"There's a way to do it better—find it." ~Thomas Edison
"Success is on the far side of failure." ~Thomas Watson Sr.
Does the title above accurately describe your professional style? Or that of your Team? Your Organization?
Why not?
Much has been written regarding the unfortunate passing of the iconic Steve Jobs. Does your own leadership experience and outlook embrace the passion for your Organization's mission that was evident as Steve Jobs spoke to those 2005 Stanford graduates? Do YOU fondly recall your own failings with the same enthusiasm that Steve Jobs exuded when describing his ouster from Apple ten years after its founding?
Are you failing enough? Are you encouraging your Team's members to fail more often?
The financial services industry continues to evolve at breakneck speed. Online bill payment, account aggregation, bank-to-bank online transfers are now "old" technologies. Single location institutions have launched mobile banking. As soon as your Public Relations Team can place a piece on the PRNewswire, a dozen other competitors or peers simultaneously issue similar independent press releases.
Despite infinite media attention and blogs devoted to the "rise of regulation amidst Dodd-Frank" and all of the other horror stories about "new fees" that abound, a select few of your competitors are conceiving, testing, retooling, retesting and preparing to launch tomorrow's customer-friendly product or service. What are YOU doing to lead your Organization to the front of that cadre? Is your Board of Directors inspired...or mired in risk aversion?
Every merger has an acquirer and an acquired (regardless of how the Communications Team attempts to portray it). Yesterday's mergers were often about growing the footprint, expanding the brand to new markets, leveraging complementary channels for optimizing profits and controlling redundant costs.
Is your Organization untamed? Are you confident enough in your professional Team to accord them a percentage of their time to be unruly enough to identify, develop and launch the products and services that will satisfy tomorrow's customers/members?
Your Organization, under your leadership, will either be the acquirer--or the acquired--in tomorrow's merger. You will either be seeking to acquire an institution through which your Organization can channel its innovative products, services and servant leaders to WOW! new customers/members...or you will be explaining to your employees why many of them will need to seek employment elsewhere?
YOU are the Leader that everyone in your Organization is looking up to. Are you the Leader that everyone in your Industry is looking up to and attempting to emulate?
If not, then perhaps it's time you moved out of the way to allow that Leader to emerge...that Leader who will ensure that your Organization and each of its fully-invested Teams become and remain: UNSTOPPABLE!
"Reducing challenges that diminish our ability to fully serve our financial institution consumers' needs..."
Showing posts with label collaboration. Show all posts
Showing posts with label collaboration. Show all posts
Monday, June 16, 2014
Tuesday, November 5, 2013
Regulatory Compliance: Tear Down That Ivory Tower!
I recently ran into a Compliance colleague, “Jill”, whom I hadn’t seen in a while. As we exchanged pleasantries, Jill explained how busy she has been at her organization, to a point where she “couldn’t even get out of her office for lunch most days.” I understood her sentiment, but I challenged Jill’s premise that her most effective oversight of her Compliance Management Program was being accomplished sitting at her desk with her nose to the proverbial grindstone.
“What do you mean?”, Jill inquired.
“For starters, how are you assessing the compliance culture within and across your organization?”, I responded. I waited for the predictable response.
“I receive reports from each department head on a quarterly basis. I meet with those same department heads at least annually as we update our risk assessment. “ And then she punctuated her response, “I always know what is going on from a Compliance perspective.”
We visited for a few more minutes before continuing on our respective journeys. I have the utmost respect for Jill, and the many colleagues with whom I’ve engaged in similar conversations over the years. But I was reminded again that day that differing viewpoints pervade our Compliance Management profession.
I liken the practice of our craft to that of a world traveler. In fact, given the international nature of Regulatory Compliance, many of us have become world travelers from time to time. But one cannot truly experience traveling the world by reading other people’s written accounts of foreign lands. Similarly, Compliance professionals cannot simply read stacks of reports, formally engage depart heads once or twice annually, and conclude that they have traveled the organizational “globe”.
We’ve got to come down out of our ivory towers. In fact, we’ve got to tear down our ivory towers in the Compliance Department and never return to our old ways. Instead, let’s engage leaders at all levels across our organizations as often as possible. Informal dialogue that may occur within the context of a scheduled project meeting, or a chance meeting in the hallway, can often generate useful information that lends itself well to a holistic risk assessment.
Leaders want to tell you what concerns they are facing, and when those concerns signal regulatory compliance exposure, you have an opportunity to collaborate further toward a resolution. Internal Audit provides another natural source of regulatory compliance risk data gleaned from its expansive reach throughout your organization. Regulatory Compliance also finds a natural ally in the Information Technology Department, where governance, risk management and compliance looms large over an ever-evolving landscape. Compliance professionals grow to become trusted confederates with leaders of lines of business, Internal Audit and Information Technology.
So join me! Grab your water bottle or coffee cup, and explore your organization more freely. Engage others daily and take a more genuine interest in the regulatory compliance challenges facing your fellow leaders. Collaborate with them to develop lasting compliance solutions. Your risk assessments and resultant regulatory compliance program will flourish, producing more meaningful results for the entire organization. You won’t want to return to the ivory tower.
“What do you mean?”, Jill inquired.
“For starters, how are you assessing the compliance culture within and across your organization?”, I responded. I waited for the predictable response.
“I receive reports from each department head on a quarterly basis. I meet with those same department heads at least annually as we update our risk assessment. “ And then she punctuated her response, “I always know what is going on from a Compliance perspective.”
We visited for a few more minutes before continuing on our respective journeys. I have the utmost respect for Jill, and the many colleagues with whom I’ve engaged in similar conversations over the years. But I was reminded again that day that differing viewpoints pervade our Compliance Management profession.
I liken the practice of our craft to that of a world traveler. In fact, given the international nature of Regulatory Compliance, many of us have become world travelers from time to time. But one cannot truly experience traveling the world by reading other people’s written accounts of foreign lands. Similarly, Compliance professionals cannot simply read stacks of reports, formally engage depart heads once or twice annually, and conclude that they have traveled the organizational “globe”.
We’ve got to come down out of our ivory towers. In fact, we’ve got to tear down our ivory towers in the Compliance Department and never return to our old ways. Instead, let’s engage leaders at all levels across our organizations as often as possible. Informal dialogue that may occur within the context of a scheduled project meeting, or a chance meeting in the hallway, can often generate useful information that lends itself well to a holistic risk assessment.
Leaders want to tell you what concerns they are facing, and when those concerns signal regulatory compliance exposure, you have an opportunity to collaborate further toward a resolution. Internal Audit provides another natural source of regulatory compliance risk data gleaned from its expansive reach throughout your organization. Regulatory Compliance also finds a natural ally in the Information Technology Department, where governance, risk management and compliance looms large over an ever-evolving landscape. Compliance professionals grow to become trusted confederates with leaders of lines of business, Internal Audit and Information Technology.
So join me! Grab your water bottle or coffee cup, and explore your organization more freely. Engage others daily and take a more genuine interest in the regulatory compliance challenges facing your fellow leaders. Collaborate with them to develop lasting compliance solutions. Your risk assessments and resultant regulatory compliance program will flourish, producing more meaningful results for the entire organization. You won’t want to return to the ivory tower.
Thursday, October 17, 2013
Don’t make the wrong call!
Ensuring compliance with the Telemarketing Sales Rule (TSR) and Telephone Consumers Protection Act (TCPA)
* The FTC has long blazed a trail of consumer protection aimed at unscrupulous telemarketers.
* The FCC has strengthened its arsenal of weapons aimed at robocallers.
* Failure to incorporate the 2013 requirements can cost your company millions of dollars.
* Compliance Departments must engage all stakeholders in the organization.
* Building a compliant outbound calling & texting program will protect profits and the brand.
No longer can any sales and service organization naively believe that it will escape the notice of United States federal consumer protection regulators. If your organization uses a telephone to reach consumers, then the Federal Trade Commission (FTC) and the Federal Communications Commission (FCC) are two such agencies for which regulatory compliance professionals must maintain a watchful eye.
In conjunction with the robust outbound communication activities that our sales and service operations undertake, careless violations of FTC and FCC consumer communications laws garner sizeable financial penalties. To understand the impact of the October 2013 FCC amendments, it is helpful to review the FTC’s Telemarketing Sales Rule requirements.
FTC Telemarketing Sales Rule 2008 Amendments
The FTC administers the Telemarketing Sales Rule (TSR). Amended in 2008, the TSR governs outbound telephone calls initiated by a telemarketer, including those involving dialing technology (“autodialers”) and pre-recorded messages. As defined by the FTC:
• “Outbound telephone call” to mean a telephone call initiated by a telemarketer to induce the purchase of goods or services or to solicit a charitable contribution;
• “Telemarketer” means any person who, in connection with telemarketing, initiates or receives telephone calls to or from a customer or donor; and
• “Telemarketing” means a plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call.1
Some prerecorded messages still are permitted under these rules — for example, messages that are purely informational. That means a consumer may still receive calls to let him/her know a flight’s been cancelled, reminders about an appointment or messages about a delayed school opening. But the business doing the calling still isn’t allowed to promote the sale of any goods or services. Political calls, calls from certain healthcare providers and messages from a business contacting a consumer to collect a debt also are permitted. Prerecorded messages from banks, telephone carriers and charities also are exempt from these rules if the banks, carriers or charities make the calls themselves.2
While notifying consumers of a store address change is considered informational (thus not telemarketing), inviting them to a grand opening celebration at the new address could be considered part of a “plan, program or campaign” to induce the purchase of goods or services. That is, merely mentioning the grand opening could be the “hook” for a court or regulator to determine that the entire script is “telemarketing.”
The amended TSR expressly bars telemarketing calls that deliver prerecorded messages, unless a consumer previously has agreed to accept such calls from the seller.3 As a result, most businesses became required to obtain the consumer’s written permission before they could call a consumer with prerecorded telemarketing messages, or “robocalls”. In fact, a business has to make it clear it’s asking to call a consumer with these kinds of messages, and it can’t require a consumer to agree to the calls in order to get any goods or services. If the consumer initially agrees to receive robocalls, the consumer also retains the right to change his/her mind and rescind his/her opt-in.
The FTC takes enforcement of the TSR very seriously when it comes to robocall violators. A May 2013 FTC action resulted in a Department of Justice settlement4 resulting from an FTC-led complaint.5 Specifically, citing 16 C.F.R. § 310.4(b)(l )(v)(A), the Defendant company was permanently restrained and enjoined from engaging in, causing others to engage in, or assisting other persons to engage in:
A. Initiating any outbound telephone call that delivers a prerecorded message to induce the purchase of any good or service unless, prior to making any such call, the seller has obtained from the recipient of the call an express agreement, in writing, that:
1. the seller obtained only after a clear and conspicuous disclosure that the purpose of the agreement is to authorize the seller to place prerecorded calls to such person;
2. the seller obtained without requiring, directly or indirectly, that the agreement be executed as a condition of purchasing any good or service;
3. evidences the willingness of the recipient of the call to receive calls that deliver prerecorded messages by or on behalf of a specific seller; and
4. includes such person’s telephone number and signature.
The Defendant was ordered to undergo federal compliance monitoring, extensive recordkeeping and detailed reporting for 10 years. Additionally, the settlement included judgment in the amount of $75,000 entered in favor of the FTC against Defendant as a civil penalty. The Defendant’s judgment was far more lenient that the $16,000 per call that the FTC is authorized to assess under the TSR.
FCC Telephone Consumer Protection Act 2012 Amendments
The FCC administers the Telephone Consumer Protection Act (TCPA). In alignment with the FTC position, revised FCC TCPA rules took effect on October 16, 2013 and require “prior express written consent” for pre-recorded telemarketing calls using autodialer technology made to both cell phones and land line phones. This rule change expressly amends the previous FCC rule which (1) had not required written consent; and (2) had allowed prerecorded telemarketing calls to land line phones where a business relationship existed.
The FCC has taken a very broad view of the use of autodialer technology. Although the rules provide a very specific definition of autodialer, regulators and the courts have interpreted the definition so broadly that any computerized dialing device could be viewed as an autodialer. It is advisable not to make non-consented calls to cellphones, unless your organization has an entirely manual process for initiating the call.
Misuse or misunderstanding the use of autodialer technology in the absence of receiving prior express written consent has expensive consequences. The TCPA has a private right of action and recent class action lawsuits have settled for tens of millions of dollars.6
Costly non-compliance
Non-compliance with the TSR and the TCPA exposes your organization to civil liability and regulatory sanctions and fines. At up to $1,500 per violation, non-compliance with the TCPA text message requirements alone could expose your organization to a sizeable civil judgment. A company that sends a mere 7,000 non-consented text messages could statutorily incur a fine in excess of ten million dollars.
This TCPA text message revision is anticipated to also invite predatory class action litigation as enterprising plaintiff attorneys seek to capitalize on the technical change to the law. Regulatory penalties and class action lawsuits give rise to negative publicity that have the potential to damage your organization’s profitability and its brand.
Build compliance into your outbound calling and texting programs
To address this potential reputational, regulatory, and legal risk exposure, compliance professionals should partner with the stakeholders in the organization who have a vested interest in outbound calling and texting programs. These stakeholder functions will likely include Sales, Marketing, E-Commerce, Call Centers, and Information Technology (yes, IT! They own the autodialer and messaging hardware and software your organization relies upon). And don’t forget those third-party service providers that may actually be managing your call lists, opt-ins, and outbound calling and texting programs.
Once you have marshaled your stakeholders, you will want to undertake:
(1) a review of existing outbound calling and texting programs, approval processes, and vendor contracts; and
(2) provide detailed guidance to management regarding required current changes and safeguards for current and future programs.
You will specifically want to address pre-recorded messages sent to both land line and cellular phones, as well as text messages sent to cellular phones.
Compliant pre-recorded messages
Your organization may call consumers who have provided written permission after being fully informed that they have expressly assented to receive prerecorded calls regarding your products and services. If your organization has not obtained such “prior express written consent” since October 16, 2013, you will want to solicit a revised affirmative written opt-in. Guidance interpreting the amended TCPA treatment of prerecorded calls suggests that a consumer must have the option to affirmatively check an unchecked box beside verbiage that explicitly and plainly explains that the consumer is opting into receiving prerecorded calls to his/her cell phone and/or land line phone.
A prerecorded message system must also adhere to the following opt-out language and activation safeguards:
• Businesses using robocalls are required by law to tell a consumer at the beginning of the message how to stop future calls, and must provide an automated opt-out the consumer can activate by voice or key press throughout the call.
• If the message could be left on voicemail or an answering machine, businesses also have to provide a toll-free number at the beginning of the message that will connect to an automated opt-out system the consumer can use any time.
Compliant text/SMS messages
Changes to existing text message marketing opt-in processes may be required at your organization to conform to the new “prior express written consent” standard. Recognizing that text messages are limited in character length, these changes should be customized for your purposes, but may resemble:
• New text/SMS enrollee receives: “Reply ‘AGREE’ to receive wkly XYZ Discount Alerts. Periodic msgs may be sent using autodialer. Consent not required for purchase. Msg&Data rates may apply” (to fulfill the FCC requirement of obtaining express written consent after the initial request is received AND that his/her consent is not required in conjunction with any other purchase)
• Once the consumer replies with ‘AGREE’, enrollee receives: “Thanks for confirming! You will receive weekly XYZ Discount Alerts! Stop reply ‘STOP XYZ’. Msg&Data rates may apply.” (to fulfill the FCC requirement of explicitly informing the requestor how he/she may rescind the opt-in)
Obtain new consent from current text/SMS subscribers
Your organization may currently have thousands (or hundreds of thousands) of subscribers. When the new rules took effect on October 16, 2013, all consent obtained under the old “prior express consent” standard were invalidated. When the FCC issued its revised rules in February 2012, the agency conveyed that once the new written consent rules became effective, companies would be required to obtain the revised “prior express written consent” before sending additional marketing messages. An established business relationship will also no longer relieve advertisers of prior written consent requirement after the effective date. You may thus seek to ensure that all current subscribers also receive the message inviting them to reply ‘AGREE’.
New text/SMS message marketing programs
These same FCC principles would apply to new text marketing programs that your organization may launch in the future. The FCC interprets “marketing” very broadly in its own favor, so you will want to ensure that your Compliance Department is involved at inception to review new text messaging programs.
Conclusion
As compliance professionals, we must daily balance our organization’s customer-focused mission with the consumer protection regulatory requirements. By taking swift action with your stakeholders now regarding the TSR and TCPA, you can reduce the risk that your organization will make the wrong call.
Notes
1 The Telemarketing Sales Rule, September 2009, http://www.consumer.ftc.gov/articles/0198-telemarketing-sales-rule.
2 Ibid.
3 FTC Issues Final Telemarketing Sales Rule Amendments Regarding Prerecorded Calls, August 19, 2008, http://www.ftc.gov/opa/2008/08/tsr.shtm.
4 United States of America v. Skyy Consulting, Inc., also d/b/a CallFire, a California corporation, United States District Court, Northern District of California, San Francisco Division, Case4:13-cv-02136-DMR, Document 3, Filed 05/13/13, http://www.ftc.gov/os/caselist/1223011/130514callfirestip.pdf.
5 United States of America v. Skyy Consulting, Inc., also d/b/a CallFire, a California corporation, United States District Court, Northern District of California, San Francisco Division, Case4:13-cv-02136-DMR, Complaint, Filed 05/09/13, http://www.ftc.gov/os/caselist/1223011/130514callfirecmpt.pdf.
6 Pari Najafi v. SLM Corporation, et al., United States District Court for the Southern District of California, Case No. 10-cv-0530 MMAAmended Settlement Agreement, October 7, 2011, http://www.manatt.com/uploadedFiles/Content/4_News_and_Events/Newsletters/AdvertisingLaw@manatt/Sallie%20Mae%20amended%20settlement%20agreement.pdf.
* The FTC has long blazed a trail of consumer protection aimed at unscrupulous telemarketers.
* The FCC has strengthened its arsenal of weapons aimed at robocallers.
* Failure to incorporate the 2013 requirements can cost your company millions of dollars.
* Compliance Departments must engage all stakeholders in the organization.
* Building a compliant outbound calling & texting program will protect profits and the brand.
No longer can any sales and service organization naively believe that it will escape the notice of United States federal consumer protection regulators. If your organization uses a telephone to reach consumers, then the Federal Trade Commission (FTC) and the Federal Communications Commission (FCC) are two such agencies for which regulatory compliance professionals must maintain a watchful eye.
In conjunction with the robust outbound communication activities that our sales and service operations undertake, careless violations of FTC and FCC consumer communications laws garner sizeable financial penalties. To understand the impact of the October 2013 FCC amendments, it is helpful to review the FTC’s Telemarketing Sales Rule requirements.
FTC Telemarketing Sales Rule 2008 Amendments
The FTC administers the Telemarketing Sales Rule (TSR). Amended in 2008, the TSR governs outbound telephone calls initiated by a telemarketer, including those involving dialing technology (“autodialers”) and pre-recorded messages. As defined by the FTC:
• “Outbound telephone call” to mean a telephone call initiated by a telemarketer to induce the purchase of goods or services or to solicit a charitable contribution;
• “Telemarketer” means any person who, in connection with telemarketing, initiates or receives telephone calls to or from a customer or donor; and
• “Telemarketing” means a plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call.1
Some prerecorded messages still are permitted under these rules — for example, messages that are purely informational. That means a consumer may still receive calls to let him/her know a flight’s been cancelled, reminders about an appointment or messages about a delayed school opening. But the business doing the calling still isn’t allowed to promote the sale of any goods or services. Political calls, calls from certain healthcare providers and messages from a business contacting a consumer to collect a debt also are permitted. Prerecorded messages from banks, telephone carriers and charities also are exempt from these rules if the banks, carriers or charities make the calls themselves.2
While notifying consumers of a store address change is considered informational (thus not telemarketing), inviting them to a grand opening celebration at the new address could be considered part of a “plan, program or campaign” to induce the purchase of goods or services. That is, merely mentioning the grand opening could be the “hook” for a court or regulator to determine that the entire script is “telemarketing.”
The amended TSR expressly bars telemarketing calls that deliver prerecorded messages, unless a consumer previously has agreed to accept such calls from the seller.3 As a result, most businesses became required to obtain the consumer’s written permission before they could call a consumer with prerecorded telemarketing messages, or “robocalls”. In fact, a business has to make it clear it’s asking to call a consumer with these kinds of messages, and it can’t require a consumer to agree to the calls in order to get any goods or services. If the consumer initially agrees to receive robocalls, the consumer also retains the right to change his/her mind and rescind his/her opt-in.
The FTC takes enforcement of the TSR very seriously when it comes to robocall violators. A May 2013 FTC action resulted in a Department of Justice settlement4 resulting from an FTC-led complaint.5 Specifically, citing 16 C.F.R. § 310.4(b)(l )(v)(A), the Defendant company was permanently restrained and enjoined from engaging in, causing others to engage in, or assisting other persons to engage in:
A. Initiating any outbound telephone call that delivers a prerecorded message to induce the purchase of any good or service unless, prior to making any such call, the seller has obtained from the recipient of the call an express agreement, in writing, that:
1. the seller obtained only after a clear and conspicuous disclosure that the purpose of the agreement is to authorize the seller to place prerecorded calls to such person;
2. the seller obtained without requiring, directly or indirectly, that the agreement be executed as a condition of purchasing any good or service;
3. evidences the willingness of the recipient of the call to receive calls that deliver prerecorded messages by or on behalf of a specific seller; and
4. includes such person’s telephone number and signature.
The Defendant was ordered to undergo federal compliance monitoring, extensive recordkeeping and detailed reporting for 10 years. Additionally, the settlement included judgment in the amount of $75,000 entered in favor of the FTC against Defendant as a civil penalty. The Defendant’s judgment was far more lenient that the $16,000 per call that the FTC is authorized to assess under the TSR.
