Compliance Perspectives

Compliance Perspectives

Download on the App Store

Compliance Perspectives episodes

  • Scott Giordano on the Risks of the Internet of Things [Podcast]
    Post By: Adam Turteltaub

    Everywhere we look there are now devices that can be connected to the internet.  Around our homes there are security systems, lights, and even refrigerators.  In the workplace it spans most everything, from medical devices to HVAC systems.

    As Scott Giordano, Senior Counsel, Privacy & Compliance at Spirion explains in this podcast, with the rise of the Internet of Things (IoT) and all that connectivity comes an enormous amount of risk.  The vulnerabilities begin, he notes, with the devices themselves, which often were not built with security in mind.  They provide an opening for hackers, even through something as seemingly innocuous as the thermostat in a fish tank.

    To manage the risk, Giordano recommends screening vendors to ask how they are protecting the devices that they are attaching to your system.  Do so via a short questionnaire that you go through question by question with the vendor, thereby avoiding a check the box exercise.

    He also recommends auditing the data your organization houses to determine what information you have, what is sensitive and what data may no longer be needed.  An audit, he notes, typically identifies many more data storehouses than an organization thinks it has.  Often this problem is caused by the  proliferation of applications used in organizations, many of which communicate with each other and start storing data on their own.

    On an ongoing basis it is important, he observes, to stay on top of what devices are added to your system and to regularly update your asset inventory.  And don’t lose track of the risks of Bring Your Own Device (BYOD) policies.  All those apps on phones are collecting data, too.

    Controls are also key to ensure that no unauthorized devices are added.  Hand in hand with that is a need to understand the issue from the employee perspective.  If you make it too difficult for them to do their jobs, they will look to work arounds that can create more data security risk.

    To learn more, he recommends reading the scarily titled Click Here to Kill Everybody.  And, of course, you can listen to this podcast to better understand IoT risks and what compliance teams need to do about them.
    11 min
  • Hiltrud Werner on Volkswagen’s Transformation [Podcast]
    Post By: Adam Turteltaub

    The Volkswagen Dieselgate scandal captured global headlines and was profoundly disruptive to the company, resulting in substantial penalties and a three-year monitorship under former Deputy Attorney General Larry D. Thompson that ended in September.

    So, how has Volkswagen changed, and what was it like from the inside? In this podcast we learn the answers to both questions from Hiltrud Werner, who serves as a Member of the Board of Management -- Integrity and Legal Affairs for Volkswagen. From this position, which was introduced in 2013, she oversees the integrity program, legal affairs, compliance and risk management. She also oversaw the US monitorship from the Volkswagen side.

    As she explains in this podcast, the position has been a great vantage point for seeing the transformation of the company in response to the scandal, and she notes that the role she occupies reflects as a clear mandate from the supervisory board.

    When she took over the job the key priorities included launching a 10-point plan in compliance and another 10-point plan in risk management. At the same time there was a need to implement the obligations under the agreement with US authorities, including changes ranging from improvements to the whistleblower system to realignment of the entire board structure. Compliance and risk management were separated, and working with colleagues, she created a new integrity program.

    What were some of the keys to a successful transformation of the company? She reports that there was a strong commitment to creating much more of a speak up culture, from hire to retire. Right from the start they focused on the human factor and sought to create and live transparency.

    Cooperation with the monitor was seen as crucial, and a liaison office was created with the vision of being much more than just a processor of requests.

    Volkswagen is now looking beyond the monitorship, she tells us. As Herbert Diess, chairman of Volkswagen’s management board said, “But the end of the monitorship is not the end of our journey.” It is just a milestone.

    Listen in to learn more about what Volkswagen did to improve its culture and compliance function, and lessons that can help your organization should it, too, need to make a profound transformation after a crisis.
    15 min
  • Lisa Miller on the World Bank, Sanctions and the Integrity Compliance Office [Podcast]
    Post By: Adam Turteltaub

    The World Bank is a powerful force for development in the world, and, unfortunately, the large sums of money it invests are often the target of fraudsters and the corrupt.

