tailoring their attacks, knowing that different scams work for different people and cultures. In fact, she explains that the organization culture you have, is the hack you invite. In a hierarchical organization the hacker will likely use authority principles. In a younger, less rules-driven culture attackers may use registration for a social activity as a way to steal passwords and IDs.

    Hackers also take advantage of human emotions and stress. As she memorably says, “Emotion kicks logic off the cliff.” That’s why techniques such as promising a prize or threatening the release of embarrassing information can be so successful in getting people to click where they shouldn’t.

    She advises companies create “cognitive firewalls” within their organization, helping employees to watch for red flags such as:

    * Any approach via email, call or social media that makes the recipient emotional
    * The mentioning of money
    * The request to act, especially if asked to act quickly

    How else can you protect your organization? By making it safe for people to come forward when they make a digital mistake. The more comfortable they are coming forward, the faster they will and the sooner the breach is remediated.

    And how do you find the internal bad actor? That, she says, falls on the shoulders of line managers, who need to be on the lookout for changes of behavior that may indicate stress.

    Listen in to learn more, including the risks that can come as employees return to the workplace.
    14 min
  • Bridget Group on Legacy Data [Podcast]
    Post By: Adam Turteltaub

    Legacy data is any data that your organization has lying around in obsolete formats that isn’t accessed regularly but is, instead, held for regulatory purposes. While that may sound innocuous enough, it can be an enormous problem for healthcare providers, says Bridget Group (LinkedIn), Corporate Counsel of Harmony Healthcare IT.

    Typically the data is held in systems which are long out of date and lack the security features that are prudent for the current environment. The hardware is equally problematic, tending to be unstable with long downtimes and high maintenance costs. That can make it hard to meet the requirements of HIPAA and the 21st Century Cures Act.

    So what should healthcare providers do to manage this challenge?

    First, she recommends setting up a registry of all the systems across the enterprise to get a handle on what data is available and where it is. The IT department and health information management team can both be helpful.

    Take the time to understand the retention requirements for the data under both Federal and State laws, the latter of which can be the more restrictive.

    Then, if you don’t have one already, set up a data governance board, with the charge to identify health information captured across the organization, understand the purpose of the data, who can access it and how long it must be kept for. The board can and should create policies for retention, destruction and access.

    Be sure also to train the workforce so it understands its obligations.

    Finally, she advises moving data into an archiving solution, the cloud or a data warehouse and off of those legacy systems.

    Listen in to learn more about how to keep legacy data from damaging your organization’s legacy.
    12 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners