Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Darja Galante on Anti-Retaliation Programs [Podcast]
    Post By: Adam Turteltaub

    Preventing retaliation is a constant uphill struggle for compliance programs.  There is something in human nature that makes people want to know who made the report and ostracize him or her for it.

    Munich-based Darja Galante, Senior Business Integrity Manager and Regional Investigations lead for Nokia, has spent considerable time thinking about and addressing the issue. She believes that one reason companies struggle in this area is that they approach the problem in traditional, company-centered way, focused on controls after the incident.  Instead, she argues in this podcast, it needs to be thought of more like biting a lemon.  It’s good for you but the bitterness can be difficult to overcome.

    Companies, she argues, need to face the problem head on, encouraging leadership to act and compliance teams to better understanding what’s in the mind of the potential retaliator.

    Case studies, she has found, can be very useful for educating the workforce.  At Nokia they even created an anti-retaliation hub for employees to make it easier to access information.

    She also advocates changing terminology from “whistleblowers” to “compliance heroes”, and using audit tools to monitor for retaliation.

    Listen in to better understand this constant, challenging issue.  Then plan on attending her session at the 9th Annual European Compliance & Ethics Institute, taking place 15-17 March.
    15 min
  • Kristin Meador and Brenda Manning on Healthcare Auditing & Workplans [Podcast]
    Post By: Adam Turteltaub

    On Tuesday, April 20th at the 2021 Compliance Institute the HCCA will be offering the session  Work Smarter Not Harder:  Effective Annual Work & Audit Plan Development Strategies.  Joining us for this podcast are two of the speakers from that session: Kristin L. Meador (LinkedIn), Director Compliance Audit & Operations Organization Integrity & Compliance, and Brenda Manning (LinkedIn), Privacy Director and Privacy Officer, both at the Carilion Clinic.

    When designing a workplan, they recommend taking a fluid approach that recognizes that risks change and plans must as well.  Start by gathering information from internal and external sources, look at what’s on the radar of CMS and OCR and where your organization is having a pattern of incidents.  Internal Audit can be a particularly valuable ally, especially if they have surveyed leadership and have identified the risks on management’s mind.

    In planning, one thing to avoid is setting goals too high and putting too much on the team’s plate.  It’s important to ensure that there are sufficient manhours available when things come up, as they inevitably do.  Also, leave time for new and emerging risks.  We have all seen how those can and have arisen over the last year.

    The key, they have found, is to have a SMART plan:  Specific Measurable Achievable, Relevant and Time-based.

    When it comes to auditing, they remind us that you can’t audit everything.  Instead, turn to the risk assessment and focus on the key areas.  Also be prepared to adjust your thinking.  Some areas may prove to have less risk than initially anticipated, others to have more.

    When it’s time to remediate, they make an interesting suggestion on training:  Instead of testing right away, give time for the education to sink it, and then audit once again.

    Listen in to learn more, and then plan on attending their session at the 2021 Compliance Institute.
    11 min
  • The French AFA on their Anti-Corruption Activities and Guidance [Podcast]
    Post By: Adam Turteltaub

    In 2016 France adopted a new law to help combat corruption. Inspired by legislation in the US, UK and Netherlands, Article 17 of what is known as Sapin II, includes provisions requiring organizations above a certain size to have an anticorruption program.

    The law also led to the creation of the Agencie Francaise Anticorruption, or AFA. To ensure the independence and integrity of the AFA, its director is a senior judge appointed by the President for a 6-year non-renewable term.

    In order to understand more about the AFA and its mandate we spoke with Julien Betolaud, Senior International Affairs Officer, and Izadora Zubek, International Affairs Officer. Julien will also be speaking at the SCCE 2021 European Compliance & Ethics Institute, which will be conducted in a virtual format 15-17 March.

    As they explain in this podcast, the AFA plays a central role in monitoring organizations that have a corruption-related DPA in place. Airbus is one notable example. AFA auditors are authorized to access documents and interview anyone whose assistance is deemed necessary. They are also authorized to interview suppliers, intermediaries, and clients.

    In addition to these responsibilities the AFA also provides extensive guidance to both public and private entities on the development of anticorruption compliance programs, including how to meet the eight points included in the Sapin II law. The list of these points will be familiar to anyone in compliance and includes a code of conduct, whistleblowing system, risk mapping, and internal monitoring.

    On the AFA website are a number of documents designed to help inform compliance efforts (Note: many of these are in English, and Google Chrome’s translate feature works very well with the site). Most notably, their recommendations were updated earlier in 2021 after an extensive review. An English version will be published to the site in late February.

    The AFA also actively engages with the business community, seeking opportunities to have as wide an impact as possible. They have held meetings with industry sectors designed to help identify the challenges they face and facilitate the sharing of solutions. They even provide direction to organizations who request it.

