No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

Scoping Out Your Program/Risk Assessment

by Jeff Kaplan
January 8, 2015
in Risk
Scoping Out Your Program/Risk Assessment

At the PLI Advanced Compliance & Ethics Workshop in NYC in October, Scott Killingsworth of the Bryan Cave law firm noted that each risk assessment should be unique.  I agree, and I believe that the case for uniqueness is even more powerful for the combined program and risk assessments companies sometime undertake.  Given the diversity of possibilities, where should you start in scoping out such an engagement?  Another way of asking this question is “How should you conduct a needs assessment for a program/risk assessment?”

To begin, it may be worth thinking in terms of the following six fields of information which can comprise the subjects of an assessment:

  1. Program assessment: tools/elements that many employees have information/views about. Examples include C&E training and the helpline.
  2. Program assessment: tools/elements that relatively few employees have information/views about. Examples include monitoring approaches and pre-hiring due diligence.
  3. Risk assessment: risk areas that are the primary responsibility of the C&E office and that are both broad (meaning they touch many employees) and deep (meaning they have a potentially high impact). Examples – at least in some companies – include corruption, competition law and possibly fraud.
  4. Risk assessment: risk areas that are the primary responsibility of the C&E office but are not so broad and/or deep. In some companies, conflicts of interest (often broad, but not that deep) or insider trading (deep, but not typically that broad) fit into this category.
  5. Risk assessment: risk areas that may be broad and deep, but that are the primary responsibility of another function at the company. In some companies, trade compliance or employment law would fit this bill.
  6. Culture assessment (which is relevant to both program and risk assessment, but for planning purposes generally should be viewed as its own effort): factors that could impact both the degree of risk and the efficacy of the program. Examples include tone at the top, accountability, openness of communication and alignment of rewards with stated C&E values.

Second, for each of the six fields, consider what the assessment need actually is for your company. For instance, for corruption (in group 3), companies that, because of the nature or locations of their business, likely have a high risk presumably will want to follow applicable law enforcement expectations (e.g., discussion in the 2012 DOJ/SEC resource guide on risk assessment and program components), and questions tracking these can and should take up a significant portion of total interview/document review time.  But for risk areas that are largely the province of other functions (meaning those in group 5), one might have a narrower gauge of inquiry in the interviews/document reviews, at least if such functions have already conducted some form of targeted assessment(s) regarding these risks. And the extent of questioning/document reviews about risks in group 4 will depend on a variety factors (e.g., the extent of that part of the assessment regarding confidential information will depend partly on how important such information is to a company).

Program assessment needs also might vary in many ways. For instance, getting a wide array of feedback on training (in group 1) will make sense if you are considering overhauling your training. Additionally, a report that is going to the Board of Directors or is expected to be reviewed by the government generally should be the subject of greater overall efforts – especially in the culture part (group 6) – than an assessment that is undertaken merely as part of a regular C&E “check-up.” Moreover, for the  program, risk and culture assessment components, the need might vary by different lines of business or geographies within a company.    Also, for some assessment topics, the extent to which one is measuring risk areas versus program tools tends to blur.  The emerging area of compliance monitoring (group 2) often falls into that category.

Finally, taking into account the results of this needs analysis, one should seek to identify which employees are likely to have relevant information for each of these six fields and then use that to develop a list of interviewees that can get you all that you need for each of the  the various aspects of an assessment.  Assuming time and budget are not unlimited, identifying individuals who can speak to multiple topics is an obvious plus.  Similarly, one should use this framework to identify and obtain pre-existing materials relevant to each group.  Examples include reports of prior C&E audits/reviews; relevant sections of employee engagement surveys; training feedback; and to a lesser extent, prior results of ERM efforts.


Previous Post

EY Names Top Fraud and Corruption Trends for 2015

Next Post

The Alstom FCPA Enforcement Action – Part I

Jeff Kaplan

Jeff Kaplan

Jeffrey M. Kaplan is a partner in the Princeton, New Jersey office of Kaplan & Walker LLP. He has specialized since the early 1990s in the practice of compliance- and ethics-related law, including assisting numerous companies in developing, implementing and reviewing C&E programs and conducting C&E risk assessments. He has also reviewed programs for many official bodies in connection with settlements of enforcement actions. He is the co-author of a C&E legal treatise, author of several e-books -- including "Compliance & Ethics Risk Assessment" -- and book chapters and many articles on C&E, a frequent speaker at C&E conferences, editor of the Conflict of Interest Blog and formerly an Adjunct Professor of Business Ethics at NYU’s Stern School of Business.

Related Posts

green sprint racers on a track

‘Green Sprint’ Your Way Past ESG Backlash

by Marga Hoek
May 21, 2025

As ESG programs face growing critique, organizations need practical approaches that deliver measurable results. Business sustainability expert Marga Hoek introduces...

no right answer

That ‘Do the Right Thing’ Mug? It’s Missing Some Fine Print.

by Vera Cherepanova
May 20, 2025

Ethics isn’t a slogan; it’s a practice

doj sign front

Assessing the Business Risks of the Trump Administration’s ‘Total Elimination’ Strategy

by José Cortina and Jennifer Christian
May 20, 2025

As cartels increasingly participate in mainstream economic activities, traditional due diligence practices become inadequate to address new material support risks

drug cartel soldier camo

Leveraging Human Rights Frameworks to Combat Emerging Cartel Risks

by Nate Lankford, Matteson Ellis and Nisha Sawhney-Murkett
May 19, 2025

As enforcement priorities shift to cartels and foreign terrorist organizations, established human rights processes can identify and mitigate emerging legal...

Next Post
The Alstom FCPA Enforcement Action – Part I

The Alstom FCPA Enforcement Action – Part I

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2025 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • Home
  • About
    • About CCI
    • CCI Magazine
    • Writing for CCI
    • Career Connection
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Library
    • Download Whitepapers & Reports
    • Download eBooks
    • New: Living Your Best Compliance Life by Mary Shirley
    • New: Ethics and Compliance for Humans by Adam Balfour
    • 2021: Raise Your Game, Not Your Voice by Lentini-Walker & Tschida
    • CCI Press & Compliance Bookshelf
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2025 Corporate Compliance Insights