Extending Ethics and Compliance to Third Parties Managing Third Party Risk of Corruption October 23, 2009

Similar documents
CODE OF CONDUCT AND ETHICS POLICY ON CONFLICTS OF INTEREST

BUSINESS ETHICS ASSESSMENT

HSBC USA INC. HSBC BANK USA, N.A. CHARTER OF THE COMPLIANCE COMMITTEE

Windham School District Procurement Policy for Federal Funds

HOC Works Program Requirements

NEENAH INC ETHICAL PURCHASING POLICY

UNITED REPUBLIC OF TANZANIA

SUMMARY FOR THIRD PARTY SUPPLIERS

School Business Manager

Are you ready for the FUTURE of your Quality Management system?

At Sungard Availability Services (Sungard AS), we believe that business thrives best in an environment of open and fair competition.

Corporate Governance Principles

Audit Committee Charter

D&B Compliance Verification

AUDIT & RISK COMMITTEE CHARTER

CHARTER OF THE NOMINATING AND CORPORATE GOVERNANCE COMMITTEE OF THE BOARD OF DIRECTORS OF PLURALSIGHT, INC. Adopted May 3, 2018

Huntington Bancshares Incorporated

Local Code Of Corporate Governance

ARIZONA FIRE DISTRICT ASSOCIATION FINANCIAL PROCEDURES POLICY

TASSAL GROUP LIMITED ABN Procedures for the Oversight and Management of Material Business Risks. (Approved by the Board 28 May 2015)

Request for Proposal. For. Unemployment Insurance Services. November 9, 2016

[AGENCY NAME] Mandate and Roles Document. (Pure Advisory Committees)

TERMS OF REFERENCE. Audit and Risk Committee (the "Committee") of Wilmcote Holdings Plc (the "Company")

Audit and Risk Management Committee Charter

Anti-bribery and Anti-corruption Compliance Policy Sociedad Química y Minera de Chile ( SQM )

University of Pittsburgh Office of the Controller General Accounting

Enterprise Risk Management Focusing on the Right Risks

ensuring staff are aware of the Principles they must follow when handling personal data ensuring appropriate controls are in place and are effective

GENERAL MOTORS COMPANY AUDIT COMMITTEE CHARTER. Amended and Restated: December 13, 2017

Collaboration Assessment Worksheets

Internal Control Requirements for Adopting New Accounting Standards

Work Instruction. for Change Management. Work Instruction Administrator John Doe Chief Corporeal Officer ACME

RISK MANAGEMENT AND BUSINESS CONTINUANCE A FAIS Standard. An AC Guidance Note. July 2010

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF PLURALSIGHT, INC. Adopted May 3, 2018

TERMS OF REFERENCE FOR THE PROVISION OF OUTSOURCED INTERNAL AUDIT SERVICE

HUMAN RESOURCES AND COMPENSATION COMMITTEE CHARTER

AUDIT, RISK MANAGEMENT AND COMPLIANCE COMMITTEE CHARTER

CITIGROUP INC. AUDIT COMMITTEE CHARTER As of January 18, 2018

Audit & Risk Committee Charter

Chapter 1. Introduction and Overview of Audit & Assurance

Guideline on the promotion of fair working conditions in the supply chain

HIPAA Privacy Rule LINKS AND RESOURCES AFFECTED ENTITIES IMPACT ON EMPLOYERS. Provided by Brown & Brown of Louisiana, LLC

Policy Coversheet. Link Tutors: appointment and responsibilities

Risk Management Policy

TERMS OF REFERENCE FOR CONSULTANTS

Sempra Energy Environmental, Health, Safety and Technology Committee Charter

CODE OF CONDUCT AND ETHICS POLICY ON COMPLIANCE WITH SANCTIONS & TRADE EMBARGOES

Anti-Bribery and Anti-Corruption Compliance Policy Sociedad Química y Minera de Chile ( SQM ) Version No. [2], June, 2018

A-1110 Wien. Privacy Notice

TD Insurance s Multi-Year Accessibility Plan

GHD Pty Ltd. Standard Operating Procedure - HSE SAFEguards HSE359

Research Data Request Form

EXECUTIVE SUMMARY INTERNAL AUDIT REPORT. IOM Kingston JM JULY 2017

Environmental Health & Safety Requirements for Master Agreement of Services

EXECUTIVE SUMMARY INTERNAL AUDIT REPORT. IOM Mogadishu SO November 7 December 2018

Board Perspective Outline for Leadership Labs

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF DROPBOX, INC.

Responsible Investment Policy

Stakeholder Relations and Communications Policy

Gifts & Hospitality. Effective Date Author Owner Approval Last Review Revise Date August 2017

Warranty Smart Blox (m-warranty) Simple, Streamlined, Smarter

ApplicantCare is an online application and candidate management tool that automates the hiring process.

Anti-Corruption Compliance Plan

Privacy & Data Protection Policy

Gifts & Hospitality Policy

Community Planning Association of Southwest Idaho FY Strategic Plan Report No Approved by the COMPASS Board, December 16, 2013

Effective Practices for Managing Student-Athlete Insurance

The CIA certification has 4 parts. The CCSA exam and the CGAP exam are single part specialty exams.

Anti-Money Laundering Policy

NCTJ Conflicts of Interest Policy and Procedures

STATE OF NEW YORK MUNICIPAL BOND BANK AGENCY

Copiague Chamber of Commerce

JAUPT Appraisal Criteria Centre Application. November 2016

Producer Statements will be accepted only in accordance with this policy.

WHOLESALE AND RETAIL SETA. Skills Development for Economic Growth. ETQA Assessor and Moderator Registration Policy

Proposal regarding the provision of administration services in respect of Isle of Man Companies

Manual of Administrative Policies and Procedures

Agency Reorganization Process

AUDIT COMMITTEE CHARGE

List of Services that we provide:

Developing Performance Goals and Expectations

NATCHITOCHES HISTORIC DISTRICT DEVELOPMENT COMMISSION STATE OF LOUISIANA

Position Description: Contracts Administrator Reports to: Project Manager

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd

JOHN L. LITTLE, D.D.S, P.A ACKNOWLEDGEMENT OF RECEIPT OF NOTICE OF PRIVACY PRACTICES. May Refuse to Sign This Acknowledgement-

Frequently Asked Questions: Broader Public Sector Procurement Directive

Board of Directors Job Description

Administrative Policies and Procedures Information Security Program Procedural Handbook for Line Managers and Supervisors (ISPHB02)

Emergency Support Function (ESF) 18 Business and Industry

THE CLOROX COMPANY AUDIT COMMITTEE CHARTER. [Effective May 8, 2017]

CMMI Institute Code of Professional Conduct, Version 1.0

Policy Planning and Analysis Team (PAT) Charter

ABOUT ACFE TANZANIA CHAPTER

FCM Grant Preparation Process:

Requirements and Best Practices for Payroll Expense Transfers (PETS)

National Planning Guide Summary A Practical Approach to Health Security Capacity Building Draft 21 July 2017

Investor Money Regulations

Assessing the Impact of Proposed California Assembly Bill No on "Pay to Play"

Summit Asset Managers Limited

Audit Follow Up. Citywide Cash Controls Development and Transportation Services (Report #0134, Issued August, 2001) As of March 31, 2002

Transcription:

Extending Ethics and Cmpliance t Third Parties Managing Third Party Risk f Crruptin Octber 23, 2009 Diana M. Lutz, JD Greg Triguba, JD, CCEP 1 Our Jurney Review the rle f third parties in cnducting business glbally Identify certain risks assciated with third parties Discuss pprtunities fr risk mitigatin Explre hw we manage risk thrughut ur rganizatins and with ur agents and cntractrs Gain insight int cntrls used t better manage antibribery risks and discuss the impact f culture Discuss yur challenges and pprtunities 1

Third Parties are Essential t Businesses Managing third party relatinships t mitigate ethics and cmpliance risks has becme a pririty fr leading cmpanies. Almst every business engages suppliers, cntract emplyees, agents, lbbyists, etc. Businesses are increasingly entering new markets and expanding the glbal reach f their prducts and services. T meet this grwing business demand, utsurcing wrk increased in ppularity, allwing cmpanies t access and leverage the glbal wrkfrce. Initially, sme cmpanies may have assumed that utsurcing meant limiting their risks and respnsibilities. Currently, use f third parties expands well beynd utsurcing and includes cntracting fr specialized and lcal prducts, services and expertise, supprting faster grwth and a greater impact in new markets. Tday, with mre defined accuntability placed n cmpanies, the reputatin f yur rganizatin, fr better r wrse, is ften placed in the hands f these third parties. Identify Yur Third Parties Third Party Types: Suppliers, Vendrs Distributrs, resellers Cnsultants - Expertise in: Legal, Accunting, Strategic Business, Lcal and Reginal Issues, etc. Industry Experts, Advisry Services Cntractrs, Temprary Services Agents, Sales Representative, Marketing Intermediaries Jint Venture Partners Recrd third parties and centrally track risk categry, due diligence file cmpletin, cmpliance prgram status, in persn visits, relatinship wner, cntract terms, prjects, payments, apprvals, etc. 2

Third Party Risk When agents and ther third parties engage in miscnduct r vilate the law they put yur cmpany at risk fr cmpliance and legal vilatins and financial and reputatinal harm. The best defense a cmpany has when a third party has vilated the law n its behalf is the absence f authrizatin cmbined with the cmpany s well dcumented best effrts t prevent and detect such miscnduct. Risk can be mitigated thrugh due diligence. While varying levels f diligence are apprpriate fr mst third parties, cnducting due diligence shuld be a pririty fr third parties representatives r business partners perating utside the U.S. and interacting with gvernment fficials. Emerging Markets and Increased Risk The Transparency Internatinal Crruptin Perceptins Index ranks the degree t which crruptin is perceived t exist amng public fficials and pliticians by cuntry. Pssible Scres Range frm 10 (very clean) t 0 (highly crrupt) http://www.transparency.rg/plicy_research/surveys_indices/cpi/2008 3

Third Party Risk Expsure Legal liability and cnsequences fr actins f third party. Third party actins n yur behalf affecting reputatin. Third party investigated r under a clud can affect yur rganizatin even if yur rganizatin is nt implicated. Specific examples f hw a Third Party can create Risk: Supplier f yur gds runs a sweat shp. New manufacturer f yur dg fd brand has quality issues and substitutes cheap, txic fillers fr ingredients. Yur agent lavishly entertains gvernment fficials. Distributr sells prduct t a legally prhibited market (i.e. sanctined cuntry). Marketing cnsultant misuses custmers private data. Lbbyist bribes gvernment fficial. Managing Third Party Cmpliance Risk Key Steps Identify third parties that present the highest risk. Cnsider crruptin index f lcatin fr business t be cnducted, interactin with gvernment, cntract size, when assigning risk ratings t third parties. Use due diligence prcess t mitigate risk and eliminate thse third parties wh present unmanageable levels f risk. Ensure third parties are educated and agree t cmpany ethics & cmpliance prgram standards. Ensure wn cmpany staff is well trained and able t spt red flags and address them. Include terms in third party cntracts that require cmpliance and audit rights and prvide fr cntract terminatin if nncmpliance situatins arise. Ensure nging mnitring and requalificatin f third parties. Cntinuus versight f third party activities and payments Always stay alert fr red flags 4

Mitigating Risk: Sample Third Party Due Diligence Prcess Field Request fr Third Party Hire business justificatin fr hiring third party review f lcal laws that require a third party rep, permit them, limit liability t right t terminate due diligence prcess experience, financial stability, qualificatins, review f cmpliance and ethics reputatin ensure prcess cmplete; due diligence file dcumentatin cmpiled and circulated t cmpliance, acct ing, legal, mngt Update upn renewal, red flag r incident Apprval added t third party file review and apprval prcess fr DD file, business justificatin, cntract, payment prvisins educate. mnitr, implement management strategies Cmpnents f a Sample Due Diligence File Befre hiring smene t act n yur behalf cnduct due diligence t ensure the agent is qualified and has a reputatin fr integrity. Questinnaire Befre engaging in business with a third party, such as a subcntractr, jint venture partner, supplier, r service prvider, yu must ensure that the third party is nt making crrupt payments. Verificatin f Inf frm 3 rd party Cmplete Diligence File Interviews Due diligence ften includes asking the third party t fill ut a questinnaire, verifying this infrmatin thrugh public surces and in many cases, cnducting in-persn interviews Lcal Resurces References Online Resurces 5

Mitigating Risk: Putting Ethics and Cmpliance Requirements in Writing Since third parties are nt yur emplyees, all bligatins related t risk with their perfrmance bligatins shuld be in a written cntract. Sample cntract tpics: Anti-crruptin clause Identify all relevant laws related t their service Right t terminate fr cmpliance vilatins Right t audit cntract fr cmpliance with terms Require prper recrd keeping Require adptin f parts f yur Cde f Cnduct (r theirs if meets standard) that relate t their service Make clear hw questins r reprts f vilatins are t be addressed, i.e. ht lines Require reprting n change in status relevant t reputatin, business wnership, legal vilatins, etc. Make training and educatin requirements clear Addressing Onging Internal Respnsibilities After a Third Party is Hired Each third party must be actively managed by smene in the cmpany This persn maintains the dcumentatin n the third party and updates it when necessary Degree f supervisin depends n degree f risk with the third party their tasks, and their gegraphy Audit schedule needs t be created and implemented Evaluatins f adherence t the cntract, and peridically analyzed fr cmpliance Stay current n changes in wnership and changes in the business mdel f third party Cmpany managers f third parties need t be mnitred and evaluated n their perfrmance f third party management tasks Third party s failure r success is an added respnsibility f the cmpany s manager fr that entity 6

