Why does investment change a company's integrity risk?
Investment does not just reveal risk. It can create new pressure, visibility, decisions and dependencies that change what investors need to check before close.
Writing
Context, culture, controls and the difficult decisions behind integrity-risk work.
112 archive entries available.
Investment does not just reveal risk. It can create new pressure, visibility, decisions and dependencies that change what investors need to check before close.
Why the loudest voice on ethics might be worth watching for all the wrong reasons (and what to do about it)
A practical first-100-days guide for operating partners who need to work out where integrity risk really sits after investment.
A practical way to judge whether third parties, distributors and intermediaries create a real integrity risk before you invest.
Auditing your true priorities under pressure, how to stop avoiding uncomfortable conversations, and match behaviour to ambition.
A practical checklist for deciding where integrity risk is likely to sit before you invest, and which questions are worth asking next.
Founder-led businesses can be impressive, fast-moving and high-potential. They can also hide risk in plain sight. Here are the signs worth probing.
A plain-English guide to when the offence is likely to matter, what investors should ask, and why smaller businesses should not ignore it.
The fear of looking foolish may be one of the fraudster’s most effective protections
A stomach-churning allegation during a swimming lesson for primary-schoolers serves up some lessons about truth-seeking in contexts where it's one person's word against another.
Referrals, networks, net worths, and when is a favour more than a favour - lessons from investors, connectors, and trial-and-error.
This week I read a fascinating white paper about the utility of behavioural analysis in the AI era. Right after, someone pitched me on LinkedIn about their software that apparently reads micro-expressions.
Earlier this year, I asked why most firms (growth-stage and beyond) *have* bribery, corruption, and sometimes money laundering frameworks, but none for other types of fraud we know to be more common (see chart from the ACCA combatting fraud survey below).
In various parts of our property, weeds take hold at this time of year.
The best, and worst, advice, depending on context, experience, and insight. When should we rely on instincts?
How do you navigate that moment in a career when people stop asking what you know and start asking whether it makes sense?
What a 1950s farmer knew about risk that we can all still learn from. Keyline design meets the environment as it is, and we adapt. Risk management needs to do the same.
There’s an island. It’s big enough to get lost in but small enough to be familiar. Here you’ll find three towns, each very different, and each with a jetty from where you can make “the crossing.
We have a smallholding near the south coast of England. The main challenge (contrary to popular belief) is not rain (we get less of that than Sydney), but wind.
This week, the UK's beleaguered prime minister faced a testy exchange with opposition members of parliament when defending his decision to hire trouser-phobic, Epstein buddy, and self-styled 'Prince of Darkness', Peter Mandelson.
It's not uncommon to see customer ratings and reviews in pitch decks. A tangible testimonial from a real person (i. e. , verifiable) is useful.
Governance is a word I'm hearing a lot more. Sometimes, in the technical (ISO) sense, but more when discussing power dynamics.
Recent examples from integrity work, from insider trading signals to AI red-teaming and risk communication.
On my way to the dentist today, what should have been a 15-minute drive took nearly 30. Not a biggy, but by the third set of temporary traffic lights, it was a little tedious.
From Herd Mentality to Peacock Power: Rethinking Risk
Anthropomorphism is a term that refers to attributing human characteristics to non-human entities, such as objects, animals, or deities.
Over the years, we have collaborated on various projects with multiple partners. Some are long-term strategic partnerships, characterised by trust, experience and respect.
How much of what you learned in school (or university) do you use? How much of what our kids learn now will they use?
From TikTok to Talent Code: Rethinking How We Learn and Lead # Changing content for changed times
Shameless cross-posting from my LinkedIn article yesterday, because this is important and we're very proud of it!
From Mindhunter to Risk Hunter: Profiling for Compliance Professionals # Time to Think Like a Criminal Profiler?
"We invest in people who know their markets, that reduces the risk. But we also do KYC [know your customer] checks. "
Earlier this week, I was on a panel at the Association of Certified Fraud Examiners Europe event. My role (on the panel) was to discuss risk assessment and the behavioural side of cybersecurity.
You've probably seen articles discussing how organisations fail to report on impact (fully or accurately). That's not a topic we can address in a newsletter.
Last week, I met with a friend who left a very high-profile role in-house (head of risk, compliance, sustainability at an S&P 500) to start a company that helps other in-house folks get the right tech providers.
On 12 March, I'll run an SCCE session around conducting practical risk assessments. Last week, I had to develop the dreaded blurb about why people should attend.
So, corruption is cool again. Not so fast!
This time last year, I finished writing "20 Risk & Sustainability Tactics That Halve Risks, Improve Impact, & Deliver Value. " What on earth prompted me to write yet another detail-packed paper?
Two things usually happen when doing the diligence before investing in, appointing, or otherwise engaging a third-party.
Shikake (not a mushroom I once saw inadvisably put in a sandwich) is a Japanese word that literally means a device or system but describes using design to shape behaviours subtly.
We've been testing a co-authored tool (and accompanying guidance) to help organisations conduct risk assessments and due diligence. One challenge in smaller or mid-cap organisations is "where to start?
Over Christmas, I took some time off. It was a necessary break. My wife also runs a business, and we've not taken time off since March 2020.
In 1996-97, I worked odd jobs to save money for university. On this day (Boxing Day) in 1996, I was ordered to be in the clothing store I was temping at by 6am.
What better topic as Christmas nears (for many of us) than the vengeful Santa? I was contemplating introducing the spectre of Old Testament Santa when No.
In some organisations, risk is a journey; in others, it's constant. There is no "best practice" risk (or compliance) framework in this context.
Some of you may remember former US Secretary of Defense Donald Rumsfeld's speech about "known unknowns and unknown unknowns. " It was widely parodied but stuck with me.
Back in the 2000s, "discreet enquiries" were all the rage. Due diligence was a festival of smokes & mirrors. Providers would "tap into our source network.
"The ick" is a common phrase in our household. The almost fourteen-year-old uses it regularly: "Eww, that gives me the ick.
How do we reach people who receive information differently?
Since leaving Control Risks (in Feb 2019), where I worked extensively on political risks, I've not spoken much about political risk. That was a mistake.
Last week, I wrote about the Grenfell Tower tragedy in London, which caused the deaths of 72 people.
I live in a country with a passionately unhelpful bureaucracy.
This is more of a personal email, as I am taking a break with the family.
In many of your roles, you may meet people on (one of) the worst days of their lives. The person who will be fired for fraud. The person who got their device hacked.
I don't like pricing projects.
It's not a stretch to see how bribery, conflicts of interest, money laundering, and other separately legislated compliance areas might also be defined as "fraud.
Yesterday morning, I was interviewed on a podcast for a risk management publication. The host supplied some talking points in advance. I usually write a few bullet points under each and have that on the second window.
Fraud is dull. There, I said it. At least, that's the consensus in my family, who associate fraud with scamming texts, older people duped out of savings, and distant Wall St types fiddling numbers on spreadsheets.
Unfortunately, many of those who speak up face retaliation. One study suggested two-thirds of whistleblowers had experienced the following forms of retaliation.
How would AI commit fraud? I asked it.
This week, I've been building three assessment tools (two more are in the works). The first of which is about fraud. Why this topic, and why now?
Consider this: have you ever found yourself in a situation where you had to choose from a multitude of recipes, all seemingly similar? How would you decide (assuming the reviews are comparable)?
This week, I started on a project where investors are looking to fund renewable energy projects across four Southern African countries.
If there's one term (beyond the benighted "zero tolerance") that is holding us (risk, compliance, sustainability, etc. practioners) back, it's "best practice.
ISO standards, including those related to AI and ethics, play a significant role in risk management. In some areas (like risk management, ISO 30001 and the infosec heavy ISO 27001), these standards are widely adopted.
Do you get feedback from your *customers* (colleagues, stakeholders, or clients if you work on the advisory side)? When? How? How does it make you feel?
When you ask for feedback (as I discussed last week), sometimes what comes back surprises you. Or it does me, at least. We all hope we're good at our core job, but that's the baseline.
How do you decide what to focus on? Sometimes, the decision is made for us—an issue explodes, a crisis occurs, or a regulator comes knocking.
As the 2022 football (soccer) World Cup in Qatar loomed, a UK mid-cap beer manufacturer went on the offensive. Confused? So was I.
I'm sure many of you have heard of the concept (and book) espousing the virtues of saying "no" more. Why should we say no more? Many people I work with are overburdened.
I'm currently working on an assessment for a healthcare disruptor in India. As they scale, they face some quite significant risks.
ABC, as easy as 123, so goes the song. That is not true for this acronym.
Is it time to take compliance "out into the snow and put a bullet in the back of its head? " That lovely phrase was beloved of a former boss, who'd use it for any idea or strategy that hadn't worked.
