Januari is meestal het beste moment om jouw compliance activiteiten uit het afgelopen jaar te evalueren en plannen te maken voor verbeteringen. Mocht je nog daarover nadenken: hier mijn tips voor het komende jaar.
1. Focus:
Focus het komende jaar op het ondersteunen van leidinggevenden (LG). Vaak is de tone at the top prima, maar the ‘mood in the middle and buzz at the bottom’ nog niet (lees het schokkende onderzoek van EY over onethisch gedrag van leidinggevenden: KLIK HIER).
LG’s hebben de grootste invloed op een psychosociaal veilige werkcultuur. Oók of zij jouw ambassadeurs zijn geworden voor het compliance programma, of dat programma als een ‘tick-the-box’ oefening ervaren. Help hen met specifieke tools, visualisaties, trainingen, ondersteuning. Zij zijn bepalend voor jullie succes of falen. Alsmede voor de hoogte van een eventuele boete, want indien jouw organisatie uit de bocht vliegt dan is de Amerikaanse analyse nogal eenvoudig:
“What actions have senior leaders and middle-management stakeholders (e.g., business and operational managers, finance, procurement, legal, human resources) taken to demonstrate their commitment to compliance or compliance personnel, including their remediation efforts? Have they persisted in that commitment in the face of competing interests or business objectives?” (bron ECCP: evaluation of corporate compliance programs 2023: KLIK HIER)
2. Evalueer:
Evalueer incidenten met jullie Ethics Committee of andere klankbordgroep:
Hebben jullie alle ‘root-cause’ analyses uitgevoerd mbt gemelde incidenten: weten jullie waarom zich integriteitsschendingen hebben voorgedaan? En wat jullie zouden moeten aanpakken om herhaling te voorkómen? Wat ging goed? Wat kan beter? Wat missen we nog? Wat krijgt dus prioriteit het komende jaar? Is jullie communicatie helder, begrijpelijk, relevant? Publiceren jullie al moresprudentie?
3. Verbeter:
Vraag aan internal audit (indien aanwezig; anders jullie externe accountant) en de afdelingen legal, finance, HR e.d. of beleid, processen, procedures, voorlichting, training e.d. moeten worden verbeterd. Een nog waardevollere bron van informatie is jullie medewerkerstevredenheidsonderzoek (MTO). Hopelijk heeft compliance een aantal vragen specifiek mbt verantwoord, integer handelen kunnen toevoegen aan het MTO? Over voorbeeldgedrag van leidinggevenden, over Speak Up (en luisteren), over zakelijke dilemma’s en ongewenst gedrag bespreekbaar maken? Durf afscheid te nemen van zaken die niet goed genoeg waren.
4. Beslis:
Beslis op basis van jullie (regelmatige?) risicoanalyses of de bakens zouden moeten worden verzet, dan wel méér nadruk op bepaalde training of maatregelen moet worden gelegd. Denk aan cybercrime, dat de komende jaren een van de grootste uitdagingen gaat worden voor veel organisaties. Denk aan CSDDD en het rapporteren in leveranciersketens. Denk aan mensenrechtenschendingen bij jullie leveranciers. Denk aan jullie gebruik van Kunstmatige Intelligentie (AI).
5. Ontwerp:
Ontwerp jouw aanpak en communiceer vanuit de ontvanger: verplaats je in hun rol, positie en verantwoordelijkheden: wat moeten zij écht van jouw programma ‘weten’? Is het echt nodig dat zij kennis opdoen over wetten? Of begrijpen wanneer ze moeten pauzeren en overleggen over rode vlaggen die zij in hun werk zijn tegengekomen? Vraag feedback op concepten en waardeer opbouwende kritiek.
Binnenkort méér over de rol van Leidinggevenden in een volgend blog.
Bel gerust om te klankborden: dat is altijd gratis!
English version:
January is usually the best time to evaluate your compliance activities from the past year and make plans for improvements. If you’re still considering this, here are my tips for the coming year.
1. Focus:
Focus on supporting managers (MGRs) this coming year. Often, the tone at the top is fine, but the ‘mood in the middle and buzz at the bottom’ is not yet there (read the shocking EY study on unethical behavior by leaders: CLICK HERE).
MGRs have the greatest influence on a psychosocially safe work culture. Also, whether they have become your ambassadors for the compliance program or perceive the program as a ‘tick-the-box’ exercise. Help them with specific tools, visualizations, training, and support. They are crucial to your success or failure, as well as the size of any potential fines, because if your organization goes off track, the American analysis is quite simple: “What actions have senior leaders and middle-management stakeholders (e.g., business and operational managers, finance, procurement, legal, human resources) taken to demonstrate their commitment to compliance or compliance personnel, including their remediation efforts? Have they persisted in that commitment in the face of competing interests or business objectives?” (source ECCP: evaluation of corporate compliance programs 2023: CLICK HERE)
2. Evaluate:
Evaluate incidents with your Ethics Committee or other advisory groups: Have you conducted all ‘root-cause’ analyses regarding reported incidents: do you know why integrity violations occurred? And what should you address to prevent recurrence? What went well? What can be improved? What are we still missing? What should be prioritized in the coming year? Is your communication clear, understandable, and relevant? Do you already publish moral jurisprudence?
3. Improve:
Ask internal audit (if present; otherwise your external auditor) and departments such as legal, finance, HR, etc., whether policies, processes, procedures, information, training, etc., need improvement. An even more valuable source of information is your employee satisfaction (engagement) survey (EES). Hopefully, compliance could add some specific questions regarding responsible, ethical behavior to the EES? About role modeling by leaders, about Speak Up (and listening), about discussing business dilemmas and unwanted behavior?
4. Decide:
Decide based on your (regular?) risk analyses whether the direction should be changed or whether more emphasis should be placed on specific training or measures. Think about cybercrime, which will be one of the biggest challenges for many organizations in the coming years. Think about CRSD/CSDDD and reporting in supply chains. Think about human rights violations at your suppliers. Think about your use of Artificial Intelligence (AI).
5. Design:
Design your approach and communicate from the recipient’s perspective: put yourself in their role, position, and responsibilities: what do they really need to ‘know’ about your program? Is it really necessary for them to gain knowledge about laws? Or understand when to pause and discuss red flags they encounter in their work? Seek feedback on drafts and value constructive criticism.
More about the role of leaders in an upcoming blog.
Feel free to call for a sounding board session: it’s always free!