{"id":1627,"date":"2018-03-20T09:00:20","date_gmt":"2018-03-20T14:00:20","guid":{"rendered":"http:\/\/blogs.luc.edu\/compliance\/?p=1627"},"modified":"2018-03-20T09:00:20","modified_gmt":"2018-03-20T14:00:20","slug":"building-a-compliance-framework-from-the-ground-up","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=1627","title":{"rendered":"Building a Compliance Framework from the Ground Up"},"content":{"rendered":"<p><em>Tierney Mason<br \/>\n<\/em><em>Associate Editor<br \/>\n<\/em><em>Loyola University Chicago School of Law, JD 2019<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>Large companies generally have well established programs and systems in place to remain compliant with ever-changing regulations within their industry. But at a time when the percentage of job seekers starting their own businesses is at a <a href=\"http:\/\/fortune.com\/2017\/02\/22\/startups-2017-challenger\/\">recent high<\/a>, young firms and start-ups are at a disadvantage when it comes to compliance, having to build a system from the ground up. In order to have an <a href=\"https:\/\/www.ussc.gov\/guidelines\/2015-guidelines-manual\/2015-chapter-8\">effective compliance program<\/a>, an organization must \u201cexercise due diligence to prevent and detect criminal conduct\u201d and must establish and maintain an organizational culture that \u201cencourages ethical conduct and a commitment to compliance with the law.\u201d Thus, management not only has to focus on structure, but also culture in building their compliance systems.<!--more--><\/p>\n<p><strong>The Elements of an Effective Compliance Program<\/strong><\/p>\n<p>The most recognized standards for an effective program were established by the U.S. Sentencing Commission within its <a href=\"https:\/\/www.ussc.gov\/guidelines\/guidelines-archive\/2012-federal-sentencing-guidelines-manual\">Sentencing Guidelines Manual<\/a>. A good compliance program generally rests on management, written policies and procedures, training and education for employees, compliance monitoring and assessments, and response to offenses. When it comes to <a href=\"http:\/\/www.corporatecomplianceinsights.com\/5-steps-for-building-an-effective-compliance-program\/\">management<\/a>, leaders up to the Board of Directors need to \u201ctalk about compliance, write about it and demonstrate through their daily conduct that compliance is heavily important.\u201d<\/p>\n<p>A leader\u2019s involvement or lack of involvement in handing the job off to others speaks volumes and sets a precedent to the rest of the company as to how seriously they should consider compliance. This might require management to <a href=\"http:\/\/www.acc.com\/legalresources\/quickcounsel\/eaecp.cfm\">submit<\/a> to background checks or other specific industry checks all new employees receive, to ensure individuals in positions of authority should not be excluded from those positions. Leaders who fail to take compliance seriously from the start are not fulfilling their responsibility to be an effective leader.<\/p>\n<p>With respect to written policies and procedures, a company <a href=\"http:\/\/www.acc.com\/legalresources\/quickcounsel\/eaecp.cfm\">must have<\/a> standards of conduct and internal controls \u201creasonably capable of reducing the likelihood of criminal and other improper conduct.\u201d The written policy should be made easily available to all employees and serve two basic functions: explaining legal requirements so that employees understand their obligations and how to conform their behavior to meet them, and encouraging managers to report suspected fraud and other improprieties without fear of retaliation.<\/p>\n<p>The easier it is for employees to access their company\u2019s policies and standards, the more likely it will be to maintain an effective compliance system. Company compliance with industry regulations both begins and ends with the employees who work there. This also applies to the training and education aspect of building a compliance program. All employees, including higher level executives and the organization\u2019s agents, should be well informed on the systems in place. Proper training includes training on the code of conduct and the basics of the company\u2019s ethics program, as well as any additional training for employees in specialized positions. Training should <a href=\"http:\/\/www.acc.com\/legalresources\/quickcounsel\/eaecp.cfm\">also<\/a> be tracked and followed-up periodically.<\/p>\n<p>Once the compliance program is in place, what remains is regular monitoring and risk assessments, and responding to offenses. <a href=\"http:\/\/www.corporatecomplianceinsights.com\/compliance-monitoring-strategic-approach\/\">Monitoring<\/a> is a \u201cbasic expectation\u201d of ethics and compliance management. This is an important part of the program as it allows the company to ensure the program is being followed and to evaluate its effectiveness. However, it can be something companies struggle to maintain since there is relatively little guidance on <em>how<\/em> companies should monitor their programs and employees. How often should risks analyzed? Who should defects be reported to?<\/p>\n<p>In fact, \u201cfew have had true success,\u201d but some industries have managed to develop helpful frameworks. The securities industry, for example, reports to <a href=\"http:\/\/www.finra.org\/\">FINRA<\/a>, which requires all of its member firms to maintain written supervisory procedures to ensure that company activities are regularly monitored for compliance. If a regular monitor or audit does produce a defect, this does not necessarily mean the program was ineffective. In fact, this could mean the program was effective in detecting an issue before it affects the company\u2019s larger work product. However, recurring defects can require a response from management, and remedial measures should be taken.<\/p>\n<p><strong>A Culture of Compliance<\/strong><\/p>\n<p>There is a <a href=\"http:\/\/www.corporatecomplianceinsights.com\/5-steps-for-building-an-effective-compliance-program\/\">common pattern<\/a> amongst troubled companies of all compliance areas, whether it be hedge funds, insurance companies, or accounting firms. In most cases, there were signs of problems that built up to disaster that officials in the company ignored. Any firm could have a flawless compliance program tailored to their industry\u2019s standards and regulations, but it\u2019s still ineffective without a culture in which employees feel comfortable coming forward about illegal or dangerous practices.<\/p>\n<p><a href=\"https:\/\/www2.deloitte.com\/content\/dam\/Deloitte\/us\/Documents\/risk\/us-aers-g2g-compendium.pdf\">Culture<\/a> is a large determinant in how people behave. When a majority of employees are in agreement of how to behave and what values apply to their workplace, it becomes easier for everyone to conform to the same values. However, there can be a gap between how managers and employees view the office culture. It is not unusual for things to get lost in translation as the message moves further and further away from management. For this reason, a compliance program with a strong structure can ensure that the company\u2019s values are clearly communicated through every level of the organization. It is also important that these values are stated consistently so the message is not lost.<\/p>\n<p>In short, a new company should focus on a strong structure in implementing a new compliance program. With a structure in place, a culture of ethics should follow.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Large companies generally have well established programs and systems in place to remain compliant with ever-changing regulations within their industry. But at a time when the percentage of job seekers starting their own businesses is at a recent high, young firms and start-ups are at a disadvantage when it comes to compliance, having to build a system from the ground up. In order to have an effective compliance program, an organization must \u201cexercise due diligence to prevent and detect criminal conduct\u201d and must establish and maintain an organizational culture that \u201cencourages ethical conduct and a commitment to compliance with the law.\u201d Thus, management not only has to focus on structure, but also culture in building their compliance systems.<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51],"tags":[468,550,904,985],"class_list":["post-1627","post","type-post","status-publish","format-standard","hentry","category-compliance-the-law","tag-compliance","tag-culture","tag-framework","tag-guidelines"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/1627","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1627"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/1627\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1627"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1627"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1627"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}