Showing posts with label compliance. Show all posts
Showing posts with label compliance. Show all posts

Monday, April 7, 2014

Compliance & Ethics Guidance: “Require” or “Recommend”?

In our capacity as Compliance & Ethics professionals, we are invited daily by business line management to provide guidance on diverse topics. Because we are managing compliance and ethics across an entire organization, each topic must be reviewed with multiple internal stakeholder interests in mind. Externally, we are subject to scrutiny by our customers, our regulators, our industry, and the press. Thus, no review is undertaken in a theoretical vacuum, nor is any resulting guidance intended to provide a one-size-fits-all solution to all similarly-situated topics. Business line management doesn’t always understand those underpinnings when receiving guidance from us.

A frequent question heard by many C&E professionals upon delivering compliance guidance or an ethics opinion is, “So, is this a requirement…or merely a recommendation?” Management attaches very different treatment to our response to that question. Requirements may entail additional cost—whether an opportunity cost of a forgone initiative or a hard cost like implementing additional information system controls. Recommendations may at first blush appear to be optional activities that can be ignored and forgotten. The seasoned C&E professional knows that she must not leave management with any ambiguity about the risks of alternative future courses of action. We only add value to our organizations when we can achieve alignment between management’s risk appetites and our own governance, risk management and control frameworks.

A little confession here…at the onset of my career as an internal auditor, I wrote my recommendations as if they were self-evident edicts born of a brilliant mind. Fortunately I was also paired with managers and mentors who were equipped to deliver humbling learning opportunities to me, for which I have been ever grateful. Those formative leaders challenged me to support my assertions with specific corporate policies, statutes, or regulations. If my assertion was one supported by a matter less well-defined, such as fair trade practices or a matter of public policy, then I was urged to develop recommendations that objectively balanced the strategic interests of the business with the external interests, so as to allow management to make fully-informed decisions. These distinctions served me well. Perhaps you can relate to this transformation from your own career path.

Today I continue to improve my craft. I take great care in drafting compliance memoranda and ethics opinions that ensure well-substantiated transparency. I employ the word “require” when I seek to guide management away from the expedient pitfalls that ultimately lead to reputational loss, fines, lawsuits, or jail time for corporate officers. I employ the word “recommend” when I seek to guide management toward actions that will improve the customer experience; enhance the value of the brand; or reduce aggregate regulatory risk. To overuse “require” when “recommend” would suffice is to invite the “Chicken Little” effect and diminish Compliance & Ethics’ effectiveness. To overuse “recommend” when “require” is truly appropriate is to dilute our own integrity as C&E professionals and ignore our fiduciary duty to our organizations.


As such, when providing compliance and ethics guidance to management, I recommend (but not require) that we choose our words purposefully and substantiate objectively.

Wednesday, March 12, 2014

Your Brother’s Keeper: the OCC & Third-Party Mortgage Vendor Relationships

Background

Nationally-chartered federal savings banks are subject to the prudential regulation of the Office of the Comptroller of the Currency (the “OCC”). National banks may engage in activities that are part of, or incidental to, the business of banking, or are otherwise authorized for a national bank. The business of banking is an evolving concept and the permissible activities of national banks similarly evolve over time.1 But when your bank’s senior management decides to outsource a critical function—especially a consumer-facing function like mortgage loan origination or servicing—you truly become your “brother’s keeper.” No Chief Executive Officer or Chief Compliance Officer wishes to find himself or herself targeted by the OCC for failure to conduct adequate third-party vendor due diligence or ongoing monitoring.

It had been historically understood that when employing third-party entities to conduct all or part of a critical banking function, by not fully understanding the nature of the risks being introduced to the bank and by not ensuring appropriate risk controls, senior management and boards of directors breach their most fundamental fiduciary responsibility to depositors and shareholders.2 The Federal Financial Institutions Examination Council (the “FFIEC”) very aptly highlights that although the technology needed to support business objectives is often a critical factor in deciding to outsource, managing such relationships is more than just a technology issue; it is an enterprise-wide corporate management issue.3

Long-standing OCC guidance

A national bank and its operating subsidiaries may make, purchase, sell, service, or warehouse house loans or other extensions of credit for its own or another’s account, including residential mortgage loans.4 A bank may conduct its mortgage operations in conjunction with a third-party not owned by the bank or bank holding company. Vendors, brokers, dealers, and agents can offer banks a variety of legitimate and safe opportunities to enhance product offerings, improve earnings, diversify assets and revenues, or reduce costs. In most instances the fundamental risks associated with activities introduced by third parties are no greater or less than the bank would have incurred had the bank performed the activity on its own.5

Historically, the OCC had very explicitly decreed that bank management cannot rely solely on third-party assertions, representations, or warranties when entering such relationships.6 Specifically, the OCC has long required that:

  • Before entering into a major relationship with a third party, a bank should establish a comprehensive program for managing the relationship.
  • Such programs should be documented and include front-end management planning, appropriate due diligence selecting a vendor, and performance monitoring.7

The requirements above were not merely satisfied by a bank relying solely upon its own internal Vendor Management Policy. The OCC expressly contemplated that the bank’s negotiators and signatories to the vendor contract would tailor the program to the specific vendor, and that the documentation would reflect the criteria and validation specific to that vendor with regard to the services for which the bank sought to contract.

OCC activity in the wake of Bulletin 2013-29

OCC treatment of third-party vendor risk management was recently further clarified when the agency issued Bulletin 2013-29: Third-Party Relationships - Risk Management Guidance on October 30, 2013.8  Among the OCC’s explicit guidance, the Agency deemed that an effective risk management process throughout the life cycle of the relationship includes:
·     plans that outline the bank’s strategy, identify the inherent risks of the activity, and detail how the bank selects, assesses, and oversees the third party;
·         proper due diligence in selecting a third party;
·         written contracts that outline the rights and responsibilities of all parties;
·         ongoing monitoring of the third party’s activities and performance;
·         contingency plans for terminating the relationship in an effective manner;
·       clear roles and responsibilities for overseeing and managing the relationship and risk management process;
·        documentation and reporting that facilitates oversight, accountability, monitoring, and risk management; and
·   independent reviews that allow bank management to determine that the bank’s process aligns with its strategy and effectively manages risks.

The OCC has wasted no time applying those third-party risk management principles immediately before and since the issuance of Bulletin 2013-29. On September 19, 2013, the OCC assessed a $60 million penalty against JPMorgan Chase and ordered the bank to reimburse consumers for unfair billing practices.9 In the JPMorgan Chase matter, the OCC order also requires the bank to take a number of corrective measures that include:
·         ensuring compliance with the FTC Act;
·   improving governance of third-party vendors associated with certain consumer products;
·    developing an enterprise-wide risk management program for such consumer products marketed or sold by the bank or its vendors; and
·         improving its consumer compliance internal audit program.

American Express Bank received an early Christmas present, when the OCC announced on December 24, 2013 that it would assess a $3 million penalty against the bank and order restitution to customers for unfair billing and deceptive marketing practices.10 The OCC order, whose restitution payments also satisfied related Consumer Financial Protection Bureau (CFPB) obligations, requires the bank to:
·  improve governance of third-party vendors associated with “add-on” consumer products;
·     develop a risk management program for “add-on” consumer products marketed or sold by the bank or its vendors; and
·    conduct an “add-on” product review to, among other things, identify and remediate consumer harm and any program weaknesses.

The OCC has clearly communicated that it intends to aggressively protect consumers from harmful activities resulting from a bank’s use of third-party vendors, and that it will hold a bank fully responsible for that third party’s missteps.

Critical Attention to Pre-Contractual Due Diligence

Every activity undertaken by bank management and its agents should accord with OCC requirements, and support subsequent examination by the OCC, the internal audit function, and external auditors. The contemplation of a significant third-party business relationship that contributes directly to a bank’s growth plan should be disclosed in sufficient detail by bank management to the bank’s board of directors to facilitate the board’s fiduciary responsibility. Negotiators of a third-party business relationship (inclusive of bank management, holding company management, and legal counsel) are in the best position to review, inquire, and edit contract provisions accordingly prior to execution to ensure that all contract provisions directly address OCC compliance requirements, including those relating directly to third-party risk and due diligence.

With reliance upon bank management and its agents who engage directly in the planning, negotiation, and execution of the third-party agreement, one should reasonably be able to conclude that those parties have conducted their activities in accordance with OCC Bulletin 2013-29.11 In advance of executing an agreement, bank management and its agents would have engaged in and fully documented both management planning and due diligence in selecting a vendor. The agreement would further have documented the ongoing performance monitoring required to evaluate the ongoing vendor risk management posture. To have failed to faithfully adhere to the details of the Bulletin by simply relying upon professional relationships or contractual representations and warranties would be both imprudent and discordant with explicit OCC guidance.

Ongoing Risk Assessment and Improved Governance

If a CEO or CCO had not been involved in contract negotiations with a third-party vendor, then that leader may not be able to independently confirm whether or not bank management and its agents adhered to OCC requirements during the pre-contractual due diligence period. Once that leader becomes aware that such a gap may have occurred, it becomes incumbent upon that leader to undertake an independent risk assessment of the third-party vendor relationship. This obligation becomes critically important when the third-party vendor is providing consumer mortgage loan services.

The auditors assigned to conduct the independent third-party risk management review should be able to request, obtain and evaluate pre-contractual documentation, and supplement their initial conclusions with interviews with the individuals directly engaged in the planning, negotiation, and execution of the third-party vendor agreement. As with any audit, should the auditors identify exceptions to the OCC’s third-party risk management guidelines that present a material risk of non-compliance or future financial loss, then in accordance with the Chief Audit Executive, you would advise that bank management and the bank board be so advised that subsequent remedial measures be undertaken.

Conclusion

It is evident that the OCC expects governance, risk management, and controls (GRC) to be in place prior to and at the inception of third-party mortgage vendor relationships. Even as bank management remediates the existing relationship with a consumer mortgage vendor, all stakeholders should take note of the lessons learned from a less-than-thorough due diligence; explicit contractual role definition; and contractual provisions for detailed oversight, accountability, and monitoring. Future third-party vendor relationships must incorporate those onboarding elements as standard requirements of a larger enterprise-wide risk management process, lest the OCC surmise that your bank’s governance practices are insufficient to take heed of Bulletin 2013-29.


References





5      Third-Party Risk, August 29, 2000. (Subsequently rescinded by OCC Bulletin 2013-29)

6      Ibid.






Monday, February 17, 2014

When Crisis Erupts: Surmount or Surrender?

“The easiest period in a crisis situation is actually the battle itself.
The most difficult is the period of indecision -- whether to fight or run away.
And the most dangerous period is the aftermath.
It is then, with all his resources spent and his guard down, that an individual must watch out for dulled reactions and faulty judgment.”  
~Richard M. Nixon, 37th President of the United States

As a Chief Compliance & Ethics Officer, you know that the eventuality of crisis striking your organization is not a matter of “if”, but only of “when.” You spend your career crafting and implementing a governance system of policies & procedures, training, monitoring, and reporting whose value will ultimately be assessed in those moments and days following the crisis. Not all systems (nor all leaders) will survive the test.