    To help protect the Bank’s investments, the Integrity Vice Presidency stands guard, explains Lisa Miller, Head of the Integrity Compliance Office and Compliance Officer at the World Bank Group.  It is responsible for helping ensure that Bank funds have been used for the purpose intended.

    The office’s ambit includes investigating cases of fraud and corruption from start to finish.  There is an intake team that looks into allegations and, if warranted investigates them.  And, should the evidence indicate wrongdoing, the investigators and litigators take the allegations through the sanctions system.

    The consequences for an organization when an allegation has been substantiated, she shares in this podcast, can be quite severe.

    Whether the case leads to a settlement or a debarment – typically for three years – a business can only regain eligibility to bid on World Bank projects if it meets several conditions, including, typically, an integrity compliance program that reflects World Bank principles.

    Listen in to learn more about what the Bank expects to see in a compliance program both before and after an incident occurs.  And don’t miss the fact that having a strong compliance program can earn credit, even if improper behavior is found.
    16 min
  • Larry Reicher on the Antitrust Division’s Office of Decree Enforcement [Podcast]
    Post By: Adam Turteltaub

    The approach to compliance programs of the Antitrust Division at the US Department of Justice has evolved considerably over the last few years, starting with the release of their watershed Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations in July 2019. This document was a dramatic step forward in providing recognition of compliance programs and encouraged prosecutors to consider three fundamental questions:

    * Is the corporate compliance program well designed?
    * Is the program being applied earnestly and in good faith?
    * Does the corporation’s compliance program work?

    In August 2020 the DOJ followed up with the creation of the Office of Decree Enforcement and Compliance (ODEC) to provide additional resources for criminal and civil antitrust cases.

    In this podcast Larry Reicher, the ODEC Chief, explains that the Office has multiple goals.  First, it seeks to ensure that companies are compliant with decrees. There have been instances in the last few years in which parties had not lived up to their obligations.

    ODEC is also charged with acting as a resource for the Criminal Section of the Antitrust Division as it analyzes compliance programs in companies seeking to earn credit for them. In addition, the Office is responsible for the section of monitors, when one is required.

    Its role is also to incentify compliance and good citizenship and, ideally, prevent problems from happening in the first place. To help achieve that goal ODEC looks for four common traits in organizations:

    * A commitment to a culture of compliance
    * The company self-reports properly
    * Full and timely cooperation
    * Thorough and timely remediation

    In addition, they are particularly focused on determining if the compliance program is tailored to the industry and company, not an off-the-shelf exercise.

    Listen in to learn more about ODEC as well as the Department of Justice’s expectations and rewards for effective antitrust compliance programs.
    16 min
  • Lori McGee on Corporate Jets and Compliance [Podcast]
    Post By: Adam Turteltaub

    Corporate jets come with large fuel bills and, as we learn in this podcast from Lori McGee, partner at Jetstream Law, substantial compliance requirements.

    It begins with the registration, which, perhaps to the surprise of many, include US citizen requirements for officers of the corporation.  In addition, some of the rules are fairly nuanced.  Any changes to corporate ownership or even membership changes to an LLC may trigger an obligation to update information on file with the FAA.  It may sound like a technicality, but if the aircraft is involved in an incident, having the incorrect information on file may be sufficient for the insurer to claim the aircraft wasn’t properly operated.

    Thinking about allowing personal use of the aircraft by an executive?  Before you do so, you need to consider both FAA and IRS rules she cautions.  Having the executive reimburse the company can be problematic on the FAA side since they general prohibit seeking reimbursement.  On the IRS side, if use of the jet is treated as a benefit, there may be tax implications.  And, if the organization is publicly-traded, there may be SEC considerations as well.

    Even maintenance issues have compliance requirements since aircraft financial firms may require the aircraft to be enrolled in a maintenance or parts program.  If the mechanic or pilot don’t know that and jettison the program to save cost, it could prove costly.

    Listen is to learn more about the compliance perils of private aviation.
    12 min
  • Maddie Bainer of HHS on the Special Fraud Alert on Speakers Programs [Podcast]
    Post By: Adam Turteltaub

    On November 16, 2020 the Office of Inspector General (OIG) at the Department of Health and Human Services (HHS) issued a Special Fraud Alert focused on “fraud and abuse risks associated with the offer, payment, solicitation, or receipt of remuneration relating to speaker programs by pharmaceutical and medical device companies.”

