22 November 2007

The GC: The Truth Can Be Adjusted...

If you are a General Counsel (GC) today for an organization doing business on a global basis, your Blackberry must be "buzzing" every few minutes. The legal risk being encountered will always be a factor of the number of deals, the number of employees and the growing number of countries you do business in.

As a corporate GC of a global enterprise, you have a fiduciary responsibility to protect the enterprise from adversaries such as the rogue employee, the government regulator, competitors and plaintiff class actions. The Rule of Law in your organization is in your hands. How you transfer the "Talking Points" on ethics and legal messages to your employees, partners, suppliers and adversaries is critical. The effectiveness of your relationship with internal CSO, CISO and Internal Audit leadership could mean the survival of the company and your job.

In the latest hollywood movie Michael Clayton with George Clooney, he plays the role of a prominent law firm's "Fixer." He finds himself taking care of the messes corporate clients put themselves into and even the internal firm problems with senior litigators who have decided to do secret battle with a prominent clients General Counsel. The GC in this film takes every precaution to ensure the settlement of a pending class action suit that has achieved over +30,000 billable hours by Michael Clayton's law firm.

While this fictitious story displays the extremes of the world many GC's live in with their outside counsel, it sets the stage for gaining insight into the legal ethics and corporate challenges global institutions face on a continuous basis. The Yin / Yang of corporate compliance and governance is consistently wrestling with the pressure to save people from losing their reputations and the longing to do the right thing. The goal is to achieve a defensible standard of care and to have peace of mind. To be able to stand behind the fiduciary duty to uphold the law and enforce the rule of law in corporate business.

When was the last time a GC took the "Ethics" and "Rule of Law" program directly to the employees in face to face sessions? To give the employees, partners or suppliers first hand opportunity to meet, greet and engage with the General Counsel of the enterprise. By doing this you are directly engaging with the people on the front line to be the "eyes and ears" for the company. To be that early warning system of potential conflicts of interest, fraud and corruption. As an example, Scott Chaplin at Stanley Associates says this:

"I deal with a wide range of issues on any given day. I support not only our business operations but also corporate support. Our recurring issues include corporate governance and securities, and we're active in the mergers and acquisitions area -- we've done several deals recently. I handle labor and employment issues on a daily basis, along with government contracts issues, litigation, IP and compliance work. I'm also the ethics officer for the company, responsible for our ethics compliance program, as well as secretary of our board of directors, where I act as legal adviser to the board."

"I recently completed our annual ethics training at a number of our offices. After each training session, I would have a line of employees waiting to speak with me about various issues. That got me thinking that a lot of employees don't feel they have a direct line of communication to me at corporate. They might not feel that the issue is important enough to bring up with the GC. It made me realize that in-house lawyers need to get out of headquarters more often and go to the employees, instead of waiting for the employees to come to us. We have to get out to the field and foster the client relationship a little bit more."

Scott is absolutely correct and what a better time than to emphasize SOX Section 806. Protecting the rights of corporate whistle-blower's is the GC's responsibility in combination with an external ethics hot line for employees. While there have been plenty of other people calling for reform on other burdensome and expensive components of SOX, no one is going to touch Section 806. Employees don't understand the implications of the law and corporate management can't under estimate the impact of this in terms of potential litigation it may face.

Achieving a Defensible Standard of Care requires a General Counsel with the vision to address a spectrum of legal and ethical risks in the modern enterprise. When this is finally accomplished, the Michael Clayton's in law firms around the globe, will be looking for a new career.

01 November 2007

Red Flags: The Oracle of Omaha...

What do you do when you see a "Red Flag"? This was the question posed to Directors in a recent poll by Corporate Board Member Magazine in the November/December 2007 issue. C. Warren Neel the Executive Director of the Corporate Governance Center, at the University of Tennessee could not have answered this any better:

I don't want to see it; I want to "hear" the red flag before I see it. I want to hear about it before it happens. And I don't want to just know it happened, I want a diagnostic as to why it happened. I want a postmortem. What led us down that track? How did it start? Was it personnel-based? Process-based? Because of a malfunctioning system? Did we have the wrong strategy? Or what?


Welcome to the world of Operational Risk Management Mr. Neel. These are the scenarios that are played out on a continuous basis in the midst of the daily humming of business throughout the organization. These Ops Risk professionals are testing, exercising, stressing, and "Thinking of the Unthinkable" everyday so you do hear it before it happens. It may not be weeks, or even days. It could be hours or minutes. And then what will the Board of Directors do next?

This is perhaps one of the largest worries these professionals have. They don't know you, the Board or the steps you might or may not take once you get the warning, the news or the prediction. As the Board of Directors it's imperative that you learn all you can about who the Operational Risk experts are in the enterprise and to know them personally. Otherwise, how are you ever going to have an early warning system that you can trust and gets you the answers sooner than later?

What you need is an extension to the "Whistleblower" mechanism that tracks potential ethics violations and other wrong doing of corporate policy. It's a risk management method integrated with your current fraud management systems and combined with the ongoing behavioral analysis of "High" risk employees. Without this early warning process and supporting system in place the Board is forever doomed to be on the "reactive" end of the spectrum, continuously wondering how to respond to an incident that has already occurred.

How did Warren Buffet get the "Red Flag" on Freddie Mac even years before their implosion with senior management?

The charges against Brendsel were filed three years ago by the Office of Federal Housing Enterprise Oversight, which regulates Freddie Mac and its larger government-sponsored sibling Fannie Mae. OFHEO, which blames the accounting scandal on management misconduct is seeking damages and penalties against Brendsel totaling nearly $1 billion, including $24 million in severance benefits and stock awards.

Buffett said he was uncomfortable, among other things, about an investment by Freddie Mac that was unrelated to its business as the nation's second-largest financer of home mortgages.

"I follow the old dictum: There's never just one cockroach in the kitchen," Buffett said.

Details of his testimony were reported in Wednesday's editions of The Washington Post. They were confirmed by people familiar with the proceeding, speaking on condition of anonymity because they weren't authorized to speak about the case publicly.

Regardless of the outcome of this proceeding, the point could be made that the board had a huge "Red Flag" that Warren was selling his stake in the company. Predictions are based upon a number of factors and there must have been many pieces of information that added up to "somethings not right" at Freddie Mac. Today, there are ten positions open at Freddie Mac for operational risk related jobs and here is what they are seeking:

Position is part of a team supporting Operations as an operational risk management partner. Significant time will be spent as the face of the Audit Liaison function. Engages with the business areas to fully understand the operational process in order to coach and support the group in identifying and assessing operational risk and designing appropriate controls to mitigate the risk. Provides subject matter expertise on operational risk management systems and Freddie Mac operational processes.

Ensures all operational risk deliverables are completed within established timeframes with a high level of quality especially the mitigation of outstanding major/critical issues and monitoring of status on all outstanding issues. Deliverables include Operational Breakdown and Loss Event Reporting, Risk and Control Self-Assessments, SOX Assessments, Internal and External Audit Responses. Also supports Quality Assurance testing of SOX Key Controls and Root Cause Analysis.

  • Skills/Knowledge needed:
  • Indepth knowledge of operational risk management and controls with minimum 2 years experience.
  • Knowledge of key principals of auditing.
  • Knowledge of key principals of mortgage operations.
  • Knowledge of financial industry operations and/or accounting is preferred.
  • Ability to work independently with strong organizational skills to meet frequent deadlines.
  • Strong interpersonal skills with ability to build working relationships.
  • Flexibility and ability to multitask.
  • Strong analytical skills.
One might wonder why they are looking for someone with in depth knowledge of operational risk management (ORM) with only two years of experience. Sadly, this is because the organization relied for too many years on their financial auditors and their armies of freshly minted MBA's from some of the best business schools in the nation. However, the main reason is that the science of ORM is new compared to other disciplines in the accounting profession.

As organizations evolve their ORM departments and combine the attributes of fraud management, systems testing, continuity of operations, records management and employee behavioral analysis the Board of Directors will have a better opportunity to predict "Red Flags". They will ultimately become more preemptive in their actions and follow through to protect the shareholders assets. Until that happens, keep your eyes and ears on the "Oracle of Omaha"...

26 October 2007

Fraud Awareness: Investing in the Consumer...

A few months ago Bank of America started offering it's online banking customers the opportunity to take advantage of a 90 day free trial of Symantec's products. The extension of the security perimeter has begun and now the institutions have realized it's time to start subsidizing, mandating and influencing customers to be more vigilant.

Recognizing that defenses are only as strong as the weakest link, Bank of America has moved to shore up an area that largely is beyond its control: customers' desktops. In a move experts say is a step in the right direction toward improving online banking security, the Charlotte, N.C.-based bank announced a partnership with Symantec (Cupertino, Calif.) in which the bank will offer the security solutions provider's software to online banking customers.

According to Bruce Cundiff, a senior analyst with Pleasanton, Calif.-based Javelin Strategy & Research, the deal represents a banking best practice whose day has come. "Deputizing the customer -- bringing them into the security process ... adds layers of security," he says. No matter how strong a bank's security measures may be, end users' PCs end up being the weak links in the security chain, Cundiff explains. So it's in the banks' best interest to engage consumers.

The question remains, will the simple use of a tool like Norton mitigate the risk to the institution? Not likely. Tools alone will not stem the risks they seek to avoid, reduce or eliminate. However, the customer loyalty, reputation management and defensible standard of care will get an up-tick from this kind of behavior from the institution.

These and other measures Bank of America has offered to consumers such as "Safepass" and a down loadable "Earthlink" powered plug-in for the IE Explorer tool bar are again the tools that give consumers a false sense of security, because the bank has asked them to use these and endorsed them. Whenever you give people the feeling that they are completely protected, that is the point in time when they become complacent. They stop learning and stop paying attention to the cues and clues that they are in the midst of a fraud scheme or their identity has been stolen.

Hackers no longer need to be technical wizards to set up an operation to steal people’s banking information and then rob their accounts.

The number of hackers attacking banks worldwide jumped 81 percent from last year, and the number of hackers targeting credit unions increased 62 percent, according to SecureWorks. The figures are based on attacks on the Atlanta-based managed information security services provider's financial institution customers.

So why are there so many more hackers today? Joe Stewart, a senior security researcher at SecureWorks, says that hackers no longer need to be technical wizards to steal people's banking information. Hacking tool kits and malware are for sale in the online underground, he explains, noting that all hackers need are basic technical skills and the knowledge of where to go to buy what they can't build themselves.

"You go to a Web site and pay $100 to several hundred dollars, and you can buy a turnkey exploit package," says Stewart. "You can buy the malware, too, and then you're in business. ... All you really need to know how to do at this point is set up a Web site."

So what is the answer for the banks who have mounting operational risks that extend into the homes of their consumers who are banking online? More tools?

