Thomas Fox
31 Days to a More Effective Compliance Program
Tom Fox is the Compliance Evangelist and is universally recognized as one of the top experts in corruption compliance, literally across the globe. In this daily podcast series, he explains how to design, create and implement a best practices compliance program. Each month, he tackles a different area of compliance. From Internal Controls, to the Role of the Board of Directors, to Communication, to the Role of HR in Compliance, Investigations, 3rd Parties and Business Ventures. Listen in each day and get one tip you can implement at little or no cost to enhance your compliance program.
Author
Thomas Fox
Category
Podcast website
Latest episode
Jan 31, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Day 21 | Continuous improvement in a compliance program 21.01.2021 7:37
The 2020 Update was very clear about the need for continuous improvement in any compliance program. It stated quite succinctly, “One hallmark of an effective compliance program is its capacity to improve and evolve. The actual implementation of controls in practice will necessarily reveal areas of risk and potential adjustment. A company’s business changes over time, as do the environments in whic...
Day 20 | Responding to investigative findings 20.01.2021 7:42
There is nothing like an internal whistleblower report about a compliance violation, the finding of such an issue, or (even worse) a subpoena from the DOJ or notice letter from the SEC to trigger the Board of Directors and senior management attention to the compliance function and the company’s compliance program. Such an event can trigger much gnashing of teeth and expressions of outrage followed...
Day 19 | The investigation protocol 19.01.2021 7:38
After the internal report comes in and you have properly triaged the matter, you need to scope out and investigate it, promptly, thoroughly and with competent personnel. In the 2020 Update, provided these series of questions about your internal investigations: Properly Scoped Investigations by Qualified Personnel – How does the company determine which complaints or red flags merit further invest...
Day 18 | Levels of due diligence 18.01.2021 7:31
Due diligence is generally recognized in three levels: Level I, Level II and Level III. Each level is appropriate for a different level of corruption risk. The key is to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward. The 2020 Update stated, “A well-designed compliance program should apply risk-based due diligence to its third- party...
Day 17 | Managing your third parties 17.01.2021 7:31
The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance program...
Day 16 | The third-party risk management process 17.01.2021 7:31
As every compliance practitioner is well aware, third parties still present the highest risk under the FCPA. The 2020 Update devotes an entire prong to third-party management. It begins with the following: Prosecutors should also assess whether the company knows the business rationale for needing the third party in the transaction, and the risks posed by third-party partners, including the third-...
Day 15 | How do you evaluate a risk assessment? 15.01.2021 7:31
After you complete your risk assessment, you must then translate it into a risk profile. If your estimate of where your bribery risk is greatest is wrong, it will be an effort to address it. As Ben Locwin explained in his BioProcess International article, entitled “Quality Risk Assessment and Management Strategies for Biopharmaceutical Companies”: Once we have assessed risks and determined a pr...
Day 14 | Risk Assessments 14.01.2021 7:44
One cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based upon a risk assessment, to understand your organization’s business from the commercial perspective, how your organization has identified, assessed, and defined its risk profile and, finally, the degree to which the program devotes approp...
Day 13 | Institutional Justice and Fairness 13.01.2021 7:44
Companies have finally come to realize that institutional justice and fairness are perhaps the most basic tenet of any successful workplace. If employees believe they will be treated fairly, it will engender a level of trust that can work to not simply motivate employees but lead to a more successful workplace and, at the end of the day, a more profitable company. This encompasses the entire lifec...
Day 12 | Financial Incentives for Compliance 12.01.2021 7:32
One of the areas that many companies have not paid as much attention to in their compliance programs is compensation. However, the DOJ and SEC have long made clear that they view monetary structure for compensation, rewarding those employees who do business in compliance with their employer’s compliance program, as one of the ways to reinforce the compliance program and the message of compliance....
Day 11 | What is Effective Compliance Training? 11.01.2021 7:28
One of the key goals of any compliance program is to train employees in awareness and understanding of the FCPA; your specific company compliance program; and to create and foster a culture of compliance. While it seems axiomatic that compliance training is a mainstay of any best practices compliance program, the conversation around training has evolved over the years. The importance of determini...
Day 10 | The Use of Social Media in Compliance 10.01.2021 8:17
What is the message of compliance inside of a corporation and how it is distributed? In a compliance program, the largest portion of your consumers/customers are your employees. Social media presents some excellent mechanisms to communicate the message of compliance going forward. Many of the applications that we use in our personal communications are free or available at very low cost. Why not ta...
