No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Compliance

In Corporate Compliance, Sometimes Less is More

by Jim Nortz
April 7, 2016
in Compliance
Are your compliance programs long on policing and short on effectiveness?

This post was originally shared in the ACC Docket and is republished here with permission from the author.

As those of us who lived through it know, airport security in the U.S. in the early 2000s – post-9/11 – was a world apart from what it was previously. The American citizenry was traumatized and frightened of another attack. The U.S. government responded by implementing draconian rules significantly restricting the items that could be carried onto commercial aircraft.

Many of these new restrictions were quite sensible and overdue. For example, prior to 9/11 you could carry through security a half-gallon jug of liquid with no procedures to test whether it was water or nitroglycerin. But other restrictions clearly overshot the mark. Do you remember the days when TSA agents confiscated nail clippers, fingernail files and small pocket knives? Even the silverware in the first class cabin needed to be plastic.

These practices not only irritated the traveling public, they also reduced airline safety. At first blush, this result may seem counter-intuitive. After all, how could preventing passengers from bringing potential weapons on aircraft make flying less safe? This was exactly the question posed to the head of the TSA when he testified several years ago in front of a congressional transportation safety committee requesting support for his agency’s proposal to loosen airport screening standards.

The TSA head explained that his agents were spending an inordinate amount of time searching for and confiscating items that had little to no impact on improving airline safety. He stated that, in addition to slowing down the lines at security check points, this focus on looking for large nail clippers was distracting TSA agents from the far more important task of detecting items – like bombs – that could take aircraft down. He further explained that given the hardened cabin doors, enhanced training of airline staff and the post-9/11 response by passengers – who by then had a history of restraining anyone in the cabin who presented a threat to the aircraft – it was no longer possible to take over an airplane with a small pocket knife. Thankfully, the U.S. Congress saw the logic in these observations and allowed TSA to promulgate less restrictive regulations.

The Problem with Draconian Controls

I think the same dynamic often comes into play in corporations that experience the trauma of a government investigation or prosecution for wrong-doing. The fear and anxiety such events cause to Boards of Directors and company executives sometimes manifests itself in the implementation of new policies, procedures and internal controls that overshoot the mark.

A typical example of this might be a company that is subject to prosecution for an employee violating anti-corruption laws. In response, many companies require all employees – regardless of their role in the company – to endure lengthy live and online anti-corruption training sessions. They may supplement this with annual attestations to comply with the company code, a large collection of new policies, procedures and controls and expensive due diligence and training of all third parties who purchase and distribute their products. In addition, auditing and compliance staffs balloon in size and busy themselves by launching dozens of compliance initiatives aimed at reducing compliance risks.

The problem with this understandable response to a compliance crisis is that corporations that develop overblown compliance programs may end up becoming less rather than more able to manage their legal and ethical risks. By imposing draconian controls on businesses, thousands of employees are often required to endure training sessions on topics completely unrelated to their jobs. Others may ultimately “click through” online training classes just to tick the box and get it done – without any real learning going on. The company may place false confidence in a third-party due diligence process that checks all the boxes, but fails to alter behavior or detect corrupt business practices. Overblown compliance programs also run the risk of causing employees to avoid rather than seek out compliance professionals and creating negative attitudes toward the compliance program in general.

Needless to say, engaging in activities that cause such a response is not the optimal means of building and sustaining a strong ethical culture. To the contrary, it breeds cynicism and creates a large cadre of scofflaws who seek to avoid key compliance program elements instead of embracing them.

Recommendations

To avoid this fate, you might consider the following three strategies:

  1. Look for opportunities to eliminate pointless compliance-related activities. These might include such simple steps as limiting the applicability of policies and procedures to only those individuals who really need to know them and reconsidering the wisdom of your annual code of conduct training and associated attestations for all employees.
  2. Hold yourself and your compliance program accountable for being able to demonstrate a reasonable return on investment for every program element. In so doing, always be mindful of the fact that every time you think up a great new idea that might make you look good in front of senior management and the Board, you might be costing the company hundreds of thousands, if not millions of dollars by imposing it on your colleagues.
  3. Seek the voice of the customer and listen – really listen. Ask your colleagues whether the various elements of your compliance program are achieving the desired results or having the opposite effect. When you receive negative feedback, don’t get defensive; get curious. Explore with them what is working, what is not working and why. And have the courage to change course – even if it means gutting one of your pet projects.

It is true that sometimes you need to hold the patient down to administer the medicine they need to heal. But, this approach only works in the short term and should only be used in the direst circumstances. Over the long term, strive to find a flavor the patient can swallow without spitting it up. And if you really listen to what they have to say, you may find a prescription that they actually like.


Previous Post

Workflow Technology and HIPAA

Next Post

Are You Creating Your Own Culture Traps?

Jim Nortz

Jim Nortz

Jim NortzJim Nortz is Founder & President of Axiom Compliance & Ethics Solutions LLC, a firm dedicated to driving ethical excellence by helping organizations implement effective compliance and ethics programs. Jim is a nationally recognized expert and thought leader in the field of business ethics and compliance with over a decade of experience serving multinational petrochemical, staffing, business process outsourcing, pharmaceutical and medical device corporations. Jim spent the first 17 years of his career as a criminal and civil litigator and Senior Corporate Counsel before becoming Crompton Corporation’s first Vice President, Business Ethics and Compliance in 2003. Since then, Jim has served as a compliance officer at Crompton and for five other multinational corporations, the most recent of which was as Chief Compliance Officer at Carestream Health. Jim has extensive experience in implementing world-class compliance and ethics programs sufficiently robust to withstand U.S. Department of Justice scrutiny. Jim is a frequent guest lecturer at the University of Rochester’s Simon School of Business, RIT’s Saunders School of Business, St. John Fisher College, Nazareth College and other law schools, universities and organizations around the country. Jim writes the monthly business ethics columns for the Association of Corporate Counsel Docket magazine and the Rochester Business Journal. Jim is a National Association of Corporate Directors Fellow, a member of the International Association of Independent Corporate Monitors and serves on the Board of Directors of the Rochester Chapter of Conscious Capitalism as the Board’s Secretary and Chair of the Governance and Nomination Committee. Previously, Jim served on the Board of Directors for the Ethics and Compliance Officers Association and the Board of the Rochester Area Business Ethics Foundation.

Related Posts

GFT Canada Update

GFT Expands AI Compliance Suite for Canadian Credit Unions

by Corporate Compliance Insights
May 8, 2025

Digital transformation company GFT has expanded its compliance suite to help Canadian credit unions combat payment scams and identity theft...

AxiomGRC Launch

Business Resilience Platform Axiom GRC Enters Global Market

by Corporate Compliance Insights
May 8, 2025

A business resilience platform called Axiom GRC has launched in the UK, backed by £500 million private equity investment from...

MyCOI Launch

myCOI Launches AI-Powered Insurance Compliance Platform

by Corporate Compliance Insights
May 8, 2025

Insuretech provider myCOI has launched illumend, an AI-powered platform designed to manage third-party insurance compliance and certificate of insurance processing....

Beachhead Documentation Launch

Beachhead Solutions Launches Compliance Documentation Tool

by Corporate Compliance Insights
May 8, 2025

Data security provider Beachhead Solutions has launched ComplianceEZ, a new compliance documentation tool built into its BeachheadSecure platform. The tool,...

Next Post
beware culture traps

Are You Creating Your Own Culture Traps?

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights