Showing posts with label policy. Show all posts
Showing posts with label policy. Show all posts

Monday, April 7, 2014

Compliance & Ethics Guidance: “Require” or “Recommend”?

In our capacity as Compliance & Ethics professionals, we are invited daily by business line management to provide guidance on diverse topics. Because we are managing compliance and ethics across an entire organization, each topic must be reviewed with multiple internal stakeholder interests in mind. Externally, we are subject to scrutiny by our customers, our regulators, our industry, and the press. Thus, no review is undertaken in a theoretical vacuum, nor is any resulting guidance intended to provide a one-size-fits-all solution to all similarly-situated topics. Business line management doesn’t always understand those underpinnings when receiving guidance from us.

A frequent question heard by many C&E professionals upon delivering compliance guidance or an ethics opinion is, “So, is this a requirement…or merely a recommendation?” Management attaches very different treatment to our response to that question. Requirements may entail additional cost—whether an opportunity cost of a forgone initiative or a hard cost like implementing additional information system controls. Recommendations may at first blush appear to be optional activities that can be ignored and forgotten. The seasoned C&E professional knows that she must not leave management with any ambiguity about the risks of alternative future courses of action. We only add value to our organizations when we can achieve alignment between management’s risk appetites and our own governance, risk management and control frameworks.

A little confession here…at the onset of my career as an internal auditor, I wrote my recommendations as if they were self-evident edicts born of a brilliant mind. Fortunately I was also paired with managers and mentors who were equipped to deliver humbling learning opportunities to me, for which I have been ever grateful. Those formative leaders challenged me to support my assertions with specific corporate policies, statutes, or regulations. If my assertion was one supported by a matter less well-defined, such as fair trade practices or a matter of public policy, then I was urged to develop recommendations that objectively balanced the strategic interests of the business with the external interests, so as to allow management to make fully-informed decisions. These distinctions served me well. Perhaps you can relate to this transformation from your own career path.

Today I continue to improve my craft. I take great care in drafting compliance memoranda and ethics opinions that ensure well-substantiated transparency. I employ the word “require” when I seek to guide management away from the expedient pitfalls that ultimately lead to reputational loss, fines, lawsuits, or jail time for corporate officers. I employ the word “recommend” when I seek to guide management toward actions that will improve the customer experience; enhance the value of the brand; or reduce aggregate regulatory risk. To overuse “require” when “recommend” would suffice is to invite the “Chicken Little” effect and diminish Compliance & Ethics’ effectiveness. To overuse “recommend” when “require” is truly appropriate is to dilute our own integrity as C&E professionals and ignore our fiduciary duty to our organizations.


As such, when providing compliance and ethics guidance to management, I recommend (but not require) that we choose our words purposefully and substantiate objectively.

Monday, January 6, 2014

Ethical Business Conduct: Context Makes a Difference

"There’s a big difference between what you have a right to do and what is right to do." ~ Potter Stewart, former U.S. Supreme Court Justice

“If everyone is thinking alike, then somebody isn't thinking.” ~ George S. Patton, former U.S. General


In this day and age, it is an increasingly popular sentiment for organizations to describe their workforce as entrepreneurial and empowered. Genuine engagement of today’s employees is a hallmark of the knowledge worker economy, and has led to continued innovation and heightened productivity. In conjunction with the advances made in employee engagement, many organizations have reduced layers of complexity and bureaucracy, and in some cases have even removed offices and walls to encourage greater collaboration between teams. Do not lose sight of the truth that roles and authority—whether explicit or implicit—continue to exist within these organizations.

Amidst this seemingly egalitarian shift in the workplace, organizations continue to implement and improve governance over ethical business conduct. Codes of Conduct flourish as more organizations recognize the real benefits, both tangible and intangible, or providing written guidance supported by training and modeled by leaders at all levels. While well-written Codes detail and illustrate appropriate business conduct guidelines and many prohibitions, these Codes do not seek to define every action for every situation. More importantly, Codes cannot be regarded in isolation of other pertinent organizational guidance and leadership structures.

The Code of Conduct should be drafted so as to apply to all levels of employees within an organization. The CEO is no less subject to conducting her business affairs in an ethical manner than is the mid-level manager or line staff. All employees should adhere to business principles that support the legal and ethical attainment of the organization’s mission. But the authority, opportunity, and tools available to senior leaders and other employees within an organization may very well differ pursuant to board approval, corporate policy, or culture.

For example, a publicly-traded company remains committed to increasing shareholder value. While the senior leadership of that company focus upon profitable long-term strategy, and salespeople focus upon generating daily and monthly revenue, both groups’ actions should align with the best interests of the shareholders. To fail to act in the shareholders’ best interests would represent an unethical (and possibly illegal) breach of duty. That being said, the day-to-day roles and authority levels of the senior leadership differ from those of the salespeople and other employees.

One area where this difference may be illustrated is in the authority to enter into contracts that bind the company. A senior level executive may have been granted authority under corporate policy to negotiate and execute large-dollar multi-year contracts with external vendors, likely with additional internal controls in place. In contrast, a salesperson may have been granted authority under corporate or departmental policy to accept orders from customers, subject to additional internal review and approvals. Both groups, acting on behalf of the company and in the company’s best interest, have been granted contractual authority, but subject to different financial thresholds and internal controls.

Thus, were the salesperson to seek to negotiate and execute a contract with an external vendor in this scenario, he would have committed a breach of corporate policy, and likely the Code of Conduct. A senior level executive, though generally not engaged in sales to customers, might not be similarly constrained from accepting a customer order.

Codes of Conduct and corporate policies serve to educate and guide employees at all levels of an organization. While Codes and policies should provide clear guidelines, especially with regard to prohibited conduct, employees must recognize that excerpts of such documents should not be read in isolation or taken out of context when evaluating business conduct. The context—including role, implicit and explicit authorization, and culture—do provide a backdrop against which all business conduct must also be ethically evaluated. Every employee has the duty to act ethically; not every employee has the authority to engage in all actions. Thus, context does make a difference when it comes to interpreting your Code of Conduct and corporate policies.