Crisis will not politely schedule an appointment with you on a lazy afternoon, but will more likely descend upon you furiously, publicly and embarrassingly at the most inopportune of moments. Crisis will arrive in the guise of a viral tweet, a regulatory inquiry, or a criminal indictment. A loyal staffer will hesitantly summon you from a meeting into the hallway to advise you of the breaking news. And so begins the moment of decision.

As Compliance leaders we have trained our entire lives to guide and protect our organizations from harm. The very same principles that we have employed to prevent and mitigate risk will come into play when we must navigate our organization, its leadership and its board through and beyond the crisis. Decisive action that engenders trust must remain at the forefront of the response.

Thus, together we must continue to:

  •        Act ethically and decisively;
  •          Communicate frequently and transparently; and
  •          Modify practices appropriately.
Act ethically and decisively

Crisis does not represent your organization in its entirety. Your mission, your values, and your people remain fundamentally sound, even when something has gone awry. Therefore, even as you and your leadership team are undertaking an investigation and crafting a response to the statement, incident, or charge, you will continue to direct your employees to perform their day-to-day responsibilities with the accustomed level of adherence to ethics, compliance, and mission-focus. Your organization will survive the crisis, and so the continued service to your employees, clients, customers, vendors and shareholders must remain highly-functioning.

Communicate frequently and transparently

Do not compound the temporary negative impact of a crisis by shrouding the crisis in a cloak of shame and secrecy. While not proud of the event that has triggered the crisis, you remain nonetheless committed to your employees, your customers, your brand, and your mission-focus for the long run. Within that long view context, communicate quickly that leadership is:

·         aware of the situation;
·         taking it seriously;
·         cooperating fully; and
·         is committed to resolving it.

Convey that future communications will follow as additional information becomes available, and adhere to that pattern, even if only limited information becomes available. Your stakeholders are better served by hearing the truth from you, than the mistrust that will take root if they begin to receive their information—accurate or misconstrued--from external sources.


Modify practices appropriately

While some crises will end with a conclusion that the crisis was merely malicious and unwarranted, often the investigation will reveal a compliance or control weakness that must be addressed by your organization. Once identified, own both the root cause and the solution, communicating the same to your stakeholders. Then set to work implementing the required changes that will ensure the situation has been appropriately addressed. If additional training is warranted, then make every effort to involve the affected employees in designing and testing the training before it is rolled out to the larger audience. Schedule subsequent time to review the modified practice and test its effectiveness, regardless of whether required to do so by a regulatory body or not.

***
Crisis will erupt. You will be called upon to act in the best interest of your organization and its stakeholders. If you have prepared yourself, your leadership team, and your board in advance of this moment, then you will pilot your organization to a brighter tomorrow with the flag flying high. Otherwise, armed only with dulled reactions and faulty judgment, you will find yourself waving the flag of surrender.

Monday, January 6, 2014

Ethical Business Conduct: Context Makes a Difference

"There’s a big difference between what you have a right to do and what is right to do." ~ Potter Stewart, former U.S. Supreme Court Justice

“If everyone is thinking alike, then somebody isn't thinking.” ~ George S. Patton, former U.S. General


In this day and age, it is an increasingly popular sentiment for organizations to describe their workforce as entrepreneurial and empowered. Genuine engagement of today’s employees is a hallmark of the knowledge worker economy, and has led to continued innovation and heightened productivity. In conjunction with the advances made in employee engagement, many organizations have reduced layers of complexity and bureaucracy, and in some cases have even removed offices and walls to encourage greater collaboration between teams. Do not lose sight of the truth that roles and authority—whether explicit or implicit—continue to exist within these organizations.

Amidst this seemingly egalitarian shift in the workplace, organizations continue to implement and improve governance over ethical business conduct. Codes of Conduct flourish as more organizations recognize the real benefits, both tangible and intangible, or providing written guidance supported by training and modeled by leaders at all levels. While well-written Codes detail and illustrate appropriate business conduct guidelines and many prohibitions, these Codes do not seek to define every action for every situation. More importantly, Codes cannot be regarded in isolation of other pertinent organizational guidance and leadership structures.

The Code of Conduct should be drafted so as to apply to all levels of employees within an organization. The CEO is no less subject to conducting her business affairs in an ethical manner than is the mid-level manager or line staff. All employees should adhere to business principles that support the legal and ethical attainment of the organization’s mission. But the authority, opportunity, and tools available to senior leaders and other employees within an organization may very well differ pursuant to board approval, corporate policy, or culture.

For example, a publicly-traded company remains committed to increasing shareholder value. While the senior leadership of that company focus upon profitable long-term strategy, and salespeople focus upon generating daily and monthly revenue, both groups’ actions should align with the best interests of the shareholders. To fail to act in the shareholders’ best interests would represent an unethical (and possibly illegal) breach of duty. That being said, the day-to-day roles and authority levels of the senior leadership differ from those of the salespeople and other employees.

One area where this difference may be illustrated is in the authority to enter into contracts that bind the company. A senior level executive may have been granted authority under corporate policy to negotiate and execute large-dollar multi-year contracts with external vendors, likely with additional internal controls in place. In contrast, a salesperson may have been granted authority under corporate or departmental policy to accept orders from customers, subject to additional internal review and approvals. Both groups, acting on behalf of the company and in the company’s best interest, have been granted contractual authority, but subject to different financial thresholds and internal controls.

Thus, were the salesperson to seek to negotiate and execute a contract with an external vendor in this scenario, he would have committed a breach of corporate policy, and likely the Code of Conduct. A senior level executive, though generally not engaged in sales to customers, might not be similarly constrained from accepting a customer order.