Day 9 | 360 Degrees of Compliance Communications 09.01.2021 8:02
A 360-degree view of compliance is an effort to incorporate your compliance identity into a holistic approach so that compliance is in touch with and visible to your employees at all times. It is about creating a distinctive brand philosophy of compliance which is centered on your consumers. In other words, it helps a compliance practitioner to anticipate all the aspects of your employees needs ar...
Day 8 | Internal Controls and Compliance 08.01.2021 8:02
What are internal controls? The best definition I have come across is from Jonathan Marks who defined internal controls as: An internal control is an action or process of interlocking activities designed to support the policies and procedures detailing the specific preventative, detective, corrective, directive and corroborative actions required to achieve the desired process outcomes or the obje...
Day 7 | Policies and Procedures 07.01.2021 8:02
There are numerous reasons to put some serious work into your compliance policies and procedures. They are certainly a first line of defense when the government comes knocking. The 2020 Update made clear that “Any well-designed compliance program entails policies and procedures that give both content and effect to ethical norms and that address and aim to reduce risks identified by the company as...
Day 6 | The Code of Conduct 06.01.2021 8:24
What is the value of having a Code of Conduct? In its early days, a Code of Conduct tended to be lawyer-written and lawyer-driven to wave in regulator’s face during an enforcement action as proof of ethical overall behavior. Is such a legalistic code effective? Is a Code of Conduct more than simply your company’s internal law? What should be the goal in the creation of your company’s Code of Condu...
Day 5 | The Board and Operationalizing Compliance 05.01.2021 8:17
In addition to a company’s senior management, there is a Board of Directors at the top. Yet the role of the Board is different than that of senior management. For the Board of Directors, the 2020 Update stated: Oversight – What compliance expertise has been available on the board of directors? Have the board of directors and/or external auditors held executive or private sessions with the complian...
Day 4 | Moving Compliance Tone Down Through An Organization 04.01.2021 8:17
Mike Volkov, in a blog post entitled “Mood in the Middle Versus Tone at the Top”, said, “Even when a company does all the right things at the senior management level, the real issue is whether or not that culture has embedded itself in middle and lower management. A company’s culture is reflected in the values and beliefs that exist throughout the company.” To fully operationalize your compliance...
Day 3 | Leadership’s Conduct At The Top 03.01.2021 8:17
Obviously, in every compliance program, the ethical tone of a company and accountability all starts at the top and, most specifically, senior management. The 2020 Guidance stated, “Beyond compliance structures, policies, and procedures, it is important for a company to create and foster a culture of ethics and compliance with the law at all levels of the company. The effectiveness of a compliance...
Day 2 | Continuous Monitoring and Continuous Improvement 02.01.2021 8:17
I want to next focus specifically on the tactical steps of moving towards both continuous monitoring and continuous improvement of your compliance program. These twin concepts are perhaps the biggest modifications in the 2020 Update. The changes began in Section 1- Risk Assessments. The question-by-question analysis begins with “Is the periodic review limited to a “snapshot” in time or based upon...
Day 1 | What 2020 Brought To Compliance Programs 01.01.2021 10:03
2020 was a very significant year for every compliance practitioner and compliance program. Not only was it the year with the single highest anti-bribery fine ever and highest annual amount of FCPA penalties. There were several significant enforcement actions, involving corporations coupled with a large number of individual prosecutions. Yet, perhaps most significantly, there were two noteworthy re...
Compliance training from the movies 30.12.2020 8:51
If there is one truism from the practices of law which translates to the practice of compliance it is that you are only limited by your own imagination. This holds true in the 360-degree realm of communication in compliance, as communications obviously comes in many forms. Many compliance practitioners will well remember the 2012 Morgan Stanley declination. In this first declination made public, t...
Measuring Compliance Training Effectiveness 29.12.2020 8:51
Since at least 2017, the DOJ has emphasized the need for a determination of compliance training effectiveness. In the 2020 Update, it stated under the section entitled, “Form/Content/Effectiveness of Training” the following questions, How has the company measured the effectiveness of the training? Have employees been tested on what they have learned? How has the company addressed employees who fai...
Compliance Training Frequency 28.12.2020 8:54
What should be your organization’s compliance training frequency? How does the amount of training can positively or negatively impact an overall training strategy? Unfortunately, these questions were not answered by the 2020 Update or the 2020 FCPA Resource Guide. Still every company should have a “well-designed compliance program is appropriately tailored training and communications.” Often comp...
Why You Should Have a Compliance Training Governance Committee 23.12.2020 8:54
One issue not often considered by compliance professionals around compliance training is that of compliance training governance. Yet a multinational organization subject to the FCPA faces many legal and regulatory risks and often many of those risks are "owned" by organizations that are outside of the compliance function. How can your organization, create a comprehensive compliance training progra...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.