TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
News Archive

Fraud In Question

by Msecadm4921

I was amazed and flattered when Professional Security asked me to join its board of advisers and to write the occasional column on fraud related subjects. At my age and with diminishing mental capabilities, I am not usually invited out of the Old Peoplesโ€™ home without an escort.

Anyway, I thought the best I could do is to question some of the modern pillars of modern fraud prevention including "The Tone from the Top", "Whistle Blowing Lines" and other politically correct placebos that do little to solve the problem of corporate dishonesty. But the place to start is with "Compliance"

If you believe in "Compliance", in Father Christmas or in fairies frolicking in the rhubarb patch at the bottom of the garden, you will not like this article one bit, but it may make you think. "Compliance" is strangling initiative and in ten years time we will all be civil servants or on the dole. You better believe it.
INAPPROPRIATE BEHAVIOUR
True enough, some businessmen have behaved badly and have ripped off shareholders and others. Cases of externally directed and widespread fraud like Enron, Versailles and the UK pensionโ€™s scandals (by both commercial and governmental perpetrators) are bad but they are exceptions. They have been used to justify a mass of regulations, enforced by hordes of regulators, quangos and fellow travellers few of whom have ever had to run a business.

"Compliance" has given new life to law firms, accountants, consultants and internal specialists who, like Dracula, are unlikely to complain about an excess of blood. "Compliance" has become an industry and an end in itself! But the totally ineffective supervision of Northern Rock by the FSA just shows how useless the whole façade is.
HONEST MANAGERS
Politicians and regulators seem to overlook the reality that most businesses, and the vast majority of managers, are honest and hardworking and donโ€™t need to be told what is right and wrong. Maybe politicians are too heavily influenced by those leaders in commerce who nuzzle up to them with generous political donations or creep around saying how wonderful they are. These supporters do not represent the managerial masses who, like us, believe that the system of political donations and political party funding is the start of the chain of corruption. There is no such thing as a free lunch and in our society political corruption, spinning and downright lies are the start of the problem.

Most major frauds are committed against good companies that employ effective managers. For example, Barings was a not a bad company and collapsed, not because of endemic control weaknesses, but because it failed to react effectively when the symptoms of fraud first emerged. This is true of most serious fraud victims and it is partly the fault of government in not providing sufficient police resources to help victims recover from fraud, a public prosecution service that is at best highly myopic and a criminal justice system that is not geared to handling fraud cases. In fraud, there is little deterrent.

A managerโ€™s task is not made easier by pressures from investors, media and stock markets, all of which expect increasingly better financial performance. They seem to misunderstand โ€“ or consciously ignore – the risky nature of business, the toughness of markets and the fact that incomes for even the best run operations may be volatile.

When the slightest blip sends markets into panic mode is it any wonder that some managers should consider equalising the results; especially when accounting standards leave almost endless space for creativity? The temptation to smooth results is ever present but it could be reduced if everyone took a more realistic and long term view of businesses. It would also be reduced if accountants worked on honest principles, rather than on spinning the fine print of the rules. And Key Performance Indicators often drive a culture of dishonesty.
SELF-FLAGELLATION
In the face of the few bad cases and oppressive (and often irrelevant) regulations that result, managers are encouraged self-flagellate and, like rabbits in the headlights, become frightened to act lest their movements are seen as non-compliant or even worse as "inappropriate". This creates a vicious circle in which compliance becomes an end in itself, or is used as justification for doing nothing.

For example, a few weeks ago we arrived at Gatwick Airport without our baggage…I joined the queue at the service desk where a young woman with two young children was being very rudely handled by an airline employee. She was being reasonable in the face of the spotty and ear pierced employeeโ€™s outrageous behaviour. When she politely asked for his name he refused to give it because of the Data Protection Act!

Unfortunately we are now headed on a course of form over substance in which statistical analysis and "out turn figures" supplant the truth. Political "spinning" has become the norm, rather than the exception. A hospital now has to deal with over 30 different regulatory agencies and if the police make a single arrest they have to waste endless hours on filling out forms. The fact is that British managers โ€“ in both commerce and government – are tied down with a morass of red tape that kills initiative and entrepreneurship. The rule seems to be "if it canโ€™t be measured, or might offend the sensitive skins of regulators, donโ€™t do it"
COMPLIANCE IS AN INPAPPROPRIATE WORD
The Oxford English Dictionary defines "Compliance" as "an action in accordance with a request or command" or "an unworthy acquiescence". It may be used as a noun, adjective or a verb โ€“ which, as you may remember from school, means doing something. In recent years the word is used only as a noun โ€“ in fact a proper noun – with a capital "C", thus ranking it alongside "King" and "Queen" and putting it ahead of common, but more important, nouns such as "golf" and "selling". This nounal use is popular because it refers to an inanimate object that requires no action. Have you noticed that verbs are becoming so unpopular or even "inappropriate"?

Whether a verb, adjective or a noun, "Compliance", its roots and derivatives, are negative or "inappropriate" words, which imply that some poor oink is being led by the nose, or kicked up the ass, to do something he would not otherwise do and, probably, does not want to do at all. It also implies that the complieror knows more than the complieree. This is the first point where the whole edifice of business compliance falls down because it is constructed on the illusion that politicians and law makers are the pillars of probity, the commonwealth of conscience and are uniquely qualified to set the tone of business ethics, for hearty regulators to enforce. Managers are a pawn in the game and are viewed in the same regulatory kaleidoscope as smokers.
TITANIC PLC
The truth is that if most Western democracies were held to Sarbanes-Oxley, the Listing Rules or other compliance standards they would fail woefully and would make Kenneth Lay of Enron or Carl Cushnie of Versailles look like Mother Theresa. Just look at the recent cases of wholly inappropriate behaviour by political leaders, including financial shenanigans, conflict of interest, abuses of power, false reporting of key statistics and other hanky panky. Then turn to European Union (which has driven much of the accounting, supposed anti-bribery and other compliance standards) and recognise that for the past nine years its accounts have been in such disarray that they could not be finalised: bribery and fraud is rampant and anyone who blows the whistle, apparently, ostracised or punished. If the European Union were a listed company it would be called "Titanic Plc". And these are the people who tell us what to do!
REGULATORY CREEP
If some of the laws and regulations are bad, the way they are interpreted by regulatory agencies makes them even worse; through a process known as "regulatory creep". There is an old saying that "you never ask a barber if you need a haircut" which holds true in the compliance area. If you ask a regulator if you can do something the answer is unlikely to be positive: at best they will keep their options open, so that they can criticise later.

Unsurprisingly most regulatory agencies see their jobs as pivotal to the survival of the universe. If you want a simple example (and there are plenty more) just look at the office of the Information Commissioner. This illustrious body started as the "Data Protection Registrar" whose job was, as its name implies, simply to keep a register of organisations that process data automatically: mainly by computer.

It now grandly announces that it is "the independent champion of public openness and personal privacy". Whoever gave it that role? Has no one told the distinguished Commissioner that there is not a "privacy law", as such, in the UK and that if anyone ever detects truthful "public openness" they should have it framed and mounted on the wall, alongside the picture of their Granny.

Over the years, the office of the Information Commissioner has repeatedly expanded its Empire and, for example, after the passing of the Data Protection Act 1998, dictated that "relevant filing systems" (such as paper based personnel files) also fell within its ambit and issued almost endless tomes (usually called "guidelines" but intended as mandatory standards") including some incredible instructions on employment practices and the conduct of investigations when fraud is suspected.

In 2003, the Court of Appeal ruled that many of the Information Commissionerโ€™s rulings on "relevant filing systems" were inappropriate or plain wrong, but has the Commissioner withdrawn the offending guidelines and thereby shrunk its Empire? You guess. Regulations are easy to make but impossible to withdraw.

You will also remember the tragic murder of Holly and Jessica at Soham and the scandal that followed when the police admitted that, supposedly though a misunderstanding over the Data Protection Act, they had destroyed intelligence records which would have exposed Ian Huntley, their murdered, as a paedophile. The Information Commissioner denied responsibility and the police took the hit. At this stage, it is impossible to say who was to blame, but the case illustrates the dreadful process of regulatory creep through which those regulated increasingly err on the side of caution; thereby emasculating themselves. Excessive and unnecessary compliance is a dangerous as under compliance.
REMOVING THE TOOLS
While the standards demanded of businesses have increased the tools available to businesses to comply have decreased. For example the Information Commissionerโ€™s guidance on pre-employment screening and the conduct of internal investigations are naïve bordering on harebrained. If any company were to follow them, fraud would run rampant, regulations broken and managers (but not the regulators) held accountable for failure. There seems to be no consistency in the laws and regulations, nor any understanding of the problems they create at a working level.
ASSERTIVE INTEGRITY
Luvvies may not like to accept that businesses exist to make money. In doing this they employ people, pay taxes and do a lot of other things that are essential for human survival and, believe or not, are even "appropriate".

The fact that managers should he held personally accountable for failures at work is a given but they (and not regulators) must run their businesses and exercise this right based on an internally generated tone and framework of what may be called "assertive integrity".

Having dealt, over the past 40 years, with crooks in all shapes, sizes, colours, sexes (all five) and ages, the one common feature appears to be that their self-image was inconsistent with honest behaviour. Their value system was skewed, enabling them to rationalise dishonesty as being acceptable or even the norm. Also most had fancy shoes and appeared to be compliant: sometimes to extremes. Honesty comes from within.

By setting the tone from the top – really meaning it – creating a set of positive "self-image" and "collective image" values, effective Key Performance Indiators and recruiting honest people and keeping them that way by clearly defined operating procedures, positive encouragement as well as severe and certain punishment, compliance with regulatory standards will be surpassed while retaining innovation and profitability.

The threat of punishment, for breaking some esoteric regulatory whim that the subject regards as meaningless, is not likely to change anyoneโ€™s inner values. This is especially true if, at the end of the day, punishment is avoided because the criminal justice system fails. Similarly, penalties will achieve nothing if all the subject sees is minor rule-breakers being punished while the gross offenders escape. This is often the result when regulators prosecute the easy, technical cases, because the real villains are too difficult to catch. You see these cases every day, when legitimate banks are severely punished for not filling in the right form at the right time while corrupt political and commercial leaders are able to stash away billions through trusts and other complex skulduggery.

In the unlikely event that politicians would accept advice it would be to cut back on the esoteric red tape and the regulatory hordes, encourage managers to manage through assertive integrity and by instilling inner values; provide a law enforcement framework, (including changing the laws on bribery in line with the 1998 report of the Law Commission) and to take all other reasonable steps to help managers deter real fraud and not just irrelevant technical failures. Finally, they should build more prisons and fill them with the real offenders.