Codes of Conduct and corporate policies serve to educate and guide employees at all levels of an organization. While Codes and policies should provide clear guidelines, especially with regard to prohibited conduct, employees must recognize that excerpts of such documents should not be read in isolation or taken out of context when evaluating business conduct. The context—including role, implicit and explicit authorization, and culture—do provide a backdrop against which all business conduct must also be ethically evaluated. Every employee has the duty to act ethically; not every employee has the authority to engage in all actions. Thus, context does make a difference when it comes to interpreting your Code of Conduct and corporate policies.

Tuesday, November 5, 2013

Regulatory Compliance: Tear Down That Ivory Tower!

I recently ran into a Compliance colleague, “Jill”, whom I hadn’t seen in a while. As we exchanged pleasantries, Jill explained how busy she has been at her organization, to a point where she “couldn’t even get out of her office for lunch most days.” I understood her sentiment, but I challenged Jill’s premise that her most effective oversight of her Compliance Management Program was being accomplished sitting at her desk with her nose to the proverbial grindstone.

“What do you mean?”, Jill inquired.

“For starters, how are you assessing the compliance culture within and across your organization?”, I responded. I waited for the predictable response.

“I receive reports from each department head on a quarterly basis. I meet with those same department heads at least annually as we update our risk assessment. “ And then she punctuated her response, “I always know what is going on from a Compliance perspective.”

We visited for a few more minutes before continuing on our respective journeys. I have the utmost respect for Jill, and the many colleagues with whom I’ve engaged in similar conversations over the years. But I was reminded again that day that differing viewpoints pervade our Compliance Management profession.

I liken the practice of our craft to that of a world traveler. In fact, given the international nature of Regulatory Compliance, many of us have become world travelers from time to time. But one cannot truly experience traveling the world by reading other people’s written accounts of foreign lands. Similarly, Compliance professionals cannot simply read stacks of reports, formally engage depart heads once or twice annually, and conclude that they have traveled the organizational “globe”.

We’ve got to come down out of our ivory towers. In fact, we’ve got to tear down our ivory towers in the Compliance Department and never return to our old ways. Instead, let’s engage leaders at all levels across our organizations as often as possible. Informal dialogue that may occur within the context of a scheduled project meeting, or a chance meeting in the hallway, can often generate useful information that lends itself well to a holistic risk assessment.

Leaders want to tell you what concerns they are facing, and when those concerns signal regulatory compliance exposure, you have an opportunity to collaborate further toward a resolution. Internal Audit provides another natural source of regulatory compliance risk data gleaned from its expansive reach throughout your organization. Regulatory Compliance also finds a natural ally in the Information Technology Department, where governance, risk management and compliance looms large over an ever-evolving landscape. Compliance professionals grow to become trusted confederates with leaders of lines of business, Internal Audit and Information Technology.

So join me! Grab your water bottle or coffee cup, and explore your organization more freely. Engage others daily and take a more genuine interest in the regulatory compliance challenges facing your fellow leaders. Collaborate with them to develop lasting compliance solutions. Your risk assessments and resultant regulatory compliance program will flourish, producing more meaningful results for the entire organization. You won’t want to return to the ivory tower.

Thursday, October 17, 2013

Don’t make the wrong call!

Ensuring compliance with the Telemarketing Sales Rule (TSR) and Telephone Consumers Protection Act (TCPA)

* The FTC has long blazed a trail of consumer protection aimed at unscrupulous telemarketers.
* The FCC has strengthened its arsenal of weapons aimed at robocallers.
* Failure to incorporate the 2013 requirements can cost your company millions of dollars.
* Compliance Departments must engage all stakeholders in the organization.
* Building a compliant outbound calling & texting program will protect profits and the brand.



No longer can any sales and service organization naively believe that it will escape the notice of United States federal consumer protection regulators. If your organization uses a telephone to reach consumers, then the Federal Trade Commission (FTC) and the Federal Communications Commission (FCC) are two such agencies for which regulatory compliance professionals must maintain a watchful eye.

In conjunction with the robust outbound communication activities that our sales and service operations undertake, careless violations of FTC and FCC consumer communications laws garner sizeable financial penalties. To understand the impact of the October 2013 FCC amendments, it is helpful to review the FTC’s Telemarketing Sales Rule requirements.

FTC Telemarketing Sales Rule 2008 Amendments

The FTC administers the Telemarketing Sales Rule (TSR). Amended in 2008, the TSR governs outbound telephone calls initiated by a telemarketer, including those involving dialing technology (“autodialers”) and pre-recorded messages. As defined by the FTC:

• “Outbound telephone call” to mean a telephone call initiated by a telemarketer to induce the purchase of goods or services or to solicit a charitable contribution;
• “Telemarketer” means any person who, in connection with telemarketing, initiates or receives telephone calls to or from a customer or donor; and
• “Telemarketing” means a plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call.1

Some prerecorded messages still are permitted under these rules — for example, messages that are purely informational. That means a consumer may still receive calls to let him/her know a flight’s been cancelled, reminders about an appointment or messages about a delayed school opening. But the business doing the calling still isn’t allowed to promote the sale of any goods or services. Political calls, calls from certain healthcare providers and messages from a business contacting a consumer to collect a debt also are permitted. Prerecorded messages from banks, telephone carriers and charities also are exempt from these rules if the banks, carriers or charities make the calls themselves.2

While notifying consumers of a store address change is considered informational (thus not telemarketing), inviting them to a grand opening celebration at the new address could be considered part of a “plan, program or campaign” to induce the purchase of goods or services. That is, merely mentioning the grand opening could be the “hook” for a court or regulator to determine that the entire script is “telemarketing.”

The amended TSR expressly bars telemarketing calls that deliver prerecorded messages, unless a consumer previously has agreed to accept such calls from the seller.3 As a result, most businesses became required to obtain the consumer’s written permission before they could call a consumer with prerecorded telemarketing messages, or “robocalls”. In fact, a business has to make it clear it’s asking to call a consumer with these kinds of messages, and it can’t require a consumer to agree to the calls in order to get any goods or services. If the consumer initially agrees to receive robocalls, the consumer also retains the right to change his/her mind and rescind his/her opt-in.

