Categories
Compliance and ethics business case studies

Silicon Valley and undoing the normalization of sexism as corporate culture

Much of the attention on Silicon Valley in recent months has been not for new technological innovations or advances in the markets. Unfortunately, the public discussion surrounding the high-tech and start-up world, and the individuals and companies that finance that industry, has been focused on worst practices for corporate cultures. As society at large grapples with gender equity, racial and ethnic representation, generational workstyles, politics in the workplace, and many other diversity challenges, the most frequent conclusion seems to be that the state of things in 2017 is not as progressive or integrated as may have been assumed.

Many high-profile Silicon Valley organizations have coped with this revelation of corporate intolerance very publicly. Among them is Kleiner Perkins Caulfield & Byers, a high-profile venture capital firm. Managing partner John Doerr was an investor in some of the highest profile first generation technology companies to come to market: Intuit, Netscape, Amazon, Google. When he hired Ellen Pao in 2005 as his chief of staff, it seemed like he was assertively signalling that Kleiner Perkins wanted to take the lead on elevating qualified women to visible leadership roles in Silicon Valley, where men have overrepresented women in management, and within the even more traditionally male-focused venture capital domain.

Pao’s experiences throughout her tenure at Kleiner Perkins, capped off with her 2015 gender discrimination lawsuit and her firing before that lawsuit came to trial, indicate a different environment. Rather than being valued for her contributions and promoted on her merits, Pao alleges that she was harassed after a workplace romance went bad and that she was often marginalized in her role, expected to take on essentially personal assistant type duties while investing or higher level tasks went to male colleagues. Instead of contributing to a gender-integrated workplace where individuals were elevated for their accomplishments, insights, and commitment to their jobs, Pao paints the picture of a dysfunctional and increasingly hostile environment.

Kleiner Perkins did not have policies or training against sexual harassment at the time Pao worked there. A control framework to identify, prevent, and address these corporate culture issues is imperative. Any company that does not set a tone on these matters and take the time to thoughtfully and proactively set expectations for an integrated, balanced organizational culture demonstrates no credible commitment to workplace equality and the merits of the diversity of viewpoints this brings with it.

Many cultural changes have been underway for so long that they are taken for granted or even pushed against by now as creating an undue burden in the other direction. The truth, however, is that these movements toward a more balanced, integrated workplace are still stymied by a lack of genuine commitment. Ideally the office would looks much more the best version of the world, where people are elevated for their merits and not their demographic traits, and are not kept from even getting on the road to success because of someone else’s decisions about their right to work because of a trait like gender. In order for this to really develop, though, leaders in business (both established ones like Kleiner Perkins and start-ups who are defining their corporate values for the first time) need to take ethical stock of where they stand and if they can commit to creating a culture where all people are accepted and utilized for their merits, then they need to do so visibly and meaningfully. The time of tokenism or promises without true intention needs to be past so that people of all kinds can get into legitimate leadership positions and then pay it forward to the next generation behind them.

Pao did not prevail in her lawsuit, but perhaps it will endure anyway as a test case. While it did not result in a guilty verdict, cases like this one can be a cultural watershed for policy and enforcement standards in companies to mitigate legal risk. Perhaps also other women working in, or fired from, Silicon Valley under similar circumstances can see where Pao succeeded and failed in her legal strategy and take up the cause on their own behalves. Bringing these issues into the public light can certainly drive change in creating a cultural imperative for women in tech to speak up and out.

For more insight on Pao’s experiences in Silicon Valley and happened with her lawsuit against her former employer, see this excerpt from her book on The Cut, originally from New York Magazine.

Categories
Compliance in current and historical events

Cybersecurity and the hacking of Hollywood

Cybersecurity appears near the top of any compliance officer’s risk assessment. Addressing the ever-evolving concerns around it is a priority on the strategic annual plan for any compliance program. Modern society’s reliance on technology and the internet is always increasing. Along with the many benefits of technology’s interconnectedness and conveniences comes risks to data privacy, information theft, unauthorized intrusions, and security breaches.

While all businesses are vulnerable to these threats, recently the spotlight has been on Hollywood and some high-profile hacking campaigns that have seriously impacted the entertainment industry. Damaging emails have been published, produced shows and scripts have been ransomed, and private photos have been leaked due to storage and server facilities being breached.

