Governance, Fraud, & Corporate Culture: Sorting Through a Complicated Relationship

I recall being asked to perform a cultural risk assessment in late 2004 because certain members of a client company’s board of directors were concerned about communication and information flow. Specifically, they wanted to know if issues were being raised timely and appropriately and not extinguished by mid-level managers. The board and senior management were not concerned about fraud or ethical violations, even though some events should have caused concern.

Read More

Ethics and Compliance: Active Board Involvement Is a Must

Establishing and supporting a corporate compliance program is widely recognized as one of the fundamental responsibilities of a corporate board of directors. But merely seeing that there is a compliance program in place is by no means an adequate effort. The Board must also actively oversee that function.
Active oversight is essential if a company’s business plan includes strategies, practices, or other elements that could be considered high-risk. Such situations call for even more involvement and active engagement by the Board.

Read More

FCPA - The Role of The Board and More!

One of the FCPA themes for 2020 has been hiding in plain sight all along. The FCPA requirement that “reporting companies to devise and maintain a system of internal accounting controls sufficient to provide reasonable assurances that, among other things, transactions are executed following management’s general or specific authorizations, and access to assets is permitted only in accordance with management’s general or specific authorization.” But what if the violation of this requirement occurs in a non-foreign (IE., the U.S.) and in a non-bribery situation.

Read More
ACFE, AICPA, Anti-fraud, Baker Tilly, Bank Secrecy Act, Board of Directors, Books and records, Bribery, Business Intelligence, Compliance, Culture, Disclosure, Dodd-Frank, DOJ, Enforcement, Enterprise Risk Resili..., Ethics, Evidence, False Claims Act, FCPA, Federal Sentencing Gui..., Foreign Corrupt Practi..., Forensic Accounting, Forensically Speaking, Fraud and Forensic, Fraud and Forensic Inv..., Fraud Investigations, Fraud Pentagon, Fraud Risk Management, Fraud Task Force, General Counsel, Governance, GRC, Hotline, IIA, Internal Audit, Internal Control Defic..., Internal Controls, Jonathan T- Marks, Kickbacks, KYC, Leadership, Legal, Management Override, Money Laundering, Monitoring, NACD, Not for Profit, OFAC, Policies and Procedures, Process Improvement, Qui Tam, RegTech, Regulatory, Remediation, Remote Internal Invest..., Remote Investigations, Risk Assessment, Risk factors, Risk Management, Risk-focused, Root Cause, Sarbanes-Oxley, SEC, Third Party, Thought Leadership, Webinar, Whistleblower, White Collar Crime Jonathan T. Marks ACFE, AICPA, Anti-fraud, Baker Tilly, Bank Secrecy Act, Board of Directors, Books and records, Bribery, Business Intelligence, Compliance, Culture, Disclosure, Dodd-Frank, DOJ, Enforcement, Enterprise Risk Resili..., Ethics, Evidence, False Claims Act, FCPA, Federal Sentencing Gui..., Foreign Corrupt Practi..., Forensic Accounting, Forensically Speaking, Fraud and Forensic, Fraud and Forensic Inv..., Fraud Investigations, Fraud Pentagon, Fraud Risk Management, Fraud Task Force, General Counsel, Governance, GRC, Hotline, IIA, Internal Audit, Internal Control Defic..., Internal Controls, Jonathan T- Marks, Kickbacks, KYC, Leadership, Legal, Management Override, Money Laundering, Monitoring, NACD, Not for Profit, OFAC, Policies and Procedures, Process Improvement, Qui Tam, RegTech, Regulatory, Remediation, Remote Internal Invest..., Remote Investigations, Risk Assessment, Risk factors, Risk Management, Risk-focused, Root Cause, Sarbanes-Oxley, SEC, Third Party, Thought Leadership, Webinar, Whistleblower, White Collar Crime Jonathan T. Marks

Still time to join us on February 23-25! Baker Tilly’s 1st Annual Virtual Fraud and Compliance Summit

We are introducing our first annual virtual Baker Tilly Fraud and Compliance Summit, hosted by Jonathan T. Marks, who leads Baker Tilly’s Global Forensic, Compliance, and Integrity Services Practice.

Read More
10-80-10, 10-A, 3 Lines, ACFE, AICPA, Analytics, Anti-fraud, Antitrust, Audit, Audit Committee, Automation, Baker Tilly, Blockchain, Board of Directors, Books and records, Bribery, Business Intelligence, Caremark, Cash, Chief Audit Executive, Chief Compliance Officer, Chief Legal Counsel, Colleges and Universities, Collusion, Compliance, Compliance Coordinator, Conflict of Interest, Continuous Auditing, Continuous Monitoring, Control, Control Environment, Coronavirus, Corporate Fraud, Corruption, COSO, Court, COVID -19, Crisis, Crisis Management, Critical Audit Matters, Cross Border Investiga..., Cryptocurrency, Culture, Culture Assessment, Cyber, Damages, Data, Data Analytics, Data Integrity, Directors, Disclosure, Dodd Frank, Dodd-Frank, DOJ, Due Diligence, Dunning Kruger, Enforcement, Enterprise Risk Resili..., Enterprise Risk Resili..., EQS, ERM, Ethics, Evidence, Exit Interview, Fake Invoices, False Claims Act, FCPA, Federal Sentencing Gui..., Financial reporting an..., FinCen, Food Safety, Foreign Corrupt Practi..., Forensic Accounting, Forensically Speaking, Four eyes approval, Fraud, Fraud and Forensic, Fraud and Forensic Inv..., Fraud Investigations, Fraud Pentagon, Fraud Risk Management, Fraud Task Force, Fraud Triangle, GAAP, GDPR, General Counsel, Gifts, Global, Governance, GRC, Guidance, Hidden Assets, Hotline, IDORP, IIA, IIA Philadelphia, IIOT, Impairment, Initial Coin Offering, Insider Trading, Internal Audit, Internal Control Defic..., Internal Controls, Interview, Investigations, Jonathan T- Marks, Judgment and Estimates, Keyword, Kickbacks, Leadership, Legal, Lessons Learned, Management Override, Materiality, MD&A, Money Laundering, Monitor, Monitoring, Monitorship, NACD, Nonprofit, Not for Profit, OFAC, Office of Foreign Asse..., Oversight, Phishing, Podcast, Policies and Procedures, Process Improvement, Proxy, Qui Tam, ransom, Ransomeware, Red Flag, RegTech, Regulatory, Related Party, Remediation, Remote Internal Invest..., Remote Investigations, Reputation, Restatement, Risk, Risk Assessment, Risk factors, Risk Management, Robotic, Root Cause, Sampling, Sarbanes-Oxley, Seaboard, SEC, Shell Company, Skepticism, Slush Fund, Supreme Court, Tax, Tax Fraud, Technology, Theft, Third Party, Thought Leadership, Three Lines, Three Lines of Defense, Tips, tone at the top, Tone from the Top, Training, Treasury, Triage, Uncategorized, Values, Webinar, Whistleblower, White Collar Crime, Yellow Flag Jonathan T. Marks 10-80-10, 10-A, 3 Lines, ACFE, AICPA, Analytics, Anti-fraud, Antitrust, Audit, Audit Committee, Automation, Baker Tilly, Blockchain, Board of Directors, Books and records, Bribery, Business Intelligence, Caremark, Cash, Chief Audit Executive, Chief Compliance Officer, Chief Legal Counsel, Colleges and Universities, Collusion, Compliance, Compliance Coordinator, Conflict of Interest, Continuous Auditing, Continuous Monitoring, Control, Control Environment, Coronavirus, Corporate Fraud, Corruption, COSO, Court, COVID -19, Crisis, Crisis Management, Critical Audit Matters, Cross Border Investiga..., Cryptocurrency, Culture, Culture Assessment, Cyber, Damages, Data, Data Analytics, Data Integrity, Directors, Disclosure, Dodd Frank, Dodd-Frank, DOJ, Due Diligence, Dunning Kruger, Enforcement, Enterprise Risk Resili..., Enterprise Risk Resili..., EQS, ERM, Ethics, Evidence, Exit Interview, Fake Invoices, False Claims Act, FCPA, Federal Sentencing Gui..., Financial reporting an..., FinCen, Food Safety, Foreign Corrupt Practi..., Forensic Accounting, Forensically Speaking, Four eyes approval, Fraud, Fraud and Forensic, Fraud and Forensic Inv..., Fraud Investigations, Fraud Pentagon, Fraud Risk Management, Fraud Task Force, Fraud Triangle, GAAP, GDPR, General Counsel, Gifts, Global, Governance, GRC, Guidance, Hidden Assets, Hotline, IDORP, IIA, IIA Philadelphia, IIOT, Impairment, Initial Coin Offering, Insider Trading, Internal Audit, Internal Control Defic..., Internal Controls, Interview, Investigations, Jonathan T- Marks, Judgment and Estimates, Keyword, Kickbacks, Leadership, Legal, Lessons Learned, Management Override, Materiality, MD&A, Money Laundering, Monitor, Monitoring, Monitorship, NACD, Nonprofit, Not for Profit, OFAC, Office of Foreign Asse..., Oversight, Phishing, Podcast, Policies and Procedures, Process Improvement, Proxy, Qui Tam, ransom, Ransomeware, Red Flag, RegTech, Regulatory, Related Party, Remediation, Remote Internal Invest..., Remote Investigations, Reputation, Restatement, Risk, Risk Assessment, Risk factors, Risk Management, Robotic, Root Cause, Sampling, Sarbanes-Oxley, Seaboard, SEC, Shell Company, Skepticism, Slush Fund, Supreme Court, Tax, Tax Fraud, Technology, Theft, Third Party, Thought Leadership, Three Lines, Three Lines of Defense, Tips, tone at the top, Tone from the Top, Training, Treasury, Triage, Uncategorized, Values, Webinar, Whistleblower, White Collar Crime, Yellow Flag Jonathan T. Marks

2020 Top 10 Articles on Fraud, Compliance, and Risk Management

Happy New Year, and thank you to the more than 100,000 people that visited Board and Fraud in 2020!
With everything that happened last year, fraud, compliance, and risk management have arguably become more important than ever.

Read More

Herbalife - “Quis Custodiet Ipsos Custodes” - Translated: Who Will Guard the Guards Themselves, or Who will Watch the Watchmen?

Herbalife's business relationship in China was committed to illegal activity, which it knew or should have known violated the FCPA. Specifically,  beginning in late 2006, Herbalife China provided improper benefits and payments to government officials to obtain direct selling licenses for two cities.
Herbalife paid out millions of dollars in bribes. Fraudulent expense reimbursements were used to fund the bribes, which is is a common tactic for these types of bribes.Specifically, the SEC found that Herbalife China paid bribes through extravagant meals, gifts, and other benefits given to Chinese officials to obtain sales licenses and remove negative media coverage in China. Managers at the subsidiary asked employees to falsify expense report documents, for example, adding names to meal receipts to get below the company's per head spending limit. It also found that the payments and benefits were inaccurately recorded and that Herbalife failed to maintain a sound system of internal controls.

Read More

Are you ready? New EU Whistleblower Protection Law!

Soon all public and private organizations in the EU with more than fifty (50) employees will soon be required to comply with a new EU Whistleblower Protection law. The new law highlights the importance of responsive, transparent, and timely whistleblowing case management. So just implementing a hotline is not enough. Organizations must consider confidentiality, acknowledgment of the tip or compliant, response times, the competence of persons receiving the reports, communication with the whistleblower, and feedback on how the case is being processed. The new law also includes the right to report concerns externally while remaining legally protected. That's a risk organizations must avoid. With the December 2021 deadline fast approaching, there is no better time for management and boards to act. Read more!

Read More

Compliance snubbed? Three Lines Model or Enterprise Resiliency Model?

In July 2020, The Institute of Internal Auditors ("IIA") updated its Three Lines of Defense Model ("Model") to emphasize more active forms of risk management and governance that appear to go beyond merely defensive maneuvers made by the internal audit function.  Some believed the old model sent a message that we should fear risk. I never saw it that way. I understood the subliminal message was the model was about achieving objectives, which requires both the creation and the protection of value. The new model does a much better job of confirming that risk management contributes "to achieving objectives and creating value, as well as to matters of "defense" and protecting value."Learn why the Enterprise Risk Resilient Model might be a better choice.

Read More

Webinar - July 28, 2020 - Best Practices for Conducting Remote Internal Investigations

In this pandemic era, global companies have been challenged to maintain a reliable and effective internal investigation program. Companies have relied on remote investigation strategies to collect and review documents and conduct interviews. In conducting remote investigations, companies have to ensure that they follow investigation requirements, maintain the confidentiality of the process, and comply with applicable data privacy rules and security requirements.In this webinar, Jessica Sanderson, Partner at The Volkov Law Group, and Jonathan T. Marks, Partner| Leader of the Global Forensic Investigation, COmpliance & Integrity Practice at Baker Tilly, will discuss best practices for conducting remote internal investigations. They will outline strategies for collecting and reviewing documents, analyzing financial data, and conducting interviews using remote technologies.

Read More

SEC & DOJ Release Second Edition of the Resource Guide to the U.S. Foreign Corrupt Practices Act

The SEC and DOJ Resource Guide is intended to provide information for businesses and individuals regarding the U.S. Foreign Corrupt Practices Act (FCPA). The guide has been prepared by the staff of the Criminal Division of the U.S. Department of Justice and the Enforcement Division of the U.S. Securities and Exchange Commission.The key changes to the Second Edition reflect developments and issues that are well-known to experienced practitioners. Nevertheless, the updated Guide emphasizes the importance of effective (and “adequately resourced”) compliance programs, risk-based diligence efforts, and voluntary self-disclosures.   

Read More

COVID-19 - Fraud On The Rise is No Surprise!

Last week, the Association of Certified Fraud Examiners (” ACFE”) published the results of a survey taken by more than 1,800 anti-fraud professionals in late April and early May 2020, while we were deep into the Covid-19 crisis.  The findings, for the most part, are not surprising, but does reveal some disappointing information.  While I have not seen a raw copy of the survey, I was surprised the ACFE didn’t ask if the company’s fraud risk assessment was reviewed and modified accordingly.In addition, the survey highlights trends in the overall level of fraud. Survey respondents provided information about their current observations and expected changes regarding ten (10) specific types of fraud.

Read More

DOJ Revises its Guidance on the Evaluation of Corporate Compliance Programs

Without any fanfare, the U.S. Department of Justice Criminal Division has once again revised its Evaluation of Corporate Compliance Programs (“ECCP”).  The ECCP  remains  organized around three overarching questions that prosecutors ask when evaluating compliance programs, with some revisions, which are in bold text below:Is the corporation’s compliance program well designed?Is the program being applied earnestly and in good faith? In other words, is the program being implemented adequately resourced and empowered to function effectively?Does the corporation’s compliance program work in practice?While most of the document is identical to the 2019 Guidance, there are subtle and noticeable revisions.  The revisions appear to be designed to help provide additional clarity when answering the above three questions. 

Read More

Tone from the top: Leadership’s challenge during a crisis

Leaders must find ways to engage with their people to motivate them, and this becomes increasingly important during uncertain or trying times. If done correctly, talking can be incredibly powerful. It can help relieve anxiety and help people find the strength they didn't know was in them. Studies have shown that talking shuts down the brain's fear center.As Dr. Judson A. Brewer stated in a recent New York Times article, "Anxiety is a strange beast. As a psychiatrist, I have learned that anxiety and its close cousin, panic, are both born from fear.”Fear and anxiety can be debilitating. Without proper communication in a crisis, it's easy for people to spin and spread stories of fear, creating social contagion. To balance this tendency, in a crisis, leaders need to take their "tone from the top" to the next level.

Read More

Whistleblowers: Tipsters not trusting the system?

Whistleblowers: Tipsters not trusting the system? Here's how to win them back.Anonymous hotlines and tip-reporting structures are useless, of course, if informants don’t trust them. Employees won’t blow the whistle if they fear reprisals. So, their concerns often don’t enter case-management systems and frauds continue. Here’s how to earn back their trust, take them seriously and transform raw tips into valuable fraud examinations.Ovem lupo commitere!

Read More

Whistleblowers: A Fraud Triage System to Manage Burgeoning Caseloads

As the use of whistleblower programs continues to grow, many organizations find themselves struggling to manage burgeoning caseloads. As a result, serious fraud investigations can be delayed (with mounting losses) while less consequential complaints are being investigated. The lack of a timely, systematic, and repeatable process for evaluating and prioritizing whistleblower tips that contain allegations of ethical breaches can also expose an organization to increased regulatory risk. While there is no single “right” method for following up on whistleblower complaints, the most effective approaches often resemble the medical triage programs that hospitals and first responders use to allocate limited resources during emergencies or a crisis situations. Here are some useful guidelines for designing and implementing a fraud triage system.

Read More

A Violation of Trust: Fraud Risk in Nonprofit or Not-for Profit Organizations

The risk of fraud is a serious concern for all types of enterprises, but fraud can be particularly damaging to a nonprofit or not-for-profit organization, for which a damaged reputation can have devastating consequences.

Read More

The Role of the Board of Directors in Compliance Oversight

Under the U.S. Federal Sentencing Guidelines, in order to receive credit for having an effective compliance program, and thereby reduce the fines imposed on the organization, a Board of Directors must be “knowledgeable about the content and operation of the compliance and ethics program,” and must “exercise reasonable oversight with respect to the implementation and effectiveness of the compliance and ethics program.” In addition, in criminal actions against a business organization, including the FCPA, the DOJ’s Justice Manual instructs prosecutors to ask and answer several questions, including: 1) Do the Directors exercise independent review of the company’s compliance program? and 2) Are Directors provided timely and accurate information sufficient to enable the exercise of independent judgment?

Read More

Fraud, Compliance & Integrity Risk During a Crisis and a Downturn

As a crisis unfolds, like Coronavirus, and markets decline globally, fraudsters will be adapting and new risks will emerge and some risks will increase. Remember, white collar criminals adapt by profiling us, so they can exploit our weaknesses. That being said, companies need to develop a strategy that enables the deployment of appropriate tactics to manage these new or increasing risks.This writing explores some fraud, compliance, and integrity risks and is intended to provoke discussion.

Read More