Thomas Fox

31 Days to a More Effective Compliance Program

Business EN ↓ 652 episodes

Tom Fox is the Compliance Evangelist and is universally recognized as one of the top experts in corruption compliance, literally across the globe. In this daily podcast series, he explains how to design, create and implement a best practices compliance program. Each month, he tackles a different area of compliance. From Internal Controls, to the Role of the Board of Directors, to Communication, to the Role of HR in Compliance, Investigations, 3rd Parties and Business Ventures. Listen in each day and get one tip you can implement at little or no cost to enhance your compliance program.

Author

Thomas Fox

Category

Business

Latest episode

Jan 31, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

One Month to More Effective Internal Controls- Discipline and Rigor in Your Internal Controls 02.02.2023

New York Times columnist David Brooks’ thoughts on building and maintaining order inform the discussion on rigor in your internal controls. In internal controls, I believe it is incumbent to consider not only the most obvious risk areas for your internal controls but also the universe of potential transactions within the operations of a company. There is a clear need for rigor in your internal con...

One Month to More Effective Compliance on Business Ventures: Introduction 01.02.2023

For the month of March, we will be considering how to create a more effective compliance program involving business ventures. This will include the role of compliance in M&A, JV agreements, distributorships, teaming agreements and franchises as well as other forms of business relationships. The FCPA Resource Guide, 2nd edition made clear that one of the Hallmarks of An Effective Compliance Program...

One Month to More Effective Internal Controls- What Are Internal Controls? 01.02.2023

What specifically are internal controls in a compliance program? Internal controls are not only the foundation of a company but are also the foundation of any effective anti-corruption compliance program. Internal controls expert Joe Howell, has said that internal controls are systematic measures, such as reviews, checks and balances, methods and procedures, instituted by an organization that perf...

Day 31 - Using a root cause analysis for remediation 31.01.2023

The 2020 Update re-emphasized the need for both performing a root cause analysis but equally importantly using it to remediate your compliance program. It stated, “a hallmark of a compliance program that is working effectively in practice is the extent to which a company is able to conduct a thoughtful root cause analysis of misconduct and timely and appropriately remediate to address the root cau...

Day 30 - What is a root cause analysis? 30.01.2023

One of the biggest changes in the 2020 FCPA Resource Guide, 2nd edition was the addition of a new Hallmark, entitled “Investigation, Analysis, and Remediation of Misconduct”, which reads in full: The truest measure of an effective compliance program is how it responds to misconduct. Accordingly, for a compliance program to be truly effective, it should have a well-functioning and appropriately fun...

Day 29 - Post-acquisition integration plan 29.01.2023

Your company has just made its largest acquisition ever and your CEO says they want you to have a compliance post-acquisition integration plan on their desk in one week. Where do you begin? A good place to start would be the 2020 FCPA Resource Guide, 2nd edition language: Pre-acquisition due diligence, however, is normally only a portion of the compliance process for mergers and acquisitions. DOJ...

Day 28 - Pre-acquisition due diligence in mergers and acquisitions 28.01.2023

A company that does not perform adequate due diligence prior to a merger or acquisition may face both legal and business risks. Perhaps most commonly, inadequate due diligence can allow a course of bribery to continue - with all the attendant harms to a business’s profitability and reputation, as well as potential civil and criminal liability. While most compliance practitioners have been long awa...

Day 27- Operationalizing Compliance Through Payroll 27.01.2023

One of the areas articulated in the 2020 Update was around payments and payroll. For the both the compliance professional and the corporate payroll function, there is a significant role to play in the operationalization of a corporate compliance program. The 2020 Update was replete with references to payment and its critical nature to any best practices compliance program. This includes references...

Day 26 - Compliance function in an organization 26.01.2023

The role of the compliance professional and the compliance function in a corporation has steadily grown in stature and prestige over the years. When it came to the corporate compliance function, 2020 FCPA Resource Guide, under the Hallmarks of an Effective Compliance Program, simply noted the government would “consider whether the company devoted adequate staffing and resources to the compliance p...

Day 25 - CCO authority and independence 25.01.2023

The role of the CCO has steadily grown in stature and prestige over the years. In the 2020 FCPA Resource Guide, under the Hallmarks of an Effective Compliance Program, it focused on the whether the CCO held senior management status and had a direct reporting line to the Board. The new requirement for CCO certification has only emphasized this reality. This Hallmark was significantly expanded in bo...

Day 24 - Updates and feedback 24.01.2023

One of the critical elements found in the 2020 Update is the need to use the information you obtain, whether through risk assessment, root cause analysis, investigation, hotline report or any other manner to remediate the situation which allowed it to arise. Your company should establish a regular monitoring system to spot issues and address them. Effective monitoring means applying a consistent s...

Day 23 - Assessing Compliance Internal Controls 23.01.2023

What happens when controls are continually overridden? Does that necessarily mean that companies are engaging in activities which violate the FCPA or some other law such as Sarbanes-Oxley (SOX). Cristina Revelo said she would start out with some basic questions such as “How often would something be manually approved? How often are controls skipped, what are the level of approvals that you have and...

Day 22 - Internal Reporting and Triaging Claims 22.01.2023

The call, email, or tip comes into your office; an employee reports suspicious activity across the globe. That activity might well turn into an FCPA issue for your company. As the CCO, it will be up to you to begin the process, which will determine, in many instances, how the company will respond going forward. This is more than simply maintaining hotlines. Companies have to make real efforts to l...

Day 21 - Continuous improvement in a compliance program 21.01.2023

The 2020 Update was very clear about the need for continuous improvement in any compliance program. It stated quite succinctly, “One hallmark of an effective compliance program is its capacity to improve and evolve. The actual implementation of controls in practice will necessarily reveal areas of risk and potential adjustment. A company’s business changes over time, as do the environments in whic...

Day 20 - Responding to investigative findings 20.01.2023

There is nothing like an internal whistleblower report about a compliance violation, the finding of such an issue, or (even worse) a subpoena from the DOJ or notice letter from the SEC to trigger the Board of Directors and senior management attention to the compliance function and the company’s compliance program. Such an event can trigger much gnashing of teeth and expressions of outrage followed...

Day 19 - Your investigation protocol 19.01.2023

After the internal report comes in and you have properly triaged the matter, you need to scope out and investigate it, promptly, thoroughly and with competent personnel. In the 2020 Update, provided these series of questions about your internal investigations: Properly Scoped Investigations by Qualified Personnel – How does the company determine which complaints or red flags merit further investig...

Day 18 - Levels of due diligence 18.01.2023

Due diligence is generally recognized in three levels: Level I, Level II and Level III. Each level is appropriate for a different level of corruption risk. The key is to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward. The question becomes how you use the information you obtained in the business justification and the questionnaire to de...

Day 17- Managing your third parties 17.01.2023

The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance program...

Day 16 - The third-party risk management process 16.01.2023

As every compliance practitioner is well aware, third parties still present the highest risk under the FCPA even in 2023. The 2020 Update devotes an entire prong to third-party management. It begins with the following:  Prosecutors should also assess whether the company knows the business rationale for needing the third party in the transaction, and the risks posed by third-party partners, includi...

Day 15 - How do you evaluate a risk assessment? 15.01.2023

After you complete your risk assessment, you must then translate it into a risk profile. If your estimate of where your bribery risk is greatest is wrong, it will be an effort to address it. As Ben Locwin explained in his  BioProcess International article, entitled “Quality Risk Assessment and Management Strategies for Biopharmaceutical Companies”: Once we have assessed risks and determined a proc...

Day 14 - Risk Assessments 14.01.2023

One cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based upon a risk assessment, to understand your organization’s business from the commercial perspective, how your organization has identified, assessed, and defined its risk profile and, finally, the degree to which the program devotes approp...

Day 13: Podcasting for Compliance Training and Communication 13.01.2023

If there is one truism from the practice of law which translates to the practice of compliance it is that you are only limited by your own imagination. This holds true in the 360-degree realm of communication in compliance, as communications obviously comes in many forms. Many compliance practitioners will well remember the 2012 Morgan Stanley declination. In this first declination made public, th...

Day 12 - Financial Incentives for Compliance 12.01.2023

One of the areas that many companies have not paid as much attention to in their compliance programs is compensation and incentives. However, the DOJ and SEC have long made clear that they view monetary structure for compensation, rewarding those employees who do business in compliance with their employer’s compliance program, as one of the ways to reinforce the compliance program and the message...

Day 11 - Tailored and Effective Compliance Training 11.01.2023

One of the key goals of any compliance program is to train employees in awareness and understanding of the FCPA; your specific company compliance program; and to create and foster a culture of compliance. While it seems axiomatic that compliance training is a mainstay of any best practices compliance program, the conversation around training has evolved over the years. Beginning in the fall of 201...

Day 10 - The Use of Social Media in Compliance 10.01.2023

What is the message of compliance inside of a corporation and how it is distributed? In a compliance program, the largest portion of your consumers/customers are your employees. Social media presents some excellent mechanisms to communicate the message of compliance going forward. Many of the applications that we use in our personal communications are free or available at very low cost. Why not ta...

Listen to the 31 Days to a More Effective Compliance Program podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.