Compliance at the Beginning
In the 1970s when I first started doing corporate[1] compliance work, compliance was done by specific risk area. I was not a compliance lawyer. I was an antitrust lawyer and my work included training and written guides on antitrust. The company had a code of conduct and that included some language about antitrust. There were not conferences or books on “compliance,” although there were such activities and materials related to antitrust compliance.
Gradually in my inhouse work, however, I began to realize that compliance work done in other legal risk areas – environment, regulatory, FCPA, EEOC, OSHA – was very similar to what I was doing in antitrust compliance. Training, policies, checking to see what was actually being done, incentives, etc., had a role to play in every compliance risk area. I could see that I had more in common with others doing compliance in those different risk areas than I did with fellow lawyers who did wills and estates or litigation or tax work. Yet being a lawyer was one profession, whereas compliance was not seen that way.
Professor Jay Sigler, my college mentor and a distinguished professor at Rutgers University, and I saw this pattern as a good reason to explore “compliance” as being a potentially discrete field of study, different from the practice of law. In 1988 the result of our work together was a book titled Interactive Corporate Compliance, published by Greenwood Press. When we wrote this book we used the concept of being “interactive” on two levels. Looking back over the past 50 years those levels still seem to define much of the discussion today, albeit phrased differently.
Interaction between government and companies
The first element of interaction was between government and organizations. The second, discussed further below, related to how compliance was done within companies – that it has to be interactive with the employees, and not just one-way messages. The interaction with government is based on a power/political science perspective. Jay was both a lawyer and a political science expert, and political science had been my focus as a student guided by Jay.
As we saw it, compliance in companies largely involves controlling the use and abuse of power within the organization. Corporate leaders may wrongly use their power to cause the company to break the law, and to force employees to conduct themselves improperly. A fundamental element of political science is recognizing that it requires power to control and contain power. Leaders in organizations have power. To a substantial extent this comes close to being absolute power over the employees.
If we want to prevent corporate crime and misconduct, then we have to ask who else has enough power to call this to account and impose safeguards and controls. In theory, for public companies it is the owners, but in large organizations this is not actually the case. The reality of information asymmetry makes the idea of shareholder control closer to fiction than to fact. Public shareowners do not have that level of contact with the company, and larger, institutional investors typically do not have the interest, expertise or motivation to do this. By contrast, government does have power that can be used to control and therefore influence organizations. However, that government leverage has to be used intelligently. If government leverages its power effectively it can get corporations to do more to control their own actions.
Interaction within companies
Looking within companies, an essential point, and one that often seems to escape academics and others who study this area, is one that seems obvious to anyone who has worked in a large company. Jay and I recognized that companies are not just unitary, single things. A company is not simply one giant being acting in unison, with everyone in the company thinking the same way and pursuing the same interests. In reality, there are different groups or constituencies within organizations.
What are the differences within companies? Examples of such groups could be the legal department, finance, HR, sales, production, etc. There is also a significant difference between the field and headquarters. There are the officers and the managers. The environmental group and the marketing group. Even within these groups there are subgroups that compete for recognition and control. Similarly, what gets rewarded and incented among groups can vary significantly. For example, salespeople are rewarded for the business they bring in, whereas the creative folks are rewarded for developing memorable and effective advertising copy. The internal auditors would operate under a more control-oriented focus.
On the same basis, companies do not have one, consistent and uniform culture throughout. There are subcultures that apply to each of these groups within the company. The dynamics among these different structures and constituencies could be used as the foundation for building systems to influence conduct and control those who might otherwise engage in misconduct. If there were a compliance constituency or constituencies that were empowered to prevent misconduct – drawing some of their strength based on the overhanging strength of government (e.g., fear of enforcement and knowing that an effective program would count in the company’s a favor when it was needed) – this could play a leading role in controlling corporate misconduct. How much or how little this would apply would be orchestrated by government’s leverage. The more the government did to recognize and reward effective (but only truly effective) compliance programs, the stronger those compliance constituencies would be.
What about mandated compliance programs?
On the other hand, given what we knew about incentives and corporate behavior, we had no faith in detailed compliance program mandates pushed down on companies by government. First we considered the odd logic of mandating compliance programs. If mandates worked then we would not need compliance programs because companies would already be obeying the mandates of the substantive law in the first place! Mandating compliance programs just means if a company is breaking the law anyway, here is another one they can violate at the same time.
Moreover, there is another negative element of this mandate dynamic. When government sets a minimum, that same standard can quickly become the maximum. For example, if government tries to mandate that training be “interactive,” companies will interpret this as merely requiring that they allow 5 minutes for questions at the end. Government mandates would generally mean that in enforcement actions the burden of proof would be on the government to prove that you broke the law that required certain compliance program steps. So, a “bare minimum” following the literal words of a government mandate will typically suffice for purposes of convincing a judge that the government failed to carry its burden of proof – proving that you did not have a program that met the legal minimum. This also leads to a phenomenon known as “malicious compliance,” where the literal language of the compliance program is applied, but in a way that does nothing to achieve the government’s intent.
Consider examples of compliance program mandates. The classic is California’s assumption that the way to stop harassment was to have 2 hours of training every 2 years. It is notable that this became law well before #metoo, which revealed widespread patterns of sexual harassment and worse. I could always picture the general counsel with a stopwatch, ending the training after two hours, and announcing the plan to return in two years. I also picture a room of employees using their time productively on their phones, paying no attention to the training.
Another example can be seen in the banking and finance field. In this arena government dictates a pile of technical details, resulting in large teams of compliance technicians. But outside of the detailed government compliance program mandates, where are the real decisions made about how to treat the Epsteins of the world? Despite the government mandated details, the real decisions are left to the people in the companies with real power. Mastering a series of acronyms – SARs, KYC, AML – does not prevent crime. Without genuine power among the compliance constituencies, these mandates of technical details do not work at the most important times. And lest we forget Lord Acton’s insightful observation: “Power tends to corrupt, and absolute power corrupts absolutely.” In the business world bosses can have unchecked power over employees’ fate. Compliance and ethics need to be that check, but it cannot be if it is merely a government mandate to check boxes, use a 2-hour timer and file reports.
How would government effectively use its power to energize internal compliance efforts?
Rather than the quick and shallow approach of compliance program mandates, we saw that government needed to use an open-ended incentive system. Thus, the best potential approach could be seen in systems like the US Organizational Sentencing Guidelines and government programs giving credit for real compliance programs. In both these examples, the burden of proof rests squarely on the company. In order for a company to receive a meaningful benefit for a compliance program the company needs to carry the burden of proof. The Guidelines and DOJ’s approach allow companies to earn a break when they are most vulnerable – facing enforcement actions.
Companies know themselves better than anyone outside would, so it was only fair that the “How to” of program implementation rests with the company to show that its program was effective. Of course, this cannot just be a matter of mere trust by the government. A dog and pony show by outside counsel is not enough. As the US Antitrust Division has made clear in its guidance on compliance programs, the assessment of a company’s program needs to start right at the beginning of any investigation.[2] If employees who appear before a grand simply do not recall anything about the compliance program, then the enforcers know there was not one. Presentations by outside counsel will be dismissed as window dressing, if the program never actually reached the employees. It is also important to note that in the US enforcement system, the benefits are discretionary by the enforcers. So, companies know they need to have a very convincing case. This means they cannot depend on a mere checklist or a pile of policies. The real test is whether employees have been reached and respond to DOJ interviews in a way that is convincing.
Interactive compliance within the company.
But this was only half the “interactive” analysis. The other half is what makes compliance programs effective. We had seen a tendency in previous compliance work to just send messages out into the ether from the law department on the hope or assumption they would work. Lawyers would write up messages and send them out, with no follow up. While those of us who early on were trying to look at this realistically were not then using the label “behavioralists” in developing our approach, we were aware of human nature. We did not see how the one-way message alone could work. In every other aspect of the business, we did not see things effectively accomplished by mere one-way memos, so why think this would work for compliance? There needed to be the element of interaction – between those responsible for the compliance program and its message, and those in the business running its operations.
We saw two elements of interactive conduct within the companies. One was the establishment and empowerment of compliance constituencies within corporations that would interact with the rest of the organization. These would be the internal champions for doing the right thing. The other, fundamental point, was that all compliance work itself had to be interactive. It could not just be arrows pointing out from HQ. There must be real interaction with all the other groups and people throughout the corporation. We were also seeing a core truth about the work of compliance. It was not the practice of law; it was the practice of management. Every tool that was used by managers to get results also had to be used in compliance. Management, after all, was about interaction among management and the employees.
Where we have traveled.
In the journey we started with Interactive Corporate Compliance in 1988, we have seen a transformation where compliance and ethics is considered a discrete field, based on some core elements:
Companies are not solid blocks. Emotionally, especially when we are angered by corporate conduct, we often find it much more satisfying to identify wrongdoing companies as if they were just giant persons. But that is fantasy. They consist of different internal groups and constituencies, as well as enormous varieties of individuals.[3] Compliance and ethics looks to create and empower constituencies in each company that work to prevent and detect wrongdoing.
The power of the compliance constituencies[4] within companies comes indirectly from government. Companies know they can get in trouble and face enforcement and litigation. (There can also be influence from customers, investors, suppliers, etc., but none have the power of government.) Governments must credibly communicate to companies that they will receive better treatment if, but only if, they can prove they have an effective compliance and ethics program. Government must make clear that only programs that are truly empowered get credit.[5]
The focus of compliance and ethics is to prevent and detect misconduct. It is there to protect not just the company, but all those who can be hurt by the company: customers, workers, investors, neighbors, and others. It is the voice within the company for those who have no voice.
This profession is about the application of effective management techniques to prevent and detect misconduct. Senior management must interact with the rest of the company in a way that sends a message of ethics and compliance. Compliance and ethics must be at the big table when decisions are being made, not sitting at the Kiddie table.[6]
Interactive compliance going forward.
When we started writing this book in the 1980’s we were particularly inspired by Christopher Stone’s “Where the Law Ends.” Stone’s core insight stuck with us. When you are working in a large organization your immediate fear and focus is your boss. If you know your boss is going to come in and yell at you if you don’t make your numbers, that is an immediate and real fear. That someday, some way, some government might find out what questionable things you did to make those numbers is too remote to matter. The law sits outside the immediate room, not inside it. Interactive Corporate Compliance focused on the nuanced ways governments could influence companies to develop and empower internal compliance constituencies, and how those internal compliance champions could effectively use management tools to prevent and detect misconduct. Since we started down this trail in the 1980s there have been real successes, but there is a great deal more that can and should be done.
[1] “Corporate” here is used to cover all forms of organizations, including non-profits, universities, partnerships and government agencies. It is the same standard for “organizations” used in the US Organizational Sentencing Guidelines.
[2] See Joe Murphy, How do you evaluate compliance programs? One government agency has the answer, but no one has noticed!, Compliance and Ethics: Ideas & Answers, https://ideasandanswers.com/how-do-you-evaluate-compliance-programs/
[3] One more recent example of this truth is the growing awareness of neurodiversity among employees. Approaches that may work for one group may have a different impact for others.
[4] When we wrote the book we gave much more attention to corporate legal departments, although not to the exclusion of managers in the company who worked on compliance issues. In the book we did state: “Indeed, the development of an independent sector of compliance professionals may be one of the future consequences of interactive compliance.” p. 186 In fact, over time compliance and ethics has evolved into its own profession, with legal departments sometimes their active supporters, but sometimes sadly a barrier to success. See Corporate Compliance Insights, “Caught between Conscience and Career,” https://ideasandanswers.com/caught-between-conscience-and-career-an-ec-directors-confession/
[5] Failure to communicate this effectively has been a serious flaw thus far. While enforcers talk positively and specifically about compliance efforts installed after a crime is committed, there is precious little said about prior existing compliance programs. So, we are not currently hearing from the government about actual cases where specific compliance efforts earned credit, or where specific weaknesses undercut credit. See Kaplan & Murphy, “Unfinished Business at the Department of Justice,” https://ideasandanswers.com/unfinished-business-at-the-department-of-justice/
[6] Credit to Nick Gallo for the memorable reference to compliance not being confined to “the kiddie table.”