Showing posts with label governance. Show all posts
Showing posts with label governance. Show all posts

Wednesday, May 28, 2014

Compliance Management Programs: Good Enough is NEVER Good Enough

Audit, Compliance & Ethics professionals are not generally known for settling for mediocrity or resting upon their laurels. We spend our careers focused upon identifying, documenting, and mitigating risks. We employ people, systems, and procedures to comply faithfully with laws, regulations, and corporate policies. After decades of building and reporting on our detailed processes, we may confidently conclude to our colleagues that we are operating a best-in-class audit, compliance and ethics programs.

But every once in a while we get a reminder that our compliance management program may require a little refreshment. Like a well-intentioned home gym gathering dust in the corner of your basement, your program becomes increasingly less relevant when it is not subjected to frequent and ongoing maintenance. When I am speaking with colleagues about this topic, I hear consistent two consistent themes emerge: (1) we developed a state-of-the-art program back in 19xx, and then we got busy as the organization grew; or (2) we thought that [insert department or title] was watching over that part of the program and keeping it updated. “Best-in-class” became diluted by other competing priorities until it came to rest at “good enough” to keep the organization out of trouble with the board, the auditors, and the regulators.

Then the other shoe drops. At one time or another many of us will be faced with the realization that our compliance program has developed cob webs. Perhaps you can recall a moment of truth…a request from a board member in light of a recent penalty received by a competitor?…a finding in an internal audit report?…an observation made by a prudential regulator? Regardless of the source, having to admit that maintaining the currency and accuracy of our program may have lagged as a priority is an uncomfortable spot to find ourselves in. In the words of President Harry S. Truman, “The buck stops here,” when you’re the Chief Compliance Officer.

Your CEO and your board do not want to hear how busy you’ve been overseeing the increasingly complex regulatory compliance environment. If that is your best response when cracks in your program have been publicized, then you had better clean out your office to make way for your successor who will be up to the task. No, if you find yourself having to admit you’ve neglected the care and feeding of your compliance management program, then will be well advised to also come armed with your contingency plan to remediate your program gaps and a schedule of ongoing review and updating that will take place thereafter.

Before it gets to the point of asking for that mea culpa from your board, CEO, and regultor, perhaps it would be easier to gather the team, risk-rank elements of the compliance management program, and schedule a review of each element. While this may be a bit time-consuming in the initial phase, each subsequent periodic review should be shorter, especially if also paired with an ongoing monitoring of emerging legislation, regulation, and policy changes.


We’ve spent our entire careers getting out in front of the risks. Maybe we became complacent. Let’s return to the basics and declare boldly that “good enough” just isn’t good enough anymore.

Monday, April 7, 2014

Compliance & Ethics Guidance: “Require” or “Recommend”?

In our capacity as Compliance & Ethics professionals, we are invited daily by business line management to provide guidance on diverse topics. Because we are managing compliance and ethics across an entire organization, each topic must be reviewed with multiple internal stakeholder interests in mind. Externally, we are subject to scrutiny by our customers, our regulators, our industry, and the press. Thus, no review is undertaken in a theoretical vacuum, nor is any resulting guidance intended to provide a one-size-fits-all solution to all similarly-situated topics. Business line management doesn’t always understand those underpinnings when receiving guidance from us.

A frequent question heard by many C&E professionals upon delivering compliance guidance or an ethics opinion is, “So, is this a requirement…or merely a recommendation?” Management attaches very different treatment to our response to that question. Requirements may entail additional cost—whether an opportunity cost of a forgone initiative or a hard cost like implementing additional information system controls. Recommendations may at first blush appear to be optional activities that can be ignored and forgotten. The seasoned C&E professional knows that she must not leave management with any ambiguity about the risks of alternative future courses of action. We only add value to our organizations when we can achieve alignment between management’s risk appetites and our own governance, risk management and control frameworks.

A little confession here…at the onset of my career as an internal auditor, I wrote my recommendations as if they were self-evident edicts born of a brilliant mind. Fortunately I was also paired with managers and mentors who were equipped to deliver humbling learning opportunities to me, for which I have been ever grateful. Those formative leaders challenged me to support my assertions with specific corporate policies, statutes, or regulations. If my assertion was one supported by a matter less well-defined, such as fair trade practices or a matter of public policy, then I was urged to develop recommendations that objectively balanced the strategic interests of the business with the external interests, so as to allow management to make fully-informed decisions. These distinctions served me well. Perhaps you can relate to this transformation from your own career path.

Today I continue to improve my craft. I take great care in drafting compliance memoranda and ethics opinions that ensure well-substantiated transparency. I employ the word “require” when I seek to guide management away from the expedient pitfalls that ultimately lead to reputational loss, fines, lawsuits, or jail time for corporate officers. I employ the word “recommend” when I seek to guide management toward actions that will improve the customer experience; enhance the value of the brand; or reduce aggregate regulatory risk. To overuse “require” when “recommend” would suffice is to invite the “Chicken Little” effect and diminish Compliance & Ethics’ effectiveness. To overuse “recommend” when “require” is truly appropriate is to dilute our own integrity as C&E professionals and ignore our fiduciary duty to our organizations.


As such, when providing compliance and ethics guidance to management, I recommend (but not require) that we choose our words purposefully and substantiate objectively.

Wednesday, March 12, 2014

Your Brother’s Keeper: the OCC & Third-Party Mortgage Vendor Relationships

Background

Nationally-chartered federal savings banks are subject to the prudential regulation of the Office of the Comptroller of the Currency (the “OCC”). National banks may engage in activities that are part of, or incidental to, the business of banking, or are otherwise authorized for a national bank. The business of banking is an evolving concept and the permissible activities of national banks similarly evolve over time.1 But when your bank’s senior management decides to outsource a critical function—especially a consumer-facing function like mortgage loan origination or servicing—you truly become your “brother’s keeper.” No Chief Executive Officer or Chief Compliance Officer wishes to find himself or herself targeted by the OCC for failure to conduct adequate third-party vendor due diligence or ongoing monitoring.

It had been historically understood that when employing third-party entities to conduct all or part of a critical banking function, by not fully understanding the nature of the risks being introduced to the bank and by not ensuring appropriate risk controls, senior management and boards of directors breach their most fundamental fiduciary responsibility to depositors and shareholders.2 The Federal Financial Institutions Examination Council (the “FFIEC”) very aptly highlights that although the technology needed to support business objectives is often a critical factor in deciding to outsource, managing such relationships is more than just a technology issue; it is an enterprise-wide corporate management issue.3

Long-standing OCC guidance

A national bank and its operating subsidiaries may make, purchase, sell, service, or warehouse house loans or other extensions of credit for its own or another’s account, including residential mortgage loans.4 A bank may conduct its mortgage operations in conjunction with a third-party not owned by the bank or bank holding company. Vendors, brokers, dealers, and agents can offer banks a variety of legitimate and safe opportunities to enhance product offerings, improve earnings, diversify assets and revenues, or reduce costs. In most instances the fundamental risks associated with activities introduced by third parties are no greater or less than the bank would have incurred had the bank performed the activity on its own.5

Historically, the OCC had very explicitly decreed that bank management cannot rely solely on third-party assertions, representations, or warranties when entering such relationships.6 Specifically, the OCC has long required that:

  • Before entering into a major relationship with a third party, a bank should establish a comprehensive program for managing the relationship.
  • Such programs should be documented and include front-end management planning, appropriate due diligence selecting a vendor, and performance monitoring.7

The requirements above were not merely satisfied by a bank relying solely upon its own internal Vendor Management Policy. The OCC expressly contemplated that the bank’s negotiators and signatories to the vendor contract would tailor the program to the specific vendor, and that the documentation would reflect the criteria and validation specific to that vendor with regard to the services for which the bank sought to contract.

OCC activity in the wake of Bulletin 2013-29

OCC treatment of third-party vendor risk management was recently further clarified when the agency issued Bulletin 2013-29: Third-Party Relationships - Risk Management Guidance on October 30, 2013.8  Among the OCC’s explicit guidance, the Agency deemed that an effective risk management process throughout the life cycle of the relationship includes:
·     plans that outline the bank’s strategy, identify the inherent risks of the activity, and detail how the bank selects, assesses, and oversees the third party;
·         proper due diligence in selecting a third party;
·         written contracts that outline the rights and responsibilities of all parties;
·         ongoing monitoring of the third party’s activities and performance;
·         contingency plans for terminating the relationship in an effective manner;
·       clear roles and responsibilities for overseeing and managing the relationship and risk management process;
·        documentation and reporting that facilitates oversight, accountability, monitoring, and risk management; and
·   independent reviews that allow bank management to determine that the bank’s process aligns with its strategy and effectively manages risks.

The OCC has wasted no time applying those third-party risk management principles immediately before and since the issuance of Bulletin 2013-29. On September 19, 2013, the OCC assessed a $60 million penalty against JPMorgan Chase and ordered the bank to reimburse consumers for unfair billing practices.9 In the JPMorgan Chase matter, the OCC order also requires the bank to take a number of corrective measures that include:
·         ensuring compliance with the FTC Act;
·   improving governance of third-party vendors associated with certain consumer products;
·    developing an enterprise-wide risk management program for such consumer products marketed or sold by the bank or its vendors; and
·         improving its consumer compliance internal audit program.

American Express Bank received an early Christmas present, when the OCC announced on December 24, 2013 that it would assess a $3 million penalty against the bank and order restitution to customers for unfair billing and deceptive marketing practices.10 The OCC order, whose restitution payments also satisfied related Consumer Financial Protection Bureau (CFPB) obligations, requires the bank to:
·  improve governance of third-party vendors associated with “add-on” consumer products;
·     develop a risk management program for “add-on” consumer products marketed or sold by the bank or its vendors; and
·    conduct an “add-on” product review to, among other things, identify and remediate consumer harm and any program weaknesses.

The OCC has clearly communicated that it intends to aggressively protect consumers from harmful activities resulting from a bank’s use of third-party vendors, and that it will hold a bank fully responsible for that third party’s missteps.

Critical Attention to Pre-Contractual Due Diligence

Every activity undertaken by bank management and its agents should accord with OCC requirements, and support subsequent examination by the OCC, the internal audit function, and external auditors. The contemplation of a significant third-party business relationship that contributes directly to a bank’s growth plan should be disclosed in sufficient detail by bank management to the bank’s board of directors to facilitate the board’s fiduciary responsibility. Negotiators of a third-party business relationship (inclusive of bank management, holding company management, and legal counsel) are in the best position to review, inquire, and edit contract provisions accordingly prior to execution to ensure that all contract provisions directly address OCC compliance requirements, including those relating directly to third-party risk and due diligence.

With reliance upon bank management and its agents who engage directly in the planning, negotiation, and execution of the third-party agreement, one should reasonably be able to conclude that those parties have conducted their activities in accordance with OCC Bulletin 2013-29.11 In advance of executing an agreement, bank management and its agents would have engaged in and fully documented both management planning and due diligence in selecting a vendor. The agreement would further have documented the ongoing performance monitoring required to evaluate the ongoing vendor risk management posture. To have failed to faithfully adhere to the details of the Bulletin by simply relying upon professional relationships or contractual representations and warranties would be both imprudent and discordant with explicit OCC guidance.

Ongoing Risk Assessment and Improved Governance

If a CEO or CCO had not been involved in contract negotiations with a third-party vendor, then that leader may not be able to independently confirm whether or not bank management and its agents adhered to OCC requirements during the pre-contractual due diligence period. Once that leader becomes aware that such a gap may have occurred, it becomes incumbent upon that leader to undertake an independent risk assessment of the third-party vendor relationship. This obligation becomes critically important when the third-party vendor is providing consumer mortgage loan services.

The auditors assigned to conduct the independent third-party risk management review should be able to request, obtain and evaluate pre-contractual documentation, and supplement their initial conclusions with interviews with the individuals directly engaged in the planning, negotiation, and execution of the third-party vendor agreement. As with any audit, should the auditors identify exceptions to the OCC’s third-party risk management guidelines that present a material risk of non-compliance or future financial loss, then in accordance with the Chief Audit Executive, you would advise that bank management and the bank board be so advised that subsequent remedial measures be undertaken.

Conclusion

It is evident that the OCC expects governance, risk management, and controls (GRC) to be in place prior to and at the inception of third-party mortgage vendor relationships. Even as bank management remediates the existing relationship with a consumer mortgage vendor, all stakeholders should take note of the lessons learned from a less-than-thorough due diligence; explicit contractual role definition; and contractual provisions for detailed oversight, accountability, and monitoring. Future third-party vendor relationships must incorporate those onboarding elements as standard requirements of a larger enterprise-wide risk management process, lest the OCC surmise that your bank’s governance practices are insufficient to take heed of Bulletin 2013-29.


References





5      Third-Party Risk, August 29, 2000. (Subsequently rescinded by OCC Bulletin 2013-29)

6      Ibid.






Monday, February 17, 2014

When Crisis Erupts: Surmount or Surrender?

“The easiest period in a crisis situation is actually the battle itself.
The most difficult is the period of indecision -- whether to fight or run away.
And the most dangerous period is the aftermath.
It is then, with all his resources spent and his guard down, that an individual must watch out for dulled reactions and faulty judgment.”  
~Richard M. Nixon, 37th President of the United States

As a Chief Compliance & Ethics Officer, you know that the eventuality of crisis striking your organization is not a matter of “if”, but only of “when.” You spend your career crafting and implementing a governance system of policies & procedures, training, monitoring, and reporting whose value will ultimately be assessed in those moments and days following the crisis. Not all systems (nor all leaders) will survive the test.

Crisis will not politely schedule an appointment with you on a lazy afternoon, but will more likely descend upon you furiously, publicly and embarrassingly at the most inopportune of moments. Crisis will arrive in the guise of a viral tweet, a regulatory inquiry, or a criminal indictment. A loyal staffer will hesitantly summon you from a meeting into the hallway to advise you of the breaking news. And so begins the moment of decision.

As Compliance leaders we have trained our entire lives to guide and protect our organizations from harm. The very same principles that we have employed to prevent and mitigate risk will come into play when we must navigate our organization, its leadership and its board through and beyond the crisis. Decisive action that engenders trust must remain at the forefront of the response.

Thus, together we must continue to:

  •        Act ethically and decisively;
  •          Communicate frequently and transparently; and
  •          Modify practices appropriately.
Act ethically and decisively

Crisis does not represent your organization in its entirety. Your mission, your values, and your people remain fundamentally sound, even when something has gone awry. Therefore, even as you and your leadership team are undertaking an investigation and crafting a response to the statement, incident, or charge, you will continue to direct your employees to perform their day-to-day responsibilities with the accustomed level of adherence to ethics, compliance, and mission-focus. Your organization will survive the crisis, and so the continued service to your employees, clients, customers, vendors and shareholders must remain highly-functioning.

Communicate frequently and transparently

Do not compound the temporary negative impact of a crisis by shrouding the crisis in a cloak of shame and secrecy. While not proud of the event that has triggered the crisis, you remain nonetheless committed to your employees, your customers, your brand, and your mission-focus for the long run. Within that long view context, communicate quickly that leadership is:

·         aware of the situation;
·         taking it seriously;
·         cooperating fully; and
·         is committed to resolving it.

Convey that future communications will follow as additional information becomes available, and adhere to that pattern, even if only limited information becomes available. Your stakeholders are better served by hearing the truth from you, than the mistrust that will take root if they begin to receive their information—accurate or misconstrued--from external sources.


Modify practices appropriately

While some crises will end with a conclusion that the crisis was merely malicious and unwarranted, often the investigation will reveal a compliance or control weakness that must be addressed by your organization. Once identified, own both the root cause and the solution, communicating the same to your stakeholders. Then set to work implementing the required changes that will ensure the situation has been appropriately addressed. If additional training is warranted, then make every effort to involve the affected employees in designing and testing the training before it is rolled out to the larger audience. Schedule subsequent time to review the modified practice and test its effectiveness, regardless of whether required to do so by a regulatory body or not.

***
Crisis will erupt. You will be called upon to act in the best interest of your organization and its stakeholders. If you have prepared yourself, your leadership team, and your board in advance of this moment, then you will pilot your organization to a brighter tomorrow with the flag flying high. Otherwise, armed only with dulled reactions and faulty judgment, you will find yourself waving the flag of surrender.

Sunday, January 26, 2014

Starving for Compliance? Bring your Risk Appetite

“If it's your job to eat a frog, it's best to do it first thing in the morning. And if it's your job to eat two frogs, it's best to eat the biggest one first.”  ~Mark Twain
 

As Audit, Compliance & Ethics professionals, it is often our job to “eat a frog” and you likely find yourself sitting down to a banquet of frogs when crisis strikes your organization. Some of us consciously chose to enter the AC&E profession, while others with whom I’ve spoken tell me how their roles morphed into compliance functions. Either way, once we’ve accepted the responsibility to safeguard our organization’s enterprise risk management program, we must faithfully deploy an appropriate compliance framework.
One cannot simply purchase a compliance program at an online retailer, download it to your tablet, and check that task off your list. There is no one-size-fits-all compliance program that is going to align perfectly with every organization’s ERM model. The design of the compliance program begins with a studied understanding of the organization’s risk appetite. Delivering an off-the-shelf or generic compliance program to an organization without factoring in its risk appetite is like delivering a freeze-dried meal to a guest’s table without inquiring of her culinary preferences.

Risk appetite is that level of risk that an organization is prepared to willingly accept before mitigating actions are required to reduce it. Formulating the risk appetite requires the Board of Directors to consciously identify its consensus balance between the anticipated benefits of a chosen course of action and the threats that an uncertain future inevitably brings. Each area of risk may enjoy differing risk appetites. For instance, a well-capitalized organization bearing a trusted brand may be more averse regarding reputation and litigation risks, but more inclined to accept a moderate degree of financial and strategic risks. Such may be the variations found also in compliance risk appetites.
A compliance purist—if such a person exists—would trend strongly toward risk aversion. A Gordon Gekko (credit to Oliver Stone’s “Wall Street” fame) would trend strongly toward risk hunger. Since compliance is not generally viewed as a profit center, a typical organization’s Board of Directors will formulate a compliance risk appetite that represents its view of an appropriate balance (i.e. expects ethical business conduct that achieves its mission). A publicly-traded company may seek to maximize shareholder value and profit, but likely seek to avoid criminal and civil prosecution. A non-profit organization may seek to maximize its impact serving the largest number of people in a community, but likely seek to minimize its administrative cost ratio and excessive CEO compensation.

Organizations that design, employ, and monitor compliance programs that align with the Board of Directors’ risk appetite will encounter fewer compliance failures over the long-term. I am careful to point out that all organizations, no matter how well-run, will experience a compliance failure at some time. A risk appetite acknowledges that while risk may be mitigated, it generally cannot be entirely eliminated. To eliminate all risk is to forgo meaningful opportunities that competing organizations would be willing to accept, thus neutralizing your organization’s effectiveness in the space in which it competes. This fact does not apply only to for-profit companies, because non-profit organizations also compete for scarce resources and relevancy. Risk must always be recognized as a factor to be managed.
Whether you are designing a new program or enhancing an existing compliance program, you will want to ascertain your organization’s defined compliance risk appetite. Your compliance program, including training, monitoring, and Board-level reporting, must align to that risk appetite to provide appropriate risk management tools to support your organization. Finally, periodically revisit the relationship between the stated risk appetite and your program elements to ensure that you are making appropriate adjustments.

Don’t starve your compliance program. Embrace the risk appetite. Be prepared to one day confidently defend your compliance risk management program to your external auditors and prudential regulators…and enjoy that frog sooner than later.

Monday, January 6, 2014

Ethical Business Conduct: Context Makes a Difference

"There’s a big difference between what you have a right to do and what is right to do." ~ Potter Stewart, former U.S. Supreme Court Justice

“If everyone is thinking alike, then somebody isn't thinking.” ~ George S. Patton, former U.S. General


In this day and age, it is an increasingly popular sentiment for organizations to describe their workforce as entrepreneurial and empowered. Genuine engagement of today’s employees is a hallmark of the knowledge worker economy, and has led to continued innovation and heightened productivity. In conjunction with the advances made in employee engagement, many organizations have reduced layers of complexity and bureaucracy, and in some cases have even removed offices and walls to encourage greater collaboration between teams. Do not lose sight of the truth that roles and authority—whether explicit or implicit—continue to exist within these organizations.

Amidst this seemingly egalitarian shift in the workplace, organizations continue to implement and improve governance over ethical business conduct. Codes of Conduct flourish as more organizations recognize the real benefits, both tangible and intangible, or providing written guidance supported by training and modeled by leaders at all levels. While well-written Codes detail and illustrate appropriate business conduct guidelines and many prohibitions, these Codes do not seek to define every action for every situation. More importantly, Codes cannot be regarded in isolation of other pertinent organizational guidance and leadership structures.

The Code of Conduct should be drafted so as to apply to all levels of employees within an organization. The CEO is no less subject to conducting her business affairs in an ethical manner than is the mid-level manager or line staff. All employees should adhere to business principles that support the legal and ethical attainment of the organization’s mission. But the authority, opportunity, and tools available to senior leaders and other employees within an organization may very well differ pursuant to board approval, corporate policy, or culture.

For example, a publicly-traded company remains committed to increasing shareholder value. While the senior leadership of that company focus upon profitable long-term strategy, and salespeople focus upon generating daily and monthly revenue, both groups’ actions should align with the best interests of the shareholders. To fail to act in the shareholders’ best interests would represent an unethical (and possibly illegal) breach of duty. That being said, the day-to-day roles and authority levels of the senior leadership differ from those of the salespeople and other employees.

One area where this difference may be illustrated is in the authority to enter into contracts that bind the company. A senior level executive may have been granted authority under corporate policy to negotiate and execute large-dollar multi-year contracts with external vendors, likely with additional internal controls in place. In contrast, a salesperson may have been granted authority under corporate or departmental policy to accept orders from customers, subject to additional internal review and approvals. Both groups, acting on behalf of the company and in the company’s best interest, have been granted contractual authority, but subject to different financial thresholds and internal controls.

Thus, were the salesperson to seek to negotiate and execute a contract with an external vendor in this scenario, he would have committed a breach of corporate policy, and likely the Code of Conduct. A senior level executive, though generally not engaged in sales to customers, might not be similarly constrained from accepting a customer order.

Codes of Conduct and corporate policies serve to educate and guide employees at all levels of an organization. While Codes and policies should provide clear guidelines, especially with regard to prohibited conduct, employees must recognize that excerpts of such documents should not be read in isolation or taken out of context when evaluating business conduct. The context—including role, implicit and explicit authorization, and culture—do provide a backdrop against which all business conduct must also be ethically evaluated. Every employee has the duty to act ethically; not every employee has the authority to engage in all actions. Thus, context does make a difference when it comes to interpreting your Code of Conduct and corporate policies.

Wednesday, July 3, 2013

EXPOSING MY DIRTY LAUNDRY: Responding to Ethical Incidents in Advance

“Ethics is knowing the difference between what you have a right to do and what is right to do.”
~Potter Stewart, former U.S. Supreme Court Justice

“The time is always right to do what is right.”
~Martin Luther King, Jr., U.S. civil rights leader


Today’s revelation that former Olympus Corporation Chairman Tsuyoshi Kikukawa had received a suspended sentence for his role in a $1.7 billion accounting fraud is a reminder that neither business ethics courses nor prior real-world examples have stemmed the tide of high-profile executive wrongdoing.  In addition to former Olympus Executive Vice President Hisashi Mori, Hideo Yamada, the former auditing officer, also received a suspended sentence, debunking any myths that corporate audit and compliance professionals are above temptation.

Sufficient ink has been dedicated to detailing the corporate, government, and NGO ethical downfalls throughout the modern age. Fraud observes no geographical, political or industry boundaries. Ethical lapses remain pervasive and persistent, but I believe they are preventable.

What are you doing within your organization currently to acknowledge and mitigate the risks posed by executive ethical lapses?

Tone at the top is more than an email, a poster, or even a video distributed by your chief executive officer expounding the importance and benefits of maintaining an ethical cultural. Real ethical leadership takes root within an organization when the board of directors and senior leadership infuse the culture with relevant actions.

·         Strategic planning conferences and periodic governance meetings should include ethics discussions on the agenda.
·         Tabletop exercises should be built around current ethical lapse events in your industry.
·         Internal metrics should be tracked and benchmarked against other like organizations.
·         Employees at all levels must be encouraged to ask questions and report observed ethical lapses in good faith without fear of retaliation.

What are you doing when a significant ethical lapse strikes from within your own organization?

At one time or another nearly every organization, be it for-profit, government agency, faith-based, etc., will need to address an ethical incident that emanates from within its own walls. More than just the fear of negative publicity or criminal prosecution should drive the organization’s response. Many a relatively minor ethical incident has morphed into fodder for bloggers and 24/7 cable news outlets simply due to senior level fumbling and obfuscation amidst embarrassing revelations.

In fact, the best time to publicly address ethical lapses within your organization is before one has emerged.

·         Plan, document and test your organization’s Ethical Incident Response Plan (E-IRP).
·         Educate senior leadership regarding effective and transparent communication strategy, obtaining communication training in advance where needs dictate.
·         Communicate in a coordinated, transparent and timely manner both internally and externally to your organization, erring on the side of humility and candor.

Organizations are governed and led by human beings. Men and women, regardless of demographic variables across cultures, shun the humiliation and ridicule that scandal generates. Applying an objective E-IRP model in advance of ethical lapses will mitigate the risk that my dirty laundry—or yours—will hang too long on the proverbial corporate clothesline.

Thursday, March 28, 2013

Enterprise Risk Management: Captain Kirk Confronts the Final Frontier

When faced with the regulatory mandate to incorporate or improve your organization's enterprise (or enterprise-wide) risk management (ERM) process, we can sometimes feel like a Klingon confronting Tribbles. To succeed with ERM within our organization, we must instead adopt the attitude expressed by Captain James Kirk in the'Day of the Dove episode: "There's another way to survive. Mutual trust...and help."
Several years ago, the federal banking regulators set off on a mission to bring Enterprise Risk Management (ERM) to the forefront of financial institution governance expectations. In the ensuing years, state insurance regulators have joined the mission through the National Association of Insurance Commissioners (NAIC) Own Risk and Solvency Assessment (ORSA) model act. The topic continues to get considerable attention in recent regulatory guidance, including Federal Reserve Board (FRB) supervisory letters 12-7 and 08-8. The Federal Reserve Bank of Chicago (FRB-C) devoted considerable attention to the topic at its 2011 conference.

What appeared to be a distant risk management galaxy in the late 1990s has certainly become an oft-discovered governance imperative for financial institutions. As a financial industry executive, you know that you have been charged with the responsibility “to boldly go where no man has gone before.” Much like the voyage of the storied U.S.S. Enterprise, your voyage has taken you to strange new worlds as you have sought to develop or improve your ERM model.

When you have set out to build a robust risk management infrastructure to integrate, coordinate and facilitate forward-looking risk management throughout the enterprise, you invariable have encountered (or will encounter) skeptics. Captain Kirk addressed this challenge in the 'A Private Little War' episode: "The only solution is...a balance of power. We arm our side with exactly that much more. A balance of power...the trickiest, most difficult, dirtiest game of them all. But the only one that preserves both sides."
But make no mistake about it—ERM is not optional and is here to stay. Thus, we often will find ourselves educating senior leadership colleagues and independent directors about ERM, in parallel with obtaining the necessary data to build, enhance, and report upon our ERM model. ERM cannot simply become a once-and-done exercise that ends up on a binder on your credenza.

Building a culture around ERM involves acclimating leadership throughout the organization to a continuous reporting system that identifies and addresses emerging risks. Strategic initiatives and ongoing business planning are evaluated in light of current and emerging risks and incorporated into analysis and leadership and board decision-making. ERM becomes a discussion item on at least a weekly basis within the leadership team, and a standing agenda item for your board, often through an ERM committee. Reports are designed to be condensed, accurate and meaningful for decision-making.

Internal Audit and Compliance play key roles in the ERM process. The periodic review and validation of the model through targeted risk assessments must be conducted under the direction of the organization’s senior leadership to support the organization’s risk appetite.

Occasionally, Captain Kirk and his officers would find themselves enmeshed in a scene from Earth's pre-space travel history, yet the episode always ended with our beloved travelers safely back aboard the U.S.S. Enterprise. As your ERM model and methodology evolve, it is likely that the organization will also never return by the way that it arrived, because external variables will continually infiltrate the ERM model. Most notably, your organization’s ERM will remain under the scrutiny and be subject to the recommendations of your prudential regulator. There simply is no going back.

Continue to be the evangelist for sound enterprise risk management in your organization, devoting yourself to encouraging, educating and embracing your colleagues as you faithfully fulfill the ERM governance role entrusted to you. Much like Kir, may you live long and prosper in your role.

Wednesday, March 6, 2013

Strength and Sustainability: Collaborative Compliance Amidst Complexity

I simply do not have all of the answers. There, I have said it.
My simple statement sums up the collective admission of Compliance, Audit and Ethics professionals globally. The annual proliferation of domestic and international regulatory requirements continues to proceed at an ever increasing rate. When only a decade or two ago, a chief compliance officer might likely have understood the details of all regulatory responsibilities within his/her realm, many of us have now grown accustomed to reliance upon specialized colleagues to identify the details of specific branches within our own compliance universe. At least two easily recognizable trends have led to this reality: global commerce and systemic failure.
Global commerce has both driven and benefited from technological and economic advances throughout history. Progressing beyond the steamships that replaced clipper ships, the internet built upon the initial success of the transoceanic cables laid long ago. While local trade rules and customs remain, the international Law of the Sea has been joined by International Free Trade Agreements and transcontinental legal structures, most notably the European Union, where supranational legal structures both supplant and co-exist with domestic laws and regulations.
Systemic failures that have led to financial crises within nations as diverse as Greece, Ireland, Japan and the United States have resulted in the now-familiar remedies of International Monetary Fund austerity measures, the Third Basel Accord, and Dodd-Frank  Wall Street Reform and Consumer Protection Act, to name a few examples. Regulators have sought to eliminate pathways to fraud, largess and market manipulation widely blamed for the global crises by promulgating lengthy and complex regulatory solutions.
Compliance professionals who once may have laid claim to comprehending and administering compliance programs involving an entire continent or nation have succumbed to a level of regulatory complexity that makes such independent mastery incomprehensible. Even for those of us who oversee primarily domestic compliance programs, international influences are now omnipresent in Dodd-Frank, the Bank Secrecy Act, FCPA and the U.K. Bribery Act of 2010.
At the end of the day, Compliance, Audit and Ethics professionals are exactly that—professionals. We do not simply throw our hands up and decry the unfairness of increasingly complex regulatory requirements. True to our nature, we seek to understand as much as possible about our responsibilities to fulfill those compliance requirements in conjunction with our organization’s core mission and objectives. But our inquiries and information gathering must extend beyond our own individual knowledge and planning. Today’s increasingly complex regulatory environment requires us to collaborate with colleagues both within our organizations and beyond.
I would propose that now is the time to build stronger, more sustainable Compliance Programs through intelligent collaboration. It must not be viewed as a sign of ignorance or laziness when we humbly and actively partner with fellow Compliance, Audit and Ethics professionals to ascertain best practices. Likewise, we must continue to embrace the business line leaders within our own organizations to build collaborative compliance solutions that fulfill our regulatory responsibilities without unnecessarily impeding daily operations and long-term strategies.
Effective Regulatory Compliance…we may not each be able to do it alone, but we can certainly do it more constructively together.