Showing posts with label compliance officer. Show all posts
Showing posts with label compliance officer. Show all posts

Friday, 13 October 2017

Internal Control and Compliance in your SSC? Let's do it!




I had a pleasure to be a speaker on SSON conference (Budapest, 9-11 October, 2017). That was a great event, with enormous number of  presentations and discussion. What I wanted to share with others was my experience from organizing a shared function around Internal Control and Compliance.

This is still a very niche topic, and many managers from SSC / GBS prefer to keep it in HQ. I totally agree with approach that – due to its strategic importance – Internal Control & Compliance needs its stable and direct link to “top” of the organization.

Nothing stops us from making it customer-oriented, efficient, integrated, collaborative, technology-driven, though. Internal Control and Compliance is a great “product” to be shared as a function, act as-a-service and bring value in terms of standardization to the wider business.

Our mantra should be: as global as possible and as local as necessary.


Find a blueprint on building-in a governance & compliance into your SSC:



Monday, 19 June 2017

3 Levels of Defense



Does any statement below sounds familiar to you?

  • You are Internal Control team, so you are controls owner. 
  • You are Internal Control team, so we cannot tell you what is wrong with our processes, cause you will put that into official audit report.
  • You are Internal Controls team, so need to tell me how to perform controls.


There is a lot of confusion and misunderstanding in terms of split of responsibilities between business process owner, Internal Control and Audit. 

These can be easly explained by 3 level of defense in the process of internal controls. Here is what the differences are:


1)       Control Owner is the owner of the process or sub-process (eg. Acoount Payable Manager), and is responsible for identifying risks & control objectives, along with specifying controls and effectively implement control activity while performing it.

2)     Internal Control team is to support creating process documentation and validating its accuracy. The team also propose new controls or changes to existing ones, and help the wider team to prepare for an audit. Internal Controls also actively search for synergies and improvements within company processes. It is an advisor and consultant for Control Owner. 
3)     Internal Audit is an independent function from both business and Internal Control. It is not acting as advisor or consultant. Internal Audit is testing controls design, effectiveness and completeness of evidences. IA designs controls methodology and tools (Chart of Controls, ICFR) and conduct audits as per annual plan.

Monday, 5 June 2017

Get off the starting blocks!

Congratulation! You got a job and just starting as a new Compliance Manager.

Staring a new job is always, both, exciting and challenging. Don’t let the new environment overwhelm you. Take your time and use first month to gain as much knowledge on the new company as you can.


3 times LEARN!

Read and Learn!

Take your time and review Intranet, check if a Code of Conduct exists, check out for the shape of documented policies, procedures, finance manuals, chart of controls, etc. Create you initial “compliance check list”, i.e. a very simple list of what is missing or outdated. Make your initial comments to documents, especially if you don’t understand something.

This whole exercise may does not sound like an exciting thing to do, but trust me, it is worth your time and effort. You will gain an absolute overview and will know where to go and check for information.

Greet and Learn!

Make sure you have a chance to introduce yourself, don’t let HR to only send short and dull note or post it on intranet. Use stand-up meetings, dinners, unofficial after work drinks. Keep professional but don’t let yourself to stay disconnected. Your colleagues need to trust you and feel that you are part of the team.

Spend some time on organization chart to have a good overview of who does what and what interactions comes in place. Make relations. Don’t wait for invitations, just go around the office, shake hands, ask what the person is doing. Send invitations to different managers for an 1 hour meetings (try to invite for breakfast, lunch if possible). Ask every individual about the role, key projects, challenges and issue. Ask what you can do for them. Listen to them. Make notes (you will use them next months!).

Meet and Learn!

Your boss just grabs you to join different meeting. You feel lost? Don’t be, it’s great! Take as much as you can from these opportunities. Listen carefully and put down all key topics discussed, issues raised and useful references to teams, documents, projects, etc.

Remember that you don’t need to play active role yet. Rather be an astute observer! This is the very time you have during your career which is a given time. Simply as that, everybody understands that you are new to the company, and obviously you don’t have actions and deadlines at your plate yet.

This is the moment to ask questions, all questions that comes to your mind! Use first month to learn as much as you can. Asking questions is always good and valuable, however some questions are not appreciated after some time in the company, like.. “so what is our finance system”, or “who is our external auditor”.

Good luck!

Tuesday, 30 May 2017

Childhood dream job: When I grow up I will be … a Compliance Officer? :)

When we are young, we are dreaming of being fireman, doctor, movie or rock star, teacher, … . Becoming a Compliance Officer is not something that can be named as a child dream. None of us woke up in the middle of the night and run to parents to share a desire of working with regulations, policies and corporate governance. So how all of that begins?

Why one wants to become Compliance Officer? I asked that question to students who are just about to receive the certificate of Compliance Officer. In all of the responses I could recognize one common goal. They all want to influence and guard, either business or government, politics or other forms of human activities.


Being a Compliance Officer means you have a desire to change the world. You want to have a great impact on it. You have a courage and persistence to fight for an ethical values.



21 new Compliance Officers from Wroclaw University of Economics are just entering workforce. I am extremely proud that I had a chance to be part of their journey. During the last year we discussed a lot our daily job challenges. We all have this very understanding that we are all vulnerable to fear and persuasion. However, our conviction of acting as a face of ethical values is much stronger. That is why we all made a choice:


STAY STRONG. Stick to the values.  

Friday, 6 January 2017

Compliance Officers - it’s time for marketing!

It's not in our nature and DNA to promote and sales, I totally understand that! We are focused on advisory and consultancy so much, that we sometimes suffer from not be visible.

Our work is crucial for the success of wider organisations, it is essential part of all projects and initiatives. We do really protect our colleagues and management from failure..


All in all, it is really important to do some marketing around our work. Why not to produce some leaflet or short article for the internal magazine.

Be creative! Think about key aspects of the spotlight you want to share and how you want to be visualize by your colleagues.

Or simply use some templates, like this one.



Sunday, 11 December 2016

The Sound of Compliance


There are always two sounds of compliance. The first is SILENCE. The second one is NOISE.

We are usually working quietly, ensuring that all regulations and rules are met by organization. We are doing a hard job to keep business out of trouble, financial losses, reputational harm or … ever securing our colleagues from jail. It is a Silence Sound of compliance.

From time to time something may go wrong. Then we are in action. Then it is a Noise Sound of compliance.


There is one simple rule. When Compliance is invisible in organization all is fine and business is in a good shape. Once Compliance needs to interfere and intervene into the daily business, it is a signal that something went wrong. 


Prevention is the key to success. This is why we spend so much time on education, providing trainings, writing procedures, sharing knowledge. If you think that you are not being listened enough and your work is not valued by management, don’t stop! Show them how effective you are by using examples of companies who were not, and how much money they lost.

Prevention is better, even if organization needs to invest for many years… without hearing that much about compliance. This is actually what every management desire. Nobody wants to make and pay for mistakes.

What all of these famous brands have in common? 


They all paid a lot for non-compliance.

This list is just a shortcut, there is much longer and maybe your company is already on it. This is  a choice for management and yourself if you want to keep away from the list or how far you want to risk?

Examples of non- compliance and fees:
British Airways: Fined $300 million by DoJ for colluding on fuel surcharges on top of a £120 million fine imposed by UK Competition Authorities (2007)
Lloyds Bank: Fined $350 million for sanctions violating by colluding with clients to transfer funds to Libya, Sudan and Iran (2009).
Carrefour: Fined €27.4 million for fixing price of toys by French Competition Authority (2007).
LIDL: Fined by German Data Protection Authorities for illegally tracking employees’ medical conditions.
Volkswagen: Bribery of Union officials.
Chiquita: Fined $25 million for paying protection money to terrorist groups in Colombia (2007).
DHL: Fined $9.4 million for violating US sanctions laws (Iran, Syria and Sudan (2009)).
Johnson & Johnson: Civil penalties of $4.75 million for false or misleading statements to doctors about its products (2009).
Wal-Mart: Fined for child labor violations; teenagers to operate hazardous equipment; e.g. fork lift trucks (2005).
And... Wal-Mart has so far incurred expenses of approximately $147 million dealing with the investigation of an alleged Mexican Bribery case –without counting management lost time
Coca-Cola: “Channel stuffing” to pull sales forward into a current period (2005) – SEC investigation and civil law suit.
Boeing: $600 million fine for trade secrets allegation and hiring a senior air force procurement official while she was awarding government contracts worth billions of dollars to Boeing (2006).
Intel: Fined $1.45 billion for abuse of a dominant position (2009).
Deutsche Bank: Allegations DB violated privacy laws when it used private investigators on “dissident” shareholder (2009).
Microsoft: Fined $1.35 billion by EU for failing to comply with an earlier order relating to licensing (2008).
Novartis:  (2010) A Novartis pharmaceuticals unit was ordered to pay a group of 5,600 female employees punitive damages of $250 million, the largest-ever employment discrimination verdict (Bloomberg).
Daimler: (2010) Fined $185 Million For Bribery Further, Daimler was accused of violating the terms of the United Nations’ Oil for Food Program with Iraq by including kickbacks 10 percent of the contract values to the Iraqi government. 

Sunday, 20 November 2016

From Professional to .. Superhero

It was few years ago when I joined compliance world. It is an amazing journey.. however not that easy.


Back then I heard from my boss: „Your work will never be the same. You are no longer only professional. This company expects from you much more. You are a superhero now! Every day you will fight for better business, for values, for good workplace for others, for proper behavior. You will encounter many people who will not like what you do. Don’t let all the difficulties stop you. You need to be like Spiderman, always fighting for rights!

There is one fundamental thing about being a superhero. COURAGE.

You need to be like a lion among sheep to be effective. However courage comes from something deeper. To become a compliance officer and keep you’re the faith in what you do, you need to build strong emotional connection with you inner values and believes.

Believe in what you do. Do what you believe in.


Ask yourself what is the value you want to bring to the organization, make sure that it is something that your organization really needs. Make sure that your work brings improvements. Be persistence and stay professional.


These are HIGH FIVE rules of every compliance person!

      1. Don’t just say NO, you are not in the role to stop the business
2. Provide solutions, give advisory, be helpful
3. Always explain your opinion and provide examples
4. Talk about business, not law and regulations
5. Be positive. LISTEN!