Thomas Fox
FCPA Compliance Report
The FCPA Compliance Report is the longest running podcast in the in compliance and business ethics. Join its award-winning host, Tom Fox, the Voice of Compliance as he visits with top compliance practitioners, key figures from business, the government and law firms in the top podcast dedicated to all things compliance.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Joanne Taylor on the UK Airbus Enforcement Action 17.02.2020 22:15
In the Episode, I visit with Joanne Taylor, Managing Director at K2, an industry leading investigative, compliance and cyber defense services firm. Joanne joined K2 Intelligence with 20 years of experience in legal, investigations, and financial crime compliance. This includes fraud risk management, anti-bribery and corruption, regulatory enforcement, and fraud investigations within leading intern...
James Koukios on the MoFo Top 10 International Anti-Corruption Developments for December 2019 10.02.2020 23:04
In the Episode, I visit with James Koukios, partner at Morrison & Foerster, Editor-in-Chief of the firm’s Top 10 International Anti-Corruption Developments. We visit about the firm’s Top 10 International Anti-Corruption Developments for December 2019. Some of the highlights include: South Korea Passes Bill to Establish New Anti-Corruption Agency. Four of the top 6 FCPA enforcement actions of all-t...
James Koukios on the MoFo Top 10 International Anti-Corruption Developments for November 2019 03.02.2020 23:57
In the Episode, I visit with James Koukios, partner at Morrison & Foerster, Editor-in-Chief of the firm’s Top 10 International Anti-Corruption Developments. We visit about the firm’s Top 10 International Anti-Corruption Developments for November 2019. Some of the highlights include: The Lambert guilty verdict. Can you have a guilty verdict for conspiracy without a conviction of the underlying offe...
Day 31 | Levels of due diligence 31.01.2020 10:56
Due diligence is generally recognized in three levels: Level I, Level II and Level III. Each level is appropriate for a different level of corruption risk. The key is to develop a mechanism to determine the appropriate level of due diligence and then implement that going forward. The question becomes how you use the information you obtained in the business justification and the questionnaire to de...
Day 30 | Using a root cause analysis for remediation 30.01.2020 9:24
We previously considered the Prong in the Evaluation that was not present in the Ten Hallmarks of an Effective Compliance Program; that being root cause analysis. The requirement was first raised in the 2017 Evaluation. It was then carried forward as a requirement in the FCPA Corporate Enforcement Policy, later in 2017. It was discussed again in the 2019 Guidance. You should begin with the questio...
Day 29 | What is a root cause analysis? 29.01.2020 9:24
Well known fraud investigator Jonathan Marks, defined a root cause analysis as “a research based approach to identifying the bottom line reason of a problem or an issue; with the root cause, not the proximate cause the root cause representing the source of the problem.” He contrasted this definition with that of a risk assessment which he said “is something performed on a proactive basis based on...
Day 28 | Post-acquisition integration plan 28.01.2020 9:24
Your company has just made its largest acquisition ever and your CEO says they want you to have a compliance post-acquisition integration plan on their desk in one week. Where do you begin? A good place to start would be the 2012 FCPA Guidance language: Pre-acquisition due diligence, however, is normally only a portion of the compliance process for mergers and acquisitions. DOJ and SEC evaluate wh...
Day 27 | Pre-acquisition due diligence in mergers and acquisitions 27.01.2020 9:24
A company that does not perform adequate due diligence prior to a merger or acquisition may face both legal and business risks. Perhaps most commonly, inadequate due diligence can allow a course of bribery to continue - with all the attendant harms to a business’s profitability and reputation, as well as potential civil and criminal liability. While most compliance practitioners have been long awa...
Philip Urofsky on the Shearman & Sterling 2020 FCPA Digest 27.01.2020 36:47
In the Episode, I visit with Philip Urofsky, partner at Shearman & Sterling, Editor-in-Chief of the firm’s most excellent FCPA Digest. We visit about the firm’s 2020 FCPA Digest, Recent Trends and Patterns in the Enforcement of the FCPA and consider some of the highlights from the report. We also take a deep dive into the issue of agency under the FCPA, which was a major legal issue in the Hoskins...
Day 26 | Operationalizing compliance through payroll 26.01.2020 9:24
One of the areas articulated in the 2019 Guidance was around payments and payroll. For the both the compliance professional and the corporate payroll function, there is a significant role to play in the operationalization of a corporate compliance program. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) was replete with references to payment and its critical nat...
Day 25 | Compliance function in an organization 25.01.2020 9:24
The role of the compliance professional and the compliance function in a corporation has steadily grown in stature and prestige over the years. When it came to the corporate compliance function, 2012 FCPA Guidance, under Hallmark Three of the Ten Hallmarks of an Effective Compliance Program, simply noted the government would “consider whether the company devoted adequate staffing and resources to...
Day 24 | CCO authority and independence 24.01.2020 9:24
The role of the CCO has steadily grown in stature and prestige over the years. In the 2012 FCPA Guidance, under Hallmark Three of the Ten Hallmarks of an Effective Compliance Program, it focused on the whether the CCO held senior management status and had a direct reporting line to the Board; stating: In appraising a compliance program, DOJ and SEC also consider whether a company has assigned resp...
Day 23 | Updates and feedback 23.01.2020 9:24
One of the critical elements found in the 2019 Guidance is the need to use the information you obtain, whether through risk assessment, root cause analysis, investigation, hotline report or any other manner to remediate the situation which allowed it to arise. It stated: Evolving Updates – How often has the company updated its risk assessments and reviewed its compliance policies, procedures, and...
Day 22 | Assessing compliance internal controls 22.01.2020 9:28
Control Testing – Has the company reviewed and audited its compliance program in the area relating to the misconduct? More generally, what testing of controls, collection and analysis of compliance data, and interviews of employees and third-parties does the company undertake? How are the results reported and action items tracked? Fortunately, the Committee of Sponsoring Organizations of the Tr...
Day 21 | Continuous improvement in a compliance program 21.01.2020 9:25
The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) was very clear about the need for continuous improvement in any compliance program. It stated quite succinctly, “One hallmark of an effective compliance program is its capacity to improve and evolve. The actual implementation of controls in practice will necessarily reveal areas of risk and potential adjustment. A...
Day 20 | Responding to investigative findings 20.01.2020 9:38
There is nothing like an internal whistleblower report about a compliance violation, the finding of such an issue, or (even worse) a subpoena from the DOJ or notice letter from the SEC to trigger the Board of Directors and senior management attention to the compliance function and the company’s compliance program. Such an event can trigger much gnashing of teeth and expressions of outrage followed...
Dave Lefort on 10 Stories CW Will Follow in 2020 20.01.2020 35:28
In the Episode, I visit with Dave Lefort, Editor in Chief for Compliance Week. Dave recently wrote “It’s hard to tell whether the age we’re living in is the calm before the storm or if it is the storm. One way or another, we’ll likely get some clarity in the year ahead for CCOs navigating these choppy waters.” I asked him to come on the podcast and discuss his 10 predictions on what will dominate...
Day 19 | The investigation protocol 19.01.2020 9:24
After the internal report comes in and you have properly triaged the matter, you need to scope out and investigate it, promptly, thoroughly and with competent personnel. Your company should have a detailed written procedure for handling any complaint or allegation of bribery or corruption, regardless of the means through which it is communicated. The mechanism could include the internal company ho...
Day 18 | Internal reporting and the triaging of claims 18.01.2020 9:24
The call, email or tip comes into your office; an employee reports suspicious activity somewhere across the globe. That activity might well turn into a FCPA issue for your company. As the CCO, it will be up to you to begin the process which will determine, in many instances, how the company will respond going forward. This scenario was driven home by the SEC in a 2015 FCPA enforcement action invol...
Day 17 | Managing your third parties 17.01.2020 9:49
The building blocks of any compliance program lay the foundations for a best practices compliance program. For instance, in the life cycle management of third parties, most compliance practitioners understand the need for a business justification, questionnaire, due diligence, evaluation and compliance terms and conditions in contracts. However, as many companies mature in their compliance program...
Day 16 | The third-party risk management process 16.01.2020 9:49
As every compliance practitioner is well aware, third parties still present the highest risk under the FCPA. The Evaluation of Corporate Compliance Programs - Guidance Document (2019 Guidance) devotes an entire prong to third-party management. It begins with the following: A well-designed compliance program should apply risk-based due diligence to its third-party relationships. Although the degree...
Day 15 | How do you evaluate a risk assessment? 15.01.2020 9:49
After you complete your risk assessment, you must then translate it into a risk profile. If your estimate of where your bribery risk is greatest is wrong, it will be an effort to address it. As Ben Locwin explained in his BioProcess International article, entitled “Quality Risk Assessment and Management Strategies for Biopharmaceutical Companies”: Once we have assessed risks and determined a pro...
Day 14 | Risk Assessments 14.01.2020 9:49
One cannot really say enough about risk assessments in the context of anti-corruption programs. This is because every corporate compliance program should be based upon a risk assessment, to understand your organization’s business from the commercial perspective, how your organization has identified, assessed, and defined its risk profile and, finally, the degree to which the program devotes approp...
Day 13 |Institutional Justice and The Fair Process Doctrine 13.01.2020 9:49
Companies have finally come to realize that institutional justice and fairness are perhaps the most basic tenet of any successful workplace. If employees believe they will be treated fairly, it will engender a level of trust that can work to not simply motivate employees but lead to a more successful workplace and, at the end of the day, a more profitable company. This encompasses the entire lifec...
André H. Paris on the Brazilian Compliance Scene 13.01.2020 19:49
In the Episode, I visit with André H. Paris, a Brazilian Compliance Consultant and Lawyer. He is a specialist in building a Corporate Culture based on Ethics, Transparency and Respect. Paris has experience in Corporate Risk Analysis and Management, as well as in Protecting Corporate Reputation and Crisis Management. He is also quite enthusiastic on building a more ethical and transparent business...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.