The FTC takes enforcement of the TSR very seriously when it comes to robocall violators. A May 2013 FTC action resulted in a Department of Justice settlement4 resulting from an FTC-led complaint.5 Specifically, citing 16 C.F.R. § 310.4(b)(l )(v)(A), the Defendant company was permanently restrained and enjoined from engaging in, causing others to engage in, or assisting other persons to engage in:

A. Initiating any outbound telephone call that delivers a prerecorded message to induce the purchase of any good or service unless, prior to making any such call, the seller has obtained from the recipient of the call an express agreement, in writing, that:
1. the seller obtained only after a clear and conspicuous disclosure that the purpose of the agreement is to authorize the seller to place prerecorded calls to such person;
2. the seller obtained without requiring, directly or indirectly, that the agreement be executed as a condition of purchasing any good or service;
3. evidences the willingness of the recipient of the call to receive calls that deliver prerecorded messages by or on behalf of a specific seller; and
4. includes such person’s telephone number and signature.

The Defendant was ordered to undergo federal compliance monitoring, extensive recordkeeping and detailed reporting for 10 years. Additionally, the settlement included judgment in the amount of $75,000 entered in favor of the FTC against Defendant as a civil penalty. The Defendant’s judgment was far more lenient that the $16,000 per call that the FTC is authorized to assess under the TSR.

FCC Telephone Consumer Protection Act 2012 Amendments

The FCC administers the Telephone Consumer Protection Act (TCPA). In alignment with the FTC position, revised FCC TCPA rules took effect on October 16, 2013 and require “prior express written consent” for pre-recorded telemarketing calls using autodialer technology made to both cell phones and land line phones. This rule change expressly amends the previous FCC rule which (1) had not required written consent; and (2) had allowed prerecorded telemarketing calls to land line phones where a business relationship existed.

The FCC has taken a very broad view of the use of autodialer technology. Although the rules provide a very specific definition of autodialer, regulators and the courts have interpreted the definition so broadly that any computerized dialing device could be viewed as an autodialer. It is advisable not to make non-consented calls to cellphones, unless your organization has an entirely manual process for initiating the call.

Misuse or misunderstanding the use of autodialer technology in the absence of receiving prior express written consent has expensive consequences. The TCPA has a private right of action and recent class action lawsuits have settled for tens of millions of dollars.6

Costly non-compliance

Non-compliance with the TSR and the TCPA exposes your organization to civil liability and regulatory sanctions and fines. At up to $1,500 per violation, non-compliance with the TCPA text message requirements alone could expose your organization to a sizeable civil judgment. A company that sends a mere 7,000 non-consented text messages could statutorily incur a fine in excess of ten million dollars.

This TCPA text message revision is anticipated to also invite predatory class action litigation as enterprising plaintiff attorneys seek to capitalize on the technical change to the law. Regulatory penalties and class action lawsuits give rise to negative publicity that have the potential to damage your organization’s profitability and its brand.

Build compliance into your outbound calling and texting programs

To address this potential reputational, regulatory, and legal risk exposure, compliance professionals should partner with the stakeholders in the organization who have a vested interest in outbound calling and texting programs. These stakeholder functions will likely include Sales, Marketing, E-Commerce, Call Centers, and Information Technology (yes, IT! They own the autodialer and messaging hardware and software your organization relies upon). And don’t forget those third-party service providers that may actually be managing your call lists, opt-ins, and outbound calling and texting programs.

Once you have marshaled your stakeholders, you will want to undertake:

(1) a review of existing outbound calling and texting programs, approval processes, and vendor contracts; and
(2) provide detailed guidance to management regarding required current changes and safeguards for current and future programs.

You will specifically want to address pre-recorded messages sent to both land line and cellular phones, as well as text messages sent to cellular phones.

Compliant pre-recorded messages

Your organization may call consumers who have provided written permission after being fully informed that they have expressly assented to receive prerecorded calls regarding your products and services. If your organization has not obtained such “prior express written consent” since October 16, 2013, you will want to solicit a revised affirmative written opt-in. Guidance interpreting the amended TCPA treatment of prerecorded calls suggests that a consumer must have the option to affirmatively check an unchecked box beside verbiage that explicitly and plainly explains that the consumer is opting into receiving prerecorded calls to his/her cell phone and/or land line phone.

A prerecorded message system must also adhere to the following opt-out language and activation safeguards:

• Businesses using robocalls are required by law to tell a consumer at the beginning of the message how to stop future calls, and must provide an automated opt-out the consumer can activate by voice or key press throughout the call.
• If the message could be left on voicemail or an answering machine, businesses also have to provide a toll-free number at the beginning of the message that will connect to an automated opt-out system the consumer can use any time.

Compliant text/SMS messages

Changes to existing text message marketing opt-in processes may be required at your organization to conform to the new “prior express written consent” standard. Recognizing that text messages are limited in character length, these changes should be customized for your purposes, but may resemble:

• New text/SMS enrollee receives: “Reply ‘AGREE’ to receive wkly XYZ Discount Alerts. Periodic msgs may be sent using autodialer. Consent not required for purchase. Msg&Data rates may apply” (to fulfill the FCC requirement of obtaining express written consent after the initial request is received AND that his/her consent is not required in conjunction with any other purchase)

• Once the consumer replies with ‘AGREE’, enrollee receives: “Thanks for confirming! You will receive weekly XYZ Discount Alerts! Stop reply ‘STOP XYZ’. Msg&Data rates may apply.” (to fulfill the FCC requirement of explicitly informing the requestor how he/she may rescind the opt-in)

Obtain new consent from current text/SMS subscribers

Your organization may currently have thousands (or hundreds of thousands) of subscribers. When the new rules took effect on October 16, 2013, all consent obtained under the old “prior express consent” standard were invalidated. When the FCC issued its revised rules in February 2012, the agency conveyed that once the new written consent rules became effective, companies would be required to obtain the revised “prior express written consent” before sending additional marketing messages. An established business relationship will also no longer relieve advertisers of prior written consent requirement after the effective date. You may thus seek to ensure that all current subscribers also receive the message inviting them to reply ‘AGREE’.

