IN THIS LESSON

PLAY LESSON

Building a Compliance Team

Compliance departments have been an essential component of Wall Street, banking, insurance, healthcare, and other highly regulated industries. As the burden of regulations has grown, both within the US and globally, so too has recognition for the importance of a disciplined approach to compliance management. For companies who do not operate in heavily regulated industries, this module is probably overkill. As you grow, you will need to adapt to some compliance related stuff regarding taxes, financials, and stock transactions but most of those kicks in post-IPO.

According to the Baker McKenzie Global Compliance Benchmark 2016, a compilation of the most respected studies worldwide, 83% of compliance professionals feel that compliance has become more complex and challenging in the last couple of years. In line with that, corporations are recognizing the need to make the CCO a standalone C-level position, with 59% of companies reporting in 2015 they have a standalone CCO, compared to just 37% in 2013 — a continued trend.

We’re now seeing industries that hadn’t previously viewed compliance as a core business requirement change their minds. Often an issue in their company or industry is needed to raise awareness of the importance of compliance. As a result, many business leaders are looking at compliance as an indelible component of their business.

Today’s Chief Compliance Officers often view their jobs as both compliance and risk managers, and this broadened scope makes building an effective compliance team even more intimidating.

 Start at The Top

Since your company is in the early stages of building a compliance team, consider that this needs to start with you and your leadership team. The C-suite and board should set the tone by declaring compliance and risk management a strategic imperative crucial to company sustainability. Here’s how you can show that you mean it:

  • Create a board-level committee to provide oversight on compliance planning.

  • Provide audience-specific messaging to set expectations.

  • If there’s a CCO already in place, involve him or her in strategic discussions.

  • Set expectations for executive involvement and establish accountability

Company culture is affected by the actions that signal commitment, not just words and lip-service. Commitment can signal to your organization that new behaviours aimed at improving transparency are expected. In the world of compliance, nothing says commitment like a formal compliance risk assessment because of the resources involved and the effort spent to conduct it properly.

Conduct Compliance Risk Assessment

There are several consultants you can bring in to conduct a proper risk assessment due to the disciplined dive it takes into all aspects of business operations that internal audits required.

That’s not to say you couldn’t do it yourself, but consultants can help you see with a fresh set of eyes — their work will be thorough and comprehensive. Anything less than thorough and comprehensive is just unacceptable for compliance standards.

A risk assessment will help you identify and understand your top compliance risks. The reasons risk may occur, the likelihood of occurrence, and the expected impact to the business are all core elements of an assessment. At the end, you will be given a view on risk prioritization and internal ownership, plus some thoughts on resource allocation.

Hire a Chief Compliance Officer

If you don’t have a CCO and your business is in a regulated industry, it’s time to consider getting one. It’s best to look for a senior professional that will build organizational expectations, practices, roles, processes, and situational protocols. A new CCO has a directive to create everything that’s needed to successfully establish compliance as an organizational priority.

Note: Don’t forget to leverage your board! Having your board directly involved in the search helps candidate recruitment — plus, it will send the right message to your company regarding expectations of the impact this position will have attached to it.

Compliance and Risk Management

To create a comprehensive code of conduct that ensures your compliance with laws and regulations at all levels, your CCO will need help from other people within the company. This is where you will designate some of your most knowledgeable employees (it may even need to be yourself) to be part of your compliance team. Your team will have to contend with the emergence of new risks such as cyber-threats and potential regulatory changes that may affect your company overall.

Compliance and risk assessment becomes the best starting point to create an effective compliance management plan with your new compliance team. In broad strokes, here’s what that plan should try to tackle:

  • Corporate code of conduct

  • Policies, procedures, and controls addressing all compliance requirements and risk areas.

  • Communication tools and policies for reporting concerns and misconduct

  • Defined protocols for capturing and cataloguing issues, conducting investigations, and taking corrective action.

  • Training tools and expectations for everyone involved.

  • Compliance visibility and organizational engagement

  • Testing, auditing, results measurement, reporting

Too many companies and industries have treated compliance and risk management as a reaction to a crisis or short-term situation, only thinking about it when they’re stuck between a rock and a hard place, but then quickly forgetting about it when they’ve averted the crisis — even when they got to close for comfort! Don’t be that company. Plan and prepare.

In the world we now live in, local and global companies realize that good compliance management is a strategic imperative that provides sustainable protection and value.

 

Elements of an Effective Compliance Program

What follows is more of a guideline than anything else. Compliance programs are not a one-size-fits-all. Although you can follow the guidelines on how to create a compliance program and what to include, you must develop a plan that meets your company’s specific needs. For building a compliance program, there’s no need to recreate the wheel so look at the following for guidance:

The Affordable Care Act outlines seven key elements of an effective compliance program.

  • Establish and adopt written policies, procedures, and standards of conduct. Having clear written policies and procedures in place that describe compliance expectations fosters uniformity within your company.

  • Create program oversight. Determine who will oversee, monitor, and enforce the compliance program and serve as your go-to company “watchdog” with questions and concerns.

  • Provide staff training and education. Employees at every level need to understand your compliance program expectations and standards to comply with them. Implement a training program that communicates your company’s program requirements, with an annual refresher course that reminds employees of your code of conduct and incorporates any changes.

  • Establish two-way communication at all levels. Set forth the expectation that employees should proactively communicate in a timely manner, whether that means asking compliance questions, reporting issues, or addressing ethical concerns. Include a way for employees to anonymously report compliance issues or fraudulent or illegal behaviour without fear of retaliation.

  • Implement a monitoring and auditing system. You must measure the effectiveness of your corporate compliance program and identify risks. To accomplish this, develop a system of both internal and external monitoring, including formal audits.

  • Enforce consistent discipline. Develop a plan to enforce standards of conduct in a timely manner, outlining appropriate disciplinary measures for employees who do not comply with program requirements.

  • Take corrective action. When you identify vulnerabilities or violations through monitoring and auditing, take timely, consistent action to correct the issue.

Keep in mind that this list is designed specifically for healthcare facilities. However, it serves as a solid guideline for any industry, touching on the key components of an effective compliance program.