Thomas Fox
31 Days to a More Effective Compliance Program
Tom Fox is the Compliance Evangelist and is universally recognized as one of the top experts in corruption compliance, literally across the globe. In this daily podcast series, he explains how to design, create and implement a best practices compliance program. Each month, he tackles a different area of compliance. From Internal Controls, to the Role of the Board of Directors, to Communication, to the Role of HR in Compliance, Investigations, 3rd Parties and Business Ventures. Listen in each day and get one tip you can implement at little or no cost to enhance your compliance program.
Author
Thomas Fox
Category
Podcast website
Latest episode
Jan 31, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Opinion Release 14-02: Dis-linking illegal conduct 05.10.2020 12:03
One of my favorite words in the context of FCPA enforcement is dis-link. It a useful adjective in explaining how certain conduct by a company must be separated from the winning of business and more broadly it works on many different levels when discussing the FCPA. The concept of dis-linking was most prominently laid out in Opinion Release 14-02. It provided one of the most concrete statements fro...
Key M&A cases under the FCPA 02.10.2020 12:22
What are some of the key FCPA enforcement actions involving M&A? These enforcement actions, FCPA Resource Guide and the Evaluation of Corporate Compliance Program (and Update) have all made clear that the DOJ and SEC will vigorously prosecute companies which allow bribery and corruption to continue after a merger or purchase occurs. The key point to remember is that if a company was engaging in br...
Introduction to Business Ventures 01.10.2020 10:20
We next consider how to create a more effective compliance program involving business ventures. This will include the role of compliance in M&A, JV agreements, distributorships, teaming agreements and franchises as well as other forms of business relationships. The FCPA Resource Guide, 2nd edition made clear that one of the Hallmarks of An Effective Compliance Program is around M&A, in both the p...
Culture as a Foundational Internal Control 30.09.2020 13:08
To conclude this month's series on Internal Controls, I am joined by Vin DiCianni, Founder and CEO of AMI. We discuss how corporate culture is a foundational internal control. It is a fascinating topic that is not discussed enough by compliance professionals. 3 Key Takeaways. It must start at the top. Hiring is critical to creating and sustaining an ethical culture. Creative internal controls a...
Gap Analysis 29.09.2020 11:49
A gap analysis is a method of assessing the differences in performance between a business’ internal controls to determine whether business requirements are being met and, if not, what steps should be taken to ensure they are met successfully. Moreover, it is a determination of the degree of conformance of your organization to the requirements of an internal controls standard. A gap analysis is mai...
Assessing compliance internal controls under COSO 28.09.2020 9:19
Next, consider what COSO says about assessing compliance internal controls. In its Illustrative Guide, COSO laid out its views on “how to assess the effectiveness of its internal controls.” It went on to note, “An effective system of internal controls provides reasonable assurance of achievement of the entity’s objectives, relating to operations, reporting and compliance.” Moreover, there are two...
COSO Objective V: Monitoring Activities 25.09.2020 9:38
The fifth and final Objective is Monitoring Activities and as with all other components of the COSO Cube, Monitoring Activities are part of an inter-related whole and cannot be taken singularly. For the CCO or compliance practitioner, Monitoring Activities has been growing in importance over the past few years and will continue to do so in the future as is reinforced in the COSO 2013 Internal Cont...
COSO Objective IV: Information and Communication 24.09.2020 11:00
As with the other components of the COSO Cube, the objective of Information and Communication is not to be taken in a vacuum. Indeed, one of the more interesting aspects of this objective is that it runs not only vertically but also horizontally. Principle 13: Use of relevant and quality information. Principle 14: Communicate internally. Principle 15: Communicate externally. Discussion. Obviously...
COSO Objective III: Control Activities 23.09.2020 9:37
In its Framework Volume, COSO Control Activities “are the actions established through policies and procedures that help ensure that management’s directives to mitigate risks to the achievement of objectives are carried out.” They should be performed at all levels in an organization’s process cycle. Principle 10: Selects and develops controls activities. Principle 11: Selects and develops general...
COSO Objective II: Risk Assessments 22.09.2020 11:24
Objective II is designed to provide a company with a dynamic and iterative process for identifying and assessing risks. For the compliance practitioner, none of this will sound new or even insightful, However the Framework requires a component of management input and oversight that was perhaps not as well understood. The objective of Risk Assessment consists of four principles. Principle 6: Suita...
COSO Objective I: Control Environment 21.09.2020 11:33
The first of the five objectives is control environment and it sets the tone for the implementation and operation of all other components of internal control. It begins with the ethical commitment of senior management, oversight by those in governance, and a commitment to competent employees. The five principles of the control environment object are as follows: Principle 1: Commitment to integrit...
What is the COSO 2013 Internal Controls Framework? 18.09.2020 10:56
COSO was adopted in 1992 as a framework for basis to design and then test the effectiveness of internal controls. In 2010, it was deemed necessary to update this more than 20-year old COSO Framework, to provide a more supportable approach when adversarial third parties challenged whether a company has effective internal controls (such as the SEC). While the COSO 2013 Internal Controls Framework is...
Code of Conduct as an internal control 17.09.2020 12:53
In 2016, one of the most interesting non-international focused FCPA enforcement actions was announced by the SEC. It involved a clear quid pro quo benefit paid out by United Airlines, Inc. to David Samson, the former chairman of the Board of Directors of the Port Authority of New York and New Jersey, the public government entity which has authority over, among other things, United’s operations at...
Board of Directors’ oversight as an internal control 16.09.2020 10:38
Is a Board of Directors a compliance internal control? The clear answer is yes. In the 2020 FCPA Resource Guide, Hallmarks of an Effective Compliance Program, there are two specific references to the obligations of a Board in a best practices compliance program. One states, “Within a business organization, compliance begins with the Board of Directors and senior executives setting the proper tone...
Internal controls for gifts, travel and entertainment 15.09.2020 9:13
It is reasonable to expect that internal controls over gifts, travel and entertainment be designed to ensure that they satisfy the criteria as defined in company policies. These are narrow, including a definition of the dollar limit, which must not be exceeded for gifts to be permissible, coupled with some subjective criteria such as the legality of the gifts for the recipient and whether the prac...
Internal controls for third parties 14.09.2020 9:50
One of the questions GSK faced during the bribery and corruption investigation of its Chinese operations was how an allegedly massive bribery and corruption scheme occurred? Where were the appropriate internal controls? You might think that a company as large as GSK and one that had gone through the ringer of a prior DOJ investigation resulting in charges for off-label marketing and an attendant C...
Implementing internal controls 11.09.2020 13:21
Next, I consider some ways in which a compliance professional can work to implement internal controls in a multi-national organization. The first step is to convert your company’s compliance risks into internal control objectives. The internal control objectives are then given to each business unit with instructions to develop controls, which meet the objectives. This process should allow more of...
Mapping Internal Controls 10.09.2020 9:56
As they made clear with several FCPA enforcement actions in 2020, the SEC has continued to emphasize the accounting provisions of the FCPA, specifically the internal controls provisions. Charles Cain, the Chief, FCPA Unit; Division of Enforcement of the SEC, reiterated that the SEC is committed to protecting investors in U.S. public companies and those which list other securities in the U.S., thro...
Risk assessments and internal controls 09.09.2020 10:54
Next, I will review how to use the risk assessment you have performed as a tool to provide a structured approach to establishing effective internal controls. After preparation of the risk assessment, the next step is to prioritize the listing of the risks and which locations they are common. This begins by mapping existing internal controls to risks and then assessing whether the internal controls...
Assessing internal controls in international operations 08.09.2020 12:56
How should you assess your internal controls regime for international operations? It is incumbent that you need to review as much information as you can to understand the financial and operational structure of an entity and how it is integrated with the corporate headquarters, or the U.S. business unit’s financial and operation structure, if the foreign operation is part of a U.S. business unit. ...
Internal controls in international locations 04.09.2020 10:48
Next, I want to consider some of the issues around internal controls outside the U.S. and why your company’s internal controls might require changes for different countries across the globe. However, this provides an opportunity to further operationalize your compliance program through internal controls more narrowly tailored to mirror your business practices. Every CCO should consider entity-wide...
The four key internal controls for compliance 03.09.2020 11:39
There are four significant controls that I would suggest the compliance practitioner implement initially. They are: 1) DOA; 2) maintenance of the vendor master file; 3) contracts with third parties; and 4) movement of cash/currency. Your DOA should reflect the impact of compliance risk including both transactions and geographic location so that a higher level of approval for matters involving thir...
Discipline and rigor in your internal controls 02.09.2020 10:53
New York Times columnist David Brooks’ thoughts on building and maintaining order inform the discussion on rigor in your internal controls. In internal controls, I believe it is incumbent to consider not only the most obvious risk areas for your internal controls but also the universe of potential transactions within the operations of a company. There is a clear need for rigor in your internal con...
What are internal controls? 01.09.2020 12:53
What specifically are internal controls in a compliance program? Internal controls are not only the foundation of a company but are also the foundation of any effective anti-corruption compliance program. Internal controls expert Joe Howell, former Executive Vice President (EVP) at Workiva, Inc., has said that internal controls are systematic measures, such as reviews, checks and balances, methods...
Twenty questions directors should ask about its Compliance Committee 28.08.2020 10:43
In an area of inquiry entitled Oversight, the 2020 Update asks three basic questions which we have explored throughout this chapter: What compliance expertise has been available on the Board of Directors? Have the Board of Directors held executive or private sessions with the compliance function? What types of information has the Board of Directors examined in their exercise of oversight in the a...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.