New text/SMS message marketing programs

These same FCC principles would apply to new text marketing programs that your organization may launch in the future. The FCC interprets “marketing” very broadly in its own favor, so you will want to ensure that your Compliance Department is involved at inception to review new text messaging programs.

Conclusion

As compliance professionals, we must daily balance our organization’s customer-focused mission with the consumer protection regulatory requirements. By taking swift action with your stakeholders now regarding the TSR and TCPA, you can reduce the risk that your organization will make the wrong call.

Notes

1 The Telemarketing Sales Rule, September 2009, http://www.consumer.ftc.gov/articles/0198-telemarketing-sales-rule.

2 Ibid.

3 FTC Issues Final Telemarketing Sales Rule Amendments Regarding Prerecorded Calls, August 19, 2008, http://www.ftc.gov/opa/2008/08/tsr.shtm.

4 United States of America v. Skyy Consulting, Inc., also d/b/a CallFire, a California corporation, United States District Court, Northern District of California, San Francisco Division, Case4:13-cv-02136-DMR, Document 3, Filed 05/13/13, http://www.ftc.gov/os/caselist/1223011/130514callfirestip.pdf.

5 United States of America v. Skyy Consulting, Inc., also d/b/a CallFire, a California corporation, United States District Court, Northern District of California, San Francisco Division, Case4:13-cv-02136-DMR, Complaint, Filed 05/09/13, http://www.ftc.gov/os/caselist/1223011/130514callfirecmpt.pdf.

6 Pari Najafi v. SLM Corporation, et al., United States District Court for the Southern District of California, Case No. 10-cv-0530 MMAAmended Settlement Agreement, October 7, 2011, http://www.manatt.com/uploadedFiles/Content/4_News_and_Events/Newsletters/AdvertisingLaw@manatt/Sallie%20Mae%20amended%20settlement%20agreement.pdf.

Friday, October 11, 2013

WHEN ETHICS AND EXPEDIENCY COLLIDE

“It is the mark of an educated mind to be able to entertain a thought without accepting it.” ~Aristotle

“There are no easy answers' but there are simple answers. We must have the courage to do what we know is morally right.” ~Ronald Reagan


As Compliance and Ethics Professionals, we are daily reminded that violations of law and dignity are no less common now than they were in ancient civilizations. We report upon and read about corporate, government, and personal scandals that boggle the mind. Acts and omissions that defy common sense are nonetheless undertaken out of expediency, greed and ignorance, only to eventually expose the perpetrators in the public square.

Why?

Why--with all the failed historical examples, complex laws, regulatory bodies, education and training—do some organizations continue to succumb to poor judgment and wrongdoing, while other organizations rise above?

While we speak often about the ‘tone at the top’, we must also acknowledge that ideas and actions emanate at all levels of our organizations. Driven by deadlines, profits, corporate goals, marketplace competition, etc., individuals contemplate ideas and execute upon those ideas. But not all ideas for generating revenue, decreasing expenses, or streamlining processes merit the same consideration.

An organization’s culture, modeled by its leaders at all levels, must unambiguously communicate that execution must meet its values. A healthy exchange of ideas should always be weighed sufficiently and transparently by knowledgeable stakeholders, so as to expose potential ethical, legal and financial pitfalls. Though we are charged with educating our operational and administrative colleagues about our Code of Conduct and our Legal and Regulatory obligations, we have the additional obligation to actively counsel them as well.

Leveraging our Anonymous Reporting Hotlines, Internal Audit Departments, and industry and regulatory trends, we ourselves must be prepared to actively engage our colleagues across our organizations to probe for prospective lapses. In a highly-charged competitive environment, we cannot idly sit by and fail to question if expediency is trumping ethical decision-making. Let’s not forget that we are the protagonists—not the villains—in this story.

Wednesday, August 21, 2013

YOUR DREAM TEAM: Where Everyone is a Compliance Leader

"In looking for people to hire, you look for three qualities: integrity, intelligence, and energy. And if they don't have the first, the other two will kill you." ~ Warren Buffet

“The supreme quality for leadership is unquestionably integrity. Without it, no real success is possible, no matter whether it is on a section gang, a football field, in an army, or in an office.” ~Dwight D. Eisenhower

Who leads legal and regulatory compliance at your organization?

How many of your employees are in a compliance role?

Before you respond, consider this…every employee in my organization is in a compliance role...and is charged with being a compliance leader. We only hire compliance leaders to fill each open position throughout the organization. Sales. Operations. Human Resources. Accounting. Facilities Maintenance.

You may be wondering why an organization would engage in such a hair-brained staffing strategy. (You may also be wondering how much longer such an organization could remain in business.) But hearkening back to the words of Warren Buffet and President Eisenhower above, how else could you possibly select talent?

In today’s increasingly complex international regulatory topography, no function within your organization escapes the need to develop policies, processes and training that will address compliance requirements at all employee levels. A CEO cannot simply rely upon on an Internal Audit function, a Legal Department, or a Regulatory Compliance team to identify and mitigate all enterprise-wide risks.

Further, day-to-day compliance and risk management responsibility cannot fall solely upon the shoulders of department heads or supervisors. As leaders, each of you knows that there are far more events occurring for which you are unaware than those that do rise to your attention. Each of our employees—from the most senior to the newly-hired—must understand his/her vital role in preventing, identifying, reporting, and resolving the compliance issues that affect his/her respective role and department.

We must hire individuals that bring the added skill of compliance awareness. I want:

• a talented facilities maintenance employee who also appreciates the impact the EPA and OSHA have at our organization;
• a certified public accountant who also appreciates the impact that the SEC and PCAOB can have;
• a customer-focused call center agent who also appreciates the impact that the FTC and FCC can have; and so forth.

Myself, I’d rather have thousands of sets of eyes mitigating risk globally than to rely only upon my own comparatively limited viewpoint. So, let me ask those questions a different way now…

Who doesn’t lead legal and regulatory compliance at your organization, and why not?

How many of your employees aren’t in a compliance role, and why not?

Tuesday, July 30, 2013

BUILDING EFFECTIVE COMPLIANCE PROGRAMS: It Takes a Village

“No member of a crew is praised for the rugged individuality of his rowing” ~Ralph Waldo Emerson

“If everyone is moving forward together, then success takes care of itself” ~Henry Ford


I had recently been contacted by an individual who had been tapped by her organization to launch a corporate compliance program. My colleague approached me with that perennial question, “How did you build your program?...” I paused to consider my response.

Despite the mythology to which some may wish to subscribe, individuals don’t design, build or improve corporate compliance programs alone. While certainly individuals contribute significant leadership, ideas, and work product to a successful compliance program, it is truly the efforts of interconnected contributors that weaves the fabric of the program.

From scoping and documenting the program charter through defining and populating a comprehensive compliance risk universe, it takes a village of invested professionals to build the program. Since a compliance program likely encompasses several lines of business and diverse operating functions spread across multiple locations, personal interaction with a variety of leaders and staff is necessary to identify, quantify, and rank risks across an organization. I don’t know about you, but I certainly have experiential limitations regarding various functions outside my areas of expertise. Without those subject matter experts, my program would be neither comprehensive nor effective.

Thus, while it would have been terribly tempting to my ego to lead my fellow professional colorfully through an anecdotal reprisal of my rugged journey to locate the holy grail of corporate compliance on a lonely mountaintop, my better angels prevailed. “Katherine, I’d be pleased to share with you how we built our program, and the lessons we’ve learned…” And with that discussion, another member was added to the compliance program “village.”

Tuesday, June 18, 2013

Why I Love Regulatory Examinations

“The superior man understands what is right; the inferior man understands what will sell.”
~Confucius

“Happiness does not come from doing easy work but from the afterglow of satisfaction that comes after the achievement of a difficult task that demanded our best.”
~Theodore Isaac Rubin


To this day, I enjoy going to the dentist. Almost nothing feels as good as that squeaky-clean sensation after the hygienist completes a thorough cleaning. When I was a child and others feared that periodic visit to the reclining chair, I looked forward to the cleaning, fluoride, and constructive criticism about my brush I received as I sat there. While not cavity-free, I have experienced far fewer than I otherwise would have.

Similarly, I’ve never experienced an unfavorable regulatory examination, though my experiences haven’t been “cavity-free.” Jokes comparing audits to root canal aside, I believe the same lessons learned in the dentist’s chair apply equally well amidst the increasingly complex regulatory landscape we face in our organizations. We each lead our organizations with our mission top of mind, but those of us who achieve the greatest success know that we must continuously improve our products/services, our processes, and our people. That is where our regulatory examinations and internal audits come into play.

But some of us have also led in organizations where government regulators were regarded by some of our colleagues as the barbarians at the gate. Those doomsayers would have us believe that examiners and auditors are the malicious brainchild of fiendish state and federal bureaucrats committed to descending our state or nation into communism. 

I’m not a fan of senseless or redundant government regulation by any means, but even Ronald Reagan retained most aspects of the federal regulatory infrastructure throughout his tenure. Judicious regulation has its rightful place in the untamed marketplace, and thus serves to balance the interests of fair-minded consumers and businesses against the carelessness of the few.

A fair-minded organization operates with a high-degree of transparency and employs efficient controls and feedback mechanisms to drive improvement. While operational metrics, financial reporting, and focus groups can provide much important data, the superior organization incorporates the findings and observations of its internal auditors, external information security auditors, and state & federal government regulators into its continuous improvement mechanisms.

I have had the pleasure to speak with countless committed regulatory professionals throughout my career. Well-educated, knowledgeable about their industries, insatiably curious—these men and women have provided me and my colleagues with great insight not only into our own organizations, but have also previewed industry trends before they became regulatory mandates.

Because we were willing to listen, anticipate and prepare, we were able to adapt practices, install or modify systems, and educate our employees and customers in a manner that displayed our genuine integrity as an organization. While I’ve led at organizations that have garnered awards and praise, I am pleased not to have worked at organizations that have headlined the scandal pages.

The truth is…regulatory professionals care deeply about their respective agencies’ missions. As within our own organizations, they are also subject to the ambiguity and uncertainty that new laws, regulations, and political battles entail. Without speaking ill of a rule, regulation or politician, a forthright regulatory professional will admit when the landscape is rocky, shifting or unstable. A wise leader walks that rocky road with the regulator, listening closely, communicating openly, and seeking clarity where clarity may be had. And even when we must agree to disagree on a matter, the relationship remains strong well into the future.

A forward-leaning organization positioned to succeed well into the future expands itself atop a firm foundation build solidly into the regulatory landscape. When regulatory examinations and internal audits inevitably occur, the transparent integrity and compliant processes we employ will carry the day. Importantly, our ability to humbly accept and evaluate the findings, recommendations and observations that are shared with us (formally or informally) may well drive adaptions or improvements that our stubborn competitors will be unwilling to receive. Hubris begets truth decay.