    Listen in to learn more about the AFA’s work, and then plan on joining us 15-17 March for the 9th Annual European Compliance & Ethics Institute.
    18 min
  • Deborah Adleman on Managing Privacy Requirements [Podcast]
    Post By: Adam Turteltaub

    Privacy is a huge compliance concern, but, as demanding as it can be it’s not unique.

    In this podcast compliance veteran Deborah Adleman, advises that organizations need to remember that privacy is a compliance risk like so many others. Deborah is the author of the chapter “A Data Privacy Compliance Program primer: A Snapshot of Data Privacy Regulations, Risks and Compliance Program Effectiveness Strategies” in The Complete Compliance & Ethics Manual.

    Start, she recommends, by applying your existing compliance framework. Looks to see who is involved in overseeing privacy, prepare regular briefings for the board and leadership, and determine when the last privacy risk assessment took place. Given the proliferation of privacy laws – CCPA, CPRA, GPR, as well as those of Canada, Brazil and others – a risk assessment can quickly grow out of date.

    Don’t stop there, she warns. Spend time with functional and business leaders to figure out what data is being processed and for what purpose. Communicate to staff on security issues, especially those working from home.

    And, also, conduct a privacy impact assessment. Knowing the risks is one thing. Understanding how a failure could affect both the business and individuals impacted is another. While you are doing it, don’t stop at the doors of your organization. Look, too, at suppliers to ensure they are handling the data properly and with sufficient safeguards.

    Listen in to learn more, and be sure to also check out The Complete Compliance & Ethics Manual.
    14 min
  • Monica Ramirez on Money Laundering [Podcast]
    Post By: Adam Turteltaub

    The numbers on money laundering are shocking. Monica Ramirez Chimal, Partner at Asserto reports in this podcast that between $3 and $7 trillion is laundered annually. Despite the large number of dollars, enforcement tends to lag, with only a small fraction of cases reviewed by authorities or even caught by compliance programs.

    Part of the challenge, she reports, is that compliance programs are often not up the challenge. Controls are not as strong or comprehensive as they could be. In addition, the pandemic is creating new opportunities for money launderers. There are less face-to-face meetings and transactions may have less documentation, and what documents there are may not be reviewed as closely as they should be.

    At the same time money launderers are changing their tactics, using students and housewives, for example, to open dummy accounts. They are even taking advantage of the explosion in pet ownership, passing money to people while they are out walking their dogs.

    Listen in to learn more about the complexities of this issue and what organizations can be doing to ensure that they are not caught up in a money laundering scheme.
    16 min
  • Angela Osborne on Harassment and the Remote Workforce [Podcast]
    Post By: Adam Turteltaub

    The workforce has moved online and harassment has followed, reports Angela Osborne, Regional Director of Guidepost Solutions. In fact, from the data she has seen, it has actually been increasing.

    Some employees are feeling more emboldened in this remote environment, and they are aided by the fact that with online harassment it can be difficult to identify the perpetrator. Imposter profiles, burner phones and anonymous postings to online forums make it extremely difficult to find out who the bad actor is, especially for in-house teams that are less familiar with the required forensic work.

    And, if that weren’t enough to worry about, physical threats remain since it’s relatively easy to figure out where a colleague lives.

    So, what should organizations do? In this podcast she recommends setting expectations for proper online behavior in the virtual environment, including what constitutes virtual harassment.

    Also critical: making it easy for victims to come forward. Help them identify what is harassment, how to report it, and how to operate safely online to protect themselves.

    Listen in to learn more about how to manage an old problem in a new environment.
    12 min
  • Jessica Simpson on Hiring and Changing Jobs During the Pandemic [Podcast]
    Post By: Adam Turteltaub

    One of the many strange things during this time is that it’s possible to follow a stay-at-home order, be locked down and still change jobs. Companies are hiring, and, reports Jessica Simpson, Recruiting Director at Conselium, candidates, both employed and unemployed, are looking for new positions.

    In fact, the job market for talented compliance professionals has remained very strong. The consolidations early in the pandemic have abated, she tells us, as organization have realized the importance of the compliance role and resumed hiring.

    In this podcast she provides advice to both employers and job candidates.

    To help retain talent she advises that employers:

    * Provide clear growth maps for managers and employees
    * Set realistic, competitive incentive plans
    * Accepts the new flexible work environment
    * Listen to employees

    When hiring she recommends getting over the mental hurdle and accept that Zoom interviews can work. In fact, they can make the hiring process much faster since there’s no longer the need to find a day for the candidate to come in when everyone is in the office. That’s very important since it enables your organization to snatch up that highly qualified candidate before someone else does.

