anatomy of a compliance audit - kathleen marcus

1
20 Smart Business Orange County | September 2012 Insights Legal Affairs Insights Legal Affairs is brought to you by Stradling Yocca Carlson & Rauth Anatomy of a compliance audit How a compliance audit can ensure your public or private company’s policies measure up Interviewed by Adam Burroughs O ver lunch, a CFO recently shared the dif- ficulties C-level management face since the enactment of Sarbanes-Oxley (SOX) with Kathleen M. Marcus, Shareholder at Stra- dling Yocca Carlson & Rauth and Chair of its Compliance and Corporate Governance Prac- tice Group. He spoke of joining a company whose books and compliance policies are “a mess” and his struggle to put the company on the right path without alienating the team. “In recent years, SOX and the Dodd-Frank Wall Street Reform and Consumer Protection Act have put a new emphasis on compliance programs,” says Marcus, a former Enforce- ment attorney with the SEC. SOX effectively requires a code of ethics for public companies, the implementation of a complaint hotline and raises the bar for management on financial statement accuracy. Dodd-Frank took it to the next level with fi- nancial incentives for employees to bypass internal company reporting and become whis- tleblowers. Today, public and private compa- nies face a very aggressive regulatory environ- ment. For any company concerned about an unwanted visit, letter or subpoena from any number of regulatory agencies, having a legal compliance audit can ease the pressure. Smart Business spoke with Marcus about what compliance audits involve and how an audit can ensure your policies are up to date. Why would a company need a compliance audit? Any business operating in heavily regulated areas, such as the medical device or pharma- ceutical industries, government contractors or businesses with international offices or sales, needs to be wary of regulations. Compliance audits are not just for public companies. In fact, the explosion of regulatory enforcement activity has begun to usurp private litigation as the bigger overall threat. In a company’s early stages of growth, only a few basic compliance policies are required. As companies mature, they frequently enact new policies without revisiting the old ones. This can result in incomplete, inconsistent or out- dated policies with large gaps in utility. A com- pliance audit streamlines the total compliance package, places policies under a single source of control and provides a plan for routine up- dating and distribution. The audit report is a roadmap for a company to take advantage of all the protections offered by a comprehen- sive compliance program, and provides peace of mind for executives. Notably, compliance audits are not expensive, and some changes can be easily made in-house. As a former SEC enforcement officer now in the compliance business, what would you say are the key benefits of a compliance audit? By altering certain high-risk practices, com- pliance audits can protect individuals and entities from becoming the subject of an in- vestigation. Audits also help facilitate organic conversations about topics such as the wis- dom of certain business or reporting practices and corporate risk appetite. In addition, in the critical period following a crisis, a streamlined compliance program ensures pre-designated individuals have a plan for taking immediate action in the best interests of the organization. When investigations do occur, the audit and/or the policy improvements can provide significant protection for the company and its management. At the onset of an investiga- tion, government regulators routinely request relevant compliance policies. Robust policies lessen sanctions because they demonstrate a genuine culture of compliance and best ef- forts by management. With so many compliance-related organizations in the marketplace, who is best suited to perform a compliance audit? And, what does it involve? A customized compliance audit report de- veloped by an attorney is not discoverable in an investigation or lawsuit. Therefore, hiring an attorney to perform your audit and pro- vide recommendations gives executives con- trol about whether and when to implement changes. The audit itself is fairly simple. A law firm should first provide an industry specific audit checklist to help identify existing policies. Be certain to search for policies in various depart- ments, as they may be housed with human re- sources, the CFO/CEO and/or the legal team. The audit should then begin with a full poli- cy review by a team of attorneys. Lawyers ana- lyze the policies in their specific practice area and provide assessments. The firm should then author a privileged report highlighting the strengths and weaknesses of each policy and detailing recommendations. Depending on the complexity, a company can choose to close the identified gaps itself or seek help. Upon request, a law firm should provide training to company personnel. Training is a vital component of compliance, particularly in complex legal areas such the Foreign Corrupt Practices Act or the False Claims Act where enforcement activities are skyrocketing. One estimate suggests the government is recover- ing $15 for every $1 it invests in the enforce- ment of False Claims Act violations in the health care arena. What could happen if a company’s policies are not comprehensive? If investigated and found in violation, out- comes range from career-ending industry bars for executives to massive financial penalties for management and entities. Government settlements usually involve some aspect of compliance reform. Regulators may mandate: n The appointment of a compliance moni- tor paid for by the company to oversee com- pliance activities; n Mandatory self-reporting by the company to the government concerning any violation, no matter how small; or n Stringent amendments to compliance policies. In contrast, when a company has adopted a comprehensive compliance program, it pro- vides a layer of protection for the company, as well as board members and management. A customized compliance program may pre- vent an investigation entirely, and should an investigation occur, tailored policies provide an excellent defense. << KATHLEEN M. MARCUS is a Shareholder and Chair of the Compliance and Corporate Governance Practice Group at Stradling Yocca Carlson & Rauth. Reach her at (949) 725-4080 or [email protected]. Kathleen M. Marcus Shareholder, Chair of Compliance and Corporate Governance Practice Group Stradling Yocca Carlson & Rauth

Upload: stradling

Post on 28-Apr-2015

167 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Anatomy of a Compliance Audit - Kathleen Marcus

20 Smart Business Orange County | September 2012

Insights Legal Affairs

Insights Legal Affairs is brought to you by Stradling Yocca Carlson & Rauth

Anatomy of a compliance auditHow a compliance audit can ensure your public or private company’s policies measure up Interviewed by Adam Burroughs

Over lunch, a CFO recently shared the dif-ficulties C-level management face since the enactment of Sarbanes-Oxley (SOX)

with Kathleen M. Marcus, Shareholder at Stra-dling Yocca Carlson & Rauth and Chair of its Compliance and Corporate Governance Prac-tice Group. He spoke of joining a company whose books and compliance policies are “a mess” and his struggle to put the company on the right path without alienating the team.

“In recent years, SOX and the Dodd-Frank Wall Street Reform and Consumer Protection Act have put a new emphasis on compliance programs,” says Marcus, a former Enforce-ment attorney with the SEC.

SOX effectively requires a code of ethics for public companies, the implementation of a complaint hotline and raises the bar for management on financial statement accuracy. Dodd-Frank took it to the next level with fi-nancial incentives for employees to bypass internal company reporting and become whis-tleblowers. Today, public and private compa-nies face a very aggressive regulatory environ-ment. For any company concerned about an unwanted visit, letter or subpoena from any number of regulatory agencies, having a legal compliance audit can ease the pressure.

Smart Business spoke with Marcus about what compliance audits involve and how an audit can ensure your policies are up to date.

Why would a company need a compliance audit?

Any business operating in heavily regulated areas, such as the medical device or pharma-ceutical industries, government contractors or businesses with international offices or sales, needs to be wary of regulations. Compliance audits are not just for public companies. In fact, the explosion of regulatory enforcement activity has begun to usurp private litigation as the bigger overall threat.

In a company’s early stages of growth, only a few basic compliance policies are required. As companies mature, they frequently enact new policies without revisiting the old ones. This can result in incomplete, inconsistent or out-dated policies with large gaps in utility. A com-pliance audit streamlines the total compliance package, places policies under a single source of control and provides a plan for routine up-dating and distribution. The audit report is a roadmap for a company to take advantage of all the protections offered by a comprehen-sive compliance program, and provides peace of mind for executives. Notably, compliance audits are not expensive, and some changes can be easily made in-house.

As a former SEC enforcement officer now in the compliance business, what would you say are the key benefits of a compliance audit?

By altering certain high-risk practices, com-pliance audits can protect individuals and entities from becoming the subject of an in-vestigation. Audits also help facilitate organic conversations about topics such as the wis-dom of certain business or reporting practices and corporate risk appetite. In addition, in the critical period following a crisis, a streamlined compliance program ensures pre-designated individuals have a plan for taking immediate action in the best interests of the organization.

When investigations do occur, the audit and/or the policy improvements can provide significant protection for the company and its management. At the onset of an investiga-tion, government regulators routinely request relevant compliance policies. Robust policies lessen sanctions because they demonstrate a genuine culture of compliance and best ef-forts by management.

With so many compliance-related organizations in the marketplace, who is best suited to perform a compliance audit? And, what does it involve?

A customized compliance audit report de-veloped by an attorney is not discoverable in

an investigation or lawsuit. Therefore, hiring an attorney to perform your audit and pro-vide recommendations gives executives con-trol about whether and when to implement changes.

The audit itself is fairly simple. A law firm should first provide an industry specific audit checklist to help identify existing policies. Be certain to search for policies in various depart-ments, as they may be housed with human re-sources, the CFO/CEO and/or the legal team.

The audit should then begin with a full poli-cy review by a team of attorneys. Lawyers ana-lyze the policies in their specific practice area and provide assessments. The firm should then author a privileged report highlighting the strengths and weaknesses of each policy and detailing recommendations. Depending on the complexity, a company can choose to close the identified gaps itself or seek help.

Upon request, a law firm should provide training to company personnel. Training is a vital component of compliance, particularly in complex legal areas such the Foreign Corrupt Practices Act or the False Claims Act where enforcement activities are skyrocketing. One estimate suggests the government is recover-ing $15 for every $1 it invests in the enforce-ment of False Claims Act violations in the health care arena.

What could happen if a company’s policies are not comprehensive?

If investigated and found in violation, out-comes range from career-ending industry bars for executives to massive financial penalties for management and entities. Government settlements usually involve some aspect of compliance reform. Regulators may mandate:

n The appointment of a compliance moni-tor paid for by the company to oversee com-pliance activities;

n Mandatory self-reporting by the company to the government concerning any violation, no matter how small; or

n Stringent amendments to compliance policies.

In contrast, when a company has adopted a comprehensive compliance program, it pro-vides a layer of protection for the company, as well as board members and management. A customized compliance program may pre-vent an investigation entirely, and should an investigation occur, tailored policies provide an excellent defense. <<

KATHLEEN M. MARCUS is a Shareholder and Chair of the Compliance and Corporate Governance Practice Group at Stradling Yocca

Carlson & Rauth. Reach her at (949) 725-4080 or [email protected].

Kathleen M. MarcusShareholder, Chair of Compliance and Corporate Governance Practice GroupStradling Yocca Carlson & Rauth