    To better understand the alert and the compliance implications, we sat down with Maddie Bainer, Senior Counsel, Office of Counsel to the Inspector General. In this podcast she explains that the alert was triggered by what OIG saw as a troubling trend of manufacturers sponsoring events in which healthcare professionals were paid to speak to their peers at entertainment and sports venues and very high end restaurants. There were even cases in which the physician paid to speak never actually spoke, and the audience was made up of individuals which no professional reason to be in attendance.

    Such practices had already led to at least one high profile settlement, and to curb the practices the OIG issues the Alert.

    The Special Fraud Alert provides a list of “suspect characteristics”, Bainer explains, that could be indicative of problematic behavior:

    * The company sponsors speaker programs where little or no substantive information is actually presented;
    * Alcohol is available or a meal exceeding modest value is provided to the attendees of the program (the concern is heightened when the alcohol is free);
    * The program is held at a location that is not conducive to the exchange of educational information (e.g., restaurants or entertainment or sports venues);
    * The company sponsors a large number of programs on the same or substantially the same topic or product, especially in situations involving no recent substantive change in relevant information;
    * There has been a significant period of time with no new medical or scientific information nor a new FDA-approved or cleared indication for the product; 11 Id. at 23. 5
    * Health Care Professionals (HCPs) attend programs on the same or substantially the same topics more than once (as either a repeat attendee or as an attendee after being a speaker on the same or substantially the same topic);
    * Attendees include individuals who don’t have a legitimate business reason to attend the program, including, for example, friends, significant others, or family members of the speaker or HCP attendee; employees or medical professionals who are members of the speaker’s own medical practice; staff of facilities for which the speaker is a medical director; and other individuals with no use for the information;
    * The company’s sales or marketing business units influence the selection of speakers or the company selects HCP speakers or attendees based on past or expected revenue that the speakers or attendees have or will generate by prescribing or ordering the company’s product(s) (e.g., a return on investment analysis is considered in identifying participants);
    * The company pays HCP speakers more than fair market value for the speaking service or pays compensation that takes into account the volume or value of past business generated or potential future business generated by the HCPs.

    These characteristics should be noted not just be manufacturers but also by practitioners and the health care providers that employ them. As she points out, the Anti-Kickback statue applies both to those offering the rem...
    15 min
  • Jeffrey Kaplan on Assessing Corporate Culture [Podcast]
    Post By: Adam Turteltaub

    Having the right corporate culture is essential to an effective compliance program, but building and assessing that culture can be a very tricky thing. Few know this better than Jeffrey Kaplan, a partner in the firm Kaplan & Walker, who specializes in compliance program assessments.

    There is an eagerness, he explains to measure the culture, but doing so in a quantitative way can be difficult. Some things just don’t lend themselves to a numbers-based score. In those cases it’s best to rely on common sense born of experience.

    What should compliance teams look for when assessing culture? He recommends examining several factors including:

    * Tone at the middle
    * How easy it is to speak up in the organization on all issues, not just compliance
    * Organizational justice
    * How conflicts of interest are managed
    * The industry’s culture
    * How customers are treated
    * Incentive plans
    * Rule following

    There is a lot of subtlety in these measures. For example, while on the whole it’s good to have a culture where the rules are followed, there could be a cost if ethics is not considered.

    He also encourages granularity: don’t just look at the culture as a whole. It should be examined by geography and even department.

    Listen in to learn more about how to better assess your own organization’s culture, or cultures, and the best way to present the findings to management.
    16 min
  • What’s New in the Healthcare Privacy Compliance Handbook, 3rd Edition [Podcast]
    Post By: Adam Turteltaub

    Recently the Health Care Compliance Association released the new Health Care Privacy Handbook, 3rd Edition. To learn what’s new in the book and in healthcare privacy we sat down with editorial lead Darrell W. Contreras, Chief Compliance Officer, Millennium Health and one of the authors, David Nelson, PrivacyGuy Solution.

    As they explain in the podcast, the new version provides a baseline on updates to the many laws and regulations affecting privacy in the healthcare industry, including:

    * HIPAA
    * Breach notifications
    * Research
    * FERPA
    * Health plan and payer issues
    * 42 CFR Part 2
    * The Privacy Act of 1974

    There are also tips and guides for privacy professionals.

    What makes the book so valuable, they explain, is that the contributors were able to provide not just what the rules say but also a perspective from years of experience, helping to make complex issues easier to understand.

    Staying current on these issues is more important than ever, with Homeland Security warning of increased phishing attempts by bad actors during the pandemic, a time when many people are working remotely and on less-secured laptops.

    Listen in to learn more about what’s going on in privacy and what you can find inside the pages of the third edition of the Healthcare Privacy Compliance Handbook.
    15 min
  • Gerry Zack on a New Tool for Applying the COSO ERM Framework to Compliance [Podcast]
    Post By: Adam Turteltaub

    There has been much discussion over the years about the relationship between enterprise risk management (ERM) and compliance risk management. Making the discussions more complex has been a tendency to approach risk management from very different perspectives. Risk managers have long looked to the COSO ERM Framework, while compliance teams have turned to the Federal Sentencing Guidelines and other documents. Adding to the complexity are language issues. “Risk appetite” is a common term for risk managers and one that is oft-misunderstood and provokes great concern among compliance professionals.

    To help bridge the gap  the Society of Corporate Compliance and Ethics & Health Care Compliance Association, working under the auspices of COSO (the Committee of Sponsoring Organizations of the Treadway Commission) developed a new publication, entitled Compliance Risk Management: Applying the COSO ERM Framework. As SCCE & HCCA CEO Gerry Zack explains in this podcast, this new guidance is designed to help apply the COSO ERM framework to the management of compliance risks  and better align it with the framework used by compliance and ethics professionals in the design of effective compliance and ethics programs.

    There are numerous benefits from better integration between compliance and enterprise risk management, Gerry reports. For one, it can start breaking down the silos that often lead to inefficiencies and confusion.

    For risk management professionals it brings greater understanding of the complexities and nuances of compliance, including the fact that not all matters of compliance risk can be easily quantified.

    For compliance professionals, it enables them to better speak in the language of risk professionals and management in general. It also creates an opportunity to move compliance from being perceived as a cost center to being recognized as a protector and creator of value for the organization, a concept that is central to the COSO ERM framework.

    Listen in to learn more about this valuable new tool for compliance teams and its many uses, including as a self-assessment tool.
    11 min
  • Matt Silverman on Creating a Compliance Champions Program [Podcast]
    Post By: Adam Turteltaub

    Every compliance team has only so many eyes and ears to know what’s going on in the company, and so many voices to get the word out.

    How do you get more without adding paid staff? Some companies, such as Arizona-based ASML, have created a compliance champions program. As Matt Silverman, Senior Manager, Export Controls explains in this podcast, a champions program can be exceptionally helpful, especially at times like these when compliance leaders can’t travel.

    Champions can help the central compliance team get a better understanding of what is going on in the business units and at offices far away. They can provide employees with a face that they know and trust when reporting incidents. They can also do outreach as well, helping spread compliance-related messages at local meetings. Sometimes they can even handle a piece of the compliance training. Just don’t ask them to be subject matter experts, he advises.

    To get started with a champions program, Matt recommends getting the business unit on board. Let them know what you are doing and why. Explain the concept of the champions network fully, develop an implementation plan, share it with them and take heed of any constructive feedback you receive. In fact, take the time to solicit it.

    Then, once the program is implemented continue to solicit the business team’s input.

    When it comes to recruiting your compliance champions, look for diversity in experience and thought: different sectors of the business, site and location and titles, also different levels of experience. You want to find employees that are trusted, know their sites well, how they function and their typical compliance issues.

    Listen in to learn more and find out if you’re ready to champion having compliance champions.
    17 min

About Compliance Perspectives

From the publisher's feed

An SCCE Podcast

More shows like Compliance Perspectives

The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

227,497 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,362 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,702 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,245 Listeners

Pivot by New York Magazine

Pivot

9,625 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,449 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,240 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

42 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

800 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

15,904 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,436 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

19,273 Listeners