Tag: Risk Management

Herbalife – “Quis Custodiet Ipsos Custodes” – Translated: Who Will Guard the Guards Themselves, or Who will Watch the Watchmen?

Herbalife’s business relationship in China was committed to illegal activity, which it knew or should have known violated the FCPA. Specifically,  beginning in late 2006, Herbalife China provided improper benefits and payments to government officials to obtain direct selling licenses for two cities.
Herbalife paid out millions of dollars in bribes. Fraudulent expense reimbursements were used to fund the bribes, which is is a common tactic for these types of bribes.

Specifically, the SEC found that Herbalife China paid bribes through extravagant meals, gifts, and other benefits given to Chinese officials to obtain sales licenses and remove negative media coverage in China. Managers at the subsidiary asked employees to falsify expense report documents, for example, adding names to meal receipts to get below the company’s per head spending limit. It also found that the payments and benefits were inaccurately recorded and that Herbalife failed to maintain a sound system of internal controls.

» Read More

Donut Holes! Dunkin’ Data Breach Settlement

Dunkin’ was repeatedly alerted to attackers’ ongoing attempts to log in to customer accounts by a third-party app developer. The app developer even provided Dunkin’ with a list of nearly 20,000 accounts that had been compromised by attackers over just a sample five-day period. “Yet, Dunkin’ failed to investigate the attacks to identify other customer accounts that had been compromised, determine what customer information had been acquired, or whether customer funds had been stolen.

Dunkin agreed to pay $650,000 as penalty settlement costs for the lawsuit over its failure to respond to credential stuffing attacks.

» Read More

Erasing the “Lines” to Enhance Risk Management

In July 2020, The Institute of Internal Auditors (“IIA”) updated its Three Lines of Defense Model (“Model”) to emphasize more active forms of risk management and governance that appear to go beyond merely defensive maneuvers made by the internal audit function.  

Some believed the old model sent a message that we should fear risk. I never saw it that way. I understood the subliminal message was the model was about achieving objectives, which requires both the creation and the protection of value. The new model does a much better job of confirming that risk management contributes “to achieving objectives and creating value, as well as to matters of “defense” and protecting value.”

Learn why the Enterprise Risk Resilient Model might be a better choice.

» Read More

Baker Tilly US LLP Global Forensic Investigations, Compliance & Integrity Practice Continues to Impress and Grow!

Our experience conducting fraud investigations, domestically and globally, allows us to advise our clients on measures they can take to prevent fraud from occurring and detect issues before they expand. Our clients look to us to design anti-fraud programs and controls, perform anti-bribery and anti-corruption compliance assessments, and perform proactive fraud examinations to identify possible red flags or indicators of fraudulent activity. Because of our collective skills and the depth and breadth of our experiences, we are also able to design and enhance compliance programs and serve as integrity monitors. 

Correcting deficiencies, addressing gaps in controls, and remediation of specific issues is important at the end of every investigation to prevent the same or similar frauds from recurring.

We address these important client needs at the end of our investigations and can assist with implementing remedial actions.

» Read More

The Continued Evolution of Best Practices for Compliance Programs

In 2019 and 2020, the federal government released significant information which directly impacted compliance professionals. We cover all three releases in this eBook, the 2020 Evaluation of Corporate Compliance Programs – Guidance Document, the 2019 Framework for OFAC Compliance Commitments, and the 2019 Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations.

These three documents provided not only the government’s refreshed thinking on what constitutes a best practices compliance program. I have combined all three onto a best practices document.

» Read More

Fraud On The Rise is No Surprise!

Last week, the Association of Certified Fraud Examiners (” ACFE”) published the results of a survey taken by more than 1,800 anti-fraud professionals in late April and early May 2020, while we were deep into the Covid-19 crisis.  The findings, for the most part, are not surprising, but does reveal some disappointing information.  While I have not seen a raw copy of the survey, I was surprised the ACFE didn’t ask if the company’s fraud risk assessment was reviewed and modified accordingly.

In addition, the survey highlights trends in the overall level of fraud. Survey respondents provided information about their current observations and expected changes regarding ten (10) specific types of fraud.

» Read More

DOJ Revises its Guidance on the Evaluation of Corporate Compliance Programs

Without any fanfare, the U.S. Department of Justice Criminal Division has once again revised its Evaluation of Corporate Compliance Programs (“ECCP”).  The ECCP  remains  organized around three overarching questions that prosecutors ask when evaluating compliance programs, with some revisions, which are in bold text below:

Is the corporation’s compliance program well designed?
Is the program being applied earnestly and in good faith? In other words, is the program being implemented adequately resourced and empowered to function effectively?
Does the corporation’s compliance program work in practice?

While most of the document is identical to the 2019 Guidance, there are subtle and noticeable revisions.  The revisions appear to be designed to help provide additional clarity when answering the above three questions. 

» Read More

COSO Releases Thought Leadership on Risk Appetite

Organizations encounter risk every day as they pursue their objectives. In conducting appropriate oversight, management and the board must deal with a fundamental question: How much risk is acceptable in pursuing these objectives? Added to this, regulators and other oversight bodies are calling for better descriptions of organizations’ risk management processes, including oversight by the board.

COSO has released a thought leadership piece to help understand and communicate risk appetite, an amorphous concept to many.

» Read More

Fraud Pentagon – Enhancements to the Three Conditions Under Which Fraud May Occur

Today’s fraudster is clever and operates in an environment ripe for criminal activity. Economic unrest is making it easier for employees to find ways to set fraud in motion – and a new breed of offenders is finding cunning ways to do so. After more than 60 years, the classic fraud triangle of three elements or events that motivate an employee to cross the line has morphed into the Fraud Pentagon.

Company boards and senior management must take an offensive stance against the five conditions that precipitate fraud with a clear plan that limits the opportunity for fraud and minimizes the impact when fraud does occur.

» Read More

Tone from the top: Leadership’s challenge during a crisis

Leaders must find ways to engage with their people to motivate them, and this becomes increasingly important during uncertain or trying times. If done correctly, talking can be incredibly powerful. It can help relieve anxiety and help people find the strength they didn’t know was in them. Studies have shown that talking shuts down the brain’s fear center.

As Dr. Judson A. Brewer stated in a recent New York Times article, “Anxiety is a strange beast. As a psychiatrist, I have learned that anxiety and its close cousin, panic, are both born from fear.”

Fear and anxiety can be debilitating. Without proper communication in a crisis, it’s easy for people to spin and spread stories of fear, creating social contagion. To balance this tendency, in a crisis, leaders need to take their “tone from the top” to the next level.

» Read More

Fraud, Compliance & Integrity Risk During a Crisis and a Downturn

As a crisis unfolds, like Coronavirus, and markets decline globally, fraudsters will be adapting and new risks will emerge and some risks will increase. 

Remember, white collar criminals adapt by profiling us, so they can exploit our weaknesses. That being said, companies need to develop a strategy that enables the deployment of appropriate tactics to manage these new or increasing risks.

This writing explores some fraud, compliance, and integrity risks and is intended to provoke discussion.

» Read More

Speaking and Training on Fraud, Compliance, Ethics, and More…

Welcome to my site. I have spoken and been the keynote speaker for many conferences, including the ABA, ACC, ACFE, IIA, and IMA to name a few. I have designed customized training for the board, senior leadership, legal, compliance, internal audit, and others for some of the world’s largest organizations.

» Read More

Fraud: Department of Justice (DOJ) Announces Procurement Collusion Strike Force

On November 5th, the Department of Justice announced the formation of the new Procurement Collusion Strike Force (PCSF) “focusing on deterring, detecting, investigating and prosecuting antitrust crimes, such as bid-rigging conspiracies and related fraudulent schemes, which undermine competition in government procurement, grant and program funding”.

The Strike Force is an inter-agency partnership comprised of prosecutors from the Antitrust Division, and prosecutors from thirteen (13) U.S. Attorneys’ Offices.  Aiding in the prosecutors’ efforts are investigation partners such as the Offices of Inspector Generals from the Department of Justice, Department of Defense, U.S. Postal Service, and General Services Administration Office. The Department of Justice’s announcement proclaimed that investigating and prosecuting those who “cheat, collude and seek to undermine the integrity of government procurement” will have more to concern themselves with when executing their crimes. Prosecutors and investigators alike expressed enthusiasm to be working as a part of this new team.

» Read More
Skip to toolbar