Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Amii Barnard-Bahn on Promotability [Podcast]
    Post By: Adam Turteltaub

    While most of the work in compliance is selfless, there needs to be a bit of self-interest when it comes to career.  Even if a compliance officer doesn’t want to make it to the top, he or she likely would, at some point, want to move up.

    How best to do that?  In this podcast we talk with long-time compliance veteran and executive coach Amii Barnard-Bahn about promotability.  She has developed a Promotability Index and is author of the book The PI Guidebook.

    Amii reports that from her analysis there are five key elements of promotability:

    * Self-awareness
    * External awareness
    * Strategic thinking
    * Executive presence, and
    * Thought leadership

    External awareness is worth special attention and centers around how your behaviors impact others and how others perceive you.  The latter is particularly important since that perception becomes their reality when working with you.

    Notably absent from the list is technical expertise.  It is a requirement, to be sure, but above a certain level technical acumen starts to be less important than the ability to manage people and affect change through others.

    When it comes to seeking a promotion she advises to avoid having discussions with supervisors about the topic during the annual evaluation.  That conversation is more about compensation, and it is better to separate the two.  Also, it is ill-timed for another reason:  typically succession planning conversations by management and HR are held months earlier.  Better to raise the topic about six months before the annual review cycle.

    If you do approach your manager about moving up, make sure she or he knows it is safe to give you candid feedback.  In addition, be sure to understand the power structure and culture of your company to know the likelihood of whether you are a candidate to move up the ladder.  Ask questions such as:  “How am I seen?”  “Am I working on the things I should be?”  “Are there perceptions that block me?”

    Finally, she counsels individuals that the days of just working harder to get ahead are gone.  Instead, build around your strengths and remove bad habits.  Focus on areas such as the ability to influence and working with and through others.

    Listen in to learn more about how you may be able to improve your own promotability index.
    13 min
  • Debra Geroux and Scott Wrobel on Responding to Data Breaches [Podcast]
    Post By: Adam Turteltaub

    When a data breach occurs, one step is often overlooked in the rush to remediate:  preserving as much of the data logs and backups as possible  That’s a mistake, say Debra Geroux, Shareholder at Butzel Long and Scott Wrobel, Co-Owner, N1 Discovery, because that data illuminates what happened, how it happened, and what data was taken.

    In this podcast they also advise hiring cyber counsel immediately to obtain guidance through the legal and regulatory issues.  They may also be able to help you conduct the subsequent investigation under privilege.  Counsel can also help identify outside resources, deal with law enforcement, and help healthcare organizations determine if the breach is a reportable one.

    In addition to outside counsel, Geroux and Wrobel argue strongly for leveraging the organization’s communication team.  Managing messaging is critical.  The communication targets—victims, employees, the board, public, media -- have to be identified and given the information they need.  But, be judicious.  Limit your communications to essential information to reduce the opportunity to spin the story.

    Most importantly, they advise, make the effort to understand what the root cause of the incident was.  Often, that’s not as evident as it may seem.  Sometimes the first suspected point of breach is not the actual one.

    To reduce the risk of future incidents, they recommend adopting two-factor authentication.  Workforce training is also essential since so often employee errors (and vulnerability to sophisticated phishing efforts) are a factor.

    Hiring a third-party security company to conduct an internal and external vulnerability assessment can also be helpful.  It should identify every device and piece of software on or connected to your network, their vulnerabilities and how to remediate them.

    That assessment should also address any cloud-based solutions your organization is using.  While, generally speaking. those solutions are secure, if your organization leaves the default settings in place, it could leave you exposed to bad actors.

    Listen in to learn more about how to protect your organization, including the need to take a second look at your cyber insurance policy.
    15 min
  • Marti Arvin and Anthony Buenger on the CMMC Framework [Podcast]
    Post By: Adam Turteltaub

    America’s data is under attack. Solar Winds and other recent headline-grabbing stories have demonstrated that foreign adversaries are eager to hack into computer systems for a wide range of purposes.

    The US Department of Defense has had its supply chain hit hard, and to help protect both the chain and the nation’s assets has pursued the Cybersecurity Maturity Model Certification (CMMC), with a multi-level approach requiring outside certification, not the self-certification as in the past.  Although only for defense contractors, it is a model worth watching since it may eventually expand, in one form or another, to additional areas of government contracting.

