Uncategorized

Risk assessment for small companies

Designing and implementing a compliance and ethics (C&E) risk assessment can be a daunting task.  This is true for many types of organizations, but it can be especially difficult for small businesses. Small companies often lack, among things, the resources, culture, enforcement-related incentives and relevant experience necessary to be successful in a risk assessment. For these and other reasons, it can be important for small companies to have an easy-to-use and effective risk assessment procedure. It may also  be ideal for small companies to hire a business lawyer.

The first step

For many companies new to the C&E area the first step in designing/implementing a risk assessment (or, for that matter, taking many other C&E measures) should be assigning management responsibility for the process.  In theory this should be straightforward, but that may not always be the case with small organizations.

That is, a small company without an in-house lawyer may need to appoint an executive with operations, HR, finance or other duties to be what is in effect a part-time C&E officer role for the risk assessment.  However, that role is not a “machine that will run by itself.”  

Therefore, extra care should be taken to document and reinforce the risk assessment responsibilities of the manager(s) responsible for the process, e.g., inclusion of compliance duties in job descriptions, strategic plans and other responsibility-defining company documents.  

Using outside counsel

Note that some companies hire outside counsel to assist with this effort.  While often valuable, having outside counsel is not strictly necessary for every small company’s risk assessment process.  For very small companies it might make sense to work through a business association, such as a trade association or Chamber of Commerce to hear from a compliance professional with experience in this area.   

One benefit of having a lawyer is that the process of conducting interviews can be done under attorney-client privilege. That, in turn, should make it easier for interviewees to be candid.

Developing the risk list 

The next step in this process is to develop an initial list of risks to be assessed.  As described below this will be used for interviews with company personnel.

The starting point here can be the company’s code of conduct, if it has one. If it does not it can consider looking at publicly available codes from larger companies in the same industry. While that does not ensure that all relevant risks will be covered, it can be a helpful start.

It is also generally advisable to follow industry and business news.  A company could start by having the designated compliance person read the Wall Street Journal to keep up on developing compliance risks and areas where government agencies are focusing their enforcement efforts.   

The initial risk list will often need to be modified in several ways .In fact, this can be true for even the largest, most sophisticated companies.

First, with some risk areas the topics seen in codes of conduct may already be an area of focus for the company, such as environmental, health, safety, privacy and fraud.  For such risk areas, there is generally no need to “reinvent the wheel” and to reassess a risk that has already been on the company’s radar.

Second, and in a related vein, for some areas there may be a need for more granularity than what appears in codes of conduct.  Examples include corruption and misuse of confidential information.  

Finally, for each item on the list the assessment should be of both risks involving wrongdoing by the company but also including areas where the company is the victim and might discover that it has a cause of action against others, such as competitors.  Competition law may be a good topic in this regard.

Risk assessment interviews

The risk process should involve conducting interviews of company personnel.

To that end the company should distribute the draft risk list to those who will be interviewed.

Who should be involved in the process will, of course, vary by company.  However, at least in my experience, staff involved in controls – law, audit, finance, HR, procurement – tend to do better with providing risk assessment information and ideas than do businesspeople. However business people may be more aware of what is actually happening in the field, and may surface business activities that were not known to control personnel and that may raise unexpected risks.

What gets assessed

This is the heart of the risk assessment. It includes two types of analysis.

The first concerns the likelihood and impact of violations. It is, of course, quantitative information and is standard fare in risk assessments. In other words, how likely is it that a particular violation will occur, and what are the possible consequences if it does. 

However, there is a risk here that busy managers will underrate both factors.  For example, while retaliation is a dangerous and prevalent risk, it is routinely downplayed by managers who think it “never happens here because we say we won’t tolerate it.” 

An example of the assessment process can be seen for conflicts of interest (COI), assessing what is the likelihood and impact of different possible COIs, e.g., hiring relatives in a different part of the company (by business line and/or geography).

The qualitative dimension

A second level of analysis is largely qualitative. It is more complex than the quantitative type – and more judgment based.  It seeks to identify causes of risk and to use that information to identify areas for enhancement of mitigation.

For instance, are there parts of the company where particular risks are not sufficiently understood/appreciated? If so, should training and communications be enhanced?  

The same inquiry should be made with respect to other causes of risk – e.g., undue pressure, weak process controls, misaligned incentives – all on both an enterprise and granular level.

Interviewees should also be asked for identification of any risks that are not, but should be, on the list.

Finally, small companies looking for ideas on C&E program design, development and maintenance should consider using Joe Murphy’s excellent book on  501 Ideas Compliance Ethics Program, and the SCCE white paper, A Compliance & Ethics Program on a Dollar a Day.

Mitigating project risks – the under-discovered country

40Yg0sd

Handling undue pressure: the role of the compliance and ethics office, and others

One of the most important business ethics experiments ever took place in the early 1970s in Princeton NJ.  In it, interview subjects were asked to travel from one place to another, but some were told that they had to hurry and others were not told this. Along the way, all saw an individual in apparent distress. Individuals put under time pressure were about six times more likely to engage in unethical conduct (not helping the individual in distress) than were those not under such pressure.

This was an incredible result. It – along with other subsequent behavioral ethics experiments – has led to an understanding of wrongdoing that places greater emphasis on the situation facing an individual and less on that individual’s character.  This, in turn, helps make the case for strong C&E efforts.

Turning from the world of research to that of the courtroom and prosecutors’ offices,  the corrupting influence of high-pressure is an oft-told tale. In recent years the most prominent case of this sort involved Wells Fargo, where a toxic corporate culture pressured many employees to engage in serious legal and ethical transgressions.

So, what is to be done about this potentially perilous risk?

At the outset, I note that C&E programs are not expected to eliminate all pressure to perform. That would be impossible and indeed undesirable.  But what a C&E officer and others at a company can and should do is to mitigate undue pressure.

One very important part of such an effort is risk assessment. Based on a variety of factors – both internal (e.g., employee surveys) and external market conditions (e.g., hyper competitiveness) – the risks of undue pressure can be identified.

Of course, the fact that risky conditions exist at one company does not necessarily mean that they also exist at a competitor. But it can suggest a line of inquiry both as to risk and to the efficacy of mitigation that should be explored.

Another approach is having the managers’ duties section of the code of conduct address the issue of avoiding undue pressure. That is, the code and related documents (C&E policies, charters, among other things) should spell out that a manager is responsible for addressing pressure that might lead their subordinates to cross a legal or ethical line.

Yet another available measure is having the CEO speak at an all-company or other major event about the need to avoid undue pressure  – particularly at key times (such as near the end of a financial reporting period). One should also cascade the message down through the ranks of management (both operations and staff).

In a related vein one might develop pressure-related scenarios for use in training and other communications.  This would seem to be an obvious compliance measure, but my belief is that too few companies go this route.

Less obvious still, one should consider including undue pressure in audits.  By this I mean that some audit interviews should seek to determine whether pressure at the company is unduly risky. Note that I am not suggesting that this be an extensive effort.  A single question asked of individuals in high-risk positions (e.g., sales) and locations should be sufficient in many audits.

There should also be a C&E monitoring component to the effort. This could take a wide variety of forms and  generally be driven by the risk assessment.

Investigations and discipline have a key role in this aspect of compliance.  Both in how one conducts an investigation and in related discipline one should make sure that those responsible for undue pressure are held accountable. One practical measure to ensure that this happens is to speak to this issue in the company’s investigations manual. Alongside compliance, maintaining on-site safety is essential. Visit https://fastfirewatchguards.com to explore professional fire watch services that help keep workplaces secure. Preventing burn injury accidents starts with safe handling of hot surfaces, electrical equipment, and flammable materials. Discover guides for injury victims that explain what to do after an accident and how to protect your interests.

One should, as well,  consider addressing the issue in performance evaluations and other incentive related policies and procedures. .By this I mean including in evaluations the extent to which a manager projects undue pressure onto their subordinates – or shields them from it.

Finally, one should ensure the board of directors (typically via the audit committee) is alert to undue pressure risks. They have the ultimate power in a company to mitigate those risks.

Of course, not every company needs to do all of these. And some will address the issue of undue pressure in other ways.  But all should be actively engaged on this risky area.

Elon Musk – the biggest conflict of interest?

The first big COI issue of the season. It will be interesting to see it unfold.

According to a recent piece in The Guardian: Elon Musk, “the richest man on Earth, has a wider and deeper range of potential conflicts of interest with the federal government than perhaps any person has ever had.” https://www.theguardian.com/technology/2024/dec/23/elon-musk-conflict-of-interest-benefits The potential conflict arises, in part, from Musk’s having been  named to serve as co-lead of the “Department of Government Efficiency” (DOGE).   As detailed in The Guardian: “Musk owns, directs or invests in a wide .array of industries, touching dozens of departments and agencies of the federal government, from the Department of Transportation with Tesla, to the Department of Defense with SpaceX, to the Department of Health and Human Services with Neural ink. His companies are the subject of federal investigations and regulatory actions, including accusations of hiring discrimination, environmental damage and safety deficiencies.”

Sen. Elizabeth Warren wrote to Donald Trump in this connection:  “Mr. Musk’s substantial private interests present a massive conflict of interest with the role he has taken on as your ‘unofficial co-president,’” “Currently, the American public has no way of knowing whether the advice that he is whispering to you in secret is good for the country—or merely good for his own bottom line.” https://www.forbes.com/sites/alisondurkee/2024/12/17/elon-musk-should-face-conflict-of-interest-rules-for-trump-doge-work-elizabeth-warren-argues/

Of course, all these relationships do not prove that a conflict (or conflicts) exists. However, they speak to the likelihood of risk, which seems high.

The response to this was that  Musk is so rich he’s “removed from the potential financial influence.” https://www.rollingstone.com/politics/politics-news/sununu-musk-too-rich-conflicts-of-interest-1235220668/ 

However, based on my more than 40 years’ experience  practicing criminal and compliance law this is not how it works. The rich are often the worst when it comes to all manners of business ethics. Indeed, one need  look no further than a then-young but wealthy Trump’s cheating  his  economically vulnerable subcontractors on some of his projects. https://www.usatoday.com/story/news/politics/elections/2016/06/09/donald-trump-unpaid-bills-republican-president-laswuits/85297274/

As noted above, this issue is far from resolved and I look forward to seeing how it develops.

Assessing your “conflict-of-interest discount”

In The Conflict-of-Interest Discount in the Marketplace of Ideas https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4979205  John Barrios of Yale University, together with other scholars, conducted a survey of “economists and a representative sample of Americans to infer the reduction in the perceived value of a paper when its authors have conflicts of interest (CoI), i.e., they have financial, professional, or ideological stakes in the outcome of the results. On average, a CoI decreases trust in the conclusions of an economics paper by 30%. This reduction in trust reflects a combination of the frequency of conflicted papers and the bias of papers when they are conflicted.”

“ To isolate the second term, we introduce a key construct: the CoI Discount, which measures the reduction in the value of a conflicted paper relative to a non-conflicted one. We show that, on average, conflicted papers are worth less than half of non-conflicted ones.”

The study provides detailed findings on different types of CoIs: (i) monetary incentives, (ii) career incentives, (iii) access to data, (iv) academic conflict, and (v) ideological conflict.

The study will likely be of  greater interest to academics than others. However, I can see companies developing compliance and ethics training in which trainees are asked (perhaps in a focus group setting) what the applicable discount would be in different circumstances .  E.g., how a customer’s trust in the company might be discounted by learning of questionable gift giving or hiring practices.

A Conflict of Interest thought experiment  for Joseph Biden – and others

The pardon by President Joseph Biden of his son Hunter for weapons and tax charges was the subject of near universal condemnation as a conflict of interest.  We at the COI Blog share that concern, but are less interested in the facts  of individual cases as we are about what they tell us about how to  identify and  address  COIs generally.

Consider  how in 1973  Chicago Mayor Daley, in speaking to colleagues on the  Cook County Democratic Committee, defended his having directed a million dollars of insurance business to an agency on behalf of his son John with the immortal words: “If I can’t help my sons, then [my critics] can kiss my ass. I make no apologies to anyone.”

Or, consider the case from the 1980’s which  concerned the hiring (by a former Miss America) of a NY judge’s daughter to influence the judge’s decision on a pending case Judge's daughter takes the stand in Myerson trial – UPI Archives

 In 2016, JP Morgan settled a “Princeling” case, which involved the bank’s hiring the sons and daughters of important Chinese officials in return for business.  https://www.finews.asia/finance/23431-jp-morgan-princelings-china-settlement-hiring-quid-pro-quo-hong-kong

And then there is the college admission scandal – where various individuals engaged in bribery to help their children get into elite colleges. https://www.bestcolleges.com/blog/operation-varsity-blues-college-admissions-scandal/.

There are doubtless many other cases like these – presumably going back to our early history.

This should be no surprise. After all, we are conditioned to protect our young at essentially any cost. But that doesn’t mean doing  so should  be acceptable

I think that a simple “thought experiment” could be instructive in this regard, which is to ask:  Are there things that – for ethical reasons – you would do for your children that you would not do for yourself?  

This can be used in C&E training and communications,

It is not a panacea for all COIs.

But it could be helpful in addressing many.

Conducting Ethics Interviews

My latest from CEP

https://bit.ly/3V6yL9l

Dealing with Ethics Slobs

The various investigations of President Trump and some members of his administration and others have focused attention on an age-old debate:  whether careless wrongdoing is as reprehensible as is the intentional sort.

The answer is, I believe, Yes.  Indeed, crimes of carelessness may in some ways be even more perilous than is intentional wrongdoing.

The first word on this always interesting issue may belong to Samuel Johnson, who once said: “It is more from carelessness about truth than from intentionally lying that there is so much falsehood in the world.”

Indeed, I believe that as the economy and other aspects of society become ever more complex the need to address carelessness risks will likely become even greater.  

There will, I think, be more things to get wrong, and thus more of a need to make things right. .Some companies do rise to this occasion, meaning they do a good job in educating managers on the need for carefulness on C&E matters. But many others could and should do more.  The same is true of governmental bodies.

What else can be said about dealing with “ethics slobs”?

First, I should stress that the suggestion here is not to be taken too literally. A company should not, as a general matter, formally designate its employees as “ethics slobs,” (unless they are being terminated).  But using a more dignified approach to dealing with this issue one can achieve a similar result.

Second, C&E personnel should keep track of “carelessness cases” that arise at the company. This could include violations of law or applicable policy that led to harmful activity even though there was no intentionally wrongful conduct.

Third, based on this inventory of “carelessness cases” one should address this area in company-wide training, other (e.g., targeted) training and other communications. There should be a risk assessment aspect to ethics slobs risks.

Fourth, company compensation schemes should be reviewed for carelessness risk.  Indeed, the importance of incentives has been recently re-enforced by Justice Department memoranda on C&E programs.

Finally, the pitfalls of being an “ethics slob” should be addressed in auditing, monitoring and risk assessment. Here – and elsewhere – what one measures is what counts.

Where law and ethics meet

https://www.kaplanwalker.com/wp-content/uploads/2024/10/Where-Law-and-Ethics-Meet-Selected-Postings-from-the-Conflict-of-Interest-Blog.pdf

Do dogs have conflicts of interest?

https://conflictofinterestblog.com/2013/01/do-dogs-have-conflicts-of-interest.html