Workshop 2 August 20, 2024 (AWST) 1 Team 2 –

Published  . 0 views
↓ Download
Workshop 2 August 20, 2024 (AWST) 1 Team 2 –
1 / 1
Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 1 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 2 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 3 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 4 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 5 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 6 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 7 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 8 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 9 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 10 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 11 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 12 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 13 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 14 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 15 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 16 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 17 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 18 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 19 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 20 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 21 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 22 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 23 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 24 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 25 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 26 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 27 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 28 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 29 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 30 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 31 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 32 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 33 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 34 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 35 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 36 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 37 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 38 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 39 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 40 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 41 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 42 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 43 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 44 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 45 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 46 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 47 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 48 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 49 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 50 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 51 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 52 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 53 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 54 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 55 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 56 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 57 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 58 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 59 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 60 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 61 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 62 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 63 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 64 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 65 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 66 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 67 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 68 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 69 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 70 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 71 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 72 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 73 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 74 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 75 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 76 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 77 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 78 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 79 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 80 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 81 of 82 Workshop 2 August 20, 2024 (AWST) 1 Team 2 – - slide 82 of 82
Description: Workshop 2 August 20, 2024 (AWST) 1 Team 2 Wells Fargo 2 Module 3 Compliance, Ethics and Legal Risk Management 3 Corporate Compliance: A Critical Skill for In-House Counsel 2024 ACC CLO Survey Regulations and enforcement (53), data

Related Topics

Download Presentation

"Workshop 2 August 20, 2024 (AWST) 1 Team 2 –" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Workshop 2 August 20, 2024 (AWST) 1<br>
slide2. Team 2 – Wells Fargo 2<br>
slide3. Module 3

Compliance, Ethics and Legal Risk Management 3<br>
slide4. Corporate Compliance: A Critical Skill for In-House Counsel 2024 ACC CLO Survey Regulations and enforcement (53%), data privacy (41%), and cybersecurity (37%), remain the top three issues that CLOs consider to be the most important to the business. 4<br>
slide5. Corporate Compliance: A Critical Skill for In-House Counsel
2024 ACC Chief Legal Officers Survey 69% Respondents were presented with a comprehensive list of 19 corporate functions and were asked to indicate which
function reports to them. More than three in four CLOs oversee the compliance function in their organization 5 44% 43% 38% 22% What Functions Report To The CLO?<br>
slide6. Compliance, Ethics and Legal Risk Management are Intertwined In-house counsel should remember that legal compliance is “the right things to do!” This means having a checklist of requirements (i.e. “things to do”) under the law.
To create a checklist of the relevant legal risks your company needs to address, you need to conduct a legal risk assessment.
But remember, it is not enough to comply with the laws, in-house counsel must also know “the right thing to do!”, i.e. the ethical thing. Checklist 6<br>
slide7. Your Company’s Compliance With All Laws and
Regulations Globally is an Enormous Task* The ACC Report on Law Department Management states that
“Sixty-two percent of in-house counsel worldwide have cross-border
or transnational work.”
The executive summary goes on to explain, “with geographic expansion comes the need to implement both business and legal strategies that make it possible to conduct operations within multiple territories.”
Ultimately, geographic expansion has led to “an exponentially intensified regulatory environment.” * Association of Corporate Counsel, ACC Law Department Management 2016 Report, Executive Summary at 4 (2016). 7<br>
slide8. Corporate Compliance in an
Exponentially Intensified Regulatory Environment* This has led to a “rise in compliance as a corporate priority.” Further, as they expand across the globe, “corporations must now take extraordinary steps to ensure the integrity of far-flung supply chains.”
“In discussing the great importance of compliance in a global sense, it is clear that local and foreign regulations are equally important.” And so companies must “comply with a vast number of regulations in a changing landscape…” *Association of Corporate Counsel, ACC Law Department Management 2016 Report, Executive Summary at 4 (2016). 8<br>
slide9. Complying with Laws and Regulations Globally
Requires a Legal Risk Assessment, Ethics and Integrity Ethics must guide an effective corporate compliance program. As the Corporate Culture Influencer white paper states, “A strong general counsel can establish the practices that reinforce a corporate culture that values ethics and integrity.”* *Richardson and Blatch, “Leveraging Legal Leadership: The General Counsel as a Corporate Culture Influencer,” at 6 (2017). 9<br>
slide10. Complying with Laws and Regulations Globally Requires a Legal Risk Assessment, Ethics and Integrity A legal risk assessment is the foundation of complying with laws and regulations globally and is therefore the foundation of an “effective” compliance program
A legal risk assessment is a major undertaking for in-house counsel and/or compliance officers
But it is not sufficient to comply with the laws and regulations if the outcome is not ethical 10<br>
slide11. Compliance = Ethics
Must Foster a Culture of Ethics Regardless of department size, Ethics must be the guiding principle of
an effective compliance program, regardless of the size of the law department.

Based on Awareness
Ethics awareness requires a “tone at the top”.
The Chief Executive Officer, the C-Suite Officers and the Board of
Directors need to lead by setting high ethical standards for themselves and their employees.
“Tone from the top is not a motivational crusade. Most [negative] changes happen where there are doubts about whether the tone is the right one. Ultimately chairmen should change the CEO if the values and ethics aren’t present to the right extent.”*

*Richardson and Blatch at 4 (quoting “Tone From the Top: How Behavior Trumps Strategy,” by Ian Muir, Keeldeep Associates Ltd, UK. First published in 2015 by Gower Publishing LOC Control, No. 2014957909). 11<br>
slide12. Boeing
Boeing’s merger with rival McDonnell Douglas in 1996 was key, because it
led to a wholesale change in the airline giant’s ethos, much to the displeasure of staff . . .

“The idealism just went out,” one insider told Robison. “It was about something else – I guess shareholder value.”

McDonnell executives, later described by federal mediators as “hunter killer assassins,” clashed with Boeing’s “Boy Scouts,” and the workforce grew increasingly disgruntled.

Boeing knew doomed 737-Max plane was ‘pig with lipstick’ but still let it fly (November 24, 2021)
https://nypost.com/2021/11/24/boeing-knowingly-flew-pig-with-lipstick-737-max-plane/ Culture Matters 12 Boeing has achieved the unthinkable this week: It managed to fall even deeper into crisis. CNN 4-10-24
https://www.cnn.com/2024/04/10/investing/boeing-safety-problems/index.html Boeing entered into a consent decree with the US Department of State for $51 million in fines to resolve 199 violations of the Arms Export Control Act. Due to Boeing’s unauthorized exports and retransfers of technical data to foreign-person employees and contractors; unauthorized exports of defense articles.
U.S. Department of State Concludes $51 Million Settlement Resolving Export Violations by The Boeing Company - United States Department of State<br>
slide13. Google
According to the US Department of Justice, statements such as "adding legal" or "adding [attorney] for legal advice" appear in thousands of Google documents. These emails apparently lacked any specific request for advice and attorneys rarely respond to them. In the brief, the department said the practice "pervades the entire company" and is being used even by Alphabet CEO Sundar Pichai.

US Justice Department says Google misuses attorney-client privilege to hide documents (March 22, 2022)
https://www.yahoo.com/news/us-justice-department-google-misuse-attorney-client-privilege-072951407.html Culture Matters Note: Court found in favor of Google 13 Tesla
2023- Elon Musk talks Tesla: “We dug our own grave with the Cybertruck” 10-19-23
https://arstechnica.com/cars/2023/10/elon-musk-talks-tesla-we-dug-our-own-grave-with-the-cybertruck/

2024
11,688 Cybertrucks from the 2024 model year because the front windshield wiper motor controller failed due to excessive electrical current.
11,383 Cybertrucks because the trunk bed trim sail applique could have been improperly attached, creating the potential to become loose and create a road hazard.
4,000 Cybertrucks in April to fix an accelerator pedal pad that could come loose and get lodged in the interior trim.<br>
slide14. Ethics Awareness and Culture Change Ethics awareness and culture change can be the result of fear of prosecutors and regulators investigating and indicting the company, officers, and/or board of directors for illegal activities.

Fear can be enhanced by citing investigations and legal cases in the news with billion-dollar consequences, for example, Wells Fargo ($3.7 billion)8; JPMorgan ($13 billion)9; and Bank of America ($16.65 billion).10 8. Matt Egan, “Wells Fargo ordered to pay $3.7 billion for ‘illegal activity’ including unjust foreclosures and vehicle repossessions”, CNN, https://www.cnn.com/2022/12/20/investing/wells-fargo-cfpb-foreclosure-fine/index.html (December 2022)
9. Karen Freifeld et al., “JPMorgan agrees $13 Billion settlement with U.S. over bad mortgages,” Reuters, https://www.reuters.com/article/us-jpmorgan-settlement/jpmorgan-agrees-13-billion-settlement-with-u-s-over-bad-mortgages-idUSBRE9AI0OA20131120 (Nov. 19 2013).
10. U.S. Dept. of Justice, “Bank of America to Pay $16.65 Billion in Historic Justice Department Settlement for Financial Fraud Leading up to and During the Financial Crisis,” https://www.justice.gov/opa/pr/bank-america-pay-1665-billion-historic-justice-department-settlement-financial-fraud-leading (Aug. 21, 2014). 14<br>
slide15. Board of Directors’ Duty and Liability In-house counsel should make sure the board of directors understands
that in many jurisdictions the board members might have personal liability for failing to adequately ensure the company has an effective compliance program. 15<br>
slide16. Evolving Duties and Responsibilities Board of directors’ duties and responsibilities are evolving to include the following:
1. The fourth line of defense in the company-corporate governance; (the three lines of defense are 1) the business people, 2) the compliance and legal departments, 3) the internal audit department) and
2. ESG (Environmental, Social and Governance) ACC ESG Resource Center
https://www.acc.com/resource-library/esg 16<br>
slide17. Why Have an “Effective” Compliance Program? An “effective” compliance program can help insulate the company, and its officers and employees from criminal and civil penalties, protect the board of directors from personal liability and create a culture of the “good citizen” corporation.
A poorly constructed program can serve as a roadmap for prosecutors to indict the corporation, damage the morale of employees who will view the corporate compliance program as a sham, and encourage fraud and unethical conduct to continue. 17<br>
slide18. Dual Roles of General Counsel and Chief Compliance Officer in Legal Risk Assessment In “solo” and small legal departments, remember that the general counsel may also function as the chief compliance officer. In this dual role, in-house counsel should be aware of inherent conflicts of interest due to the general counsel providing legal advice at the same time as being the chief compliance officer and providing auditing and monitoring of compliance with laws and regulations.
This may make it more difficult for a dual role general counsel/chief compliance officer to assess legal risk. 18<br>
slide19. Conducting a Legal Risk Assessment A legal risk assessment is the foundation of an effective compliance program 19<br>
slide20. Steps for an “Effective” Legal Risk Assessment A legal risk assessment requires the following steps:
Creating an Inventory of documents
Drafting Interview questions
Interviewing key stakeholders
Determining inherent risks and creating a heat map of inherent risks
Establishing controls where possible for each inherent risk and determining the residual risks, then creating a heat map for residual risks, and
Creating an executive summary, including heat maps. 20<br>
slide21. Inventory of documents A legal risk assessment starts with an inventory of documents and includes the following:

Organizational charts reflecting company partnerships or affiliations and management responsibilities
Business plans, annual reports, and other materials describing business operations and strategic business initiatives
Handbooks and any other policies or procedures reflecting company standards or operational protocols
Existing compliance structure or program and any previous internal or external reviews or assessments of the compliance program
Business partner inventory lists, including any government officials or entities with whom the company interacts 21<br>
slide22. Inventory of Documents
Additional Examples Training curriculum and related materials (diversity, sexual harassment, etc.)
Corporate audit document checklist
Previous internal or external reviews and investigations of reports received through a whistleblower hotline or other misconduct reporting mechanisms
Litigation lists and settled cases for past five years
Crisis management policies and/or manuals
Data retention policies and/or manuals
Employee application forms
Human resources annual reports In Exit/termination checklists
Interview checklist or performance evaluation form
Insider trading guidelines
Environmental policies and reports
Community Right to Know reports (for U.S. based businesses)
Advertising materials
Search of relevant public documents concerning the company, its competitors and product market(s) 22<br>
slide23. How to Use the Inventory of Documents Based on the inventory of documents, in-house should create a preliminary list of risks to be used to create interview questions on the risks and interview key stakeholders about the legal risks.

Some legal risks to look for when creating the risk assessment inventory of documents and the interview questions are provided in the following list: 23<br>
slide24. Legal Risks Legal risks to look for when creating the risk assessment inventory of documents and the interview questions: Anti-Money Laundering Act (AML)
Antitrust/ Competition
Conflicts of Interest
Conflict Minerals
Corporate Social Responsibility (CSR) and Environmental,
Social and Governance (ESG)
Customs, Export Controls, and Sanctions
Cybersecurity, Physical Security
Employment
Environmental
False and Deceptive Advertising
Foreign Corrupt Practices Act/ UK Bribery Act, OECD, and local bribery acts
Fraudulent Financial Reporting

Gifts and Gratuities
Government Contracting
Insider Trading
Intellectual Property
Lobbying, Political Contributions, and other political activities
Modern Slavery Act
New Business “Alliances”
Procurement of Goods/Services
Records Management
Privacy and Data Protection
Sexual Harassment
Social Networking
Subcontractors, Subsidiaries, and Consultants
Tax
Workplace Safety 24<br>
slide25. Interview Questions Sample interview questions: Based on the interviews, prepare a report on Legal Risk Assessment, including Best Practices and Areas of Deficiency (gaps) based on the following questions:
What are your key LEGAL risk areas?
What are the standards and procedures that you now have in place in these LEGAL risk areas?
What are the areas you have successfully limited LEGAL risk and how?
What areas could you improve through controls to limit LEGAL risk?
What is happening in such key LEGAL areas as antitrust, environmental, employment, intellectual property and insider trading?
Describe the company culture toward corporate compliance and limiting LEGAL risk. 25<br>
slide26. Interview Key Stakeholders 26 Interview key stakeholders about legal risks including: CEO, C-suite officers, employees, outside counsel, insurance brokers, accountants and legal providers for the company who know about legal risks.<br>
slide27. Heat Map of Inherent Risks Create heat map of based on the risks found.
These are the inherent risks. Risk Impact Likelihood 27<br>
slide28. Heat Map of Residual Risks Create a heat map of the residual risks by developing controls for each inherent risk. Once the controls are developed, subtract the control from the inherent risk and this equals the residual risks (Inherent risk minus control equals residual risk).
An example of an internal control is to have the internal audit department review gift and entertainment expenses for foreign officials to determine if these are reasonable and bona fide expenses.
An example of an internal control is to have a second signature on any expenses over $1,000. Risk Impact Likelihood 28<br>
slide29. Executive Summary Including Heat Maps Create an executive summary of the legal risk assessment including heat maps of the inherent and residual risks. 29<br>
slide30. Using the Legal Risk Assessment to Develop
The Law Department Strategic Plan 1. General counsel should create a committee to oversee law department strategic planning.
2. The strategic plan should be based on a legal risk assessment of the challenges facing the legal department.

3. The planning committee should review the company’s mission statement and create or revise the legal department’s mission statement so it aligns with the company’s mission statement and with the risk assessment.
The strategic plan should, at a minimum, include a one-year plan and a five-year plan. The one-year plan and five-year plan should each be accompanied by a budget plan and a reporting plan.
The strategic plan should also include an implementation plan.
The strategic plan should be presented to the CEO (or other c-suite officers) and to the board of directors. 30<br>
slide31. Maintaining Privilege of The Legal Risk Assessment Where Possible Consider Civil Law vs. Common Law

Consider how to mark the document
(confidential, client legal privilege, internal use only). 31<br>
slide32. Seven Steps for an “Effective” Compliance Program Standards, procedures, and controls to prevent and detect criminal conduct.
Board must be knowledgeable about and oversee program; top management must ensure effectiveness of program; specific individual(s) within high level personnel must have responsibility for program.
Reasonable efforts not to include within substantial authority personnel individuals whom the organization knew or should have known engaged in illegal activities or conduct inconsistent with an effective program.
Communicate standards and procedures– to directors, employees and, as appropriate, agents– by training and by other means.
Auditing and monitoring to detect criminal conduct; evaluate program periodically; have and publicize a system for reporting suspected violations and seeking guidance.
Promote and consistently enforce the compliance program through appropriate incentives and appropriate discipline.
After criminal conduct is detected, take reasonable steps to respond appropriately and prevent further similar criminal conduct, including necessary modifications to the program. A legal risk assessment is the foundation of the seven steps. The legal risk assessment plus the seven steps are as follows: 32<br>
slide33. Seven Steps for an Effective Compliance Program

Step One:
Written Policies, Procedures and Internal Controls: After completing the legal risk assessment as provided above, the first step is having written policies, procedures and internal controls for the risks identified.
These should include the mission statement, the letter from chief executive officer, code of conduct, employee handbook, corporate compliance guidelines, and aligning the code of conduct, policies, procedures and internal controls. 33<br>
slide34. Step Two:
Reporting Lines and Creating a Compliance Office with a Compliance Officer The second step is having appropriate reporting lines so that the Board of Directors as well as the Chief Executive Officer can oversee the compliance program.
The legal department and/or the compliance department needs effective reporting lines to the Board and CEO for the corporate compliance program.
Reporting lines may be direct or indirect. This depends on whether the compliance officer reports directly to the CEO and the Board or the compliance officer reports indirectly (“dotted line” reporting) to the General Counsel or C-suite officer and indirectly (“dotted line” reporting) to the Board. 34<br>
slide35. Step Two continued:
Reporting Lines and Creating a Compliance Office with a Compliance Officer: Remember that in a solo/small law department, the general counsel may have the dual role of the compliance officer.
Under those circumstances, the general counsel would report directly to the CEO and Board.
The compliance officer and/or in-house counsel should be aware of centralized or decentralized reporting if subsidiaries are involved.
Specific high-level personnel should oversee the compliance program, such as the compliance officer and/or the in-house counsel.
The compliance officer and/or in-house counsel should have sufficient funds and staffing to carry out their responsibilities in developing an effective compliance program as set forth in the seven steps.
Remember, the company has three lines of defense: 1) the business people, 2) the compliance and legal departments, 3) the internal audit department. (There is a new fourth line of defense- governance- which refers to corporate governance by the board of directors.) 35<br>
slide36. Step Three:
Background Checks The third step is having background checks for all employees, as well as
agents, suppliers, vendors and other third-parties working with the company.
Background checks should occur at the time of employment, based on legal requirements, as well as other times according to the customs and practices in each jurisdiction of employment.
This is the most localized step since employment requirements vary by countries, states, and localities.
Background checks should also be done on agents, suppliers, vendors, and other third-party providers. These third-parties, including law firms and accounting firms, often have access to company computer systems and can be a vulnerable access point for cybersecurity breaches. Also, third-parties can be a conduit for bribery of foreign officials and for commercial bribery. 36<br>
slide37. Step Four: Training All employees should have training on the corporate compliance program. Training should be on the code of conduct as well as on specific high priority risk areas.
Code of conduct training should be given at the time of hiring as well as scheduled at least once a year.
Every employee should have a training schedule that is based on his or her job description.
Different training may be provided to the chief executive officer and the c-suite officers to correspond to the need for specific risks such as bribery or creating “tone at the top”.
Training can be coordinated by the compliance department, legal department or human resources depending on availability, expertise and personnel.
The Board should receive training on the code of conduct as well as on the overall compliance program so that they can properly oversee the compliance program under their fiduciary duties.
The types of training include in-person training, live virtual training, online self-paced training, and train the trainer programs. 37<br>
slide38. Step Five:
Auditing, Monitoring and Reporting Auditing, monitoring, and reporting include the use of hotlines, heat maps, dashboards, testing, and surveillance.

The hotline must be available internationally with toll-free numbers and preferably using an independent third-party hotline provider.

The global third-party provider should have the capability to respond in multiple languages twenty-four hours a day/seven days a week.

The hotline should have the capacity to provide anonymous reporting. While the hotline process is anonymous, it must be clear to employees that only anonymity but not confidentiality can be offered. 38<br>
slide39. Step Five continued:
Auditing, Monitoring and Reporting Auditing and monitoring should be based on legal risks as determined by the legal risk assessment.
Best practice today is to have heat maps on the risks and use dashboards to show where the compliance and/or legal department is in the process of auditing and monitoring the highest priority legal risks. The chief compliance officer and/or general counsel should set up a regular auditing and monitoring schedule including on-site visits and spot checks.
To supplement auditing and monitoring, the chief compliance officer and/or general counsel should set up testing and surveillance programs to assess the effectiveness of the compliance program.
The results of auditing and monitoring must be reported internally to the CEO or the c-suite officer in charge of compliance (either directly or indirectly) and to the board of directors.
Where the report results need to be forwarded to government regulators, the general counsel and/or chief compliance officer should have the authority to forward this report. 39<br>
slide40. Step Six:
Consistent Enforcement Through Discipline and Incentives: Discipline and incentives foster an “effective” compliance program and a culture of ethics. This requires a systematic written standard for disciplining employees who violate the code of conduct, policies and procedures of the company.
An excellent compliance program tool to deal with discipline and incentives for all employees is yearly performance evaluations that include criteria for compliance values, ethics, integrity and attendance at compliance training sessions.14 14. Carole Basri, Corporate Compliance Practice Guide, at 10-26. § 10.07. 40<br>
slide41. Step Seven:
Updating the Compliance Program and Creating Internal Investigation Protocols Continually update the compliance program and follow up with internal investigations using internal investigation protocols.
This requires that compliance officers and/or general counsel have a fluency with the legal risk assessment and the seven steps for an “effective” compliance program. 41<br>
slide42. 42 Rolling Out the Compliance Program<br>
slide43. Phase I: Conducting a High-level Compliance Risk Assessment During Phase I:
Form a committee.
Request an inventory of documents.
Interview key officers and employees.
Prepare a report on Risk Assessment, including Best Practices and Gaps .
Compare the inherent risk minus controls to find the residual risk.
Prepare heat maps and dashboards.
Prepare an executive summary, if appropriate. 43<br>
slide44. Phase I: Conducting a High-level Compliance Legal Risk Assessment (continued) The committee should be composed of at least the following:
CEO or President
General Counsel
Chief Financial Officer (CFO)
Internal Audit Director 44<br>
slide45. Phase I: Conducting a High-level Compliance Legal Risk Assessment (continued) The Committee should report to the Audit Committee of the Board of Directors or directly to the Board of Directors

Request an inventory of documents including written policy and procedures on key risk areas, employee handbooks, litigation logs, training manuals, corporate filings, existing codes of conduct, insurance policies, etc.
President
Business Development/Sales Marketing
General Counsel/Outside Counsel
Chief Financial Officer
Human Resources Director
Environmental Health and Safety, if any
Chief Compliance Officer, if any, and
Other key officers and employees, as necessary 45<br>
slide46. Phase I: Conducting a High-level Compliance Legal Risk Assessment (continued) Based on the interviews, prepare a report on Legal Risk Assessment, including Best Practices and Areas of Deficiency (gaps) based on the following questions:
What are your key LEGAL risk areas?
What are the standards and procedures that you now have in place in these LEGAL risk areas?
What are the areas you have successfully limited LEGAL risk and how?
What areas could you improve through controls to limit LEGAL risk?
What is happening in such key LEGAL areas as antitrust, environmental, employment, intellectual property and insider trading?
Describe the company culture toward corporate compliance and limiting LEGAL risk. 46<br>
slide47. Phase I: Conducting a High-level Compliance Legal Risk Assessment (continued) If appropriate, present the report on Legal Risk Assessment, including Best Practices and Gaps:

The report should provide a legal risk assessment for relevant areas of law.
The report should be presented to senior management and the Board of Directors.
The report should be presented to the officers of all subsidiaries who were interviewed.
The report should include heat maps and dashboards.
Buy-in on the report should be encouraged.
Create a work plan, which should include a timetable and an action plan. 47<br>
slide48. Phase II: Developing an Overall Compliance Blueprint During Phase II:
Look at other codes of conduct;
Use the committee and focus groups to develop a Code of Conduct;
Customize the Code of Conduct to the company culture;
Customize the Code of Conduct so it is suitable for all employees;
Make sure the Code of Conduct is user-friendly and attractively packaged;
Create a Mission Statement and Letter from the CEO to accompany the Code of Conduct; and
Create Corporate Compliance Program Guidelines. 48<br>
slide49. Phase III: Evaluating and Developing Policies and Procedures in Substantive Areas During Phase III:
Inventory policies and procedures already in place
(e.g., internal controls for antitrust/competition, sexual harassment policy, environmental policy, etc.).
Align the Code of Conduct, policies and procedures, internal controls and employee handbook.
Develop policies and procedures where gaps exist as indicated from the report on Best Practices and Gaps and borrow best practices, where necessary from other subsidiaries or outside the organizations (see trade associations, industry practice groups, law firms, consultants, seminars, such as Practicing Law Institute (PLI) and the Association of Corporate Counsel). 49<br>
slide50. Phase IV: Communication, Training and Implementation During Phase IV:
Introduce Code of Conduct and Program
Ongoing Communications Plan
Training Plan
Training Materials/on the Intranet
Training Schedule 50<br>
slide51. 51 2021 ACC LEGAL OPERATIONS WHO USES WHAT LEGAL TECHNOLOGY? SURVEY RESULTS<br>
slide52. Phase V: Continually Refining Program, Self-assessment, Monitoring and Reporting During Phase V:
Internal Controls
Internal Audit
Incentive System
Internal Investigation Protocols
Publicize Reporting Results 52<br>
slide53. Gatekeeper Liability The general counsel and/or the chief compliance officer are considered gatekeepers for the corporation. As gatekeepers, they are liable for failing to maintain an adequate compliance program. 53<br>
slide54. Responding to Regulators’ Requests Who received the request?
What is the scope of the information requested?
When is the information due?
Is the request reasonable?
Does the legal department have a member available on location?
Remember to consult outside counsel
Remember to create a timeline and a work plan to comply with the request 54<br>
slide55. Morgan Stanley Declination from Prosecution:
The Shield of an “Effective” Compliance Program Morgan Stanley had many of the hallmarks of an “effective” corporate compliance program.
As discussed in the Morgan Stanley Declination, an “effective” compliance program resulted in Morgan Stanley not being prosecuted under the Foreign Corrupt Practices Act (“FCPA”) for violations by a “rogue” employee, Garth Peterson. 55<br>
slide56. 3.1. Should hotlines be conducted as follows? Offer confidentiality but not anonymity to reporting individuals.
Offer confidentiality and anonymity to reporting individuals.
Only conduct hotlines through internal resources of the company and not through outside hotline providers.
Offer anonymity but not confidentiality to reporting individuals. Module 3 Review: Compliance, Ethics, and Legal Risk Management 56<br>
slide57. 3.1. Should hotlines be conducted as follows? Offer confidentiality but not anonymity to reporting individuals.
Offer confidentiality and anonymity to reporting individuals.
Only conduct hotlines through internal resources of the company and not through outside hotline providers.
Offer anonymity but not confidentiality to reporting individuals. Module 3 Review: Compliance, Ethics, and Legal Risk Management 57<br>
slide58. 3.2. Before doing the seven steps for an “effective” compliance program, what should you do as the foundation for the compliance program?

Create an organizational chart for the company
Understand direct and indirect reporting lines for the company and legal department.
Conduct a legal risk assessment
All of the above 58<br>
slide59. 3.2. Before doing the seven steps for an “effective” compliance program, what should you do as the foundation for the compliance program?

Create an organizational chart for the company
Understand direct and indirect reporting lines for the company and legal department.
Conduct a legal risk assessment
All of the above 59<br>
slide60. 3.3. What is the first step in the seven steps for an “effective” compliance program?

Training all employees
Background checks on all employees and vendors, suppliers and agents
To have standards, procedures, and controls to prevent and detect criminal conduct
Auditing, monitoring and reporting 60<br>
slide61. 3.3. What is the first step in the seven steps for an “effective” compliance program?

Training all employees
Background checks on all employees and vendors, suppliers and agents
To have standards, procedures, and controls to prevent and detect criminal conduct
Auditing, monitoring and reporting 61<br>
slide62. 3.4. What does a legal risk assessment include?

An inventory of documents and interviews with employees and others
Heatmaps of inherent and residual risks
An executive summary of legal risks
All of the above 62<br>
slide63. 3.4. What does a legal risk assessment include?

An inventory of documents and interviews with employees and others
Heatmaps of inherent and residual risks
An executive summary of legal risks
All of the above 63<br>
slide64. 3.5. When should background checks be performed on employees?

Only at the time of hire.
Only at the time of promotion.
Only at the time of a salary increase.
It depends on the law in the jurisdiction where the employee is hired. 64<br>
slide65. 3.5. When should background checks be performed on employees?

Only at the time of hire.
Only at the time of promotion.
Only at the time of a salary increase.
It depends on the law in the jurisdiction where the employee is hired. 65<br>
slide66. 3.6. What types of compliance training are “effective”?

In person training
Internet training
Train the trainer
All of the above 66<br>
slide67. 3.6. What types of compliance training are “effective”?

In person training
Internet training
Train the trainer
All of the above 67<br>
slide68. 3.7. What is the seventh step of the seven steps for an “effective” compliance program?

Publish an annual report on compliance results
Creating internal investigation protocols
Updating the compliance program and creating internal investigation protocols
None of the above 68<br>
slide69. 3.7. What is the seventh step of the seven steps for an “effective” compliance program?

Publish an annual report on compliance results
Creating internal investigation protocols
Updating the compliance program and creating internal investigation protocols
None of the above 69<br>
slide70. 3.8. Who are considered to have “gatekeeper” liability for the corporation?

The board of directors
Chief financial officer
General counsel
General counsel and/or chief compliance officer 70<br>
slide71. 3.8. Who are considered to have “gatekeeper” liability for the corporation?

The board of directors
Chief financial officer
General counsel
General counsel and/or chief compliance officer 71<br>
slide72. 3.9. Can performance evaluations be used as a tool for incentives and discipline in a corporate compliance program?

Yes
No 72<br>
slide73. 3.9. Can performance evaluations be used as a tool for incentives and discipline in a corporate compliance program?

Yes
No 73<br>
slide74. 3.10. Is “the right thing to do” legally always the same as “do the right thing” ethically?

Yes
No 74<br>
slide75. 3.10. Is “the right thing to do” legally always the same as “do the right thing” ethically?

Yes
No 75<br>
slide76. 3.11. Can ethics awareness help a company create “tone at the top” and a “culture of ethics”?

Yes
No 76<br>
slide77. 3.11. Can ethics awareness help a company create “tone at the top” and a “culture of ethics”?

Yes
No 77<br>
slide78. End of Module 3 78<br>
slide79. Presentation Criteria 79<br>
slide80. Team project 1: Conducting a legal risk assessment and creating one year and five-year strategic plans. Objective: To demonstrate understanding of the essential elements of a legal risk assessment and the importance of strategic planning. Students will break into teams to work on the project requiring imagination, research and power-point skills. The teams will be assigned to work on one of the following companies:

Team 1: Astra Zeneca (Pharmaceuticals)
Team 2: Wells Fargo (Financial)
The team project on legal risk assessment and strategic planning involves the team researching and developing the power-point presentation during this workshop. In the following workshop, each team will present their research on the legal risks and strategic planning to the board of directors and executive leadership of the company. Project: 80<br>
slide81. Assignment: As a new general counsel, complete the following:

In order to ascertain company legal risks, identify an inventory of documents that are publicly available, such as recent annual reports, the code of conduct, press releases, and other public filings.
Explain how you identified the legal risks, using the internet to find information on the company’s risks, product risks and the company’s industry risks.
Create sample interview questions and a list of who to interview.
Create heat maps to illustrate inherent risks and residual risks, including footnotes explaining the source of your inherent risks. Also, you should explain the controls you used to determine the residual risk, including footnotes detailing how you chose the control and how the control will reduce risk.
Create the executive summary including the heatmaps for inherent risks and residual risks.
Create the one year and five-year strategic plans based on the legal risk assessment.
Present the executive summary on the legal risk assessment, including the heat maps, as well as, the one year and five-year strategic plans. 81<br>
slide82. You may present in any order and add or delete the items below as you wish:

Moderator/introduction: explain why the board of directors and executive leadership need to know about the legal risk assessment (Please include an agenda and organizational chart for the legal department and the company.).
Identify and explain the inventory of documents, including legal risks you identified from the annual reports and the code of conduct, as well as other documents.
Explain how you identified legal risks from internet sources and other research.
Explain your interview questions and list of interviewees.
Create your heat maps for inherent risks and residual risks and explain your controls.
Create the executive summary including the heatmaps for inherent risks and residual risks.
Create the one year and five-year strategic plans based on the legal risk assessment.
Present the executive summary on the legal risk assessment, including the heat maps, as well as, the one year and five-year strategic plans.

You have 2.5 hours to organize your team, assign roles and develop your presentation.
Presentations should be limited to 10-15 minutes. Please keep to the time limits.

Note: Each participant must present at least one of the slide in each presentation. 82<br>