Thomas Fox
31 Days to a More Effective Compliance Program
Tom Fox is the Compliance Evangelist and is universally recognized as one of the top experts in corruption compliance, literally across the globe. In this daily podcast series, he explains how to design, create and implement a best practices compliance program. Each month, he tackles a different area of compliance. From Internal Controls, to the Role of the Board of Directors, to Communication, to the Role of HR in Compliance, Investigations, 3rd Parties and Business Ventures. Listen in each day and get one tip you can implement at little or no cost to enhance your compliance program.
Author
Thomas Fox
Category
Podcast website
Latest episode
Jan 31, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Operationalization of your Code of Conduct 11.05.2020 9:19
How can you work to operationalize your Code of Conduct as articulated in the DOJ 2019 Guidance? The 2019 Guidance focuses not on whether a company has a paper compliance program but whether a company is actually doing compliance. A company does compliance by moving it into the functional business units as a part of an overall business process. That is what makes a compliance program effective at...
Training on your Code of Conduct 08.05.2020 9:19
What about the training on your finalized Code of Conduct? While there have been criticisms of code training, if you consider training as one source of your 360-degrees of compliance communications, the rollout of a new or updated code can be an opportunity. This rollout fits directly into the concept of 360-degrees of compliance communications as rollout is part of both communications and engagem...
Design of your Code of Conduct 07.05.2020 9:19
Next is the design of your Code of Conduct. Through attention to detail in the design process, you should be able to come out at the end with a code which will help you to more fully operationalize your compliance program. You must begin with a determination of what you are trying to accomplish. It does not serve you to try and list every compliance risk you might think your company may encounter....
Code of Conduct: Structure and format 06.05.2020 9:19
Next comes the evolution of the structure and format of a best practices Code of Conduct. Initially, my experience with this is that they were written by lawyers, largely for lawyers. This included ‘thou shalts’ and ‘thou shalt nots’ liberally sprinkled throughout a lengthy written document. This was what is now referred to as Code 1.0. The compliance community then evolved to Code 2.0, where the...
Code of Conduct 05.05.2020 9:19
What is the value of having a Code of Conduct? I have heard many business folks ask that question over the years. In its early days, a Code of Conduct tended to be a lawyer-written and lawyer-driven document to wave in regulator’s face during an enforcement action by using it to claim, “we are an ethical company”. Is such a legalistic code effective? Is a Code of Conduct more than simply your comp...
Clearly articulated written standards 04.05.2020 9:19
The written standard requirements have long been memorialized in the U.S. Sentencing Guidelines, which contain seven basic compliance elements that can be tailored to fit the needs and financial realities of any given organization. From these seven compliance elements, the DOJ has crafted its minimum best practices compliance program, which is now attached to every DPA and NPA issued. These requir...
Introduction to written standards 01.05.2020 6:12
The cornerstone of any best practices compliance program is written protocols. This includes a Code of Conduct, policies and procedures. These elements have long been memorialized in the US Sentencing Guidelines; the Department Of Justice’s (DOJs) Opinion Releases regarding compliance programs, the 2012 FCPA Guidance, both DOJ and Securities and Exchange Commission (SEC) enforcement actions, the 2...
Conclusion to continuous improvement in a compliance program 30.04.2020 9:19
Over the course of this month, I have presented a variety of specific tools and techniques for the compliance practitioner to utilize to continuous improve their compliance regime. They include financial audit, the culture audit, controls monitoring, various risk management strategies which can become continuous monitoring. The tools are both quantitative and qualitative. Pick and choose the right...
Use of social media for continuous improvement 29.04.2020 9:19
Compliance does not exist in a time-warp vacuum, with compliance programs living in 1977 when the first major anti-corruption legislation, the FCPA, was passed. The law has advanced since that time, as has compliance and society as well. One of the ways that you can engage in continuous improvement for your compliance program is based upon the two-way use of social media. Social media can be used...
Email sweeps for continuous improvement 28.04.2020 9:19
The 2012 FCPA Guidance specified, “a good compliance program should constantly evolve. A company’s business changes over time, as do the environments in which it operates, the nature of its customers, the laws that govern its actions, and the standards of its industry. In addition, compliance programs do not just exist on paper but are followed in practice will inevitably uncover compliance weakne...
Continuous Improvement Through Compliance Program Upgrades 27.04.2020 9:19
Continuous improvement can come in many different, shapes, sizes and packages. As with all things compliance, you are only limited by your imagination. Have you ever thought about a tech implementation as a way for continuous improvement? Probably not but it is also a way forward for continuous improvement. Think about that for a moment as this is taking the concept of continuous improvement and a...
Proactive monitoring for continuous improvement 24.04.2020 9:19
There are multiple areas in the DOJ’s 2019 Guidance which intersect with the area of continuous improvement. They include the following: Prior Indications – Were there prior opportunities to detect the misconduct in question, such as audit reports identifying relevant control failures or allegations, complaints, or investigations? What is the company’s analysis of why such opportunities were miss...
Measuring the effectiveness of a compliance program 23.04.2020 9:19
Determining effectiveness is a key part of continuous improvement. Yet how to do so still bedevils many compliance professionals. You need to consider both outcomes and outputs. Outcomes will show you the results of specific actions, such as investigations and conclusions to them. Numbers are attractive because they can form a “straight line” about how your compliance program is functioning. But y...
Using Data For Continuous Improvement 22.04.2020 9:19
Vince Walden has posited that “the black box is dead”. He meant that there is no single tool to use to identify high-risk transactions, customer, employees or third parties. Yet, it is now even easier to ask big insightful questions from your data. Every compliance professional should embrace this. Properly seen, compliance is a business process. As such you should keep in mind certain queries, su...
Big data and continuous improvement 21.04.2020 9:19
Consider again the use of big data, this time to facilitate continuous improvement. Alistair Croll, in an eBook entitled “Planning for Big Data” published by O’Reilly Radar, informs this discussion of continuous improvement in a best practices compliance program. Croll believes that big data will allow continuous improvement through the “feedback economy.” This is a step beyond the information eco...
Keeping track of current events for continuous improvement 20.04.2020 9:19
Keeping track of current events for continuous improvements a part of the mandates found in the 2019 Guidance. The DOJ clearly expects companies to update its risk assessment, policies, procedures and practices in light of changing circumstances. This means that if a third-party changes characteristics, so that it becomes subject to FCPA scrutiny, a company must be able to evaluate and react appro...
Monitoring for continuous improvement 17.04.2020 9:19
Another mechanism for continuous improvement of your compliance program is through risk-based monitoring. Under the topic of Control Testing DOJ’s 2019 Guidance posed the following questions, Has the company reviewed and audited its compliance program in the area relating to the misconduct? More generally, what testing of controls, collection and analysis of compliance data, and interviews of empl...
The mock audit 16.04.2020 9:19
A program manager in a power plant process group told me about the “mock audit” that his company performs in its power plants across the country. He explained that his industry is heavily regulated at both the state and federal level. Power plants are subject to numerous levels of oversight including various ISO standards to which they must comply. ISO is the International Organization for Standar...
The Integrity Audit 15.04.2020 9:19
Yet another way to consider using audit for continuous improvement is through the Integrity Audit. Mary Jo White in an article entitled “What I’ve Learned About White Collar Crime” provided insight into not only white-collar criminals but the integrity of companies. Her framework lays out a way for you to think through an underutilized tool for continuous improvement, the integrity audit. When Mar...
The Fraud Audit 14.04.2020 9:19
Consider how a fraud audit using data analytics can help to detect or prevent bribery and corruption where the primary sales force used by a company are China based employees defrauding their company by using false expense reports to create a pot of money to use as a slush fund to pay bribes. Here you can think back to the Eli Lilly FCPA enforcement action up to the GSK problems as examples of whe...
The culture audit 13.04.2020 9:19
What is organizational culture? Eric R. Feldman, SVP at Affiliated Monitors Inc. (AMI), has said it comprises the mission, vision and values of an organization. A similar way to consider it might be as a company’s values, visions, norms and beliefs. Whichever way you define it or look at it, corporate culture affects how groups within a company interact with each other. A key inquiry is whether th...
Supply Chain audits 10.04.2020 9:19
In my last corporate position, my company was at the compliance forefront because we required compliance related audits for vendors in the supply chain. This was cutting edge in 2007-08. However, now an audit for adherence to compliance requirements has become a standard best practice in the management of business relationships with third-party vendors in the supply chain. In several settlements o...
Financial health of third-parties 09.04.2020 9:19
Continuous improvement can take many ways, shapes and forms. One thing that is most generally not considered is the financial health of the third-party. It turns out such an oversight may have some significantly ramifications for an accurate picture of a third-party. The financial health of third-parties is not only a key metric but also a key due diligence tool which allows a more robust assessme...
Monitoring of third-parties 08.04.2020 9:19
How can data analytics be used for continuous improvement where the primary sales force used by a company is third-parties? A clear majority of FCPA violations and related enforcement actions have come from the use of third-parties. While sham contracting (i.e., using a third-party to conduit the payment of a bribe) has lessened in recent years, there are related data analysis that can be performe...
Auditing of third-parties 07.04.2020 9:19
Third-parties still present the highest risk around compliance. Indeed, in the area of third-parties the 2019 Guidance, posed the following question in a section entitled, Management of Relationships – How has the company considered and analyzed the compensation and incentive structures for third parties against compliance risks? How does the company monitor its third parties? Does the company hav...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.