Showing posts with label Ethics. Show all posts
Showing posts with label Ethics. Show all posts

25 September 2017

Reputation v Reality - Panama and Banking

Opening a bank account in a Tax Haven is supposed to be easy. All hush hush, sly winks, funny bank account numbers. Or as the British might say - "Nudge, nudge, wink, wink, say no more, say no more". I would not say that was my expectation when opening a bank account in Panama, but I certainly was not ready for the level of Customer Due Diligence, KYC (Know Your Customer) and AML (Anti-Money Laundering) checks that were required. And here I were thinking, I'll hand over some cash and we'll open a bank account.

Still the (new) bank insisted the checks they insisted on making were completely normal, and that there had been no change in their process. The printed and many-times photocopied forms certainly appeared to support their position.  This in contrast to my experience opening a bank account in the UK with nothing more than a Belgian identify card. I walked in, sat down, handed over my Belgian identify card and a letter from my employer (which, frankly, I could have typed and printed from my own computer). With little other than asking me for my address, I had a UK bank account, with a debit card in the mail.

At this stage let me say that this was all above-board, as we were in the process of actually moving to Panama from the UK. I'll also confess that this was a month after the world wide splash of the "Panama Papers" and the sudden spotlight that this had shown on Panama in general, and on banking and legal services in particular.

Opening a bank account is one great example of just how the stereotypes of Panama simply are not accurate. Not only did they require identification (and a Belgian identify card was not sufficient, thank you), they required a letter of introduction from our UK bank. A letter that could never touch my hands, but that had to be sent from Bank to Bank. Imagine the humor when I asked for a letter of introduction from my bank. The conversation went something like:

"I need a letter of introduction for my new bank."
"We don't usually issue those."
"This isn't a UK bank."
"Oh, okay, in what country?" said as the service representative was looking up the procedure online.
"Umm, Panama."
Big smile from the service representative "Really? Panama, like, the Papers?" Big smile.
"Yes, really. You didn't need one, but they do."
"Really?"
"Yes, really, and it must go directly from this bank to that bank."
"Oh, so I can't just print it and give it to you?"
“No, and it must be mailed to them, on UK bank’s letterhead, and from the bank’s office. I cannot touch the letter.”

There is little question that the Panama Papers scandal has been a trauma for the country and the legal and financial services industry. Regardless of how many times people are reminded that "offshore havens" are rife, and that certain US States effectively replicate the functions of offshore tax shelters and money laundering havens, the stigma now sticks to Panama. A recent estimate says that 10% of global GDP is held in "off-shore" havens. Trust me, that money is not in Panama.

The Panama Papers have already toppled the government of Iceland, and last month, the Prime Minister of Pakistan was dismissed by the Supreme Court on the grounds of corruption exposed by the papers. numerous politicians and celebrities have been exposed as having "businesses" in off-shore havens, not all in Panama, but all exposed by the release (hacked theft or internal theft, this still remains to be confirmed one way or the other) of files from Mossack Fonseca, a Panamanian law firm that operated in at least 9 countries at the time.

Multi-national corporations with regional headquarters in Panama have considered relocating, and at least one appears to be on the brink of doing so. While that organization does not have significant operations in Panama, it is the Latin America and Caribbean administrative hub.

Meanwhile, Panama has, over the past decade, maked real, tangible progress in the area of Corporate Governance, lead by the IGCP (Instituto de Gobierno Corporativo-Panamá) and various financial supervisory regulators, and the OECD. The first Corporate Governance Code was introduced in 2010, and is enshrined in the Corporate Law.

In relation to the effectiveness of banking supervision, in 2006 the IMF reported: "Panama is largely compliant with the majority of FATF Recommendations for anti-money laundering and countering the financing of terrorism (AML/CFT), reflecting the efforts of the authorities and industry to put in place an effective AML system. Nevertheless, staff makes several recommendations..." Panama has since updated its legislation in line with the IMF recommendations.

In the associated area of Risk Management, the Panamanian banking supervisor requires all banks to provide a statement that they have an effective system of Risk Management. Further, this statement must be signed by the Board of Directors. This is included in the detailed in Chapter IV of Rule 7-2014 (August 2014).

