Two things usually happen when doing the diligence before investing in, appointing, or otherwise engaging a third-party.
- We ask them to make a bunch of declarations
- We assess the risk implications
On a recent project (interviewing impact investors), some preferred to have the proposed investee self-assess business integrity risks. Others favoured conducting that diligence in-house (document reviews, interviews with investee personnel, etc.). Each approach has pros and cons.
We’ve published several self-assessment tools (compliance maturity, fraud, investment fit, etc.). The output is often sobering. For instance, an entity safeguarding vital (potentially high-risk) national infrastructure scored 16% for fraud prevention. Anyone minded to conduct one of our assessments may want to know their actual risk exposure and take action. However, that is not true when the inherent conflict of money appears.
A few years back, we were doing the risk assessment and diligence (for an investor) into a financial institution. The investor suggested we ask the investee to complete a self-assessment before our work to benchmark against reality. It was an eye-opener. The investee gave themselves the best score I’ve ever seen. One that well-resourced MNCs seeking to satiate the Department of Justice would drool over. The ensuing reality was in stark contrast - one of the worst integrity risk frameworks I’ve ever seen. The investee needed the investment = a conflict.
When we ask someone who (typically) needs our money if they manage risks the way we expect them to, they usually respond with a flurry of ‘yes’ ticks.
Should we dispense with declarations and self-assessments? Most would say no, as they also serve an evidential and legal purpose (“true to the best of my knowledge, etc.”). Additionally, positive declarations can be interrogated (“please provide evidence”) or more gently questioned during the diligence process. For these reasons, I don’t mind whether you opt for asking third-parties (including investees) to self-declare or you go to the (considerable) effort of verifying for yourself (interviews, doc review, etc.).
But there is little learning opportunity if we’re only focused on declaration and diagnosis. The best projects I’ve worked on in recent years are with investors (and corporates, especially in energy and healthcare) who look at common pain points (lack of training, weak policies, missing guidance on managing issues X or Y) and do something about it. For example, a healthcare company reliant on 11 distributors serving 14 Asian markets identified weak controls around bid management (anti-competition, conflicts of interest, bribery) as a systemic issue (present in five of the 11). They duly held a workshop (open to all 11 but mandatory for the five) on managing this issue. They also shared a sanitised version of their internal SOP. They’d potentially saved considerable pain in those few hours it took to prep and deliver the workshop.
Why use 3 words when 33 will do?
“The move from a structuralist account in which capital is understood to structure social relations in relatively homologous ways to a view of hegemony in which power relations are subject to repetition, convergence, and rearticulation brought the question of temporality into the thinking of structure, and marked a shift from a form of Althusserian theory that takes structural totalities as theoretical objects to one in which the insights into the contingent possibility of structure inaugurate a renewed conception of hegemony as bound up with the contingent sites and strategies of the rearticulation of power.”
— Judith Butler, Further Reflections on the Conversations of Our Time (1997)
The text above exemplifies Dawkins’ Law of the Conservation of Difficulty. Paraphrasing here: the easier an academic field is, the more it will try to preserve its difficulty using complex jargon.
I do and don’t agree with this. We’re all prone to overcomplication. Sometimes, it’s ego and insecurity; sometimes, we’re just in a bubble (the curse of knowledge). Whatever the case, the tricky bit turns something verbose and complex into something useful. To illustrate the point, here’s the introduction from an anti-bribery policy on a recent project:
“ACME Corp recognises and follows all applicable laws and regulations and respects lawful customs of the regions where we operate and transact. In Country A, under the provisions of Legislation B, acceptance or attempted acceptance of any form of illegal gratification (i.e., anything of value other than a legal entitlement) by a public servant is a punishable offence. Legislation C also has provisions to prevent corruption in corporate sector. In addition to the Legislation D, Legislation E, Legislation F, Legislation G, and other state-level regulations shall also apply to offences relating to or resulting in corruption and bribery and resolutions available. In conformity with that, we are committed to acting and building relationships based on integrity and fairness in all our dealings. Hence, ACME Corp has adopted a “Zero Tolerance” approach to bribery and corruption. Our Code of Conduct also articulates this intent in clear and express terms.”
Ooof!
AI won’t (yet) save either tract of text (I tried; they’re both beyond redemption), so it’s better to start afresh. However, it will provide readability scores and required reading age data. Try it. Take a tract from your (publicly available) linchpin documents (Code of Ethics, etc.) and see how it scores.
