monitor

A Tale of Two Monitor Decisions

By Matt Kelly | January 22, 2024

One dreaded outcome from a regulatory investigation is the appointment of an independent compliance monitor. Now two recent corporate misconduct settlements demonstrate how puzzling regulators’ decisions about compliance monitors can be — because for the life of me, I can’t figure out why one company received a monitor while the other didn’t. The cases involve…

Read More
compliance jobs

Compliance Jobs Report: Jan. 19

By Matt Kelly | January 19, 2024

This week the Compliance Jobs Report has a slew of promotions to note, at AbbVie, Cox Enterprises, FirstSolar, and many more. We also have new hires at Methode Electronics, AES Corp., and elsewhere; plus job leads in sports, healthcare, and medical devices. Meme of the Week goes out to sketchy intermediaries! Always remember that we…

Read More
SAP

SAP, Part II: Remediation Work

By Matt Kelly | January 18, 2024

Today, let’s return to the FCPA enforcement action announced last week against German software giant SAP, which resulted in $220 million in penalties and disgorgement, plus a long list of compliance remediation measures. Those measures are worth going through in detail. For those who missed last week’s news, the recap is as follows. SAP agreed…

Read More
pre-taliation

New Front in Pre-taliation Fights

By Matt Kelly | January 16, 2024

The Securities and Exchange Commission has opened a new front in the war against pre-taliation clauses in corporate contracts, imposing an $18 million penalty on JP Morgan Securities for including pre-taliation clauses in confidential settlements with customers. The SEC announced the enforcement action on Monday, faulting JPMorgan for asking clients to sign confidential release agreements…

Read More

Cyber, AML Lessons From a Crypto Flop

By Matt Kelly | January 16, 2024

New York financial regulators have served up another case study in poor cybersecurity, transaction monitoring, and anti-money laundering compliance, courtesy of an enforcement action against a bankrupt cryptocurrency platform found to be deficient in all three. The state’s Department of Financial Services announced the sanction against Genesis Global Trading last Friday, fining the company $8…

Read More
compliance jobs

Compliance Jobs Report: Jan. 12

By Matt Kelly | January 12, 2024

The Compliance Jobs Report has updates this week from Haleon, Capital One, Dentsply Sirona, a few fintech firms, a few airlines, and more. We also have job leads in publishing, entertainment, and mobile phones; and our Meme of the Week goes out to artificial intelligence.  Always remember that we need your help to make the…

Read More
eBay

eBay Settles Crazy Harassment Case

By Matt Kelly | January 11, 2024

eBay has agreed to a $3 million criminal penalty, a deferred-prosecution agreement, and compliance monitor, all to settle charges from a bizarre incident in 2019 of the company’s internal security team stalking and harassing an online critic of the company.  The case was cuckoo crazy at the time, and remains so today. eBay’s then-head of…

Read More
SAP

SAP Pays $220M on FCPA Violations

By Matt Kelly | January 10, 2024

German software giant SAP is paying $220 million and implementing a raft of reforms to settle FCPA violations in seven countries, in a case with lessons about the importance of internal audits to root out misconduct and about structural reforms regulators want to see to prevent repeat offenses.  The Justice Department and Securities and Exchange…

Read More
risk

‘Owning the Risk’ and Compliance

By Matt Kelly | January 9, 2024

Compliance officers and regulators alike always love to say “the business owns the risk” — and we all know that here in the real world, those words often fall short of reality. I recently had a conversation with a compliance officer friend that reminded me just how widespread that shortcoming is. With his permission, I…

Read More
cybersecurity

Qualitatively Material Cyber Incidents

By Matt Kelly | January 8, 2024

Today I want to revisit the new SEC rules for disclosing material cybersecurity incidents, and in particular those qualitatively material incidents that might seem especially tricky to assess and prevent. What internal controls become more important for that type of threat? This is on my mind because we’re already starting to see some companies disclose…

Read More