    In this podcast Tony Buenger, Cyber Security Consultant and Instructor, and Marti Arvin, Executive Advisor, both of CynergisTek explain some of the complexities of CMMC and its many levels. Level 1 covers basic hygiene and is primarily focused on technical security controls. Level 3 is a certification that requires maturity in terms of documented policies and procedures that have been institutionalized. Level 5, the highest level, is focused on persistent threats.

    Notably CMMC focuses not just on technology, but also on processes and people, even looking to ensure that the process are built into the organization’s governance. As a result, it’s not a standard for just the CISO or CIO to handle. CMMC is a commitment that needs to be institutionalized, takes time, and requires both trust and ongoing verification.

    In sum, it very much requires the maturity that is a part of its name.

    Listen in to learn more about CMMC and what your organization needs to do now, and possibly in the future.
    15 min
  • Susan Divers on Program Effectiveness [Podcast]
    Post By: Adam Turteltaub

    So what happened to ethics and compliance programs during the pandemic? Did companies throw out their commitment to doing the right thing and values in their quest to survive the upheaval? Or did they embrace them?

    The data is looking very encouraging, reports Susan Divers, Senior Advisor at LRN. As she shares in this podcast their 2021 Program Effectiveness Report found that the commitment to ethics and values actually increased during this period. Ethics and compliance were front and center, helping organizations to cope with the crisis as they emphasized values over rules.

    There were stress points, however. Many organizations didn’t pivot quickly enough to meet the demands of the new reality. For example, the majority did not move their training to mobile platforms, at least initially.

    In addition, the report found concerns about the future, including:

    * Pressure to cut compliance staff and budgets
    * Workers lacking the checks in their behavior that come from when colleagues are nearby, and not located remotely,
    * Pressures to circumvent controls as business resumes

    Listen in to learn more about the research findings and also some interesting data on the gaps between business leaders and middle management.
    13 min
  • Cheryl Curbeam on Creating a Compliance App [Podcast]
    Post By: Adam Turteltaub

    Cheryl Curbeam (LinkedIn), Vice President, Chief Risk and Compliance Officer at Corteva Agriscience has had a very interesting and unusual path to the compliance professional. She studied and began her career in mechanical engineering before moving into operations leadership. It turned out to be a great background for compliance, teaching her how to think about what is and isn’t in scope and how to solve tough problems.

    From there she went into sales, spending about 80% of her time on the road. It gave her great insight into the mind of salespeople, including the fact that their focus is on customers. Corporate work, including compliance training, is squeezed in when they can find time. As a result, sales teams want compliance to deliver clear and easy-to-find guidance.

    That experience helped her when she went to develop an app to support the compliance program for this new company, which was created in June 2019 after Dow and DuPont merged and spun Corteva off. Despite the long compliance history of both of the original organizations, the new enterprise needed to create a compliance program of its own. It launched, not too long before the pandemic and all the changes that came with it, including having even more of its workforce operating remotely.

    As she explains in this podcast and will also address at the SCCE Technology and Compliance Conference on June 24th, the company needed to train employees remotely and enable them to report concerns. An app turned out to be an ideal tool. The mobile solution housed training, the code of conduct and other assets such as quick learning topics.  It also provided a vehicle for accessing the helpline.

    What’s her advice to others considering developing an app? First, find a vendor that can support all phases of app development. Second, be sure to have a strong project manager internally to deal with the complexity inside your company. Third, know what content you need to deliver. Fourth, gain the support of your IT department. And finally, have a strong communications plan to ensure that the workforce understands the value the app provides.

    Listen in to learn more and be sure to join us June 24th for the SCCE Technology and Compliance Conference.
    12 min
  • Jonathan Rusch on Machine Learning and Anti-Corruption Compliance [Podcast]
    Post By: Adam Turteltaub

    Corporate anti-corruption efforts are a constant struggle, with compliance teams always searching for new approaches that can mitigate this very dangerous risk.