So while Panama has been making serious progress on corporate governance, anti-corruption and banking supervision for many years, still the country has a bad reputation. Having the previous president sitting in a US jail awaiting extradition for corruption does not help. Nor does a culture in which the police regularly request bribes, and in fact give lessons on how to pay those bribes.

Clearly there is a long way to go, both in actual implementation of effective corporate governance, and in inculcating a culture that rejects corruption at the grass-roots level as well as at the most senior levels of government. But the country is not the Wild West, and if anything can be learned from the Panama Papers, it is a reminder that reputation made in years, but destroyed in seconds. Panama has been spending the years demonstrating that it plays by the international rules, and in fact enshrines those rules in law.

Going through the processes of getting a bank letter of introduction was not the end of their due diligence. My employer in the UK received a telephone call from the bank in Panama. Do I actually exist, and do I really work for this company? Could they confirm by email please, from a company email address?

Remember that this is required by a bank in an off-shore tax haven. All I can do is quote the UK bank service representative: "Really?"

22 August 2017

Ethics, Audits, and Business Behaviour

So here we are again, with another corporate scandal. Who is it this week, Wells Fargo, Odebrecht, Uber, United, or someone else? The list of corporate scandals for even the past couple of years is daunting (and here, and here). Looking at the political landscape, we see the same thing, not just in the United States, but across the world. Another "breach of trust". Who would like to be dragged off the airplane today, or who would like to discover that your bank has been opening accounts in your name, that you get to pay for, without your permission?  How about that nice new bridge contract; the one that the contractor won off the back of brown envelopes, lots of envelopes?

Yet this is the reality of business today. In too many cases, the subsequent fine is significantly less than the profits from the (not proven to be criminal) activities that resulted in the scandal. Only in a few cases does the scandal result in an existential crisis for the company. Usually it only reduces management bonuses, and effectively robs the shareholders (and too frequently the customers) through destruction of share price.

Unfortunately too common following these crisis is the call for greater ethical standards. Sometimes, as happened this week with the Wells Fargo scandal, there will be calls for the audit to be improved, or the auditor sanctioned. Why unfortunately? Because such calls are meaningless.

Francine Mckenna and Andrea Riquier have written (another) strong article effectively asking "Where was KPMG, Wells Fargo’s auditor, while the funny business was going on?".  Not surprisingly, the Audit and Governance community react by pointing out that the auditor is not actually required to find or disclose non-material fraud. Nor are the auditors required to report where ethics are absent.

Pages are written about the PCAOB Auditing Standards, and the role of the Auditor. Almost all of it in defense of the audit profession. But Francine and Andrea quote Andy Green

 
“There’s been far too little attention since the crisis on how the external auditors should be looking out for the public,” Andy Green, managing director of economic policy for the Center for American Progress, told MarketWatch. They are not just bookkeepers, but the investors’, and the capital markets’ last defense against accounting manipulation and fraud.”

While extensively quoting the article, Norman Marks asks "Wells Fargo and KPMG – did KPMG fail the investors?" Actually, yes, they did. In fact, while Norman's list of things that Francine and Andrea "omitted from the article" are all correct, none of those change the fact that KPMG did fail the investors. They complied with the standards; they failed the ethical question.

Francine has a long history of taking the Audit profession to task, and while not agreeing with everything she has written, she is quite right far more times than not. The problem of course is that we do not want Auditors to tell the truth, or to opine on the ethical foundation of businesses or the individuals running those businesses.

On the one hand, they (the auditor) probably would not be able to, as they have spent so many decades as apologists for their clients. On the other hand, they would probably find that there were too few businesses or leaders that would pass a reasonable-man ethics course (based on their choices, not based on their ability to pass a test or give the "correct" answers).

Many years ago someone said to me that we didn't need more rules, we just needed better enunciated Ethical standards. I will repeat my answer:

"Ethics only apply to Ethical People".

All the ethical standards in the world will not make ethical people, especially when reward systems do not support ethical behavior. You can have all the ethical standards that you want, but fundamentally, unethical people will ignore then, and worse, will ensure that they pay for the appropriate PR to demonstrate just how ethical they and their businesses are.

I'm talking of course about people skilled in the art of managing the message. Not the bungling mouth pieces of today, who refuse to answer any question but use the time to rehearse some well scripted talking point.  I'm talking about Clive, from Telecom New Zealand (in the 1990s, so no relation to anyone there today, I'm sure).

Clive once said the secret to corporate communications was simple; "Bad news is good news, good news is no news".

While that works for managing the message, it does not demonstrate ethical behavior or even an ethical outlook, although there were a few cases where Clive most definitely was putting the positive face on what were apparently unpleasant situations.

Yet there is no way you can spin fraudulent accounts and accounting as good news. And there is no way that you can spin auditor ignorance or ignoring of fraudulent accounts as good news. There is no way that sexual harassment at the top of organizations can be spun to be good news. It is not even good news when these people are exposed, as it argues for a deeper pool of unexposed persons, all carrying on the behaviors that they have learned from their seniors (and betters?).

No, "Ethics only apply to Ethical People". For the rest there is something called "Jail time". We should stop trying to spin good news, or even trying to simply extract fines from companies. People did these things, and people should be held accountable.

If we want real Ethical behavior, then the cost of unethical behavior needs to be much higher.

That goes for Auditors as well.

02 April 2015

Why CSR is an important part of your risk universe

Well isn't that a pretty CSR / Sustainability report? All the right tables, indexes, pictures of windmills and daisies, but yes, some fairly data rich tables and reports. There is also the great summary that shows that the company met 80% of its CSR targets for the year, and can even show how those targets have evolved over a number of years. 

That report, of course, is your competitors. And the boss is not terribly happy about that.

Call in the troops, raise the alarm, set some goals, and produce that CSR report that makes us look like we care, dammit.

Yes sir, no sir, three pages full of pretty pictures sir!

And so the company starts down (or continues down the already well worn) path to CSR or Sustainability or ESG (Environmental, Social, Governance) reporting. Goals are set and agreed, business cases are produced, and external consultants are engaged to help with the process. A standard is selected, and soon, but realistically most of a year later, the company has its first CSR report ready to go. All that is needed is a nice front-piece from the CEO, written by marketing or the CSR team, and it is time for the press release and marketing event.

Did you, as the Risk Manager or Internal Auditor, know what was happening, and have you included the CSR reporting process on your risk register or audit programme? If not, why not?

I know of one Risk Manager who was invited into the CSR programme from the beginning, and he is convinced that the result has greater validity and value because of Risk Management's participation.




CSR (Corporate Social Responsibility) reporting is important, but it also exposes the business to a new set of risks; operational, reputational and regulatory. CSR (or similar) reporting processes and content represent an uncharted area for too many risk managers and internal auditors. The information has rarely been determined to be “material”, so even when the CSR programme or report has been in the risk universe, it infrequently rose to a perceived level of significance to draw attention and review.

Yet I would argue that the reputational risk alone should be enough to encourage attention. Add the regulatory risk and there is a clear rationale for Risk Management and Internal Audit (IA). IA in particular has a mandate to review and report on the effectiveness of the system of internal controls, and that the programme of reviews should be based on a risk weighting of processes, systems and operational areas of the business. For too long we have assumed that this means controls over financial reporting and IT systems.

Consider the easiest regulatory and reputational risk. Does the CSR report contain the same information as the regulatory reports? In an SEC context, are the risks reported in the 10K the same as in the CSR report. As a specific example, does the CSR report in any way discuss climate change or the risks associated with exploitation of scarce resources such as water? If these are discussed in the CSR report, then they must also be in the risks section of the 10K, or face the danger of an investor or regulator asking why there are different risk factors being reported as being important to the current or future of the company.

This is as true for statutory reports in other jurisdictions. 

This is also true regardless of the reporting standard that you use, be it the GRI, IIRC's Integrated Report, UN Global Compact, SASB, or any other standard.

There are also metrics. Imagine reporting the level of carbon emissions or carbon offsets in a CSR type report, only to not report this information in statutory reports, regardless of what IFRS or US GAAP (or any other GAAP) requires.

While there are valid and important reasons to produce CSR/Sustainability reports, the information contained should be subject to independent review, and Internal Audit would be well placed to confirm the effective functioning of controls over the production of the information.

Likewise, Risk Management can provide valuable support in the establishment and operation of a CSR programme, and can ensure effective consideration of the risks being reported, both in range and in depth. This can include ensuring that common data sources are used for CSR and statutory reports, reducing the risk of different and potentially contradictory information being reported.

Key points:

·         The world of CSR/Sustainability reporting is undergoing massive change
·         Most CSR data is financial data, just packaged differently
·         Many CSR reporting standards are little more than marketing standards
·         Most CSR reports cover only a subset of the actual business. Disclosures in CSR/Sustainability reports do not always mirror disclosures in statutory reports
·         One activist with a smartphone can seriously ruin your day
·         CSR/Sustainability reporting practices can be a bellwether of other reporting practices, good and bad

For these reason Risk Managers and Internal Auditors should take a close look at what the company is saying to the world, and IA should confirm the effectiveness of the control environment that is producing the information that is reported, including the process (and costs) and the benefits.






30 March 2015

Governance; Ethics and Morals versus Regulation


In London at the CRSA Forum last week (25th March 2015), once again speakers talked about the importance of the ethical foundation of leaders and companies, and as usual rubbished the need for or importance of "rules based systems" of governance or regulation . Implicit in the comments was the importance of ethics as the foundation of any successful business. Explicit were the statements "ethics are better than regulation" and "rule based systems are less effective than moral or ethics based systems".

Unfortunately, that is bollocks. There is simply too much weight placed on the idea that ethics and morals actually deliver more effective governance than rules. On the one hand, absolutely, effective corporate (and personal) governance for long term benefit needs a moral and ethical foundation. On the other, remove the rules and only the ethical or moral will comply.

Rules do not exist to stop ethical behaviour, nor to make companies profitable or unprofitable, or to ensure that a manager "earns" a bonus. Rules and regulations are enacted by governments to promote what the government of the day has determined to be desirable behaviours, and to discourage or punish those that are undesirable.

While the good news is that only 4% of CEOs may be psychopaths (Forbes "Why some psychopaths make great CEOs") that is four times the average in society as a whole. And while only a small percentage of CEOs may be psychopaths, their CFOs and FDs are under pressures of their own to ensure the numbers are right. The penalties for missing the quarterly numbers can be decidedly unpleasant (CFO.com).

"Comply or Explain", the UK reporting mantra, is held up as the alternative to rules based systems of reporting and governance. IFRS is a wonderful example of principles based reporting, yet the IFRS (International Financial Reporting Standard) still runs to over 2700 pages, excluding various national GAAP extensions to IFRS. Still, this is better than the 17,000 pages of US GAAP (Moss Adams LLP, 2009). Yet anyone who has attempted to use IFRS will find that it is as mired in rules as any GAAP. This also overlooks that so much of US GAAP is based on permutations of tax law specific to the US or to individual states. Oh, and US GAAP has been around a little longer than IFRS.

A victory for principles based reporting? Or, as a friends says "If self-reporting was the only requirement, there would be no murder".

Rules exist for a reason. They provide the boundaries beyond which behaviours are unacceptable in law and regulation, if not in culture and society. Yet to point out that principles based systems are inadequate is all it takes to be branded in favour of a rules based system, as if that is something bad.

There are good rules, and there are bad rules. Don't eat your soup with a fork is a good rule. Allowing companies to discriminate against any minority based on the presumed religion of the company is NOT a good law (and is not religious freedom).

Allowing the CEO and Chairman to be the same person in a public company is not a good principle, but it would be a good rule. Because as a principle, it can be applied or not, it is only a principle. Make it a rule, and there is no weasling around it, it is worse than bad practice (and a fine indicator that the company is being run for the enrichment of the managers and now the owners) and it would not be permitted.

Independent directors are a sound principle, and I see no need for a rule on this. An independent Audit Committee chair is a very sound principle. So sound that maybe it should be a rule.

Board effectiveness reviews? Great principle, but no, I wouldn't make them mandatory.

After all, the purpose of rules is not to over-ride good principles, sound ethics and strong morals. The purpose of rules is to limit the flexibility of those that pay lip services to good principles, or those that are not ethical or moral. Fraudsters, or just those under pressure to produces the target numbers by any means, can more easily justify bending principles, but they cannot justify bending the rules.

Indeed, I continue to say "Principles and ethical standards only apply to principled and ethical people".