| | May - Jun 201519The most effective way to link with your organizational partners is to make sure that everyone has a clear understanding of the strategic mission and their individual roles, responsibilities and expectations and authorities in furtherance of the missionknow how and who is actually doing the manufacture and sale--then you can develop very targeted policies, training, and controls to address the actual risk. And internal adminis-trative functions (e.g., compliance, audit, legal, sales, human resources, operations, finance, etc.) can work together to most efficiently imple-ment and enforce--and when neces-sary--improve the policies, training and controls.Developing Customized Compliance ProgramsTechnology without a strategy and plan is usually a waste of money. There are no panaceas. You must first and foremost do the hard work of un-derstanding the organizational mis-sion and strategy so you can develop a compliance program around the risks most likely to derail that mis-sion and strategy. Only after that is accomplished can you properly vet and acquire technology that might cost-effectively catalyze your effort. For example, there are a myriad of tools which allow you to continuously monitor, collect and sort control fail-ures but if you haven't designed the controls to be effective in the first place or, if you are not committed to acting on information when it's cap-tured, then you've actually made mat-ters worse. Moreover, if the cadence of the business leaders in your or-ganization is not centered around dashboards and electronic data-bases, then don't purchase those tools or you'll be collecting infor-mation that nobody will actually look at and use.Advice to Fellow Compliance OfficersAlign compliance program activities with the business. Don't be redundant or irrelevant. Take the time to talk to business leaders about what it is that they're trying to accomplish and work with them to understand where illegal or unethical behavior could lead to consequences that would cause business loss or interruption. Prioritize risks so that you develop the most effective policies, training and controls and then work with your administrative partners to see if there is a pre-existing process that already works well which you might be able to also use to implement your activi-ties. Don't create a new process or purchase anything new until you've canvassed the organization to see if you really need a new process or tech-nology. Above all, focus on building a sustainable program aligned with the business around the actual risks fac-ing the organization even if that means slower-than-hoped-for change. It's a journey, not a sprint.Paul LiebmanES
<
Page 9 |
Page 11 >