What Every Multinational Company Needs to Know About...Implementing an International Compliance Program (Part III)

Foley & Lardner LLP

We have received several requests for a list of the compliance policies that make sense for every multinational company. So, as a follow-up to our earlier two posts providing “twelve steps to international compliance” (see here and here), we thought we would add Part III, covering the core compliance policies that we commonly see at multinational companies.

The suggestions here are just that: suggestions. As we have written in several posts, the guiding star for compliance is to identify the particular regulatory risks arising at the organization and to use the company’s scarce compliance resources to address those identified risks. Thus, the appropriate compliance policies at one multinational may differ appreciably from those at another company, depending on such factors as the products sold, the type of supply chain, the countries of operation and sales, the company’s industry and customer base, whether the goods are controlled, the company’s method of operating, and so forth. Because compliance is an exercise in identifying, managing, and mitigating risk, there really is no substitute for conducting a thorough risk assessment to determine the key compliance concerns, which in turn will dictate what types of compliance policies and supporting internal controls make sense for a given organization.

It is never satisfying to answer a question such as “which compliance policies should we have?” with the answer of “well, it depends.” It also is helpful when assessing risk to understand the most common areas where multinational companies, as a general matter, tend to find risk. In our experience, most multinational companies divide compliance controls into the following areas:

  • A code of ethics, which provides the overall aspirational goals of the organization and its core compliance commitments.
  • A vendor’s code of conduct, which provides the expectations and compliance expectations for suppliers to the company. Consistent with the focus of the U.S. government on supply chain integrity, companies that procure from offshore sources are increasingly making compliance with the vendor’s code of conduct a contractual requirement.
  • A set of core compliance policies, in the range of 18–22 core policies, addressing in greater detail the higher-risk legal regimes and the company’s expectations and requirements to address these regulatory risks.
  • A set of implementing internal controls or standard operating procedures, designed to implement and systematize the application of the core internal controls.

The following are common “core compliance policies” that multinational companies should at least consider implementing, after taking into account their regulatory risk profile:

Common Core Policies

  1. Accuracy in Accounting Records/Books and Records Integrity
  2. Antiretaliation
  3. Antiharassment
  4. Antiboycott (for companies with significant dealings in the Middle East)
  5. Anticorruption/Foreign Corrupt Practices Act
  6. Antitrust/Competition
  7. Conflict of Interest
  8. Copyright & Trademark Integrity
  9. Customs & Import Matters
  10. Cybersecurity and Data Protection
  11. Data Protection & Privacy/GDPR
  12. Document Retention/Litigation Holds
  13. Economic Sanctions/Export Controls, which may each merit their own policies if the company deals with controlled dual-use goods or defense articles or controlled technical data.
  14. Email/Social Media
  15. Equal Employment /Antidiscrimination
  16. Family and Medical Leave/Disability
  17. Forced Labor & Human Trafficking/Uyghur Forced Labor Prevention Act
  18. Health, Safety & Environmental Compliance
  19. Insider Trading
  20. Internal Investigation/Dealing with Government Investigators (Dawn Raids)
  21. Labeling/Truth-In-Advertising/Made-in-USA Requirements
  22. Misuse of Company Assets
  23. Political Contributions and Lobbying
  24. Record Retention/Record Information Management

Here are some additional policies that may make sense to implement, depending upon the organization’s method of doing business and risk profile:

Policies to Consider

  1. Accident Reporting
  2. Acceptable Use of Computers and Resources/Misuse of Company Assets
  3. Anti-money Laundering (a core policy for many financial institutions)
  4. Drug and Alcohol Free Workplace
  5. Distracted Driving
  6. Environmental Reporting
  7. Gifts & Business Entertainment (a core policy for companies that operate in higher-risk jurisdictions or that frequently have dealings with government officials)
  8. Intellectual Property (proprietary information/assign inventions)
  9. Integrity & Transparency
  10. Manufacturing and Supply Quality
  11. Personal and Company-provided Portable Communication Devices
  12. Product Safety/NHTSA
  13. Recall Procedures
  14. Recordkeeping
  15. Shipping of Toxic Substances (HAZMAT)
  16. Substance Abuse/Drug Testing
  17. Technical, Business and Financial Records
  18. Theft/Misuse of Proprietary Information
  19. Use of Communication and Computer Systems
  20. Wages and Hours
  21. Weapons in the Workplace
  22. Workplace Safety and Health/Workplace Violence

While the compliance policies that make sense for any particular multinational company vary based on company specific risks such as the industry, locations of operation, supply chain, use of third-party intermediaries, and types of goods sold, , the lists above provide a good starting point for consideration. The simple exercise of gathering all available compliance policies, internal controls, and standard operating procedures, and evaluating whether there are obvious gaps and unaddressed regulatory risks, is an exercise that can readily reveal regulatory risk management gaps.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Foley & Lardner LLP | Attorney Advertising

Written by:

Foley & Lardner LLP
Contact
more
less

Foley & Lardner LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide