Showing posts with label ethics. Show all posts
Showing posts with label ethics. Show all posts

Saturday, February 4, 2012

Business Fraud Management Checklist


Business Fraud Management Checklist
By John Kyriazoglou*

This is complemented by Business Ethics Policy Example and Business Ethics Policy Checklist. See my blog: http://businessmanagementcontrols.blogspot.com/





Ethics Policy Statement

1. Does the organization have, within the corporate ethics policy, a statement with respect to fraud?

2. Who is responsible for the issue of this statement?

3. Has this policy statement been approved and ratified by the Board or other Top Management Committee?

4. Is this statement widely publicized in the organization?

5. Is this statement reviewed and improved annually (at least)?

6. Is the policy statement linked to Internal Controls?

Fraud Policy Statement

7. Does the organization have a Fraud Policy?

Consider: Procedure for a disciplinary interview, employee services termination procedure, obligations of employees during notice periods and upon termination of employment, complaints procedure, theft and threats policy, obligations of external contractors, investigating procedure, use of external approved investigators or expert internal audit personnel, and the protection procedure for the information sources.

8. How is fraud defined?

9. Has this policy been approved and ratified by the Board?

10. What kind of aspects does the policy deal with (e.g. preventive, investigative or recovery aspects)?

11. What are the objectives of the policy (e.g., avoid fraud, catch fraud, take legal action, etc.)?

12. Does the policy apply to all employees, management, board members, and external contractors?

13. Who is (manager, function, etc.) responsible for ownership and administration of the Fraud Policy?

14. How are fraud risks monitored e.g. through risk registers?

15. Is there a budget for investigative costs on potential fraud issues?

16. Does the organization specify roles and responsibilities within the Fraud Policy (e.g., for the audit committee, the Board, the HR Function, a Fraud Liaison Officer, etc.)?

Reporting Fraud and Corruption

17. What is the procedure for reporting suspicions of fraud?

18. What guidance is provided on dealing with incoming mail (such as anonymous letters, e-mails, etc.)?

19. Who are the first points of contact for reporting suspected dishonesty?

20. Does the organization operate a Fraud Hot-line?

21. Does the organization have a Whistle blowing Policy, which sets out the principles for protection of employees when reporting suspicions?

Response to Fraud and Corruption

22. Does the organization keep a register of fraud?

23. Who is responsible for maintenance of this register (e.g., A Fraud Officer)?

24. What the access rights to the fraud register?

25. Is the fraud register held securely?

26. Who is responsible for the investigation (e.g., Internal Audit)?

27. Who oversees the investigation?

28. Do written reports have to be submitted and to whom?

29. How does the organization deal with enquiries from the media?

30. Are employees suspended from work pending an investigation?

31. Are all reasonable means of recovering any identified loss pursued?

Investigation of Fraud and Corruption

32. Who monitors actual resources used against the agreed budget?

33. If a member of staff refuses to cooperate in a workplace investigation, are they liable to disciplinary action?

34. How is the interview recorded?

35. If the interview is tape recorded, is this with the permission of the suspect?

36. What does the organization do to avoid a similar occurrence of fraud in the future?

37. Who is responsible for making claims under insurance policies?

38. What is the process for notifying the police?

Rights of Employees

39. If an employee is charged with a criminal offence involving potential exposure to a term of imprisonment, are they required to report this and who to?

40. If an employee is the subject of an improper approach where a bribe is offered, is there a requirement for this to be reported and to whom?

41. Is there a presumption of innocence, unless proved otherwise?

42. At fact finding or investigative interviews, are employees suspected of dishonesty entitled to representation and by whom?



*Author’s Credentials

John Kyriazoglou, CICA, B.A(Hon), is an International IT and Management Consultant, author of the book ‘IT STRATEGIC & OPERATIONAL CONTROLS’ (published in 2010 by www.itgovernance.co.uk), and co-author of the book CORPORATE CONTROLS’ ( to be published in 2/2012 by www.theiic.org), with Dr. F. Nasuti and Dr. C. Kyriazoglou.







