The Integrity Gap

Why do we need you? Why did we hire you?

The relationship between risk management and company leaders can be tense.

The Integrity GapWhy do we need you? Why did we hire you?

The relationship between risk management and company leaders can be tense. We sometimes get this weird paradox (especially at the compliance end of that risk career spectrum): If nothing is happening, some leaders might ask, “Why do we need you?” If things are going wrong, they ask, “Why did we hire you?”

Faced with these, many resort to doing stuff. Develop a new policy, more e-learning, create a new form, etc. For example, when the Modern Slavery Act came out in the UK and Australia, some ran to create the obligatory statement (published on the website). Others did the harder work of mapping their supply chain. On the responsible supply chain projects, it required multiple stakeholders, nuance, and tough choices. For instance, should a global company implicated in a scandal a few years back on the other side of the world be replaced? What if that wrongdoing had been a lesson they learned from? How do we account for the fact that most multinationals do not behave homogenously across regions?

That work, requiring significant initial investment (time, and therefore, money), set those companies up far better than others who rushed out statements and then dealt with scandals as a firefighting exercise. I’m being glib in the interests of communicating a point quickly. But, we all know a lot of risk is CYA - cover your ass/arse. For some firms, that seems intentional. Fines and non-compliance are treated as the costs of doing business.

No risk function, no problem

Luckily (intentionally), most of my work is with impact investors, the founder teams in the growth-stage firms they invest in, and the board governing rapidly developing companies. Here, we often find very little by way of a “risk function.” So I’m always curious about the stuff they inherit and use to manage risk. Sometimes, it’s inspired. Like the sub-Saharan African agri-business that developed the best real-world training I’ve ever seen - assuming, knowing, their people would be targeted by capricious officials, corrupt cops, and scary non-state actors (ISIS, and alike). In these settings, the “Just say no, kids” zero-tolerance BS that an MNC might peddle is about as useful as a chocolate teapot. Their employees needed practical and tactical strategies to de-escalate, stay safe, and negotiate off a precipice. The training reduced panic decisions and stopped people from improvising themselves into worse trouble.

But, you also get the odd 80-page HR manual, or 18-page AML policy that they bought off one of those one-stop-legal sites after the IFC told them to. The former is the lovechild of an under-utilised HR department with an eye on empire-building. In these cases, I can see how we get into the “why do we need you… why did we hire you?” conundrum.

Why they need you

So, what to do? Well, my anecdotal experience suggests these counters for the “why do we need you” bit might help:

  1. A fraud or bribery scandal doesn’t just cost money. For investors, it can kill their next round (by one estimate, 87% of institutional investors have declined/reconsidered fund commitments due to integrity concerns, ). If you’re in a corporate, no one needs insurance until [insight plausible bad scenario for that cultural context: car crash, house fire, medical costs on that US vacation.]
  2. You need me to help you avoid the unintended consequences for the things you’ve not seen and experienced, but I have. For example, when MNCs started banging the “zero tolerance for facilitation payments” drum in their Southeast Asian subsidiaries, there was little or no consultation. How long would it take? How significant was the exposure? In permit-heavy businesses (anything requiring boots on the ground), it wouldn’t be uncommon to have anywhere from 20 to 200+ exposure points. In cultures where, as a generalisation, speaking truth to power is uncomfortable, local offices kept silent on this risk, nodded approval to the zero tolerance sermons, waited for the visiting head of legal/compliance to disappear and then turned to each other with the universal WTF expression! A few months later, my team and I were inundated with fraud investigations. They weren’t about self-enrichment; local teams set up collusive frauds with tame vendors to create a slush fund to continue making off-books (no books and records FCPA vs UKBA exposure) payments to officials.

Why they hired you

For the “why did we hire you” barb (let’s assume you/we didn’t drop the ball), it obviously requires some sensitivity, but I’d focus on data. Leaders like data. Some of the best early-warning risk indicators include delays, bottlenecks (approvals, close out, payments), exceptions and overrides, and culture data (absenteeism, churn, leave taking or not, and the knowledge, access, accountability, trust test I mentioned). With that information, you also start to frame risk differently. It no longer sits in a silo and starts to integrate into the process and culture.

Now we can do something about it. No scale-up gets through without taking risks and the subsequent scars. The tricky bit is delineating between events that were just bad luck (e.g., rogue employee, someone with a clean background, etc.) and those that point to systemic failure. The bad luck test, for me at least, is the same one I use when interacting with someone: fool me once, shame on you; fool me twice, shame on me. If it’s repeated, it’s not bad luck.

If we identify a system of cultural failure, more paper may be tempting, but it is seldom the answer, or we’ll find ourselves back in the stuff for the sake of stuff camp. Before writing anything, ask: what pressure made this the ‘sensible’ choice for the person who did it? Then fix the pressure, not just the paperwork. In more prescriptive terms, do a root cause analysis and find out what decision-making, heuristic, pressure (incentives/threats), and rationalisation led to the failure. Chances are, fixing that will address many risks beyond the ones you can stick in a policy, however elegant.

More Ethics Insight writing

Is it worth a conversation?

Tell us what you are trying to decide. We will listen, ask a few questions and tell you whether we can help.

Start a conversation