Not in my silo: How does the CECO deal with other compliance-related risk functions?

Here is a practical question I heard once at a PLI program in New York on compliance program management.  It is not unusual to have compliance-related activities that are not under the direction of the chief ethics and compliance officer (CECO).  These can include environment, workplace safety, discrimination and harassment, product safety, consumer protection, privacy, AI, and other, specially-regulated areas.[1]  In long-established companies these may be functions that predate the Sentencing Guidelines and appear to be functioning effectively. Or they may be newly identified risks just arising from new business activities (e.g., AI).  Is the answer just to give up and say they will do their own thing, or to be aggressive and wage a turf war to try to take over everything related to compliance?

One of the areas where this has been brought to the forefront is in banking and finance. In the headline case of Jeffrey Epstein and the banks that continued to do business with him, we have the sad example of the compliance technicians who knew things were wrong but were overruled by powerful higher ups. They, like those working in other compliance-related areas, should have had direct access to someone with the power and position to have escalated this, and, if necessary, brought the board into the picture. 

How do we deal with this reality? I believe the answer is to break the silos and work cooperatively.  Just like the point that compliance does not need to report to legal to work interactively with the lawyers, so it is also true that not every compliance area needs to report to the CECO but that all players can work cooperatively. 

 

Analogy to the general counsel/compliance officer dust-up

This concept of cooperation is much needed in our field.  As a leading example, a great deal of the controversy about whether compliance should report to the general counsel is a false dichotomy addressing this same point.  The general counsel reporting issue is positioned as if there was only one choice:  either compliance reports to and is subservient to the general counsel, or there is a complete divorce with a wall between the two, each blindly following its own path. This is just foolishness.  Legal can work with compliance the way it would with other control-related departments such as HR and audit. I have not seen anyone assert that HR and internal audit need to be reporting to the general counsel; only in discussions about compliance is this set up as an all or nothing proposition, built on a foundation of silos.

What, then, is the solution for the CECO and any relationship to other corporate functions, including separate compliance functions?  Let’s start with a general proposition: they need to work together.  The CECO needs to work with the other compliance functions.  Never should they be completely separated. 

 

How do you coordinate compliance-related functions?

These are nice sounding words, but how do we make them work?  Here is what I have seen as useful tools for this purpose.   First, I recommend having a senior-level compliance management committee to support the CECO.  Members would include senior people from legal, HR, audit, IT, and security (senior, but subordinate in rank to the CECO, so there is no question who is in charge).  But this would also include members from other compliance related fields such as environmental, safety, regulatory, etc.  This only works, however, if the CECO is positioned as a senior officer, high enough to have the respect of others.  But then, that is necessary for any compliance program to operate effectively and credibly. 

It is also necessary, if this is going to work, that the CECO have a direct, unfiltered line to the board, and meaningful access to those who hold power on the board, including the chair of the audit committee. The CECO needs to be able to add value for those who work with the compliance program.  This comes from the board access, but also from other essential elements of a compliance program.  For example, the CECO should have input into promotions and evaluations of other managers.[2] This ability to add value can also come from the CECO having access to an effective company-wide communications vehicle.  When I was in-house, we had a very popular newsletter – called Report on Integrity – that carried summaries of actual compliance cases.  It was an interesting read, and every feedback source indicated it had real reach. Whether it was employee surveys, requests for policies mentioned in the newsletter, or just the obvious interest in reading our stories, the impact was clear.  Others in the company came to us to have their messages included. It did not matter that their reporting line was not through the CECO.  The CECO had something they wanted and needed, and the CECO could thus aid their compliance mission.  

When the CECO is positioned this way, here is what happens.  The environmental compliance manager who wants to get a message out to the field operations, the HR leader who needs budget for an anti-harassment program, the product quality expert who believes quality controls are in dangerous disrepair – they all know the CECO can get them the visibility and resources they need.  In effect, the CECO needs to have power, access to company resources facilities and data, and independence.  This makes the CECO a go-to resource for others to value. These others will also be a key source of information on any form of misconduct in the company. Putting the CECO in this position enables the CECO to fulfill a mandate from the board to inform the board of any compliance risks.  The CECO in this position is enabled to ensure the board keeps the commitments required by Delaware corporate law under the Marchand case, making clear that the board needs to keep on top of the most serious risks the company faces.[3] 

Only in this system can each of the various compliance-related risk managers have the benefit of an established relationship with the board, know what the board’s concerns and priorities are, and know how to convey to the board what it needs to know.  From the board’s perspective, they will be dealing with one CECO – a voice for compliance that they know and trust.  This person will not need to establish credibility for each presentation and issue presented. 

This is directly analogous to how the range of legal issues is typically handled.  There is not a senior environmental lawyer or labor lawyer or antitrust lawyer who regularly reports to the board.  Rationally this is channeled through one general counsel.  When and if there is a special concern about environmental law or labor law the general counsel can bring that expert along for the special purpose.  So too, the CECO can bring the privacy expert or the workplace safety professional as needed to the board meeting. 

 

The problem of the existing, siloed system.

Consider the impact of the existing system without the CECO playing this role.  The board and audit committee only have so much bandwidth.  If there are 2, 3, 4 or more voices all seeking an opportunity to speak, they risk all being diluted and dropped down to a lower level, which results in undue screening. This significantly increases the risk of the board being blind-sided.  When the board asks the CECO to assess the compliance risks, but there are entire risk areas completely outside of the CECO’s purview with no input or current status, the potential for disaster is significant.

But if the CECO has direct senior management and board access, and others come to the CECO for this purpose, you have placed the decision at the right level of expertise.  Just as the General Counsel is the screen for which legal issues reach the board, so the CECO is the one who can determine priorities on compliance management issues.  The CECO may, in fact, have the ability to resolve issues so that board intervention is not necessary.  But the CECO is positioned to determine what compliance-related resources are available, and also what the board really needs.  Because the CECO has (or should certainly have) regular, and not ad-hoc contact with the board, that officer will know how best to approach the board, and how to prioritize compliance-related concerns and issues.

 

The CECO as a resource.

Each of the risk areas can come to the CECO for other important needs as well.  For example, the environmental compliance person may have trouble with field operations people ignoring environmental concerns.  The CECO can work with HR and management to have the assessments of field operations people include assessment elements relating to environmental compliance and awareness.  If a manager is ignoring privacy violations in her work unit, the CECO can help ensure that the investigation into the matter is conducted professionally and promptly, and that those committing violations are held accountable. 

How do we get there? Every company should have a board resolution[4] establishing the compliance and ethics program and empowering the CECO. The parameters of this relationship can be spelled out there, to ensure it is understood by all. 

If the CECO is seen as powerful and with access to important resources, others in the company will crave access to this leader.  Each side can see the value of this alliance, and at the same time ensure that the board can rely on the CECO to meet its responsibilities as well. 

Through this method the company can avoid turf wars, protect the board, help empower the CECO and avoid wasteful duplication of resources.   

 

[1] In universities, a prominent example would be dealing with compliance obligations involving sports teams.

[2] See Murphy, “Who gets promoted – Should compliance & ethics have a say?”

https://ideasandanswers.com/who-gets-promoted-should-compliance-ethics-have-a-say/

[3] See Walker, “Enhancing Board Oversight of Compliance Programs: A Strategic Guide for Directors”

https://ideasandanswers.com/enhancing-board-oversight-of-compliance-programs-a-strategic-guide-for-directors/

[4] Murphy, A Board Resolution for Your Compliance Program – An Example,

https://ideasandanswers.com/a-board-resolution-for-your-compliance-program/

Discover more from Compliance and Ethics: Ideas & Answers

Subscribe now to keep reading and get access to the full archive.

Continue reading