  • In November 2014, Sony Pictures was hacked by a group calling itself Guardians of Peace. The cyberattack used malware to steal and then overwrite and delete the data on half of Sony’s computer network worldwide. Not only did Sony have to deal with a major technology infrastructure crisis, but shortly after, the leaks began. The stolen data from the company that was subsequently published ranged from embarrassing personal emails of executives and celebrities to unreleased movies to sensitive employee information. The hack was eventually blamed on North Korea and their effort to suppress the film The Interview, a claim which is still disputed by some today. The fallout from the cyberattack and the insufficiency of the company’s preparations against it offer many difficult lessons in cybersecurity and corporate defences within it: Inside the Hack 
  • Netflix was compromised by a hacker going by the name thedarkoverlord, who posted ten episodes of the network’s hit show Orange is the New Black to a torrent site on the internet. The leak occurred after a ransom request was not met, first by a production vendor affiliated with Netflix and then by Netflix itself, demonstrating that cybersecurity at third-party vendors can also be a business risk: A Group Of Hackers Is Holding Hollywood Captive — & Here’s What It Wants
  • In another ransom case, Disney suffered a hack involving the latest movie in the Pirates of the Caribbean franchise, compromised while on the servers of a post-production facility. Work is often sent out to vendors in the industry who will do it for the lowest cost, but may not promise the most robust network security to prevent intruders from accessing the content and ransoming it to the owners. This phenomenon is becoming increasingly common and expensive: Cyberattacks once again roil Hollywood, but can anything be done about it?
  • HBO sustained a major cyberattack, possibly from various sources, on their servers which demonstrate how vulnerable major organizations can be to leaks, hacks, and social media hijackings. This event shows that HBO, and other organizations like it, face cybersecurity threats from a variety of sources: suppliers, insiders, intruders, and more. Ransom demands were involved here too, but other threats seemed designed just to test security protocols or to intimidate and embarrass: Breaking Down HBO’s Brutal Month of Hacks
  • Other than content owners such as networks and studios, Hollywood talent agencies, such as UTA, ICM, and WME, have all also been the target of cyberattacks. In the case of UTA, the intrusion occurred through the phone system and spread from there to the computer network, with a ransom demand following. Many of these hackers openly acknowledge they are motivated just by financial gains from ransom payments, so some companies are being advised to pay up and avoid damaging or embarrassing information and valuable content being leaked online: FBI Gives Hollywood Hacking Victims Surprising Advice: “Pay the Ransom”

The increasing frequency and visibility with which the technological systems of Hollywood companies are being targeted for cyberattacks indicates that this will remain a top risk for some time to come. The threats to the reputations of individuals and organizations involved, as well the economic and reputational risks, require that lessons learned from the situations above be implemented into practical and technological improvements to cybersecurity programs.

Categories
Best Practices

Compliance practices for encouraging whistleblowers

Whistleblowers are people who speak up to expose information or activities indicating wrongdoing by individuals, departments, or organizations. They may reveal this information internally, such as to a supervisor or to a designated business unit or hotline. They may also reveal it externally, such as to regulators, supervisors, or the media. Corporate cultures should enable employees to have the courage and compulsion to act as whistleblowers in situations where it may be necessitated.

  • Set clear expectations for conduct: The most ethical corporate culture is one that has clear values and norms which can be expressed and reinforced at all levels. A culture in which expectations about employee and organizational integrity are expressed openly and referred to in justifying business decisions is a culture where employees will also be comfortable challenging behavior and choices which appears to fall outside of those expectations. An organization’s culture should be openly intolerant to unethical behavior and explicit about the right processes and practices. This way, deviations can be easy to see for participants and ethical blindness or responsibility shifting can be replaced with compliance awareness and individual accountability. People will have the confidence to speak up about wrongdoing if they are certain that they know and believe in what the right action should be.
  • Model speaking out from the top: The tone at the top is an important driver of whistleblowing. Employees should see that leadership also speaks up boldly against wrongdoing and admits to shortcomings or omissions. Senior management and/or supervisory board members should be visibly engaged in seeking to prevent, identify, and correct inappropriate conduct and practices. If employees see that those at the top of the organization are reinforcing the cultural principle of exposing problems, then they will respect the necessity of this role and be empowered to take it seriously.
  • Facilitate ease of access to reporting: A major reason why employees do not take action is because they do not know how. All employees should be provided with information about whistleblowing procedures and given the opportunity to ask questions and check understanding, including discussing dilemmas, about when whistleblowing would be appropriate or applicable. It is also imperative that the mechanism for the whistleblowing, once the employee endeavors to do so, is accessible and publicized. If there is a hotline, a dedicated mailbox, or a specific person to reach out to, then employees should be able to find and follow the procedure without being discouraged by undue difficulty of the process.
  • Provide active feedback: People will not act as whistleblowers if they believe nothing will come of their reporting. Organizations must actively recognize people who come forward and keep them as informed as possible of steps that are being taken. Employees must know that if they step up to report an issue, they will be listened to meaningfully and that the appropriate people will take action. Constructively listening to the person who is whistleblowing is the first necessary step. Then, the employee should be kept informed of what will follow and, once any investigations are complete, the outcome. This way the employee knows that taking on the responsibility and risk of stepping forward will be attended to with the appropriate seriousness.
  • Control against retaliation: Most importantly, whistleblowers should be protected and shielded from recrimination. While false claims or dubious motivations need to be discouraged, genuine whistleblowers who wish to reveal and stop harmful business practices should not be punished. In order to enable people to come forward as whistleblowers, organizations must adequately reassure employees that they will not face termination, demotion, harassment, or other mistreatment in response. Corporate cultures must forbid professional retaliation in any form in order to create an environment where an employee with evidence of unethical or fraudulent business practices could step out as a whistleblower.

The role of the whistleblower is extremely important in raising the legal, ethical, and compliance standards of organizations. Having a corporate culture in which this reaction to wrongdoing is promoted is, in and of itself, crucial for developing a controls framework which prevents and addresses misconduct effectively.

Categories
This week preview

This week on Compliance Culture

Be sure to visit Compliance Culture this week for posts on these topics.

  • Monday: Best practices for encouraging whistleblowers
  • Tuesday: Cyber attacks and the Hollywood entertainment industry
  • Wednesday: Sexism and Silicon Valley corporate culture
  • Thursday: The ethics of the Internet of Things
  • Friday: Frontline documentaries on financial crisis and compliance

Don’t miss it!

Categories
Last week round-up

Last week on Compliance Culture

Check out last week’s posts on Compliance Culture, in case you missed or want to revisit them.

Many thanks for reading!

Categories
Compliance in popular culture

Selected lectures on dishonesty and mistrust

In a follow-up to last Friday’s collection of videos on honesty and trust, now the polar opposite, dishonesty and mistrust. It is equally important to understand the motivations behind unethical behaviour as it is to have a view of the reasons for good behaviour. Unsurprisingly, most often these impulses are intimately related. Dishonesty, for example, is encouraged when individuals do not see trustworthiness as an important measure of success or character. On the other side, giving trust is very difficult when credibility has not been established.

  • How to spot a liar (Pamela Meyer) – Lying is not always motivated from a desire to be actively dishonest. It can be automatic, implusive, or even motivated by altruism, insecurity, or curiosity. However, it is always deceptive. Understanding the “tells” that people give when they are being dishonest is important in remaining alert and checking for credibility before giving trust.
  • How to Spot Liars at Work and How to Deal with Them (Carol Kinsey Goman) – Also in the domain of reading people’s non-verbal cues to detect their dishonesty, there are signs specific to the workplace that someone is not trustworthy and dynamics of co-working or being in a team setting that may make people more likely to lie. Identifying when colleagues are lying and understanding why can be a management technique if this is applied to trying to create a tailored environment that will protect and reward honesty. Successful leaders will communicate clearly that they expect their employees to be truthful and will measure honesty and ethical decision-making as part of their performance.
  • The truth about dishonesty (Dan Ariely) – Self-betrayal and the rationalization it provides are major motivators of dishonest behaviour. Intrinsically, people lie and break promises to themselves in every dishonest act they do, because they are overriding their own ideas about right and wrong to give themselves permission to proceed. In this way individuals persuade themselves to ignore their conflicts of interest or flaunt what is socially acceptable because they have deceived themselves into thinking their behaviour is necessary or justified.
  • Why we think it’s OK to cheat and steal (sometimes) (Dan Ariely) – Behavioural economics goes further even than the above, to suggest that people do not always have to actively be dishonest to themselves to be deceptive to others. Possibly, people actually think lying or behaving immorally is acceptable because cultural norms often tolerate and dismiss “minor” dishonesty. Situational context, intuition, or heuristics can be very powerful and override the individual’s obligation to question or consider right from wrong. All opinions about moral behaviour should be thoroughly challenged in order to avoid relying upon false assumptions.
  • The future of lying (Jeff Hancock) – In scenarios such as taking an exam with the opportunity to cheat or filling out a form with the possibility of misstating information, moral reminders of individuals’ legal or social obligations to tell the truth have proven effective in curbing dishonest choices. Could technology and the internet, influences in our society which seemingly have made the truth ever more remote, actually discourage lying by making people’s statements and representations permanent and searchable? Perhaps the accountability of the internet to record everyone’s personal records can encourage them to avoid discrepancies by resisting dishonesty.

Causes of, and rationalizations for, dishonesty and lack of trust are everywhere in both business and life. Because of how common these forces are, it is important to recognize and understand them, so that individuals and organizations may contribute positively to working against their influence.

Categories
Trends in business compliance

Round-up on compliance issues in food technology

Food technology, concerning the production processes that manufacture, transport, and distribute foods, continues to expand as disruptive technologies in general advance. As any practice that impacts food has obvious heavy impact on consumer safety, food technology practices are coming under increased scrutiny. While public attention was once mostly limited to risk-benefit analysis of various foods and the resulting consumer preferences and perceptions, innovative technologies are driving further questions and desires for customer protections and process disclosures.

  • In response to perennial consumer demand for more flavorful and interesting plant-based products to present vegetarian and vegan friendly burgers, Impossible Foods created their Impossible Burger, with soy leghemoglobin giving it an uncanny resemblance to meat and a regulatory problem with the U.S. Food & Drug Administration; can high-profile investors and customer interest overcome food safety concerns and the burdens of government supervisory challenges:  Impossible Burger’s ‘Secret Sauce’ Highlights Challenges of Food Tech
  • Walmart and a consortium of major food companies including Unilever and Kroger are experimenting with blockchain technology to simplify and automate their supply chains, in hopes of making a very complex set of production processes much more agile and enabling quicker investigations into outbreaks of food-borne illnesses, with improved documentation:  Walmart and 9 Food Giants Team Up on IBM Blockchain Plans
  • Another fascinating, developing use of blockchain in order to make the supply chain safer by combating food counterfeiting and tampering, illegal shipping, and industry malpractice by tracking products through the process and requiring non-anonymous, reliable documentation, all informed by industry “spying” that has uncovered the causes of abuses across food business sectors and country cultures:  Inside the Secret World of Global Food Spies
  • Personalized nutrition plans combine the trend for home genetic testing with consumer desires for at-home meal delivery or menu selection services, but how does freedom of choice and a culture of individual preference with emphasis on customization fit in with the goals of libertarian paternalism that can be espoused by suggesting biometrically-determined food choices:  I sent in my DNA to get a personalized diet plan. What I discovered disturbs me. 
  • Amazon continues to search for growth opportunities in the food business after announcing plans to acquire Whole Foods earlier this summer, this time turning to U.S. military technology to aim to deliver meals that do not need to be refrigerated, but will consumers be enthusiastic or will this solution only create new potential problems in trademarking of kits and safe fulfillment of orders:  Amazon looks to new food technology for home delivery

Blockchain will likely continue to pose the most challenging and exciting advances in the food technology industry. Making the supply chain for food more transparent and accountable, and also simpler to navigate, is a lofty goal which would serve the public interest. Integrity and consumer choice in the food business, with or without the impact of regulatory supervision, should drive innovation going forward.

Categories
Compliance and ethics business case studies

THINX, Miki Agrawal, and the immature leadership of a visionary entrepreneur

THINX was founded by Miki Agrawal with the ambition of disrupting the feminine hygiene industry. The company makes underwear specially designed to be worn by women on their menstrual periods. In line with this female-centered product and its revolutionary approach to a timeless need, THINX has a mission to re-center the public discussion about periods and women’s bodies. The company has become known for its provocative, bold advertising campaigns on the internet and in the New York City subway.

However, the company has also become known for something less progressive: allegations that its founder-CEO Agrawal created a hostile work environment with inappropriate behaviour and insufficient management controls.

THINX started with the objective to normalize the way people talk about periods, making it no longer a taboo topic. This societal change is an admirable goal, but at THINX it was undermined by an immature compliance culture that perverted this openness into permissiveness for mistreatment and poor conduct. It may be a positive societal change to open and encourage dialogs about feminine hygiene practices and women’s bodies, but the standards for treatment of others and respect for people’s personal boundaries, everywhere in life but especially in the work place, should not be subverted in interests of promoting this message. Empowering women does not stop at the office door, especially in a company with this ambition as its supposed core value.

Agrawal, who has successfully started several businesses, has not been so successful in taking a professional approach to ongoing operations at those organizations. Her ideas and approaches to entrepreneurship may be disruptive in a good way – novel, unique, bold – but her management style appears disruptive in a bad way – immature, overly casual, confrontational. Personal conduct and character ethic should distinguish the profile of a CEO, not tarnish it. A true leader should focus his or her philosophy into appropriate behaviour and interactions with employees and a tone at the top of professional integrity.

Despite Agrawal’s own behaviour that crossed the line, she could have made up for her managerial shortcomings by placing people around her whose leadership could contribute to a more acceptable corporate tone for the employees while still servicing the cultural change Agrawal wanted to encourage in the world at large. Adequate management controls such as a formal, experienced HR department and written employee policies and procedures would have helped to set a standard towards which the company could mature.

THINX replaced Agrawal as CEO with Maria Molland Selby, a more traditional leader who was worked in a variety of established companies included Thomas Reuters and Dow Jones. Selby also is a passionate about the THINX product from a personal perspective, hopefully she can value the people working at THINX as individuals by treating them positively and focus on a corporate culture that will support the company’s goals of destigmatizing feminine and changing the product market to make it better. As for Agrawal, she has rebranded herself as a SHE-eo and a disrupt-“her,” indicating that her interest is really on focusing on her perceived positive accomplishments and the future, rather than learning from the criticisms of the past, which she perceives as obstacles or tests rather than self-created challenges or failures to mature.

For more detail on THINX and Miki Agrawal, read Noreen Malone’s story on The Cut.

Categories
Compliance in current and historical events

The bankruptcy of Lehman Brothers

For over 150 years, Lehman Brothers Holdings Inc. was one of the largest financial services organizations in the world. In the United States it had far-reaching business operations in investment banking, securities sales and trading, research and analysis, asset and wealth management, and private equity investments.

Despite this long history, in the early 2000s Lehman Brothers was deeply impaired by the firm’s involvement in the subprime mortgage market, the impending bursting bubble of which precipitated the 2008 global financial crisis. Losing clients, market value, and rating status rapidly, Lehman Brothers filed for bankruptcy on September 16, 2008. This date is often seen as the impetus of the subsequent financial crisis, when widespread, sustained market collapse commenced.

The Lehman Brothers businesses were almost immediately taken over by Barclays in North America and Nomura Holdings elsewhere in the world. However, the impact of the bankruptcy was seismic. It had a strong effect both in concrete terms of losses in the financial markets and stress to the economy as well as a symbolic effect in representing the “too big to fail” categorization that troubled the global financial system and the many large firms within in that suffered great losses during the ensuing crisis.

  • A Colossal Failure of Common Sense – Also a best-selling book by Lawrence G. McDonald with Patrick Robinson, this lecture goes into great detail of the events leading up to, during, and following the Lehman Brothers bankruptcy during the years 2007-2010. The study goes even further back as well, to unpack the changes in financial regulation and banking industry laws from the 1990s which allowed the business conditions under which products like the subprime mortages and resulting securities were created and sold.
  • The Last Days of Lehman Brothers: Moral Hazard – This film dramatizes the events of the weekend leading up to, and in hopes of preventing, the eventual bankruptcy of Lehman Brothers. The subtitle “moral hazard” refers to the situation in which precarious risk calculations are made by individuals who do not face the liability and/or loss if the decision was the wrong one.   This sort of risk-taking was prevalent during the lead-up to the financial crisis and in the subprime mortgage securitization market. The bankruptcy of Lehman Brothers served as both a reminder that the risk could come home to roost after all, as well as a cautionary tale for financial firms and governments in the future to continue to try to mitigate this exposure.
  • Wall Street Crash of 2008 – This is the real-time video from CNBC on the evening of September 14, 2008 which reports the unfolding story that Lehman Brothers was going to collapse and file for Chapter 11 bankruptcy protection the next day (followed by a bankruptcy filing the day after that).
  • Did Lehman Brothers Cause the Financial Crisis & Stock Market Crash on Wall Street? – This interview between Maria Bartiromo and Yves Smith analyses the effects of the Lehman Brothers bankruptcy to ask whether the firm’s collapse contributed to the causes of the global financial crisis or simply signalled the beginning of a trend.
  • Five Years After Lehman Brothers – This discussion on The Agenda with Steve Paikin from 2013 looks into what has changed, or not, in the global economy and financial services sector since Lehman Brothers went bankrupt in 2008 and the markets and industry began their prolonged collapse.

 

The story of the rapid decline and fall of Lehman Brothers, and the collapse of the global economy and markets that followed, is one that will remain captivating to students of the 2008 financial crisis for years to come. Furthermore, the events of that weekend in September 2008, and their causes and effects, serve as an interesting and important measure against which compliance professionals and decision-makers in the business should judge their assumptions of risk and expectations for liability.

Categories
Best Practices

Essential compliance tips for small businesses

Owners and managers of small businesses often may not recognize the immediate importance or value of implementing a compliance program. Small businesses, especially new ones, are concentrated on surviving financially, refining their market and/or products, and identifying themselves and their leaders in an appealing and sustainable way. With these priorities in sight, compliance may fade to seem to be an optional function, something that can be started up in the future or only when necessary or required. However, establishing a compliance program from the beginning can actually service all those priorities. There are several compliance values and practices which can be easily implemented to get any small business off to the right start.

  • Create a Compliance Manual: Similar to an Employee Handbook, a Compliance Manual is the one-stop reference bible for the policies and procedures necessary for running daily operations of the business. These can be concrete, such as policies governing equipment use, information systems, or reporting of workplace injuries, or conceptual, such as Code of Ethics, gifts and entertainment guidelines, or anti-harassment policy. The policies should be tailored to the needs of the business. Don’t be intimidated; they can be simple as well as being a work-in-progress. Contemplating what rules are needed to cover a business’s practices can help to define what those are as well as provide the fundamental structure that can always be scaled up in the future.
  • Raise compliance awareness among employees: Employee training is critical for fostering a culture of compliance. This is true even if the business is a sole proprietorship with only the employee-owner to educate. All organizations are impacted by local, state, and/or federal regulations in at least some area of their operations, and all businesses would benefit from a strong perspective on ethics and integrity. Compliance awareness doesn’t require a comprehensive or expensive suite of training materials. It can be as simple as discussing dilemmas about conflicts of interest, learning about and checking for updates from the regulator of the business’s industry, or keeping an eye out on developments with competitors, peers, and stakeholders that may indicate changing legal or risk landscapes or shifts in the market to anticipate.
  • Reward ethical behaviour and compliance adherence: Employee integrity and individual contributions to a culture of compliance should be considered basic factors in evaluating performance across the organization. Indicate to employees in all roles that their conduct matters and is a measurable part of their performance. This is the most powerful, direct way to set a tone that employee culture rewards and recognizes doing the right thing consistently and identifying with strong values that reinforce that as a priority.
  • Consider sustainability in the pursuit of profits: Small businesses are reasonably driven by the intention to make the money they need to earn in order to survive and eventually grow. However, the ends do not have to justify the means – the means by which business is done will be what defines the image of the company. A poor reputation or a business model that does not build relationships will be bad advertising for the business and emphasize short-term survival over long-term success. Clients and products should be chosen with a clear vision as to how they can scale and grow and what identity or purpose they serve now and in the future.
  • Assess risk: Get in the habit from the beginning of thinking strategically about risk. In concert with sustainability, having an accurate and reliable identification and assessment of the risks to the business will help to direct growth and act responsibly on ambitions. Challenging business procedures to brainstorm about risks and consider whether they are being protected against adequately can be straight-forward yet packs a big impact in business planning.

Encouraging sustainable business practices, reasonable risk tolerance, employee integrity, and organizational ethics are all accessible and easy to implement business values. A corporate culture that promotes these genuinely and early in its foundations is well-prepared for business success.