    For job seekers she advises you take the time to identify what makes you attractive to employers. Know what differentiates you and what skills you bring that other candidates may not. Then put that information into your LinkedIn profile and be prepared to discuss it at the interview.

    Also, do your homework on the organization you are interviewing with. Have questions prepared to see if you would be successful in their culture. Ask what made someone who had been successful their succeed. And, know what your values are and ask questions to ensure they will align with the company’s.

    Listen in to learn more whether you’re looking to change jobs or to hire a new member of your compliance team.
    14 min
  • Susan Dworak on Identity Checks [Podcast]
    Post By: Adam Turteltaub

    Who are you?

    It’s a question a wide range of organizations need to ask about everyone from their own employees to their customers.  To understand the risks we sat down in this podcast with Susan Dworak, CEO of Real Identities and author of the chapter “Compliance and Fake IDS: Complications of Checking ID and Confirming Identity” in the new SCCE Complete Compliance and Ethics Manual 2021.

    The list of organizations needing to check identities is longer than many may think. It includes the obvious ones, such as those involved in the sale of alcohol, tobacco, cannabis and firearms. But it also includes banking, notaries, government clerks, hospitality, medical, dental, and even schools.

    Training staff is difficult because of the complexities involved. There are over 800 versions of driver’s licenses in the US, each of which may have 20-100 security features, she explain.

    In the face of this, some may opt to pursue the purchase of an identity scanner, but that can be an expensive proposition.

    So what do you do? First, there’s a need to realize that if you’re collecting identification data that you need to protect this sensitive, personally-identifiable information. Determine what you are collecting, why you are collecting and storing it, and how you are doing so. And, if that data is of European citizens, you also need to recognize that GDPR likely applies.

    Talk to legal and your IT team to understand how that data is handled, including whether your organization is relying on third parties. If the data is being handled elsewhere, take the time to read the disclaimers of the vendors to understand the limits of their technology and how they will protect your organization in case of a failure.

    Finally, she advises to look inside your organization to see what kind of hardware you are using. An old router or unsecured device can provide a gateway to all this sensitive data.

    Listen in to learn more, and, to learn even more, be sure to get new SCCE Complete Compliance and Ethics Manual 2021
    14 min
  • Sonya Lawrence on Managing Conflicts of Interest [Podcast]
    Post By: Adam Turteltaub

    Sonya Lawrence wears two hats as both Senior Vice President, Enterprise Chief Compliance Officer and Conflicts of Interest Officer at Thomas Jefferson University and Jefferson Health. The position, she explains in this podcast, is both broad, and also narrow and complex. As the Chief Compliance Officer she exercises oversight of and works closely with scientists, faculty and university officials across a broad range of issues. As the Conflicts of Interest Officer, she must navigate an increasingly challenging risk area, which has earned unprecedented attention over the last few years.

    To manage the new sensitivities she advocates learning from the experiences of others.  Constantly look to see what’s the same, what’s different and what can you implement.

    Also important, although more difficult due to the pandemic, is maintaining a presence.  Being available for people is crucial, as she explains, because proactive engagement is the secret sauce. If people know where you are and know they can ask you and your team questions before conflicts arise, you and they are all the better for it.

    To make herself and her team more available, they have taken advantage of an internal social networking site. They use it to help stay connected and help employees find information they need, such as gift policies during the holiday season.

    When it comes to managing conflicts of interest, she recommends first asking employees to disclose. In their case they use an electronic system and solicit information at least once a year. Back that up with a campaign emphasizing the simplicity of the process. You want to make it as easy as possible for people to disclose from both a process and an attitudinal perspective. That includes letting people know that their personal information will be respected.

    In addition, she explains, it’s important to put this in the context of putting patients first.

    Listen in to learn more about how to improve your conflict of interest management.
    13 min
  • Hema Lakkaraju on the Ethics of Data [Podcast]
    Post By: Adam Turteltaub

    Digitalization and the proliferation of apps have changed the relationship in healthcare between data, the patient and provider, explains Hema Lakkaraju, CEO and founder of Hayag Corporation.  It is often unclear who is collecting data, why the data is being collected and for whom.  That, in turn, makes it more difficult to ensure accountability in the management and safeguarding of patient data.

    This problem, she argues, call for a grater focus on data ethics, rather than focusing on just the technical issues.  This will help provide greater clarity into what data is collected and how it is used.  It will also provide much-needed insight into who is responsible for the data at each stage of the process.

    To help bring some order to the process, she encourages organizations to ask what data is being stored and classifying it based on risks and potential impact.  Controls should then be aligned appropriately, including robust due diligence of the third parties involved, including cloud-based solutions.

    Listen in as we explore these issues, interoperability, blockchain, and AI.
    15 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners