Showing posts with label character. Show all posts
Showing posts with label character. Show all posts

Monday, June 23, 2014

Ethical Behavior: No one is truly listening to you

When leaders in other organizations ask me how they should go about launching an ethics program, they are often enthusiastic. Whether because of an article recently read or a director’s conference recently attended, these men and women have “gotten religion” and cannot wait to go forth and conquer. For those of you who heard me recently recount my discussion with Pam (here), you know that it takes a certain kind of mindset to lead the ethics program. But leaders launching an ethics program within an existing organization are also often convinced that its success will be measurable in a manner akin to counting widgets produced per hour, or similar.
The common refrain I hear is, “We’ve got to get this [ethics] program up and running fast! We’ve already drafted communications, planned all-staff meetings at each facility. We’re going to tell people all about it, so they’ll get on board right away!”
Now I don’t know about you, but when people I don’t really know are rushing toward me smiling, frantically waving their arms, and telling me in crazed fashion that “they’re here to help”, I run the other way. And so will employees when confronted with top-down headquarters-scripted communications and town hall meetings. Many of your employees have been at their facility longer than you’ve been out of college. They’ve seen the “program of the quarter” launch, fizzle and fade more than once. Don’t let your well-intentioned (and necessary) ethics program join the fizzle-and-fade folly.
Here’s the rub…your employees aren’t really listening to you most of the time. Unless you directly impact a man or woman’s paycheck, schedule, assignments, or working conditions, you are likely immaterial to their day-to-day professional landscape. An employee can only speculate what a remote company executive does each day, but he/she can surely tell you what his/her boss is doing, not doing, saying, not saying, etc.
If your line supervisor breaks promises, falsifies expense reports, or takes office supplies home for personal use, his/her employees not only know about, but they resent the supervisor for it. That very same supervisor could talk about ethics all day long, handing out buttons and pens galore, and the employees will smirk and roll their eyes.
Bottom line is that it’s not what you say about ethics that will strengthen ethical behavior in an organization, but what you and your fellow leaders model. The measure of success for a newly-launched ethics program will be that future moment where ethical behavior has been modeled so consistently from the CEO through the ranks to the shop floor, that when one employee sees another employee about acting unethically, the first employee holds the second employee accountable.
No words or fancy slogans will be necessary from that moment on…

Monday, February 17, 2014

When Crisis Erupts: Surmount or Surrender?

“The easiest period in a crisis situation is actually the battle itself.
The most difficult is the period of indecision -- whether to fight or run away.
And the most dangerous period is the aftermath.
It is then, with all his resources spent and his guard down, that an individual must watch out for dulled reactions and faulty judgment.”  
~Richard M. Nixon, 37th President of the United States

As a Chief Compliance & Ethics Officer, you know that the eventuality of crisis striking your organization is not a matter of “if”, but only of “when.” You spend your career crafting and implementing a governance system of policies & procedures, training, monitoring, and reporting whose value will ultimately be assessed in those moments and days following the crisis. Not all systems (nor all leaders) will survive the test.

Crisis will not politely schedule an appointment with you on a lazy afternoon, but will more likely descend upon you furiously, publicly and embarrassingly at the most inopportune of moments. Crisis will arrive in the guise of a viral tweet, a regulatory inquiry, or a criminal indictment. A loyal staffer will hesitantly summon you from a meeting into the hallway to advise you of the breaking news. And so begins the moment of decision.

As Compliance leaders we have trained our entire lives to guide and protect our organizations from harm. The very same principles that we have employed to prevent and mitigate risk will come into play when we must navigate our organization, its leadership and its board through and beyond the crisis. Decisive action that engenders trust must remain at the forefront of the response.

Thus, together we must continue to:

  •        Act ethically and decisively;
  •          Communicate frequently and transparently; and
  •          Modify practices appropriately.
Act ethically and decisively

Crisis does not represent your organization in its entirety. Your mission, your values, and your people remain fundamentally sound, even when something has gone awry. Therefore, even as you and your leadership team are undertaking an investigation and crafting a response to the statement, incident, or charge, you will continue to direct your employees to perform their day-to-day responsibilities with the accustomed level of adherence to ethics, compliance, and mission-focus. Your organization will survive the crisis, and so the continued service to your employees, clients, customers, vendors and shareholders must remain highly-functioning.

Communicate frequently and transparently

Do not compound the temporary negative impact of a crisis by shrouding the crisis in a cloak of shame and secrecy. While not proud of the event that has triggered the crisis, you remain nonetheless committed to your employees, your customers, your brand, and your mission-focus for the long run. Within that long view context, communicate quickly that leadership is:

·         aware of the situation;
·         taking it seriously;
·         cooperating fully; and
·         is committed to resolving it.

Convey that future communications will follow as additional information becomes available, and adhere to that pattern, even if only limited information becomes available. Your stakeholders are better served by hearing the truth from you, than the mistrust that will take root if they begin to receive their information—accurate or misconstrued--from external sources.


Modify practices appropriately

While some crises will end with a conclusion that the crisis was merely malicious and unwarranted, often the investigation will reveal a compliance or control weakness that must be addressed by your organization. Once identified, own both the root cause and the solution, communicating the same to your stakeholders. Then set to work implementing the required changes that will ensure the situation has been appropriately addressed. If additional training is warranted, then make every effort to involve the affected employees in designing and testing the training before it is rolled out to the larger audience. Schedule subsequent time to review the modified practice and test its effectiveness, regardless of whether required to do so by a regulatory body or not.

***
Crisis will erupt. You will be called upon to act in the best interest of your organization and its stakeholders. If you have prepared yourself, your leadership team, and your board in advance of this moment, then you will pilot your organization to a brighter tomorrow with the flag flying high. Otherwise, armed only with dulled reactions and faulty judgment, you will find yourself waving the flag of surrender.

Monday, September 17, 2012

COMPLIANCE: A VALUE-ADDED SERVICE TO THE ORGANIZATION

“It’s a sign of troubled times when the concept of ‘pressure’ becomes an acceptable excuse for ethical shortcuts and moral shortcomings. Pressures are just temptations in disguise and it’s never been acceptable to give in to temptation.”  ~Michael Josephson

As a profession, we have worked diligently to shed the stereotype that long-plagued us, that of being a legalistic cost-center who impeded organizational growth. [While you may not have ever personally experienced the stereotype, let me assure you that many of us have received the sarcastic “oh, here comes Audit/Compliance…”]
Like me, many of you regularly engage in projects within your organizations to provide the compliance and ethics (C&E) perspective.  In some organizations, we are routinely invited to project planning sessions and kick-off meetings, remaining to consult with the project team until implementation. In other instances, we become aware of an in-process initiative that contains elements of regulatory risk and invite ourselves into the project. Either way, C&E professionals provide valuable subject matter expertise to ensure that the organization’s we represent are well-grounded in compliant activities.
That being said, I was reminded recently that our work is not over. A colleague had relayed to me a situation at her organization that continues to cause dismay to C&E professionals. During a stakeholder meeting to explore system integration and replacement options, my colleague put forth a variety of system security and operational suggestions to strengthen the information security and consumer compliance framework from inception. After dismissively alluding to costs associated with these suggestions more than a few times during the meeting, the project leader looked up at my colleague and replied, “Well, we may not be able to incorporate each of these items, but—you know—sometimes you just have to go along to get along…” Apparently, the project leader even slyly winked at my colleague as this was said.
I get a little choked up as I recount my colleague’s reply, as with a spine of steel she looked back (without a wink) across the table and said, “Well, no. This organization doesn’t knowingly build non-compliance into its new initiatives, so I wouldn’t sign off without the controls in place.” When the project leader published the next version of the system requirements, each of the compliance components had been incorporated as submitted, and had been risk scored accordingly.
We are going to be asked to participate in many initiatives over the course of our C&E careers. Certainly we will always seek the most cost-effective and internally-conducive methods to achieve compliant outcomes, because we believe in our organizations and wish to help them succeed in the marketplace.
But occasionally we are going to be asked to step beyond the fiduciary responsibility with which our Board has entrusted us, and which society expects of us. It is in those moments when our fidelity to doing the right thing will supplant simply bowing to doing the popular thing. It is in that moment of fortitude and loyalty to duty that we will have added true value to our organization…

Monday, September 19, 2011

REGULATORS, AUDITORS AND EXAMINERS --OH MY!

Q: What do you get if you cross a wild, ferocious, man-eating tiger with an internal auditor?
A: A dull tiger.


OK, by a show of hands, how many of you are excited when you receive the audit engagement letter or regulatory exam notification? Do you mark the dates on your calendar with the same enthusiasm with which you block off your two-week mid-winter Caribbean vacation?

Given what I've observed over the years, I think not. I am here to suggest that we can and should embrace those individuals entrusted with auditing and examining our Organizations--and, no, I have not lost my good sense.

I recall my days as a bank auditor, when my arrival on site appeared to suck the joy right out of the room. Mind you, in hindsight I can humbly admit that the process owners certainly knew their craft far better and more realistically than my well-studied audit manuals could have prepared me. And while I and many of my fellow auditors throughout history have long sought to conduct dispassionate audits with collegial objectivity, management frustration often bubbled just below the surface, bursting forth as certain numbered comments touched unforeseen raw nerves.

The passing of years witnessed my migration away from the internal audit function toward the risk management function via a brief passage through a regulatory agency. At each stage, I tried to bring all perspectives together into one cohesive approach to audits and regulatory exams. I do not believe that I am alone in this regard, as many Leaders more experienced than me have found themselves reconciling multiple facets of the audit/exam process throughout our careers.

What I find fascinating is how many otherwise well-balanced, seasoned Leaders bristle at the notion that they could learn from--let alone seriously consider--the noted exceptions or discussed observations during an operational audit or regulatory examination. The very same Leaders who would pay consultants handsomely to deconstruct and reorganize entire Divisions within the Organization, or who engage high-end vendors to supplant legacy technology with enterprise solutions, will balk at the suggestion that a professional committed to assuring the safety and soundness of the Organization would be any less committed to objective and sustainable improvement.

I am certainly not suggesting that we butter up, befriend or brown nose the independent auditor or government regulator charged with overseeing the thorough examination of our Organizations. I am suggesting that we, as Leaders, owe our Organizations a fiduciary duty to approach the audit/exam with an open mind and a willingness to accept that--despite our best efforts--our Teams could be performing one or more functions with greater care. Unlike the consultants and vendors we hire, our auditors and regulators are not primarily driven by a profit motive or to extract repeat business.

My first-hand experience with administering audits, especially those supported by early warning systems, was to (1) gain a better understanding of the operational processes; (2) identify remedies that had been made to previously-identified exceptions; and (3) offer best practice guidance and foreshadowing of regulatory effects that would impact the process owner's area of responsibility. Our Audit Team certainly wasn't there to one-up management or disrupt well-functioning operations.

On the Risk Management side, despite others' tendencies to view regulatory examinations as declarations of war against the various Organizations, I sought to assume the best intentions. Though it comes as a shock to some, I generally received what I had assumed: professional auditors/examiners (a) conducting objective assessments; (b) examining and documenting the sufficiency of mitigating controls; and (c) offering improvements supported either by industry best practices or foretellings of regulatory rule making. And although I had observed other Leaders come to blows in heated battle with examiners, I never found myself in that adversarial position.

We will all certainly continue to look forward to that two-week mid-winter Caribbean jaunt with much more excited anticipation than any audit or regulatory exam, but as Leaders we can certainly adopt a more collegial and consultative approach to those periodic and foreseeable occasions. You won't be disappointed.

Thursday, August 4, 2011

CHARACTER: A Foundation of Customer Confidence

"Character is much easier kept than recovered."  -Thomas Paine

"You can easily judge the character of a man by how he treats those who can do nothing for him."  -James D. Miles

I recently visited a service provider in my local area, and received the value-added service that I have now come to expect from the organization. In fact, their service offerings are nearly identical to many local competitors, but I continue to loyally patronize the organization for one particular "plus factor": character. Quite simply, not only do their representatives not attempt to sell me products and services that don't fulfill my needs, but they will also inform and dissuade me if I am requesting a product or service for which I do not currently have a need. Now THAT is a plus factor that makes financial sense.

You have likely observed and most certainly have heard or read about other organizations' business transactions that were conducted with something less than integrity and fair dealing. One does not have to be thinking of large conglomerates or evil backroom deals to understand the deeply negative impact that such actions have upon unwary customers, innocent employees and other competitors in the industry. In fact, most of our interactions with business organizations likely occur locally, whether they be our professional or our personal dealings.

Consider the organizations that you return to for products and services. Even if the products and services themselves are fungible in the marketplace, something (quality, service, dependability, etc.) draws you back to that organization or even one particular location or representative of an organization with whom you enjoy conducting your transactions. Spend a moment jotting down 2 or 3 words that describe attributes you value in that organization. Although the words "integrity" or "character" may not appear initially among the top 2 or 3 descriptors, if we were to analyze that organization more thoroughly, we would most likely discover that foundational pillars of the culture include integrity and character.

Character cannot be taught, but it will most certainly be modeled and adopted throughout an organization. For an individual who is still developing his/her character or who struggles with integrity decisions, well-placed coaching may often provide a life-changing shift toward stronger character. Conversely, a perversion of character leading to a lack of integrity will also be modeled and adopted. When the Leaders in an organization live lives of integrity day in and day out, their character--whether at home, in the community, or in the organization--becomes firmly entrenched in making right choices.

Character-based Leaders will attract like-minded team members, provide role models for others whose character is still being formed, and repel those individuals who do not share the same value of strong character. This principle holds true whether we are speaking of a family, a youth group or a project team.

When members of a Team measure themselves against a character-based standard, their personal development, professional interactions, and service to clients/customers/members is infused with integrity. Such a culture requires less formal rules, fosters teamwork and continuous improvement, and serves to eliminate many of its own potential challenges because individuals who attempt to subvert the character-based standard are quickly identified and either choose to leave or are asked to leave. A culture built upon a character-based standard provides no haven for shortcuts, duplicity, or lazy performance.

Customers recognize when they are being dealt with fairly and transparently, because they themselves are persons of integrity. Hence they not only return to your organization and its team members, but these customers also send their friends, family and colleagues to do business with you as well. Your growing customer base and healthy bottom line attest to the success of your character-based culture being practiced by your Teams.

Unfortunately, the converse is true as well, so competitors who fail to develop a character-based culture may attempt to gain marketshare through gimmicks, duplicity, or outright disregard for true customer needs and team member welfare. In the end, such a competitor will fail in business because the Leaders failed themselves, their Teams and their customers. Not a pretty sight!

You are Leader committed to the character-based standard, so I can already envision how you treat your family, your team members, and your customers. Continue to set that standard and those who interact with you and work for you will model and adopt integrity-laden principles as well. Your investment will be well worth it, both in the short run and in the end.

TODAY'S QUESTION: Are there individuals in my organization who may be failing to support our character-based culture for whom coaching may provide the additional encouragement they need to succeed here?