Ethicast

What Compliance Teams Miss About Third-Party Risk


Listen Later

Someone set fire to a Kimberly-Clark distribution warehouse in California, caused $600 million in damage, and livestreamed the whole thing. The part that got less attention: he didn't work for Kimberly-Clark. He worked for a third-party logistics company they'd hired. Kimberly-Clark had a supplier code of conduct. They had compliance standards. They'd commissioned third-party audits. And it still happened.

That's the reality of third-party risk management — you can build a solid program and still get blindsided by something you couldn't have predicted. But that doesn't mean programs aren't worth building. It means they have to be built well, and most aren't.

In this episode, host Bill Coffin sits down with Emily Miner, Director on the Data & Services team at Ethisphere, to talk about where ethics and compliance programs fall short on third-party risk — and what strong ones actually look like. Emily draws on her work evaluating E&C programs across industries and her deep involvement in Ethisphere's World's Most Ethical Companies assessment process.

They cover:

  • Why third-party risk management tends to be less mature than other E&C program elements — and what that gap looks like in practice
  • How E&C should be involved across the full third-party lifecycle, from due diligence and onboarding through ongoing monitoring and offboarding
  • Why 90% of FCPA enforcement cases over the past 15 years have involved a third-party intermediary
  • What supplier codes of conduct typically miss — including a lack of specificity in key prohibitions, weak enforcement language, and treating the code as a checklist rather than a values statement
  • What companies like JLL and Microsoft are doing right in their third-party codes
  • Emily also discusses her article, "What Makes for a Good Third-Party Code of Conduct?" published in Ethisphere Magazine. Link below.

    Read Emily's article: https://ethisphere.com/magazine/what-makes-an-effective-third-party-code-of-conduct/

    Learn how Ethisphere can help you measure and strengthen your ethics and compliance program: https://ethisphere.com/solutions

    Subscribe for new episodes every week on YouTube, Spotify, and Apple Podcasts. Follow Ethisphere on LinkedIn for more on ethics, compliance, and what it means to do business with integrity.

    ...more
    View all episodesView all episodes
    Download on the App Store

    EthicastBy Ethicast

    • 5
    • 5
    • 5
    • 5
    • 5

    5

    6 ratings


    More shows like Ethicast

    View all
    Hidden Brain by Hidden Brain, Shankar Vedantam

    Hidden Brain

    43,594 Listeners

    The NPR Politics Podcast by NPR

    The NPR Politics Podcast

    25,795 Listeners

    WSJ What’s News by The Wall Street Journal

    WSJ What’s News

    4,353 Listeners

    Pivot by New York Magazine

    Pivot

    9,645 Listeners

    HBR IdeaCast by Harvard Business Review

    HBR IdeaCast

    155 Listeners

    Compliance Perspectives by SCCE

    Compliance Perspectives

    34 Listeners

    The Daily by The New York Times

    The Daily

    112,191 Listeners

    Post Reports by The Washington Post

    Post Reports

    5,202 Listeners

    Great Women in Compliance by Lisa Fine and Hemma Lomax

    Great Women in Compliance

    56 Listeners

    The Journal. by The Wall Street Journal & Spotify Studios

    The Journal.

    6,082 Listeners

    SmartLess by Jason Bateman, Sean Hayes, Will Arnett

    SmartLess

    58,203 Listeners

    The Ethics Experts by Nick Gallo, Giovanni Gallo

    The Ethics Experts

    73 Listeners

    Coaching Real Leaders by Muriel Wilkins

    Coaching Real Leaders

    676 Listeners

    WSJ Opinion: Free Expression by Gerard Baker, Editor at Large, The Wall Street Journal

    WSJ Opinion: Free Expression

    586 Listeners

    Prof G Markets by Vox Media Podcast Network

    Prof G Markets

    1,486 Listeners