Aviding Issues with Third Parties and Crruptin: Watch fr Warning Signs r Red Flags Red Flags when wrking with third party representatives: Representative referred by a gvernment fficial Lack f experience and qualificatins t perfrm the services Histry f crruptin in the regin r cuntry Check the transparency internatinal crruptin perceptins (TI CPI index) Refusal t certify that it will cmply with the FCPA and Cmpany cmpliance prgram Unusually high cmmissins Lack f detail n wrk t be dne Unusual payments r financial arrangements Lack f transparency in expenses and accunting recrds Summary Third parties are a necessity in tday s business wrld Business leaders must understand that they are nt necessarily a cheaper alternative The same rigr in ensuring an effective ethics and cmpliance prgram fr the cmpany, applies t its third parties Third parties wh have effective ethics and cmpliance prgrams have a cmpetitive advantage with their custmers - engenders trust Risk assessments, due diligence prcesses, prgrams addressing and mitigating particular risks, strng cntracts, and nging internal management and mnitring is essential 7

Additinal Resurces 8

Managing Third Party Risk - Imprving yur Odds Third parties are under frmal cntractual agreement with cmpany and management has cntract n file. Regular audits are cnducted by cmpany t ensure third party cntractual agreements are managed and enfrced as agreed. Cntractual agreements with third parties clearly set frth expectatins regarding the relatinship and adherence t specific cmpany standards and plicies. Third party cntracts prhibiting third-parties frm unilaterally sub-cntracting its cntractual respnsibilities with ther entities Nature f relatinship clearly identifies as is legal status f entity, place f incrpratin. Third party cnducts backgrund checks n all emplyees, cntractrs, assciates and thers wrking n its behalf. Cmpany has a Cde f Cnduct in place applicable t third parties r requirement that Third party have wn Cde. If s, hw is the Cde frmally applied and enfrced n third parties? Imprving Yur Odds, cn t Third parties certify that they have read and understand the cmpany s Cde f Cnduct r their wn substantially similar Cde. Third parties receive regular training and cmmunicatins regarding cmpany standards, culture, cmpliance, and ther legal requirements. If s, hw are these cmmunicatin and awareness effrts delivered and with what level f frequency? Are cmmunicatins translated and delivered in lcal languages? Cmpany has a widely publicized and readily available glbal reprting mechanism and prcess where emplyees, cntractrs, third parties, agents, etc, can seek guidance, reprt cncerns and ask questins (annymusly if desired). Anti-bribery/anti-crruptin standards and training is cmmunicated and prvided t everyne in the rganizatin t include emplyees, third parties, cntractrs, etc. Hw are these cmmunicatins and training delivered and with what frequency? Third parties are required t certify that they have received/cmpleted anti-crruptin/anti-bribery training. 9

Imprving Yur Odds, cn t Third-party is a current r frmer gvernment fficial, emplyee r agent r a relative. Clearly defined and legitimate business purpse exists fr engaging third parties. Third party qualified and experienced t engage in the service r activity he r she was retained t undertake. Third parties paid via standard payment prtcls established by cmpany (ex. direct depsit). Emplyees wrking with third parties are knwledgeable f applicable anti-bribery, anti-crruptin, and U.S. FCPA cmpliance standards. Third party activities clsely mnitred by cmpany management in all perating lcatins. Third parties are directly supervised and managed by cmpany emplyees in high-risk perating lcatins. Imprving Yur Odds, cn t Supply chain, prcurement, accunting, senir and lcal management, legal and cmpliance trained n third party cmpliance standards and can readily identify red flags. New third party relatinships are reviewed and apprved by the cmpany s CECO r ther fficial in high risk cuntries and/r where activities invlve regulated r high risk peratins. Cnflict f interest check cmpleted. Third party subject t any past, current and/r pending legal issues, lawsuits, gvernment investigatins/inquiries, etc. If s, describe the nature and dispsitin f these actins. Cmpany actively assists third parties in mitigating cmpliance risks. Regular and nging audits are cnducted at third party sites and perating lcatins fr all business activities. Includes risks assessment, site visits, management and emplyee interviews, dcument review. Cmpany perfrms due diligence effrts n third parties prir t entering int business relatinships. 10