FCC Telephone Consumer Protection Act 2012 Amendments
The FCC administers the Telephone Consumer Protection Act (TCPA). In alignment with the FTC position, revised FCC TCPA rules took effect on October 16, 2013 and require “prior express written consent” for pre-recorded telemarketing calls using autodialer technology made to both cell phones and land line phones. This rule change expressly amends the previous FCC rule which (1) had not required written consent; and (2) had allowed prerecorded telemarketing calls to land line phones where a business relationship existed.
The FCC has taken a very broad view of the use of autodialer technology. Although the rules provide a very specific definition of autodialer, regulators and the courts have interpreted the definition so broadly that any computerized dialing device could be viewed as an autodialer. It is advisable not to make non-consented calls to cellphones, unless your organization has an entirely manual process for initiating the call.
Misuse or misunderstanding the use of autodialer technology in the absence of receiving prior express written consent has expensive consequences. The TCPA has a private right of action and recent class action lawsuits have settled for tens of millions of dollars.6
Costly non-compliance
Non-compliance with the TSR and the TCPA exposes your organization to civil liability and regulatory sanctions and fines. At up to $1,500 per violation, non-compliance with the TCPA text message requirements alone could expose your organization to a sizeable civil judgment. A company that sends a mere 7,000 non-consented text messages could statutorily incur a fine in excess of ten million dollars.
This TCPA text message revision is anticipated to also invite predatory class action litigation as enterprising plaintiff attorneys seek to capitalize on the technical change to the law. Regulatory penalties and class action lawsuits give rise to negative publicity that have the potential to damage your organization’s profitability and its brand.
Build compliance into your outbound calling and texting programs
To address this potential reputational, regulatory, and legal risk exposure, compliance professionals should partner with the stakeholders in the organization who have a vested interest in outbound calling and texting programs. These stakeholder functions will likely include Sales, Marketing, E-Commerce, Call Centers, and Information Technology (yes, IT! They own the autodialer and messaging hardware and software your organization relies upon). And don’t forget those third-party service providers that may actually be managing your call lists, opt-ins, and outbound calling and texting programs.
Once you have marshaled your stakeholders, you will want to undertake:
(1) a review of existing outbound calling and texting programs, approval processes, and vendor contracts; and
(2) provide detailed guidance to management regarding required current changes and safeguards for current and future programs.
You will specifically want to address pre-recorded messages sent to both land line and cellular phones, as well as text messages sent to cellular phones.
Compliant pre-recorded messages
Your organization may call consumers who have provided written permission after being fully informed that they have expressly assented to receive prerecorded calls regarding your products and services. If your organization has not obtained such “prior express written consent” since October 16, 2013, you will want to solicit a revised affirmative written opt-in. Guidance interpreting the amended TCPA treatment of prerecorded calls suggests that a consumer must have the option to affirmatively check an unchecked box beside verbiage that explicitly and plainly explains that the consumer is opting into receiving prerecorded calls to his/her cell phone and/or land line phone.
A prerecorded message system must also adhere to the following opt-out language and activation safeguards:
• Businesses using robocalls are required by law to tell a consumer at the beginning of the message how to stop future calls, and must provide an automated opt-out the consumer can activate by voice or key press throughout the call.
• If the message could be left on voicemail or an answering machine, businesses also have to provide a toll-free number at the beginning of the message that will connect to an automated opt-out system the consumer can use any time.
Compliant text/SMS messages
Changes to existing text message marketing opt-in processes may be required at your organization to conform to the new “prior express written consent” standard. Recognizing that text messages are limited in character length, these changes should be customized for your purposes, but may resemble:
• New text/SMS enrollee receives: “Reply ‘AGREE’ to receive wkly XYZ Discount Alerts. Periodic msgs may be sent using autodialer. Consent not required for purchase. Msg&Data rates may apply” (to fulfill the FCC requirement of obtaining express written consent after the initial request is received AND that his/her consent is not required in conjunction with any other purchase)
• Once the consumer replies with ‘AGREE’, enrollee receives: “Thanks for confirming! You will receive weekly XYZ Discount Alerts! Stop reply ‘STOP XYZ’. Msg&Data rates may apply.” (to fulfill the FCC requirement of explicitly informing the requestor how he/she may rescind the opt-in)
Obtain new consent from current text/SMS subscribers
Your organization may currently have thousands (or hundreds of thousands) of subscribers. When the new rules took effect on October 16, 2013, all consent obtained under the old “prior express consent” standard were invalidated. When the FCC issued its revised rules in February 2012, the agency conveyed that once the new written consent rules became effective, companies would be required to obtain the revised “prior express written consent” before sending additional marketing messages. An established business relationship will also no longer relieve advertisers of prior written consent requirement after the effective date. You may thus seek to ensure that all current subscribers also receive the message inviting them to reply ‘AGREE’.
New text/SMS message marketing programs
These same FCC principles would apply to new text marketing programs that your organization may launch in the future. The FCC interprets “marketing” very broadly in its own favor, so you will want to ensure that your Compliance Department is involved at inception to review new text messaging programs.
Conclusion
As compliance professionals, we must daily balance our organization’s customer-focused mission with the consumer protection regulatory requirements. By taking swift action with your stakeholders now regarding the TSR and TCPA, you can reduce the risk that your organization will make the wrong call.
Notes
1 The Telemarketing Sales Rule, September 2009, http://www.consumer.ftc.gov/articles/0198-telemarketing-sales-rule.
2 Ibid.
3 FTC Issues Final Telemarketing Sales Rule Amendments Regarding Prerecorded Calls, August 19, 2008, http://www.ftc.gov/opa/2008/08/tsr.shtm.
4 United States of America v. Skyy Consulting, Inc., also d/b/a CallFire, a California corporation, United States District Court, Northern District of California, San Francisco Division, Case4:13-cv-02136-DMR, Document 3, Filed 05/13/13, http://www.ftc.gov/os/caselist/1223011/130514callfirestip.pdf.