    Jonathan Rusch, an Adjunct Professor at Georgetown University Law Center and American University Washington College of Law, sees an opportunity in technology. He is the author of the Coalition for Integrity’s guidance document Using Machine Learning for Anti-Corruption Risk and Compliance.

    In this podcast he shares that in other areas, such as fraud and anti-money laundering (AML), some kind of Artificial Intelligence (AI), whether rules written by programmers or machine learning, has proven productive. The Coalition for Integrity wanted to know if a similar solution could work for anti-corruption efforts.

    In his and their research three successful implementations were found: AB InBev, Microsoft and Alexion Pharmaceuticals.

    When embarking on an effort in this area, he recommends first assessing what approach makes the most sense. For a smaller organization, a simpler, rules-based approach to automation is likely more appropriate.

    For larger organizations, he suggests building a business case that encompasses what needs to be done, the costs, the ongoing staffing requirements and the overall anticipated ROI.

    If machine-based learning could be worthwhile for your organization, he advises creating a clear definition of what you want the solution to address. From there it’s time to build your data set, work with the data and train the machine learning model. And, importantly, it’s also time to make sure the model is generating predictions that are accurate and reliable.  Often at the first stages it does not.

    When it comes to the data set, he notes that there may be more data within the enterprise than is initially thought. Data to consider incorporating into the effort could include spending, sales, accounts receivable, third-party contracts and third-party transactions.

    Intrigued?  Listen in to expand your learning about machine learning.
    13 min
  • Alison Taylor and Roy Snell on ESG and Compliance [Podcast]
    Post By: Adam Turteltaub

    The Environmental, Social and Governance (ESG) movement has been around for a long time, but over the last year it has hit a tipping point. In fact, according to Roy Snell, former SCCE & HCCA CEO and now advisor to Osprey ESG Software, it has hit several tipping points.

    In this podcast he and Alison Taylor, Executive Director of Ethical Systems, outline how strong the ESG movement has become and how important it is for compliance professionals to embrace it. They will also be addressing this topic at the SCCE ESG and Compliance Conference on June 17, 2021.

    As they share here, recently the EU announced it was looking to create regulations monitoring the truthfulness of ESG claims, particularly for investment firms. The US Securities & Exchange Commission (SEC) has set up an enforcement working group of its own. Standards bodies are emerging and setting some very high bars, and many organizations have committed to various ESG goals.

    One of the difficulties of ESG is that there is a mix, Alison notes, of hard and soft obligations. In the area of modern slavery, for example, many countries already have requirements in place for, at a minimum, reporting what the company is doing to managing the risk. And in environmental arena there are already a host of laws and regulations. But, in many other areas that fall under ESG there are not yet laws. Nevertheless, a corporate commitment should be taken just as seriously and with great rigor.

    In sum, ESG has come of age, and with it has come the risk that organizations will start fudging the numbers to meet their proclaimed and required ESG goals. That leads to an opportunity and need for compliance teams to get involved. As in other areas, compliance should not necessarily be directly involved in the initiatives since it can create a conflict of interest. Instead, they advise, compliance should, as it traditionally has, ensure the integrity of the organization’s work by creating control processes and procedures and investigating claims of potential wrongdoing.

    For the compliance team to be effective they recommend working with related units in the organization: ESG, corporate social responsibility, sustainability and investor relations. Increasingly investors are demanding that organizations report on their ESG efforts, and that has caught the attention of leadership and the board.

    Listen in to learn more, and then join us at the SCCE ESG and Compliance Conference.
    15 min
  • Bettina Palazzo on Business Ethics [Podcast]
    Post By: Adam Turteltaub

    We all face ethics issues in our lives and work. Yet, while there is so much these days people feel comfortable speaking about, ethics is often not one of them.

    To better understand why, we sat down with Bettina Palazzo (LinkedIn), of Switzerland-based Palazzo Ethics Advisory.

    As she explains, ethics is a systematic way of thinking about what is good and bad, how we should live together and what makes for a good life. These are all questions people have to answer for themselves. Yet, people hesitate to talk ethics because there is often not a clear cut or easy answer. That creates ambiguity and feelings of uncertainty that make people uncomfortable, and that discomfort is more acute in a business setting where quick, certain decisions are prized.