I trialled a webinar at the end of last year. It didn't feel right. So why try again?
With increased focus on sustainability - partly regulation (like the pithily titled EU Corporate Sustainability Due Diligence Directive) and partly stakeholder-driven (ESG to consumer demand) - where does risk sit?
It's easy to overcomplicate and assume knowledge. For most of your colleagues, an investigation will be a rarity. They can be forgiven for being a bit confused.
Do you see value in being compared to other organisations? If so, what other organisations?
Over the holidays, I got stuck into some further studies - ESG.
Our six-year-old is a creature of logic. We don't have a chimney. We have a wood-burning stove where the flume is about the circumference of a medium-sized cooking pot.
I imagine your inbox is peppered with annual wrap-ups around now.
Pre-Covid, I delivered a lot of training. During Covid, as the in-person work (reliant on travel) went off a cliff, I moved to developing training and delivering remotely.
I recently read some excellent questions to reflect on work (professional life). I'll try to answer them. If you do likewise, see if they help you as much as it did me.
It's tricky to know when you'll need help. What form should this assistance take, and where to go (or who to ask).
Have you ever taken a personality assessment? Did you answer COMPLETELY truthfully? You caught the self-deception before clicking submit and altered a few responses.
I had a helpful call with an anti-money laundering specialist a few weeks back. He explained how peers cooperate to share intelligence about emerging criminal/terrorist tactics.
An obvious solution to overwhelmed and overburdened risk, compliance, and sustainability practitioners is to get help! Some might suggest ethics, risk, or whatever else we call them "ambassadors" or "champions.
You're a new joiner to ABC Corp and diligently read the Code of Conduct as you wait for IT to finish setting up your laptop (even though they've had three months to prepare).
If you've been around kids for any extended period, the temptation to say, "Because I said so," can become strong!
Red-teaming is where we put ourselves in the position of an adversary - in our case, someone trying to subvert our security, values and rules - to test the robustness of our preventative framework.
A few weeks back, I had a call with the board of an impact fund trying to get the heads around "financial crime. " They'd been managing anti-money laundering (AML) risks for a while.
How should we use AI? I'm baffled as to why this question takes up so much time. We've been here before.
You've probably seen the Ethical Excuses Bingo, crowdsourced on LinkedIn, below. My anecdotal experience of rule-breaking is that it's overwhelmingly done "for the organisation.
The Ethical Excuses Bingo, crowdsourced here 3-4 years ago, was a turning point. I'd long had a hunch - borne from anecdotal data - that building endless controls wasn't the solution to reducing integrity risks.
Depending on where you are in the world, you can tell a server how you'd like your food. There are some vagaries.
Many companies have employee surveys titled "engagement, culture, feedback, etc. " HR often controls this process.
My first foray into fraud bored me senseless. I was sure I'd never work in that area again.
In a podcast last week, I was asked how *actually* to manage corruption.
How do you collate all the various bits of risk data you gather from third-parties? How's that working for you?
Have you heard the one about.
In a recent article in The Washington Post, Terrence McCoy detailed Henry Ford's disastrous rubber plantation foray into Brazil in 1927.
Getting to the truth is essential. The use-case in investigations is self-evident. In assessments, training, strategy-setting, and developing content (or anything else), it helps to know what people actually think.
When studying behavioural analysis and deception detection techniques, I often heard the instructors say, "Focus on the act, not the person.
Let's unpack why people forget training. First, a few training myths.
In 2006, as I started in investigations, a happy client said their deal team colleague was so astonished by the findings in the due diligence (DD) report that they'd proclaimed, "Are you with the FBI?
When did you last say "No" or "I'm not accepting that"?
E, S, and G can't always peacefully coexist. Reporting on the downsides in a regulated world probably doesn't seem sensible.
Due diligence in its current form is a bit like commissioning a report before buying or leasing a second-hand machine. It makes sense if you're purchasing or renting something massive.
Knowing what to choose is hard, especially when you have little (or no positive) experience. I see this frequently, including:
The trust paradox is a disjoint that straddles organisational size and global cultures.
Crisis simulation workshops have been amongst the most effective ways to get leadership teams to take risks (including ethics & compliance) seriously.
Ten days ago, we moved into a new home. We'd been looking for 18 months, providing plenty of opportunities (and failed bids) to learn.
Twenty years ago, I contributed to a deathtrap playground in the name of charity.
No archive entries match that search yet.