5 United States of America v. Skyy Consulting, Inc., also d/b/a CallFire, a California corporation, United States District Court, Northern District of California, San Francisco Division, Case4:13-cv-02136-DMR, Complaint, Filed 05/09/13, http://www.ftc.gov/os/caselist/1223011/130514callfirecmpt.pdf.
6 Pari Najafi v. SLM Corporation, et al., United States District Court for the Southern District of California, Case No. 10-cv-0530 MMAAmended Settlement Agreement, October 7, 2011, http://www.manatt.com/uploadedFiles/Content/4_News_and_Events/Newsletters/AdvertisingLaw@manatt/Sallie%20Mae%20amended%20settlement%20agreement.pdf.
Friday, October 11, 2013
WHEN ETHICS AND EXPEDIENCY COLLIDE
“It is the mark of an educated mind to be able to entertain a thought without accepting it.” ~Aristotle
“There are no easy answers' but there are simple answers. We must have the courage to do what we know is morally right.” ~Ronald Reagan
As Compliance and Ethics Professionals, we are daily reminded that violations of law and dignity are no less common now than they were in ancient civilizations. We report upon and read about corporate, government, and personal scandals that boggle the mind. Acts and omissions that defy common sense are nonetheless undertaken out of expediency, greed and ignorance, only to eventually expose the perpetrators in the public square.
Why?
Why--with all the failed historical examples, complex laws, regulatory bodies, education and training—do some organizations continue to succumb to poor judgment and wrongdoing, while other organizations rise above?
While we speak often about the ‘tone at the top’, we must also acknowledge that ideas and actions emanate at all levels of our organizations. Driven by deadlines, profits, corporate goals, marketplace competition, etc., individuals contemplate ideas and execute upon those ideas. But not all ideas for generating revenue, decreasing expenses, or streamlining processes merit the same consideration.
An organization’s culture, modeled by its leaders at all levels, must unambiguously communicate that execution must meet its values. A healthy exchange of ideas should always be weighed sufficiently and transparently by knowledgeable stakeholders, so as to expose potential ethical, legal and financial pitfalls. Though we are charged with educating our operational and administrative colleagues about our Code of Conduct and our Legal and Regulatory obligations, we have the additional obligation to actively counsel them as well.
Leveraging our Anonymous Reporting Hotlines, Internal Audit Departments, and industry and regulatory trends, we ourselves must be prepared to actively engage our colleagues across our organizations to probe for prospective lapses. In a highly-charged competitive environment, we cannot idly sit by and fail to question if expediency is trumping ethical decision-making. Let’s not forget that we are the protagonists—not the villains—in this story.
“There are no easy answers' but there are simple answers. We must have the courage to do what we know is morally right.” ~Ronald Reagan
As Compliance and Ethics Professionals, we are daily reminded that violations of law and dignity are no less common now than they were in ancient civilizations. We report upon and read about corporate, government, and personal scandals that boggle the mind. Acts and omissions that defy common sense are nonetheless undertaken out of expediency, greed and ignorance, only to eventually expose the perpetrators in the public square.
Why?
Why--with all the failed historical examples, complex laws, regulatory bodies, education and training—do some organizations continue to succumb to poor judgment and wrongdoing, while other organizations rise above?
While we speak often about the ‘tone at the top’, we must also acknowledge that ideas and actions emanate at all levels of our organizations. Driven by deadlines, profits, corporate goals, marketplace competition, etc., individuals contemplate ideas and execute upon those ideas. But not all ideas for generating revenue, decreasing expenses, or streamlining processes merit the same consideration.
An organization’s culture, modeled by its leaders at all levels, must unambiguously communicate that execution must meet its values. A healthy exchange of ideas should always be weighed sufficiently and transparently by knowledgeable stakeholders, so as to expose potential ethical, legal and financial pitfalls. Though we are charged with educating our operational and administrative colleagues about our Code of Conduct and our Legal and Regulatory obligations, we have the additional obligation to actively counsel them as well.
Leveraging our Anonymous Reporting Hotlines, Internal Audit Departments, and industry and regulatory trends, we ourselves must be prepared to actively engage our colleagues across our organizations to probe for prospective lapses. In a highly-charged competitive environment, we cannot idly sit by and fail to question if expediency is trumping ethical decision-making. Let’s not forget that we are the protagonists—not the villains—in this story.
Tuesday, July 30, 2013
BUILDING EFFECTIVE COMPLIANCE PROGRAMS: It Takes a Village
“No member of a crew is praised for the rugged individuality of his rowing” ~Ralph Waldo Emerson
“If everyone is moving forward together, then success takes care of itself” ~Henry Ford
I had recently been contacted by an individual who had been tapped by her organization to launch a corporate compliance program. My colleague approached me with that perennial question, “How did you build your program?...” I paused to consider my response.
Despite the mythology to which some may wish to subscribe, individuals don’t design, build or improve corporate compliance programs alone. While certainly individuals contribute significant leadership, ideas, and work product to a successful compliance program, it is truly the efforts of interconnected contributors that weaves the fabric of the program.
From scoping and documenting the program charter through defining and populating a comprehensive compliance risk universe, it takes a village of invested professionals to build the program. Since a compliance program likely encompasses several lines of business and diverse operating functions spread across multiple locations, personal interaction with a variety of leaders and staff is necessary to identify, quantify, and rank risks across an organization. I don’t know about you, but I certainly have experiential limitations regarding various functions outside my areas of expertise. Without those subject matter experts, my program would be neither comprehensive nor effective.
Thus, while it would have been terribly tempting to my ego to lead my fellow professional colorfully through an anecdotal reprisal of my rugged journey to locate the holy grail of corporate compliance on a lonely mountaintop, my better angels prevailed. “Katherine, I’d be pleased to share with you how we built our program, and the lessons we’ve learned…” And with that discussion, another member was added to the compliance program “village.”
Thursday, March 28, 2013
Enterprise Risk Management: Captain Kirk Confronts the Final Frontier
When faced with the regulatory mandate to incorporate or improve your organization's enterprise (or enterprise-wide) risk management (ERM) process, we can sometimes feel like a Klingon confronting Tribbles. To succeed with ERM within our organization, we must instead adopt the attitude expressed by Captain James Kirk in the'Day of the Dove episode: "There's another way to survive. Mutual trust...and help."
Several years ago, the federal banking regulators set off on a mission to bring Enterprise Risk Management (ERM) to the forefront of financial institution governance expectations. In the ensuing years, state insurance regulators have joined the mission through the National Association of Insurance Commissioners (NAIC) Own Risk and Solvency Assessment (ORSA) model act. The topic continues to get considerable attention in recent regulatory guidance, including Federal Reserve Board (FRB) supervisory letters 12-7 and 08-8. The Federal Reserve Bank of Chicago (FRB-C) devoted considerable attention to the topic at its 2011 conference.
What appeared to be a distant risk management galaxy in the late 1990s has certainly become an oft-discovered governance imperative for financial institutions. As a financial industry executive, you know that you have been charged with the responsibility “to boldly go where no man has gone before.” Much like the voyage of the storied U.S.S. Enterprise, your voyage has taken you to strange new worlds as you have sought to develop or improve your ERM model.
When you have set out to build a robust risk management infrastructure to integrate, coordinate and facilitate forward-looking risk management throughout the enterprise, you invariable have encountered (or will encounter) skeptics. Captain Kirk addressed this challenge in the 'A Private Little War' episode: "The only solution is...a balance of power. We arm our side with exactly that much more. A balance of power...the trickiest, most difficult, dirtiest game of them all. But the only one that preserves both sides."
But make no mistake about it—ERM is not optional and is here to stay. Thus, we often will find ourselves educating senior leadership colleagues and independent directors about ERM, in parallel with obtaining the necessary data to build, enhance, and report upon our ERM model. ERM cannot simply become a once-and-done exercise that ends up on a binder on your credenza.
Building a culture around ERM involves acclimating leadership throughout the organization to a continuous reporting system that identifies and addresses emerging risks. Strategic initiatives and ongoing business planning are evaluated in light of current and emerging risks and incorporated into analysis and leadership and board decision-making. ERM becomes a discussion item on at least a weekly basis within the leadership team, and a standing agenda item for your board, often through an ERM committee. Reports are designed to be condensed, accurate and meaningful for decision-making.
Internal Audit and Compliance play key roles in the ERM process. The periodic review and validation of the model through targeted risk assessments must be conducted under the direction of the organization’s senior leadership to support the organization’s risk appetite.
Occasionally, Captain Kirk and his officers would find themselves enmeshed in a scene from Earth's pre-space travel history, yet the episode always ended with our beloved travelers safely back aboard the U.S.S. Enterprise. As your ERM model and methodology evolve, it is likely that the organization will also never return by the way that it arrived, because external variables will continually infiltrate the ERM model. Most notably, your organization’s ERM will remain under the scrutiny and be subject to the recommendations of your prudential regulator. There simply is no going back.
Continue to be the evangelist for sound enterprise risk management in your organization, devoting yourself to encouraging, educating and embracing your colleagues as you faithfully fulfill the ERM governance role entrusted to you. Much like Kir, may you live long and prosper in your role.
Wednesday, March 6, 2013
Strength and Sustainability: Collaborative Compliance Amidst Complexity
I simply do not have all of the answers. There, I have said it.
My simple statement sums up the collective admission of Compliance, Audit and Ethics professionals globally. The annual proliferation of domestic and international regulatory requirements continues to proceed at an ever increasing rate. When only a decade or two ago, a chief compliance officer might likely have understood the details of all regulatory responsibilities within his/her realm, many of us have now grown accustomed to reliance upon specialized colleagues to identify the details of specific branches within our own compliance universe. At least two easily recognizable trends have led to this reality: global commerce and systemic failure.
Global commerce has both driven and benefited from technological and economic advances throughout history. Progressing beyond the steamships that replaced clipper ships, the internet built upon the initial success of the transoceanic cables laid long ago. While local trade rules and customs remain, the international Law of the Sea has been joined by International Free Trade Agreements and transcontinental legal structures, most notably the European Union, where supranational legal structures both supplant and co-exist with domestic laws and regulations.
Systemic failures that have led to financial crises within nations as diverse as Greece, Ireland, Japan and the United States have resulted in the now-familiar remedies of International Monetary Fund austerity measures, the Third Basel Accord, and Dodd-Frank Wall Street Reform and Consumer Protection Act, to name a few examples. Regulators have sought to eliminate pathways to fraud, largess and market manipulation widely blamed for the global crises by promulgating lengthy and complex regulatory solutions.
Compliance professionals who once may have laid claim to comprehending and administering compliance programs involving an entire continent or nation have succumbed to a level of regulatory complexity that makes such independent mastery incomprehensible. Even for those of us who oversee primarily domestic compliance programs, international influences are now omnipresent in Dodd-Frank, the Bank Secrecy Act, FCPA and the U.K. Bribery Act of 2010.
At the end of the day, Compliance, Audit and Ethics professionals are exactly that—professionals. We do not simply throw our hands up and decry the unfairness of increasingly complex regulatory requirements. True to our nature, we seek to understand as much as possible about our responsibilities to fulfill those compliance requirements in conjunction with our organization’s core mission and objectives. But our inquiries and information gathering must extend beyond our own individual knowledge and planning. Today’s increasingly complex regulatory environment requires us to collaborate with colleagues both within our organizations and beyond.
I would propose that now is the time to build stronger, more sustainable Compliance Programs through intelligent collaboration. It must not be viewed as a sign of ignorance or laziness when we humbly and actively partner with fellow Compliance, Audit and Ethics professionals to ascertain best practices. Likewise, we must continue to embrace the business line leaders within our own organizations to build collaborative compliance solutions that fulfill our regulatory responsibilities without unnecessarily impeding daily operations and long-term strategies.
Effective Regulatory Compliance…we may not each be able to do it alone, but we can certainly do it more constructively together.
Monday, August 29, 2011
DROP THE PRETENSE! (AND ACHIEVE THE OBJECTIVE)
"In dwelling, live close to the ground. In thinking, keep to the simple. In conflict, be fair and generous. In governing, don't try to control. In work, do what you enjoy..." ~Lao Tzu
"Authority is always built on service and sacrifice." ~James C. Hunter, The Servant
"This project would move along much more quickly if everyone assigned to the project actually wanted to be on the team," remarked a client at the outset of our recent meeting. I prodded her for additional detail.
"For instance," she continued, "while most of us arrive for the project meetings on time and prepared to focus upon the agenda, we have a few members who straggle in, phones still attached to their ears, wearing undisguised disdain for being burdened with having to attend the meeting. We are all managers and supervisors in our various areas, but for some reason it appears that these few believe that their position should exempt them from having to work on the project. When drawn into the discussion by the Project Leader, these few individuals deflect commitments or delay sharing needed data from their areas of responsibility. Worse, they sometimes become downright abrasive when pressed by others who are relying upon those commitments or data."
As my colleague Robert Whipple discusses in "Wag More, Bark Less", a barking dog is simply warning possible encroachers to steer clear of his territory. But almost nothing could be less desirable in the workplace than an environment of feared territorial encroachment. In the ever-increasing competitiveness for consumers in our industry, as Leaders and Team Members we must become more effective collaborators at cross-training, supporting one another's efforts and ultimately delivering the best products and services to fulfill our members'/customers' needs.
As a contracted Project Team Facilitator, I cannot afford myself the luxury of brandishing my title and authority or shirking my responsibilities to the Project Team or to the Organization. An effective Project Team requires that ALL members of the team--regardless of organizational title or number of employees reporting to them--must come to the Project Team as equals in responsibility. The Organization forms a Project Team for a sole purpose: To Achieve the Objective.
Perhaps your Organization is merging with another Organization; launching a new technology platform; rolling out a new loan product. At the end of the Project, regardless of the detail of the metrics, success will ultimately be measured by: Did We Achieve the Objective?
How do you ensure that individual pretense, self-importance, and other personal blindspots do not reduce your Project Team's effectiveness?
"Authority is always built on service and sacrifice." ~James C. Hunter, The Servant
"This project would move along much more quickly if everyone assigned to the project actually wanted to be on the team," remarked a client at the outset of our recent meeting. I prodded her for additional detail.
"For instance," she continued, "while most of us arrive for the project meetings on time and prepared to focus upon the agenda, we have a few members who straggle in, phones still attached to their ears, wearing undisguised disdain for being burdened with having to attend the meeting. We are all managers and supervisors in our various areas, but for some reason it appears that these few believe that their position should exempt them from having to work on the project. When drawn into the discussion by the Project Leader, these few individuals deflect commitments or delay sharing needed data from their areas of responsibility. Worse, they sometimes become downright abrasive when pressed by others who are relying upon those commitments or data."
As my colleague Robert Whipple discusses in "Wag More, Bark Less", a barking dog is simply warning possible encroachers to steer clear of his territory. But almost nothing could be less desirable in the workplace than an environment of feared territorial encroachment. In the ever-increasing competitiveness for consumers in our industry, as Leaders and Team Members we must become more effective collaborators at cross-training, supporting one another's efforts and ultimately delivering the best products and services to fulfill our members'/customers' needs.
As a contracted Project Team Facilitator, I cannot afford myself the luxury of brandishing my title and authority or shirking my responsibilities to the Project Team or to the Organization. An effective Project Team requires that ALL members of the team--regardless of organizational title or number of employees reporting to them--must come to the Project Team as equals in responsibility. The Organization forms a Project Team for a sole purpose: To Achieve the Objective.
Perhaps your Organization is merging with another Organization; launching a new technology platform; rolling out a new loan product. At the end of the Project, regardless of the detail of the metrics, success will ultimately be measured by: Did We Achieve the Objective?
How do you ensure that individual pretense, self-importance, and other personal blindspots do not reduce your Project Team's effectiveness?
- Early in the project (best: at the kick-off meeting), communicate the shared expectation to all assigned Team Members that you are coming together as a Team of equals, chosen for the respective strengths and expertise that each individual brings to the Project Team.
- If during the project life cycle certain individuals fail to fully engage or actively disassociate themselves from the shared responsibility to the Project Team, then politely but directly remind those individuals of the path between their participation/contribution and the successful achievement of the Project Objective.
- Follow up as necessary with offline one-on-one dialogue to uncover any additional reasons that the recalcitrant individual may have for failing to support his own shared responsbility to the Project Team.
- When personal responsibility and inherent professionalism fail to spur that individual to shoulder his responsibility to effectively achieve the Project Objective, you may then use additional Organizational leverage to the extent needed.
Subscribe to:
Posts (Atom)