    To encourage more discussions of ethics issues, Dr.Palazzo advises better marketing. Safe spaces for discussing ethics have to be created, and ethics talks need to be packaged attractively and focused on real-life experiences that people are likely to encounter in the workplace.

    She also encourages ethics teams to be mindful of the perspective of the workforce.  They are adults, and if ethics training comes across as parenting – with the employee as the child – it can shut down any learning.

    The conversation concludes with a provocative discussion of leadership and ethics and how intertwined they are. Leadership, she argues, is inherently an exercise in ethics because leadership comes with power over people, and leaders must think about how that power will be used.

    Listen in to learn more, including how best to set the right ethical tone throughout the organization.
    14 min
  • Elliott Coward on Self-Disclosure and Return of Overpayments [Podcast]
    Post By: Adam Turteltaub

    Self-disclosures and returns of overpayments are a fact of life for healthcare providers in the US, but that doesn’t mean that what to do in every situation is always perfectly clear or easy.

    Elliott Coward, Associate at Morris, Manning & Martin and author of the chapter “Self-Disclosure and Return of Overpayments” for the Complete Healthcare Compliance Manual provides an excellent overview of the self-disclosure and repayment obligations this podcast.

    She explains that obligations to self-disclose and return overpayments fall into two buckets. There is a “concrete bucket” such as Medicare’s 60-Day Rule. It requires providers provide accurate bills for payment, and if any non-compliance is found to refund the overpayments.

    The second bucket is less concrete and contains carrots and sticks from the regulators. These provide incentives for self-reporting and penalties for failure to do so.

    Whatever bucket the issue you encounter falls into, she recommends coming to the government well-prepared. Make sure the audit is done thoroughly and well. Have in hand the exact amount that can be tied to a specific claim or a statistically strong extrapolation. And, be sure to have your story straight: understand what the problem was, what caused it, and what your organization’s remediation plan is.

    In addition, and especially if the self-disclosure was caused by a very significant problem, be sure to also demonstrate that the root cause has been identified and proactive steps have been taken to correct it.

    For simpler disclosures and repayments, she cautions against taking them too lightly.  Follow the instructions for repayment to a tee. Don’t skip any steps and follow all the instructions carefully. A short cut can easily trigger an inquiry and all the additional burden that comes with it.

    Listen in as she also explains some of the nuances such as the difference between a simple error, when there are indications of potential fraud, and when a Stark Law violation has occurred.
    12 min
  • Donna Abbondandolo on Redesigning Your Compliance Department [Podcast]
    Post By: Adam Turteltaub

    “How should my compliance program be designed?”

    It’s a question many are now asking in the wake of the pandemic, and it’s a question Donna Abbondandolo, Chief Compliance Officer of Bon Secours Mercy Health asked even before it.

    In her case the compliance team was divided functionally. One team was focused on revenue cycle. The other for general compliance.

    While that likely made sense at one point, it no longer did, and, adding to the need for a change was the fact that compliance was moving out from enterprise risk management and was about to report to the CEO and the audit & compliance committee of the board.

    Bottom line: it was time for something new.

    When setting goals for redesigning your program she recommends first understand the strategy of your organization, where it is going and how you can align compliance best to support the strategy.

    Also, be sure to have a good handle on the risk profile. What are the high-risk areas? How do you identify what is high risk? How do you support leadership in managing risks? The latter can be a very difficult question in a geographically- dispersed organizations.

    Even with these considerations in mind and the best intentions, she warns that there will be bumps along the way. That’s when it’s important to have already cultivated relationships with operational leaders to help smooth things over, dispel the notion that compliance is a roadblock, and build trust.

    In terms of structure, she took a functional approach to the redesigned program as a way to address compliance concerns both by function and across the enterprise. She developed key leads for various areas to help support the operating units.

    Within the compliance team, she met with staff, took the time to understand their skillsets and then leveraged their strengths to help create a strong, functional model. She also worked with HR to leverage the organization redesign principles they had, including developing a purpose statement for the compliance team.

    Listen in to benefit from her experience. It could help you when it’s time to redesign your compliance program, or just to kick the tires a bit on your current one.
    13 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners