09.01.2015 Views

The LRN ethics and compliance risk management practices report

The LRN ethics and compliance risk management practices report

The LRN ethics and compliance risk management practices report

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Function 2008<br />

Compliance 6300%<br />

Legal<br />

2008<br />

6200%<br />

Internal Audit 5900%<br />

6300%<br />

Executive<br />

6200%<br />

Team 5600%<br />

Human Resources<br />

5900%<br />

5100%<br />

Board of<br />

5600%<br />

Directors 4700%<br />

Finance<br />

5100%<br />

4400%<br />

Business<br />

4700%<br />

managers 4100%<br />

Ethics<br />

4400%<br />

3900%<br />

IT<br />

4100%<br />

3800%<br />

Data Privacy<br />

3900%<br />

3400%<br />

Risk Office<br />

3800%<br />

2300%<br />

External<br />

3400%<br />

Auditors 2200%<br />

Consultants<br />

2300%<br />

1400%<br />

2200%<br />

Managers 1400% Involved in Risk Assessments%Respondents<br />

Under 5,000 4200%<br />

Over 10,000<br />

in Risk Assessments%Respondents<br />

5600%<br />

4200%<br />

5600%<br />

Don’t know<br />

No<br />

10%<br />

19%<br />

13%<br />

Don’t know<br />

58%<br />

No<br />

Yes<br />

10%<br />

19%<br />

DETAILED RESULTS<br />

4. What is the Frequency of conducting Ethics <strong>and</strong> Compliance Risk Assessment<br />

About 4 in 10 enterprises conduct <strong>risk</strong> assessments % Respondents annually<br />

Another 25% performing % Respondentsthem periodically as part of their audit procedures.<br />

13%<br />

58%<br />

Frequency of Conducting Risk Assessments<br />

Yes<br />

42%<br />

Under 5,000<br />

employees<br />

56%<br />

Over 10,000<br />

employees<br />

42%<br />

Under 5,000<br />

employees<br />

Frequency of Conducting Risk Assessments<br />

Less than once a year<br />

Top Ethics <strong>and</strong> Compliance Risks %Respondents<br />

Top<br />

Electronic Data Protection 5200%<br />

Data Privacy 4700%<br />

Less than once a year<br />

I do not know<br />

pliance Risks %Respondents<br />

Intellectual Property 3200%<br />

5200%<br />

Environment Health <strong>and</strong> Intellectual Property 3000% I do not know<br />

4700%<br />

More than<br />

FCPA <strong>and</strong> Anti-bribery 2700%<br />

8% 5%<br />

3200%<br />

Sexual Harassment 2600%<br />

once a year<br />

ellectual Property 3000%<br />

Electronic 0% 2<br />

Export Controls 2300% More than<br />

9%<br />

2700%<br />

8% 5%<br />

Conflicts of interest<br />

2600%<br />

2100% once a year<br />

Supply Chain 2000%<br />

40% Annually<br />

2300%<br />

9%<br />

Electronic Data Protection 52%<br />

Insider Trading 2100%<br />

1600%<br />

14%<br />

Inte<br />

2000%<br />

No formal 40% or Annually<br />

Data Privacy 47%<br />

Frequency of 1600% Conducting Risk Assessments Respondents<br />

set schedule<br />

Intellectual<br />

Environment<br />

Property<br />

Health 32% <strong>and</strong> Inte<br />

Annually 144No formal 39% or 14%<br />

Periodically as part of audit 90 25%<br />

FCPA<br />

g Risk Assessments Respondents<br />

set schedule<br />

No formal or set schedule 51 14%<br />

25%<br />

Environment Health <strong>and</strong> Intellectual Property 30%<br />

144 39%<br />

More than once a year 34 9%<br />

Se<br />

f audit 90 25%<br />

FCPA <strong>and</strong> Anti-bribery 27%<br />

edule<br />

I do not know<br />

51<br />

28<br />

14%<br />

8%<br />

25%<br />

ar<br />

Less than once<br />

34<br />

a year 17<br />

9%<br />

5%<br />

Periodically as<br />

Sexual Harassment 26%<br />

28<br />

365<br />

8%<br />

part of audit<br />

Co<br />

Export Controls 23%<br />

ar 17 5%<br />

Periodically as<br />

365<br />

part of audit<br />

Conflicts of interest 21%<br />

% Respondents<br />

Supply Chain 20%<br />

Using information from Risk Assessment%Respondents<br />

Share findings 7100%<br />

% Respondents<br />

Insider Trading 16%<br />

rom Risk Assessment%Respondents<br />

Rank findings 5100%<br />

Apply findings to programs 4300%<br />

7100%<br />

Map findings<br />

5100%<br />

3200%<br />

grams<br />

Don't know<br />

4300%<br />

1000%<br />

Other metrics<br />

3200%<br />

300%<br />

1000%<br />

300%<br />

Companies conduct <strong>risk</strong> assessments on a regular basis, either once per year or scheduled<br />

periodically along with regular audits. <strong>The</strong> best practice is to conduct an <strong>ethics</strong> <strong>and</strong><br />

<strong>compliance</strong> <strong>risk</strong> assessment as consistently as possible to keep awareness up with changing<br />

laws <strong>and</strong> regulations that affect the enterprise as well as to track changes from one period<br />

to the next.<br />

Map <strong>risk</strong>s according to:<br />

% Respondents<br />

Specific employees or groups 2900%<br />

g to:<br />

% Respondents<br />

Other metrics 1100%<br />

r groups 2900%<br />

1100%<br />

5. How do you use or apply information from your <strong>ethics</strong> <strong>and</strong> <strong>compliance</strong> <strong>risk</strong><br />

assessment<br />

7 in 10 companies share <strong>risk</strong> assessments findings.<br />

Using information from Risk Assessment<br />

Ranking findings according to: % Respondents<br />

Probability of occurrence 4400%<br />

ccording to: % Respondents<br />

Monetary value 2700%<br />

Other metrics 2100%<br />

nce 4400%<br />

2700%<br />

2100%<br />

100%<br />

80%<br />

Using information from Risk Assessment<br />

100%<br />

80%<br />

60%<br />

71%<br />

Top Risk Assessment Challenges % Respondents<br />

Inadequate resources 4700%<br />

nt Challenges % Respondents<br />

Obtaining accurate/ quantifiable info 3500%<br />

Conducting a global assessment 2600%<br />

s 4700%<br />

quantifiable info<br />

Analyzing<br />

3500%<br />

<strong>and</strong> applying the findings 2000%<br />

assessment<br />

Insufficient<br />

2600%<br />

technology 2000%<br />

ing the findings<br />

No significant<br />

2000%<br />

challenges 1200%<br />

y<br />

Don't know<br />

2000%<br />

800%<br />

ges<br />

Other<br />

1200%<br />

300%<br />

800%<br />

300%<br />

60%<br />

40%<br />

20%<br />

0%<br />

% Respondents<br />

Ranking Findings<br />

71%<br />

40%<br />

51%<br />

20%<br />

0%<br />

% Respondents<br />

43%<br />

Share findings<br />

Rank findings<br />

Map findings<br />

Apply findings to programs<br />

Other metrics<br />

Don't know<br />

32%<br />

51%<br />

43%<br />

Share findings<br />

Rank findings<br />

Map findings<br />

Apply findings to programs<br />

Other metrics<br />

Don't know<br />

32%<br />

10%<br />

3%<br />

10% 3%<br />

% Res<br />

Top Risk Assessm<br />

Ranking Findings<br />

50%<br />

50%<br />

40%<br />

30%<br />

20%<br />

10%<br />

44%<br />

40%<br />

30%<br />

20%<br />

10%<br />

27%<br />

0%<br />

21%<br />

44%<br />

27%<br />

21%<br />

0% Inadequate 10% 20%<br />

resources<br />

Inadequate resourcesObtaining 47% accurate/ quantifiable info<br />

Obtaining accurate/ quantifiable info Conducting 35% a global assessment<br />

Conducting a global assessmentAnalyzing 26% <strong>and</strong> applying the findings<br />

47%<br />

35%<br />

26%<br />

20%<br />

0%<br />

% Respondents<br />

% Respondents<br />

Probability of occurrence<br />

Monetary value<br />

Probability of occurrence<br />

Monetary value<br />

Other metrics<br />

Analyzing <strong>and</strong> applying the findings 20% Insufficient technology<br />

<strong>LRN</strong> | 2008 Ethics <strong>and</strong> Compliance Insufficient Risk technology Management 20% Practices No significant Report challenges | 25<br />

No significant challenges 12%<br />

Other<br />

Other 8%<br />

Don't know<br />

20%<br />

12%<br />

8%<br />

3%

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!