Thursday, April 4, 2013

Your Compliance & Ethics Function: Aligned, Not Maligned

Today, more than ever, your organization needs you. As a Chief Compliance & Ethics Officer navigating the increasingly complex regulatory landscape, your objectivity and expertise provide your board and senior leadership team with a beacon to guide them. Oftentimes you are viewed as the guardian at the gate.

While your colleagues and directors will likely embrace and support your role, your precautionary observations, and your recommendations, that enthusiasm does not always translate vertically throughout the organization. Members of your team may already have encountered the resistance that emerges when raising regulatory compliance, ethics or internal control concerns in the midst of deadline-driven projects. Not often do the profit center managers in our organization stand up and cheer our scrutiny and counsel when we review their proposed product and service offerings, marketing materials, and incentive compensation plans.

We do not further the compliance & ethics mission in our organization when our role is viewed in isolation as too far removed from the day-to-day goals and objectives of our organization. Let’s face it—our organization was most likely founded to obtain a for-profit or not-for-profit objective, not to support our compliance & ethics function.

Over the years I have identified some key steps that allow own compliance & ethics role to align tightly with the growth strategies and objectives that our organizations strive to implement. I refer to these steps as getting down into the MUD:

·         Meet as many key managers at all levels in your organization as feasible. The more colleagues you become familiar with, the greater likelihood that your involvement will be sought out earlier in the planning, development, and execution of new programs, products, and initiatives.
·         Understand genuinely the plans, imperatives, and metrics that drive key managers in your organization in their respective roles. When you truly understand the why, what and how of each division and department, then you will be better able to anticipate and address potential regulatory compliance, ethical, or internal control exposures.
·         Defer to your operational colleagues when a decision does not require approval from you. Your credibility as Chief Compliance & Ethics Officer is strengthened when you resist the urge to exert your will upon every decision in a project, program, or product launch.

When we take the time to get to know our operational colleagues, understand their roles more fully, and defer to their subject-matter expertise, we will find that those same colleagues are much more likely to invite us to advise them regarding regulatory compliance, ethics, and internal control matters. Instead of being maligned as the killjoys at headquarters, let us become aligned with our shared organizational mission as we serve to safeguard it from foreseeable risks.

Thursday, March 28, 2013

Enterprise Risk Management: Captain Kirk Confronts the Final Frontier

When faced with the regulatory mandate to incorporate or improve your organization's enterprise (or enterprise-wide) risk management (ERM) process, we can sometimes feel like a Klingon confronting Tribbles. To succeed with ERM within our organization, we must instead adopt the attitude expressed by Captain James Kirk in the'Day of the Dove episode: "There's another way to survive. Mutual trust...and help."
Several years ago, the federal banking regulators set off on a mission to bring Enterprise Risk Management (ERM) to the forefront of financial institution governance expectations. In the ensuing years, state insurance regulators have joined the mission through the National Association of Insurance Commissioners (NAIC) Own Risk and Solvency Assessment (ORSA) model act. The topic continues to get considerable attention in recent regulatory guidance, including Federal Reserve Board (FRB) supervisory letters 12-7 and 08-8. The Federal Reserve Bank of Chicago (FRB-C) devoted considerable attention to the topic at its 2011 conference.

What appeared to be a distant risk management galaxy in the late 1990s has certainly become an oft-discovered governance imperative for financial institutions. As a financial industry executive, you know that you have been charged with the responsibility “to boldly go where no man has gone before.” Much like the voyage of the storied U.S.S. Enterprise, your voyage has taken you to strange new worlds as you have sought to develop or improve your ERM model.

When you have set out to build a robust risk management infrastructure to integrate, coordinate and facilitate forward-looking risk management throughout the enterprise, you invariable have encountered (or will encounter) skeptics. Captain Kirk addressed this challenge in the 'A Private Little War' episode: "The only solution is...a balance of power. We arm our side with exactly that much more. A balance of power...the trickiest, most difficult, dirtiest game of them all. But the only one that preserves both sides."
But make no mistake about it—ERM is not optional and is here to stay. Thus, we often will find ourselves educating senior leadership colleagues and independent directors about ERM, in parallel with obtaining the necessary data to build, enhance, and report upon our ERM model. ERM cannot simply become a once-and-done exercise that ends up on a binder on your credenza.

Building a culture around ERM involves acclimating leadership throughout the organization to a continuous reporting system that identifies and addresses emerging risks. Strategic initiatives and ongoing business planning are evaluated in light of current and emerging risks and incorporated into analysis and leadership and board decision-making. ERM becomes a discussion item on at least a weekly basis within the leadership team, and a standing agenda item for your board, often through an ERM committee. Reports are designed to be condensed, accurate and meaningful for decision-making.

Internal Audit and Compliance play key roles in the ERM process. The periodic review and validation of the model through targeted risk assessments must be conducted under the direction of the organization’s senior leadership to support the organization’s risk appetite.

Occasionally, Captain Kirk and his officers would find themselves enmeshed in a scene from Earth's pre-space travel history, yet the episode always ended with our beloved travelers safely back aboard the U.S.S. Enterprise. As your ERM model and methodology evolve, it is likely that the organization will also never return by the way that it arrived, because external variables will continually infiltrate the ERM model. Most notably, your organization’s ERM will remain under the scrutiny and be subject to the recommendations of your prudential regulator. There simply is no going back.

Continue to be the evangelist for sound enterprise risk management in your organization, devoting yourself to encouraging, educating and embracing your colleagues as you faithfully fulfill the ERM governance role entrusted to you. Much like Kir, may you live long and prosper in your role.