Blogs:Articles, Opinions, etc.: http://businessmanagementcontrols.blogspot.com/






Business Ethics Policy Checklist


By John Kyriazoglou*

This is complemented by Business Ethics Policy Example and Business Fraud Management Checklist. See my blog: http://businessmanagementcontrols.blogspot.com/

1. Does the organization have an ethics policy?

Consider: Formal approval process and contents: Guidance should be provided on how to handle issues such as, conflict of interest, gratuities and gifts, outside employment, contacts with external parties, confidentiality of information, personal obligations and commitments, etc., on the principles of fairness, openness, trust, integrity, responsibility, and mutual respect. Inclusion of the ethics and anti-fraud policy statements

2. Does the organization have a meaningful anti-fraud policy statement?

Consider: Instructions should be provided on how to manage potential fraud issues in vendor relationships and competitors, making illicit proposals and payments to get sales and contracts, proper maintenance of corporate books, systems and records, and effective management and control of corporate assets.

3. Does the organization have an ethics office and is it properly established?

Consider: Office space and computer facilities, ethics officer, support staff, ethics incidents register, office for confidential discussions and conference room.

4. Has a communication plan for ethics been formulated, approved and executed?

5. Has a training plan for ethics been formulated, approved and executed?

Consider: Budget, issues covered, attendance by all staff (Board, Executives, Managers, Employees).

6. Is an ethics culture apparent at all levels of the organization?

Consider: Behaviour of Board Members, Executives, Managers, Employees, existence of an open style of communication, a positive work environment, the procedure for getting ethics advice,   the operation of an ethics hot line, the procedure for resolution of conflict, incident investigation process, etc.

7. Is an anti-fraud ethics culture apparent at all levels of the organization?

Consider: Strong commitment of Board Members, Executives, Managers,  and Employees with the vision, mission and values of the organization, anti-fraud policy statement, compliance issues for ethics and fraud, and commercial crime prevention techniques.

8. Are all of the major players -- including stakeholders, shareholders, management, employees, customers, key suppliers, etc. participating?

9. Is there meaningful participation by board members at all stages?

10. Is a strong management committee in place to manage policy development and implementation?

11. Does the industry have a good record of similar initiatives in the past?

12. Are the organization leaders demonstrating strong commitment?

13. Have the background conditions and motivations been clearly identified?

14. Are the policy proponents inviting meaningful third-party representation and involvement by consumer groups, other standard-setting bodies, and are they prepared to pay for this involvement?

15. Are the processes for developing and implementing the policy open and transparent?

16. Is there a clear articulation and understanding of the rights and responsibilities of all stakeholders?

17. Is there clear evidence that the policy will promote the corporate interest in areas such as confidentiality, fraud protection, conflict of interest, and other ethics concerns?

18. Does the policy include effective complaints-handling and redress mechanisms accessible to everyone, effective programs to inform consumers and the public, and an evaluation framework to track progress and provide credible evidence of success and failure?

19. Will a reputable third party regularly monitor the policy?

20. Does the policy have the capacity to mature through time and respond to new learning and developments?



*Author’s Credentials

John Kyriazoglou, CICA, B.A(Hon), is an International IT and Management Consultant, author of the book ‘IT STRATEGIC & OPERATIONAL CONTROLS’ (published in 2010 by www.itgovernance.co.uk), and co-author of the book CORPORATE CONTROLS’ ( to be published in 2/2012 by www.theiic.org), with Dr. F. Nasuti and Dr. C. Kyriazoglou.







Blogs:Articles, Opinions, etc.: http://businessmanagementcontrols.blogspot.com/













Business Ethics Policy Example


Business Ethics Policy Example
By John Kyriazoglou*

Note: This is complemented by Business Ethics Policy Checklist and Business Fraud Management Checklist (See my blog: http://businessmanagementcontrols.blogspot.com/).

A typical BUSINESS ETHICS POLICY would define the framework and the boundaries of conducting business in any cultural, social, industrial, national, economic and religious environment. This policy, as an example, would contain ‘rules’, ‘instructions’ and guidance to all participants in the operations and activities of the specific organization.

This policy is usually made up of the following parts: Objectives of the Business Ethics Policy, Confidentiality of Company Information, Conflict of Interest, Outside Employment and Business Activities, Personal Obligations, Resolution Procedure and Reporting of Violations, Applicability.

Objectives of the Business Ethics Policy

1. Perspectives: he Ethics Policy of Organization/Company ‘XXX-Name of Organization or Corporate Entity’) (hereafter called ‘Company’) sets forth the values, desired expectations and ethics of service to guide and support all Executive Management, Middle and Lower Level Management, Project Management, Non- Executive Directors, Employees, External Consultants and Maintenance Contractors (hereafter called ‘Company Participants’) in all their professional activities with the Company. It will also serve to maintain and enhance public confidence and integrity in the Company, and strengthen respect for, and appreciation of, the role played by the Company within the wider local, national and international community.

Confidentiality of Company Information

2. Disclosure: In carrying out the Company's business, Company Participants often learn and have access to sensitive, confidential or proprietary data, information, trade and research secrets, and transactions about the Company, its activities, customers, suppliers or joint venture and joint project partners. This Policy prohibits the unauthorized disclosure or use of sensitive, confidential or proprietary data, trade and research secrets and information about the Company, its customers, suppliers or joint venture and joint project partners.  

3. Protection of internal data: No Company Participant entrusted with or otherwise knowledgeable about information of a sensitive, confidential or proprietary nature shall disclose, give or use that data, trade and research secret, information or transactions outside the Company or for personal gain, either during or after employment or other service to the Company, without the valid and proper written Company authorization to do so given specifically by a manager with the authority to release sensitive, confidential or proprietary information, data or transactions. An unauthorized disclosure could be harmful to the Company or helpful to a competitor or third party.

4. Protection of outside data: The Company also works with proprietary data owned by joint venture partners, and suppliers and by customers. The protection of such data is of the highest importance and must be managed with the greatest attention and care for the Company to merit the continued confidence of such parties. No Company Participant shall disclose or use sensitive, confidential or proprietary information owned by someone other than the Company to anyone without Company written authorization, nor shall any such person disclose the information to others unless a need-to-know basis is established and approved.

5. Signed Agreement: All Company staff are required to sign at the time of employment a proprietary information agreement that restricts disclosure of proprietary, trade and research secrets and certain other data and information about the Company, its joint venture partners, suppliers and customers. This Policy applies to all Company Participants without regard to whether such agreements have been formally signed.

Conflict of Interest

6. Private interests: All Company Participants should not have private interests, other than those permitted by these measures that would be affected particularly or significantly by actions in which they participate, within the realm of dealing with the Company.

7. No solicitations: All Company Participants should not solicit or accept transfers of economic benefit, and they should not step out of their official roles to assist private persons in their dealings with the Company where this would result in undue preferential treatment to the persons.

8. Taking advantage: All Company Participants should not knowingly take advantage of, or benefit from, information that is obtained in the course of their official duties and that is not generally available.   

Outside Employment and Business Activities

9. Outside activities: All Company Executive Management, Middle and Lower Level Management, Project Management, Non- Executive Directors and Employees, may engage in employment and business activities outside the Company only when they are specifically authorized to do so.

Personal Obligations

10. Performance of duties: All Company Participants must perform all duties to the fullest extent of their capabilities, ensure that all confidential information that is made available to the them by virtue of their position is not divulged without written permission, avail themselves of information and material that will improve their effectiveness for all matters relating to the business of the Company.

11. Professional associations: All Company Board Members, Executive Management, Middle and Lower Level Managers, Non-Executive Directors and Employees may improve their effectiveness for all matters relating to the business of the Company by actively participating in all activities of their Professional Association including liaison with other members in the exchange of information as allowed by the Company for their professional development.

12. Perceived conflict: All Board Members, Executive Management, Middle and Lower Level Managers, Non-Executive Directors, and Employees must use their best judgment to avoid situations of real or perceived conflict. In doing so, they must not accept or solicit any gifts, hospitality or other benefits and wards that may have a real or apparent or probable influence on their objectivity in carrying out their official duties and responsibilities or that may place them or the Company under obligation to the donor.

Resolution Procedure and Reporting of Violations

13. Ethics clarification: Any Board Member, Executive Manager, Middle and Lower Level Manager, Non-Executive Director, and Employee who wants to raise, inform, discuss and clarify issues related to this policy should first talk with his or her manager or contact the senior official designated by the Board for ethics issues, according to the procedures and conditions established by the Board.

14. Reporting violations: All Board Members, Executive Management, Middle and Lower Level Managers, Non-Executive Directors and Employees shall report, in person or in writing, any known or suspected violations of governmental laws, rules and regulations or this Ethics Policy to the Company’s President, Chief Financial Officer, Compliance Officer, other Executive or head of the Audit Committee. 

Applicability

15. Application scope: This Policy applies to all Board Members, Executive Management, Middle and Lower Level Managers, Non-Executive Directors, Employees, External Consultants and Maintenance Contractors working for the Company.

16. Legal action: Any breach of this Policy by anyone may allow the Company and its designated officers to take any legal action including dismissal of service and termination of employment or contract, including any legal actions specified by the laws of the country (state or province, etc.) where the Company operates.





*Author’s Credentials

John Kyriazoglou, CICA, B.A(Hon), is an International IT and Management Consultant, author of the book ‘IT STRATEGIC & OPERATIONAL CONTROLS’ (published in 2010 by www.itgovernance.co.uk), and co-author of the book CORPORATE CONTROLS’ ( to be published in 2/2012 by www.theiic.org), with Dr. F. Nasuti and Dr. C. Kyriazoglou.





Blogs:Articles, Opinions, etc.: http://businessmanagementcontrols.blogspot.com/






 


 


 

Saturday, October 15, 2011

COMPLIANCE, ETHICS AND RISK MANAGEMENT


COMPLIANCE, ETHICS AND RISK MANAGEMENT

A question was recently put in a discussion group, whether COMPLIANCE is distinct from ETHICS and how they interact in a corporate environment.

I think COMPLIANCE has to do with meeting fully to all standards, rules and regulations, whether external or internal to the ORGANIZATION. The term comes from Latin (COM=TOGETHER), and Ancient Greek (PLERE=TO FULLFILL).
 
ETHICS provides the background in terms of moral character (good, evil, just, etc.), nature, disposition, habit and custom of a person to obey willingly or face the moral and other consequences if he or she does not. The term comes from Ancient Greek (ETHOS=Moral Character).

The question ‘If the person complies should he/she be also ethical?’ is irrelevant.

The question ‘If the person is ethical should he/she also comply?’ is also irrelevant.

The major philosophical question for managing organizations, to be resolved, however, is this: How to handle the case and to minimize if not avoid all-together, the possibility that the person (staff member, manager, executive, etc.) might easily damage and potentially destroy the organization, its stakeholders, customers and employees, etc., when that specific corporate person (staff member, manager, executive, etc.) who is complying fully with all rules and regulations and is or is not ethical, but WITH COMPLETE DISREGARD for the RISKS involved, makes the right decision on a strategic or operational transaction, issue or activity.

In other words we should see both COMPLIANCE and ETHICS co-existing within the GOVERNANCE FRAMEWORK which should also include RISK ASSESSMENT and RISK MANAGEMENT. 

Also we should ensure that all these mechanisms resolve to a satisfactory and beneficial level, to society, economy, community, organization and individuals concerned, the classical principal-agent problem.