Categories
Best Practices

Essential compliance tips for small businesses

Owners and managers of small businesses often may not recognize the immediate importance or value of implementing a compliance program. Small businesses, especially new ones, are concentrated on surviving financially, refining their market and/or products, and identifying themselves and their leaders in an appealing and sustainable way. With these priorities in sight, compliance may fade to seem to be an optional function, something that can be started up in the future or only when necessary or required. However, establishing a compliance program from the beginning can actually service all those priorities. There are several compliance values and practices which can be easily implemented to get any small business off to the right start.

  • Create a Compliance Manual: Similar to an Employee Handbook, a Compliance Manual is the one-stop reference bible for the policies and procedures necessary for running daily operations of the business. These can be concrete, such as policies governing equipment use, information systems, or reporting of workplace injuries, or conceptual, such as Code of Ethics, gifts and entertainment guidelines, or anti-harassment policy. The policies should be tailored to the needs of the business. Don’t be intimidated; they can be simple as well as being a work-in-progress. Contemplating what rules are needed to cover a business’s practices can help to define what those are as well as provide the fundamental structure that can always be scaled up in the future.
  • Raise compliance awareness among employees: Employee training is critical for fostering a culture of compliance. This is true even if the business is a sole proprietorship with only the employee-owner to educate. All organizations are impacted by local, state, and/or federal regulations in at least some area of their operations, and all businesses would benefit from a strong perspective on ethics and integrity. Compliance awareness doesn’t require a comprehensive or expensive suite of training materials. It can be as simple as discussing dilemmas about conflicts of interest, learning about and checking for updates from the regulator of the business’s industry, or keeping an eye out on developments with competitors, peers, and stakeholders that may indicate changing legal or risk landscapes or shifts in the market to anticipate.
  • Reward ethical behaviour and compliance adherence: Employee integrity and individual contributions to a culture of compliance should be considered basic factors in evaluating performance across the organization. Indicate to employees in all roles that their conduct matters and is a measurable part of their performance. This is the most powerful, direct way to set a tone that employee culture rewards and recognizes doing the right thing consistently and identifying with strong values that reinforce that as a priority.
  • Consider sustainability in the pursuit of profits: Small businesses are reasonably driven by the intention to make the money they need to earn in order to survive and eventually grow. However, the ends do not have to justify the means – the means by which business is done will be what defines the image of the company. A poor reputation or a business model that does not build relationships will be bad advertising for the business and emphasize short-term survival over long-term success. Clients and products should be chosen with a clear vision as to how they can scale and grow and what identity or purpose they serve now and in the future.
  • Assess risk: Get in the habit from the beginning of thinking strategically about risk. In concert with sustainability, having an accurate and reliable identification and assessment of the risks to the business will help to direct growth and act responsibly on ambitions. Challenging business procedures to brainstorm about risks and consider whether they are being protected against adequately can be straight-forward yet packs a big impact in business planning.

Encouraging sustainable business practices, reasonable risk tolerance, employee integrity, and organizational ethics are all accessible and easy to implement business values. A corporate culture that promotes these genuinely and early in its foundations is well-prepared for business success.

Categories
Best Practices

Tips for e-mail handling of confidential information

To most people it’s impossible to imagine the modern office without e-mail as the primary mode of communication. With the widespread popularity of tablets and smartphones moving our e-mail accounts from our desktops to our cell phone screens and everywhere in between, the risks attendant to this ubiquitous use of e-mail is always at the forefront of compliance concerns surrounding the handling of confidential information. To handle this, ongoing controls are advisable to ensure that the flow of information is protected and restricted to sharing on a need-to-know basis only.

  • Determine recipients carefully: Recipients should be determined case-by-case by the purpose of the e-mail. Senders should also consider whether the information is intended to be used internally (for information purposes only) or also at a later stage externally (such as for promotional purposes). In general, recipients should be as limited as possible. Include broader stakeholders more remote to the work that the confidential information concerns only insofar as they are known to be interested (for example Compliance, Legal, or other functions serving the business line). Seek to avoid administrative burden on the sender to update standing lists to tailor them to a particular message, as this is where human error can lead to inadvertent dissemination.
  • Consider most appropriate method of distribution: Use individual addresses, not group mailboxes, to control the recipients, as group mailboxes can be under collective and changing ownership. Posting messages on shared, secure intranet or internet sites may be an attractive alternative to e-mails. This can help to prevent accidentally incorporating unintended recipients, but the community or site needs to be closed and carefully administered.
  • Remember strict criteria for sharing confidential information: Generally, confidential information should only be shared on a need-to-know basis, not like-to-know. Possessing confidential information should be seen as a responsibility, not a privilege, and seeking access to this information or inclusion in communications that share confidential information should be discouraged unless there is a work necessity. As a broad rule, e-mails sent to individuals or groups without first informing them of their responsibilities with handling confidential information should contain public information only.
  • Seek review/approval before dissemination: Think of clicking “send” on an e-mail as publishing the information contained within it. Are your messages up to publication standards? It would be wise to have those which contain confidential information reviewed first by business management before circulation. Management should also be comfortable seeking advice from Compliance on whether sharing the information is appropriate in terms of content or recipients if necessary.
  • Include disclaimer language regarding forwarding/use of information therein: Even with the above points considered, it still could be wise to add disclaimer language to the e-mail to discourage erroneous distribution or misuse. E-mails can easily be printed, forwarded, or copied and pasted. Standard disclosure language could be, for an example: “Information in this transmission is intended only for the person(s) to whom it is directed. Any disclosure, copying, forwarding, re-publishing, or other dissemination of the information is unauthorized. No liability is accepted for any unauthorized use of the information contained herein.”

Using e-mail has become second nature to most people, but communicating confidential information always merits extra caution. Considering the above control framework can help to use e-mail more carefully and wisely to ensure that confidential information is not mishandled or inadvertently disseminated

Categories
Best Practices

Guiding principles for a compliance advisory practice

Guiding principles formalized in mission statements or charters have long been seen as essential to positioning businesses and individuals in them for success. Virtually every major organization has such a mission statement at the center of its business principles, which is used to succinctly define its internal strategy as well as it to represent the image it wishes to present to its stakeholders and the public. Famously, the business or personal mission statement is prominently featured in Habit 2 of Stephen R. Covey’s 7 Habits of Highly Effective people. This reasoning indicates that acting with a defined purpose and memorializing it by creating a formal mission statement for this credo gives power and motivation to decision-making. This concept can be powerfully applied to a compliance officer working within an advisory practice, a function which is greatly supported by having a basis in well-articulated guiding principles and values.

  • Express and adhere to a bright-lined scope within the advisory model. Defining and sticking to a scope is essential for success. The compliance officer’s role must be well-defined and meet shared objectives determined by business needs and risk awareness analysis. The compliance officer who fails to plan scope adequately, fails to plan in the grand scheme of efficient and strategic self-positioning.   An advisory model is not a finite scope of work, such as in the Legal function where an issue-limited “go or no-go” opinion is often expected. Nor is it an operational approach, such as in Human Resources, where queries on and exceptions to practices and procedures are handled case-by-case. Instead, the compliance advisory anticipates both solicited and unsolicited advices and focuses on building a practice with business management where both modes are equally appreciated and expected.
  • Promote a risk management profile consistent with the clearly-defined role of compliance. A successful compliance advisor must represent and broadcast a profile consistent with his or her position in an integrated system of compliance risk management. Ownership of risk must be thoughtfully distributed and articulated. In the popular three lines of defense model, for example, the business is responsible for management control in the first line. Independent assurance is owned by audit in the third line. Compliance sits in the second line responsible for risk and control oversight functions. Strict adherence to this model or any other defense structure is necessary to promote the establishment, implementation, and evaluation of effective controls.
  • Pro-actively align with colleagues in other functions to strengthen integrated efforts. Strategy for compliance advisors often focuses on gaining buy-in from business management.   Foundational to this, however, is successful cooperation with other functions that also face the business from on oversight perspective. Compliance advisors should value cooperation and coordinated efforts with close peers before communicating to others. This starts with fellow compliance colleagues but extends immediately to frequent partners such as Risk, Legal, Finance, and Human Resources. All of these functions succeed in their work because of reliable credibility within the organization. High cohesion among the partner functions is crucial to model collaboration and prevent the business from shopping across functions to find favorable outcomes.
  • Incorporate the spirit of customer excellence/continuous improvement practices. A compliance advisor should embrace a service-oriented and relationship-focused way of working. In a clear and evolving view of what is needed to support the compliance function and from whom, imbuing the role with a commitment to ongoing improvement of advice provided, with the cooperation and expertise that entails, will help to maintain relevance and flexibility. Feed-forward input from business partners and a focus on efficiency and evolution helps to make sure that compliance initiatives have the support they need to be implemented and compliance investments can be viewed as integral to business strategy.
  • Demonstrate added value to business partners. Successfully persuading management that compliance adherence can support commercial sustainability under the right circumstances, rather than undermine it, more than justifies the costs of implementing and maintaining effective compliance controls. In giving advices, compiling reporting, providing and analysing management information, and updating on the intersections of business objectives and regulatory developments, compliance advisors can earn trust by demonstrating integrity as a core practice. Once this becomes a genuine shared goal, compliance can not only add value to the business, but indeed be seen as an active participant in these interests.

The ideal compliance advisory profile is one of an individual who is trusted, professional, and collaborative.  This profile, in combination with strong guiding principles setting ground rules about scope, role, and sustainability via high standards and added value, is the basis for the compliance advisor’s way of working, promoting a progressive and professional profile that is visible to the business served and functional partners.

Categories
Best Practices

Compelling arguments to encourage business buy-in on compliance training

It is essential in all industries and job functions that employees act with integrity and in compliance with applicable rules and regulations, and this must be supported with adequate training. However, a common challenge for compliance professionals concerns how to successfully and sustainably convince senior business management to invest in and support compliance training as a priority. Regulatory changes and enforcement actions, and the necessity for ethical decision-making in the regular course of business, show us that compliance awareness should be valued.   Amidst the pressures of commercial activities, changing marketplaces and political environments, and time-sensitive daily necessities, though, training on compliance topics may not always seem urgent. However, there are important incentives which can be emphasized to business partners to encourage their buy-in on this critical training.

  • Compliance training fosters prized employee engagement and encourages transparency, which is necessary to mitigate reputational risk and enable whistle-blowers. Knowledge is power, and training empowers employees to use their understanding of the regulations and policies to show good conduct and to understand the importance of acting in compliance with regulations and policies, as well as the impact of unethical behaviour and the necessity of identifying and escalating misconduct where it occurs.
  • Once emboldened with knowledge by training, employees can take compliance topics forward into discussions and practical applications. Clarity and ease of discussion are important drivers of employee integrity. Simply put, individuals must first understand what they could do in order to follow a policy or regulation, before they can be asked to make a good choice in support of this. Libertarian paternalism suggests governance structures could affect behavior positively by influencing options available to deciders without disrespecting freedom of choice. Adequate training informs this approach, so that individuals have clarity and the ability to talk, ask questions, and work through scenarios in order to develop their own mental muscles on compliance topics on an everyday basis.
  • Employee awareness of compliance risk stimulates business management to act and react, creating a robust tone at the top. Senior management can be encouraged to contribute to a culture of compliance by a version of the “warm-glow” effect. Their buy-in is supported by an egoistic motivation derived from acting as role models to the employees they lead – a positive feeling that comes from being admired and adulated as an example. Employees who are actively informed about the values of compliance, ethical decision-making, and integrity will look for accountability and responsiveness from their leaders. When employees expect and emphasize this, management teams are enabled to reward good conduct and sanction misconduct, taking visible and precedent-setting action to recognize both.
  • The subject matter of compliance training is mostly accessible to employees at all levels. While some topics are more technical or demand a more academic approach to regulations and practices, the vast majority of compliance topics – to name a few, conflicts of interest, insider trading, information handling, money laundering and sanctions, anti-bribery, code of ethics – are, at least on an introductory level, practical and interesting to discuss without any prerequisite knowledge from the employees. In the post-2008 financial crisis world, many people have a good layperson’s understanding of these general concepts from the news. They even often have a desire to increase awareness and discuss these topics, but they need familiarity first. Basic sessions can give employees a first look, so that they are prepared to discuss with their colleagues and managers, while subsequent advanced sessions can develop comfort and expertise.
  • Targeted training on compliance topics helps to normalize expectations of risk ownership in an increasingly complicated regulatory and legal environment. Many employees may be open to challenging their ideas about their business practices that originated in the less comprehensive regulatory and legal landscape of the past, but they must be convinced to make compliance a daily consideration in their work. If they are not fluently aware of compliance concepts, then they may feel overwhelmed. This gives them the impression that either they are expected to be compliance officers themselves in addition to their regular tasks or that interaction with Compliance can only be a “tick the box” exercise. Neither outcome is desirable, yet both can be overcome by raising awareness and therefore promoting relevance.

The overall impression from the foregoing is that visibility with business partners is crucial for the compliance advisory function to succeed. All compliance professionals should seek to build relationships and interact on these compelling yet challenging topics in order to make them personally meaningful to business partners.