Whether the answer is more education, mandatory downloads of new software prior to logging into the SSL banking site or increased fraud detection systems the problem will not be solved anytime soon. So what can you do to mitigate the risk as a consumer?

First off, don't do any online banking with a firm who has not implemented multi-factor authentication. Many are still dragging their customers into the false thinking that a plain old user name and password alone will do the trick.

Second, as a consumer you have to lock down your identity. Go beyond the monitoring services such as those found from Equifax or Fair Isaac and use the services offered by Lifelock.

Finally, as a bank or financial institution providing investment services you must invest in the awareness building of your employees, partners, customers and your clients. The education of the consumer is still one of the most effective means for defeating the organized criminal, face to face or online. Think about the new ad campaigns you may have seen about fake checks and I think you will see what we mean.

19 October 2007

3rd Party Outsourcing: Compliance Management...

Hedge Funds who require outsourcing products or services in conjunction with their broker-dealers and clearing banks are still under the "Regulators" microscope. The focus on "Red Flags" is a continuous challenge in addition to the latest operational risk mandates and due diligence on 3rd parties.

This was highlighted by Geofrey L. Master of Mayer Brown last May in one of his articles from Mondaq:

"Further, and even more significantly, hedge funds must deal with many compliance requirements that are applicable to other parties that are part of the fund’s operating environment. An example of such indirectly applicable requirements is the compliance obligations faced by the fund’s investment advisor, its broker-dealers, and its clearing banks. These parties face distinct, and often significant, legal and regulatory requirements that necessarily impact the fund’s operations. In addition, the demands of fund investors, as well as other business environment realities, result in a variety of selfimposed operational requirements that function effectively as (and in some cases may actually become — through fraud claims, for example) legal requirements." "With regard to laws applicable to the service provider, compliance requirements range from licensing and authority-to-do-business issues to those directly impacting service performance, such as health and safety and environmental regulations and data safeguarding requirements."

The Governance, Regulatory, and Compliance (GRC) business process within the ranks of the hedge fund has a fundamental requirement to assure that outsourced entities are executing their responsibilities. Service providers are an extension of the Hedge Funds supply chain of information services and financial intelligence that investors have taken as a natural extension of the funds operational infrastructure. The EU Market in Financial Instruments Directive (MiFID) takes effect on November 1, 2007 and directly intersects with outsourcing services to 3rd parties.

Mark A. Prinsley also of Mayer Brown sums up the impact of MiFID on firms and how they are currently managing the risk associated with outsourced services:

In substance, the rules should largely reflect no more than sound and prudent practice in any outsourcing relationships. However, in relation to the management of the outsourcing relationships, firms will be required to retain skills and exercise risk management not just for the services provided by the service provider, but also in relation to the way in which the firm manages its outsourced activities. Inevitably, this will lead to the need for more resources and skills in the areas of management and audit to be retained by firms in the financial services sector that outsource their activities.

It is also important to note that the new rules will apply retroactively. Thus, while firms will not be required to re-write their existing outsourcing arrangements, it will be prudent for them to confirm, particularly for arrangements that may not have been "material contracts" - and therefore not previously notified to the FSA - that the arrangements do meet the new rules in areas such as retention of appropriate skills and resources and management of risk.

One solution for addressing this increased scrutiny within the EU and other firms who are looking to enhance their outsourcing resilience can look no further than the BS 25999 standards for Business Continuity Management.

"Continued operations in the event of a disruption, whether due to a major disaster or a minor incident, is a fundamental requirement for any organization. BS 25999, the world’s first British standard for business continuity management (BCM), has been developed to help you minimize the risk of such disruptions.

By helping to put the fundamentals of a BCM system in place, the standard is designed to keep your business going during the most challenging and unexpected circumstances – protecting your staff, preserving your reputation and providing the ability to continue to operate and trade.

BS 25999 has been developed by a broad based group of world class experts representing a cross-section of industry sectors and the government to establish the process, principles and terminology of Business Continuity Management.

It provides a basis for understanding, developing and implementing business continuity within your organization and gives you confidence in business-to-business and business-to customer dealings. It also contains a comprehensive set of controls based on BCM best practice and covers the whole BCM lifecycle."

This new standard utilizes the same Plan-Do-Check-Act life cycle that many practitioners are already familiar with from previous implementation standards such as ISO 27001 for Information Security Management Systems. BS 25999 is suitable for any organization, large or small, from any sector. It is particularly relevant for organizations which operate in high risk environments such as finance, telecommunications, transport and the public sector, where the ability to continue operating is paramount for the organization itself and its customers and stakeholders.

03 October 2007

New Risks Require CEO Action: Beyond Awareness...

Here was our favorite question sitting in the room at the National Press Club this week during a "Deja Vu" moment, as the Department of Homeland Security and the Federal Trade Commission kicked-off the 2007 National Cyber Security Awareness Month.

"What demands, mandates or filings might be made on your organization from external organizations - public, private or regulatory - during this kind of disruption? What will your customers expect from you?"

The statistics are getting more attention these days due to the real pandemic of ID Theft and transnational crime syndicates now turning to mechanisms of financial fraud. This has surpassed the drug trade in terms of the revenue potential and the ease of acquiring and accessing our personal identifiable information.

The purpose of this summit in conjunction with the National Cyber Security Division (NCSD) of DHS is to examine ways to develop an actionable, sustained national awareness campaign and prevention program to inform Federal, State, and local government, educational institutions, small business users. The focus continues on protection of key resources, critical infrastructure and personal sensitive information and identities from man-made and natural threats.

The presentation that was most refreshing and relevant was from the Honorable Deborah Platt Majoras, Chairman, Federal Trade Commission. She highlighted some of the recent enforcement actions and the continued emphasis on business to assure their reputations by staying out of the popular press. These remarks by Betsy Broder, Assistant Director of the Federal Trade Commission’s Division of Privacy and Identity Protection at an event last month, further address the growing concern by business to adequately protect consumers information:

Law Enforcement on Data Security
"One important way to keep sensitive information out of the hands of identity thieves is by ensuring that those who maintain such information adequately protect it. To further that goal, the Commission brings law enforcement actions against businesses that fail to implement reasonable security measures to protect sensitive consumer data. Public awareness of, and concerns about, data security continue at a high level as reports about breaches of sensitive personal information proliferate."

The awareness agenda continues because it is still a long way from getting the public and the Small and Medium Enterprise to recognize the fiduciary duty they have to their customers. Even this web site OnguardOnline produced by the consortium of government agencies working together to fight cyber crime and improve awareness still have not found all of the answers.

The Business Roundtable's new publication on "New Risks Require CEO Action" has been well recieved due to greater reliance on the Internet for Business Operations. Here are a few of the most important questions that CEO's can ask:

1. Have we considered the dependence of our vendors and supply chain on the Internet?

2. What degree of consumer confidence in our data, services or products may be affected by a disruption of the Internet or corruption of data and services that are dependent on the Internet?

3. Have we set in motion a strategy for attaining early warning information to better protect our customers and corporate assets as well as our suppliers and partners?

The World Economic Forum estimates a 10 to 20 percent probability of a breakdown of the critical information infrastructure in the next 10 years - one of the most likely risks it studied. Additionally, it estimates the global economic cost at $250 Billion, one of the largest cost estimates of the risks examined.


20 September 2007

A Defensible Standard of Care: Six Million Reasons...

There are 6,000,000 reasons why Operational Risk at TD Ameritrade is in the Red Zone this week as a result of what seems to be a case of malicious code discovered last week, or over a year ago.

This author received a recent letter from TD Ameritrade regarding their so called pseudo "breach". And we quote:

"While investigating client reports about the industry-wide issue of investment-related SPAM, we recently discovered and eliminated unauthorized code from our systems. This code allowed certain information stored in one of our databases, including email addresses, to be retrieved by an external source."


What is absolutely amazing is the request to visit www.amtd.com for more information and a list of Frequently Asked Questions (FAQs) and an additional message from me, (The CEO Joe Moglia). The link to this message requires you to run Windows Media Player for what must be a sincere apology. However, the PR department must not know how many malicious code exploits are associated with .wmv files. Nor, how many people still do not have broadband connections as a consumer.

But that is not even the most fascinating aspect of this whole incident. The story gets even more disturbing if it is indeed true:

Scott Kamber of Kamber & Associates, a New York law firm that sued Sony BMG last year for its use of a rootkit, told InformationWeek on Monday that the lawsuit initially claimed that Ameritrade knew about the data breach last November. However, he says he now has information that the company knew about the ongoing breach a full year ago.

Kamber, who filed the suit this past May, had recently filed a preliminary injunction asking the court to compel Ameritrade to disclose the data breach and the compromised information to current and prospective customers. The company was given a two-week adjournment and made the public announcement during that recess.

"I am glad customers finally know of the compromise of their personal information," said Kamber. "I'm not pleased it took the company so long to do that."

Hillyer said she could not comment on ongoing litigation but said, "As soon as we discovered it, we stopped it. And as soon as we had gathered enough information, we notified our clients."

Ameritrade notified the FBI and the U.S. Securities and Exchange Commission last week, according to the spokeswoman.

It's apparent that the nexus of Information Security, Digital Forensics, eDiscovery, Legal Risk and Reputation Management have imploded in Bellevue, NE yet this will not be the last place we hear about this kind of incident. If a Rootkit is on a server there, you can be sure that there are others at a another broker or investment management firm near you.

Being vigilant about protecting privacy and doing the right thing with customers in the event of a breach has significant legal ramifications, that is for certain. What is less known at this point are the processes and corporate behavior that could be even more of a source of liability for TD Ameritrade. Who what how and why is now under investigation and will play out in a court room again soon.

The degree that any firm in the industry is "Litigation Ready" or has adequately prepared for this particular nexus between the elements of Information Security and the Law will determine the amount of Operational Risk they are potentially exposed to in incidents like this one. How can any firm prepare for an event similar to this?

1. Conduct a Litigation Readiness Audit of the firm.

2. Develop a strategic plan for achieving a "Defensible Standard of Care."

3. Train the stakeholders on Crisis, Command and Control.

4. Implement an early warning data analytics system to preempt potential threats.

Number four on this list pertains to something that is also in the authors letter. "As part of our effort to protect privacy, we have hired ID Analytics, which specializes in identity risk, to investigate and monitor potential identity theft." Let's just hope these guys didn't load up a CD at their shop handed over to them by TD Ameritrade with 6,000,000 records of personal identifiable information on it.

14 September 2007

Privileged Information: The Decision to Cooperate...

True or false: A large corporate private sector company hires an outside counsel to investigate an employee suspected of fraud. The outside counsel hires a fraud examiner to look into the facts. The fraud examiners report to the outside counsel will assist in determining whether a crime has been committed. The report and the communications with the outside counsel are protected confidential work product and is privileged. If you don't know the answer, read on.

Organizations who realize that internal investigations can pose a tremendous risk of litigation are ahead of the Operational Risk Management curve. Being proactive about prudent strategy on how to address the potential internal employee fraud is imperative, especially if you plan to pursue litigation to try and recover the stolen assets.

The two primary areas of emphasis here for the purpose of what information is discoverable is the attorney-client privilege and the work product doctrine: This Texas case from the Texas Bar Journal article by Derek Lisk illustrates the point:

In yet another case in which one party sought to protect documents from an investigation on privilege grounds, the U.S. District Court for the Eastern District of Texas took a more expansive view of the privilege. In-house counsel for Electronic Data Systems (EDS) hired outside attorneys, who in turn hired a consulting firm, to independently analyze and report on alleged misuse and misappropriation of assets by an EDS employee, Mr. Steingraber. In the ensuing litigation, EDS objected to producing documents from the investigation.

Steingraber, like Seibu Corp., argued that the documents were not privileged “because they were made to facilitate a business decision rather than the rendition of professional legal services.” This court, however, sided with the party seeking to protect the documents, finding Steingraber’s interpretation of the privilege “unduly narrow” and disagreeing with Seibu Corporation to the extent it held otherwise. Among other things, the court said, “The fact that the attorneys may have been hired to facilitate a business decision does not mean that such a decision was devoid of legal consequences.” Because EDS hired the outside lawyers to contribute legal expertise, including contract interpretation, risk evaluation, witness interviews, and evidence evaluation, the communications between them were “for the rendition of legal services.”

The status of H.R. 3013 in the US House of Representatives is unknown as it goes to be debated in committees:
7/12/2007--Introduced.
Attorney-Client Privilege Protection Act of 2007 - Amends the federal criminal code to prohibit any U.S. agent or attorney, in any federal investigation or criminal or civil enforcement matter, from demanding, requesting, or conditioning treatment on the disclosure by an organization (or affiliated person) of any communication protected by the attorney-client privilege or any attorney work product.
Prohibits a U.S. agent or attorney from conditioning a civil or criminal charging decision relating to an organization (or affiliated person) on one or more specified actions, or from using one or more such actions as a factor in determining whether an organization or affiliated person is cooperating with the government.
The question on the table here is how much as a corporation do you want to cooperate to prosecute the employee? It may make sense as a corporation to waive some rights to help recover your losses. How you architect a process for engaging outside counsel, independent investigators and fraud examiners in order to mitigate Legal Risk is crucial. The information exchanged, obtained in the process and communicated between parties must be done correctly. Not only to protect the information under the new Federal Rules of Civil Procedure but to insure the integrity and trust of the information itself.

A Board of Directors that oversees the governance of hundreds or thousands of employees is going to be continuously subjected to corporate malfeasance and white collar crime matters. The rule of law within the halls of the organization must be clear and precise. The mechanisms for the company to cooperate with investigators may mean the difference between an employee that creates irreversible economic damage to the enterprise or even worse. Our national security.

07 September 2007

BMPE: Internal Audit Awareness...

Risk in the supply chain may not always come from that vendor who provides your power, water or telecommunications. Black Market Peso Exchange (BMPE) is an Operational Risk that is starting to gain more awareness with Internal Auditors. This has been around since the 1980's yet even today some of our most sophisticated financial services institutions are being subjected to this system of fraud. The BMPE has been another way for money laundering from illicit criminal drug proceeds to impact our risk management controls:
American Express Bank International's anti-money laundering program was deficient in three of the four core elements. Namely, the Bank failed to implement adequate internal controls, failed to conduct adequate independent testing, and failed to designate compliance personnel to ensure compliance with the Bank Secrecy Act. American Express Bank International's high-risk customer base, product lines, and international jurisdiction of operations required elevated measures to manage the risk of money laundering and other financial crimes.

Nevertheless, the Bank conducted business without adequate systems and controls reasonably designed to manage the risk of money laundering, including the potential for Black Market Peso Exchange transactions that may be used by Colombian drug cartels to launder the proceeds of narcotics sales. American Express Bank International's failure to comply with the Bank Secrecy Act and the regulations issued pursuant to that Act were serious, repeated and systemic.

This method of money laundering is effective for the drug traffickers and requires more awareness on the behalf of fraud examiners and independent auditors. The IRS form 8300 requiring companies and financial entities to disclose receipts in excess of $10K in cash or equivalents doesn't work very well as wire transfers are not considered cash or cash equivalents.

Javier Sarmiento with GlassRatner has a substantive article on the subject in the last issue of the ACFE Fraud Magazine.

A point is made that needs to be emphasized here. "Don't rely on banks and financial institutions to conduct anti-money laundering (BSA/AML) procedures on behalf of the company." Is it possible that your organization has purchased inventory with funds that have been utilized as part of the BMPE scheme? What about resellers and distributors that are part of your own revenue supply chain.

In terms of Independent testing, make sure that your Internal Audit department is educated and aware of this particular mechanism for use by money launderers:

American Express Bank International's independent testing of its Bank Secrecy Act program was ineffective. Internal Audit Staff lacked sufficient training and knowledge to facilitate compliance with the Bank Secrecy Act. Audit scopes were not always tailored or designed to capture and test for compliance with certain requirements of the Bank Secrecy Act.

Internal Audit staff also failed to conduct sufficient customer transaction testing to adequately evaluate the overall sufficiency of the anti-money laundering program at the Bank. Furthermore, Internal Audit failed to assist management with tracking and following-up on previously identified regulatory examination deficiencies. In addition, Internal Audit failed to conduct adequate testing of the suspicious activity monitoring system or identify the numerous data integrity concerns associated with this system for an extended period of time. The ineffectiveness of the Internal Audit function at American Express Bank International contributed to the failure to identify significant deficiencies in this system before 2007.

03 September 2007

A-Space: Intel 2.0...

A week or so from now around 8:30AM on the East Coast of the United States there will be many people remembering where they were six years ago. On September 11, 2001 we will stop and observe a minute of silence and reflect on all that has changed and been accomplished and what has stayed the same. It may seem like a distant memory for some, yet a bad dream from last night for so many others.

Sharing intelligence or the valuable aspects of relevance, to you, or your enterprise requires the proper tools and mechanisms. This is a given. However, all the operational risk tools and systems will never be the entire answer to finding the "needle in the haystack" or "connecting the dots". The DNI has been implementing the right kinds of methods and applications to help solve the equation for preventing catastrophic incidents of the magnitude of 9/11 in search of the correct answers:

It's hard to imagine spies logging on and exchanging "whuddups" with strangers, though. They are just not wired that way. If networking is lifeblood to the teenager, it is viewed with deep suspicion by the spy.

The intelligence agencies have something like networking in mind, though, as they scramble to adopt Web technologies that young people have mastered in the millions. The idea is to try to solve the information-sharing problems inherent in the spy world - and blamed, most spectacularly, for the failure to prevent the Sept. 11, 2001, attacks.

In December, officials say, the agencies will introduce A-Space, a top-secret variant of the social networking Web sites MySpace and Facebook. The "A" stands for "analyst," and where Facebook users swap snapshots, homework tips and gossip, intelligence analysts will be able to compare notes on satellite photos of North Korean nuclear sites, Iraqi insurgents and Chinese missiles.

Sharing information is not the hard part. Analyzing it with the "grey matter" necessary to put 2 + 2 together beyond the capability of the algorithms of the software requires training and extreme context. Corporate Enterprises have been utilizing similar systems and tools on their secure Intranet's for years and the agencies are now taking the lessons learned and applying these to the social networking community of their analysts. Smart strategy as many of these "Outsourced" entities are operating from the private sector NOC or SOC and have been delivering intelligence products long before they were hired to do so for the government.

Observing the lessons from the Financial Services Industry on what works and what is treading on thin ice can be a helpful example. Sharing intelligence across organizations, platforms and between competitors has been the norm at SWIFT:

SWIFT is the industry-owned co-operative supplying secure, standardised messaging services and interface software to over 8,100 financial institutions in 208 countries and territories. SWIFT members include banks, broker-dealers and investment managers. The broader SWIFT community also encompasses corporates as well as market infrastructures in payments, securities, treasury and trade. Over the past ten years, SWIFT message prices have been reduced over 80%, and system availability approaches 5x9 reliability — 99.999% of uptime.
Swift is considered the nerve center of the global banking industry, routing trillions of dollars each day between banks, brokerages and other financial institutions. The group's partnership with the U.S. government, first revealed in media reports in June 2006, gave officials at the CIA access to millions of records on international banking transactions in an effort to trace money that investigators believed might be linked to terrorist financing. Swift agreed to turn over large chunks of its database in response to a series of unusually broad subpoenas issued by the Treasury Department beginning months after the attacks of Sept. 11, 2001.

At 8:30AM on 9/11 2007 during our moment of silence we can only pray that our Intel sharing continues and doesn't get strangled by those who have forgotten this day of remembrance.

30 August 2007

BSA/ AML: Testing the Channel...

Legal compliance with the Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) is a complex and growing concern by regulators, enforcement and Operational Risk Executives. In the United States, the FFIEC (Federal Financial Institutions Examination Council) has published the latest Examination Manual to provide guidance:

Enterprise-Wide BSA/AML Risk Assessment

Holding companies or lead financial institutions that implement an enterprise-wide BSA/AML compliance program should assess risk both individually within business lines and on a consolidated basis across all activities and legal entities. Aggregating risks on an enterprise-wide basis for larger or more complex organizations may enable an organization to better identify risks and risk exposures within and across specific lines of business or product categories. Consolidated information also assists senior management and the board of directors in understanding and appropriately mitigating risks across the organization. To avoid having an outdated understanding of the BSA/AML risk exposures, the holding company or lead financial institution should continually reassess the organization’s BSA/AML risks and communicate with business units, functions, and legal entities. The identification of a BSA/AML risk or deficiency in one area of business may indicate concerns elsewhere in the organization, which management should identify and control.

When a financial institution utilizes a strategy for it's channel or broker network the goal is to build controls into the consumer application process. These controls help the parent financial institution with compliance issues and give the independent broker or registered investment advisor with the tools and mechanisms for risk mitigation. However, to what degree do these independent brokers who interface with the consumer actually understand, implement and comply 100% with BSA/AML laws?

This question may haunt the minds of many OPS Risk professionals as they try to manage the mountain of data and documentation requirements at the home office or processing center. When there are dozens or hundreds of independent brokers in the client acquisition process your risk exposure increases dramatically. When and how often do you need to audit these important entities in your member or client supply chain?

Independent testing (audit) should be conducted by the internal audit department, outside auditors, consultants, or other qualified independent parties. While the frequency of audit is not specifically defined in any statute, a sound practice is for the bank to conduct independent testing generally every 12 to 18 months, commensurate with the BSA/AML risk profile of the bank. Banks that do not employ outside auditors or consultants or have internal audit departments may comply with this requirement by using qualified persons who are not involved in the function being tested. The persons conducting the BSA/AML testing should report directly to the board of directors or to a designated board committee comprised primarily or completely of outside directors.

Those persons responsible for conducting an objective independent evaluation of the written BSA/AML compliance program should perform testing for specific compliance with the BSA, and evaluate pertinent management information systems (MIS).

This is not any surprise to large banks and securities dealers who have been working diligently on these compliance management problems for decades. Whenever an organization is deploying a distributed and indirect model for acquiring new consumers, high net worth individuals and other business entities for financial-based products and services; BSA/AML programs should be robust. The individuals who are planning to launder money that has been obtained illegally or are part of a fraud scheme will prey on those unsuspecting and naive institutions first. In some cases, it could be an independent broker or business who is the target of a sophisticated and influential individual. They want to find a weak link in the institutions sales channel to gain access to a well known brand to leverage their scheme with new victims.

The criminal trial of ex-Refco Inc. Chief Executive Phillip R. Bennett and two other former executives has been postponed until March 2008, according to court transcripts.

During a telephone conference last month, U.S. District Judge Naomi Reice Buchwald delayed the trial of Bennett; Robert C. Trosten, Refco's ex-chief financial officer; and Tone N. Grant, the commodities broker's former president, until March 17. A transcript of the call was released publicly earlier this week.

The case was originally scheduled to go to trial in October.

The men are facing a variety of charges including conspiracy, securities fraud, bank fraud, wire fraud and money laundering.

Late Wednesday, the litigation trusts representing Refco's creditors announced they had sued Thomas H. Lee Partners LP in federal court in Manhattan, alleging the buyout firm uncovered red flags about Refco and its executives before the buyout firm's 2004 purchase of a controlling stake in Refco, but failed to follow up in hopes of profiting from Refco's initial public offering the next year. Lee has denied the claims.


13 August 2007

ESI: Authenticity of Evidence...

Legal opinions on the admissibility of evidence and electronically stored information (ESI) are becoming more prevalent and increasingly relevant to Operational Risk Management:

In Lorraine v. Markel, authentication of information is a key issue in the ruling. Maryland Courts Watcher caught this ruling and our eye recently. "In its 101 page opinion, the court dedicated at least 90 pages to providing extensive and detailed analysis and guidance on the interrelated evidentiary issues governing the admissibility of electronically stored evidence (ESI), including: analysis under Rule 104, relevance under Rule 401, authentication as required by Rule 901(a), effect of hearsay as defined by Rule 801 and any applicable exceptions, consideration of the form of the ESI being offered under the original writing rule and the admissibility of any secondary evidence to prove its content, and the probative value of the ESI considering potential unfair prejudice or one of the other factors identified by Rule 403."

Whether ESI is admissible into evidence is determined by a collection of evidence rules that present themselves like a series of hurdles to be cleared by the proponent of the evidence. Failure to clear any of these evidentiary hurdles means that the evidence will not be admissible. Whenever ESI is offered as evidence, either at trial or in summary judgment, the following evidence rules must be considered: (1) is the ESI relevant as determined by Rule 401 (does it have any tendency to make some fact that is of consequence to the litigation more or less probable than it otherwise would be); (2) if relevant under 401, is it authentic as required by Rule 901(a) (can the proponent show that the ESI is what it purports to be); (3) if the ESI is offered for its substantive truth, is it hearsay as defined by Rule 801, and if so, is it covered by an applicable exception (Rules 803, 804 and 807); (4) is the form of the ESI that is being offered as evidence an original or duplicate under the original writing rule, of if not, is there admissible secondary evidence to prove the content of the ESI (Rules 1001-1008); and (5) is the probative value of the ESI substantially outweighed by the danger of unfair prejudice or one of the other factors identified by Rule 403, such that it should be excluded despite its relevance.

Authenticity and the chain of custody of ESI will continue to be a major challenge for the general counsels of major corporations in the years ahead. Creating and maintaining trusted information through out the enterprise intersects policy, processes, people and technology. The legal risk associated with non-compliance and missed opportunities is a growing concern in executive management and Board of Directors meetings.

The explosion of information as early as 2001 started a process of discussions on the nexus of information security regarding data integrity and authenticity:

With the explosive growth of data exchange and the availability of access to services over the Web, the Trusted Information requirement is more and more an issue to providers and users of these services. Addressing this security issue, this volume is divided into eleven parts covering the essentials of information security technologies, including application-related topics, and issues relating to application development and deployment:

  • Security Protocols;
  • Smart Card;
  • Network Security and Intrusion Detection;
  • Trusted Platforms;
  • eSociety;
  • TTP Management and PKI;
  • Secure Workflow Environment;
  • Secure Group Communications;
  • Risk Management;
  • Security Policies;
  • Trusted System Design and Management.

Companies like IBM have been talking to clients about trusting their information for decades. However, when the discussions turn to litigation and admitting information stored on hard disks, dvd's, USB Thumb Drives and the data on your VOIP phone system it all starts to become more complex than one could ever imagine. That complexity and the speed that courts are asking for responsive answers puts your legal risk in the center of the discussion.

Achieving a Defensible Standard of Care requires more than a savvy outside counsel. It demands an effective CIO, CSO and Records Manager working in combination with the hundreds of law firms you may have retained to address your ongoing litigation.

22 July 2007

Show Me The Money: Complacency Risk...

The last time we checked, CFO's were still doing battle with CxO's about their budget and the growing magnitude of Operational Risks as a result of too little funding. Learning how to count differently is a consistent conversation within the ranks of corporate enterprises today. How do I address the needs of the employee, the regulators and management for software systems and safety solutions that require continuous change with this budget?
"Champions for new investments in Enterprise Content Management (ECM) solutions must make convincing arguments for change. Among many hurdles, the champion must express a business case for an ECM solution. That business case must present an economic analysis of the "before" and "after" financial impact. It must deliver measurable financial return on investment (ROI). The bottom line that is always asked is "show me the money".

Enterprise Content Management is the technologies used to Capture, Manage, Store, Preserve, and Deliver content and documents related to organizational processes.

The business case for any new investment requires an analysis of what the existing business issue or problem is and what the benefits are, making this new investment. Counting differently than in the past may require looking beyond the typical methods for creating this so called "Show me the money" step for executive management. Can ECM provide the solution to more than one of the problems in the enterprise with managing information and getting answers faster and more accurately than ever before? If it can, then this could be a path to designing a risk management architecture that provides a myriad of capabilities across a spectrum of potential vulnerabilities.

The most important job is to keep in-house information under control. The questions add up: where to put the thousands and thousands of e-mails, what to do with the electronically signed business correspondence, where to put taxation-relevant data, how to transfer information from the disorganized file system, how to consolidate information in a repository that everybody can use, how to get a single login for all the systems, how to create a uniform in-basket for all incoming information, how to make sure that no information is lost or ignored, etc. etc. Document technologies play an important role in all these questions. ECM solutions are necessary basic components for many applications. Every potential user will naturally consider his own individual needs before deciding on a system. However, putting off decisions does not make them less necessary. Every year something supposedly better and easier to use will come along, but waiting will just mean never installing anything. Every time the decision is put off, the mountain of uncontrolled and unused information gets bigger, and known problems get larger. A sensible long-term migration strategy removes the fear of fast technology change.

Complacency is a threat that many do not think about. What is the cost of complacency in delaying decisions to invest? Whether it be that latest hot stock, buying new enterprise software or the maintenance on the critical infrastructure supporting your operations, timing is everything. At some point, a decision has to be made and you are never going to have enough data to totally justify an investment one way or another. You must find the courage to do something, before complacency makes the decision for you:

One person has been killed and at least 20 others injured when a steam pipe exploded underneath a street in central New York during the evening rush hour.

The explosion in midtown Manhattan sent clouds of steam, mud and rocks into the air and forced the evacuation of nearby streets and Grand Central Station.

The New York Police Department said the incident was not terrorism-related.

Millions of pounds of steam are pumped beneath the streets of New York to help heat and cool thousands of buildings.

The 83-year-old pipe exploded just before 1800 (2200 GMT), sending people running from the scene as steam billowed up from the ground.

New York Mayor Michael Bloomberg later ruled out the possibility of a terrorist attack.

"There is no reason to believe whatsoever that this is anything other than a failure of our infrastructure," he told a news conference.

"The big fear that we have is whether there may or may not have been asbestos released."

Maintaining, upgrading and investing in your IT software systems is no different than looking after your power generation pipelines or critical infrastructure conduits along right of ways. Lack of robust Software Quality Assurance and the complacency for justification of new systems may not result in human fatalities such as the explosion in NYC. Unless of course the information you desire can't be found or can't be accessed when you need it.

Connecting the Dots and Show Me The Money are what complacency risk is all about.

17 July 2007

4GW: Trusted Information Class Actions...

The SEC is in the middle of a Supreme Court battle and they have called in the "A" team to assist. Former SEC officials William H. Donaldson, Arthur Levitt and Harvey J. Goldschmid want to expand investors' abilities to sue in frauds:

The big-money issue has mobilized lawyers who bring class-action lawsuits and the companies and executives they target in one of the most important securities-law issues to reach the Supreme Court in years.

In cases in which fraud-ridden corporations have filed for Chapter 11 bankruptcy protection, investors may not be able to wrest money from the company itself. Lawsuits against business partners and advisers such as accountants and lawyers may present the only rich and viable option for shareholders and plaintiff lawyers, experts said.

What have we learned since Enron? Do we not have a more ethics based atmosphere at the professional services firms? In the long run, will investors be better off with the ability to sue the advisors of the companies as accomplices to wrong doing? You can bet that if the US Chamber of Commerce has it's way, the SEC is in for a real fight on this one.

Some people are behind bars. Some companies are out of business. And the Dow is again at an all time high nearing the 14,000 threshold. All of the legislation, class actions and fraud allegations are all about one thing. Information. Trusted Information.

A number of trends focused on corporate data continue to distract today's IT departments. Shareholders are clamoring for more transparency as a result of the financial scandals that have shaken confidence in corporate governance around the world. Compliance legislation such as the U.S. Sarbanes-Oxley Act (whose impact is reaching far beyond the U.S.) can result in jail sentences for executives who - even unintentionally - report erroneous information. New privacy laws around the world restrict the use of customer information. Increasing global competition has put pressure on organizations to use their expensive information assets more strategically.

All these issues can be summed up in a single concept: trusted information. Simply accessing data is no longer enough. Today's CEOs, CFOs and knowledge-workers must be able to reliably track the information they use for decisions back to the original source systems in order to ensure its timeliness, accuracy and credibility.

Over the last decade, organizations have invested millions of dollars in systems to collect, store and distribute information more effectively. Despite this, information users at all levels of the organization are often uncomfortable with the quality, reliability and transparency of the information they receive.

Today's organizations rarely have a "single view of the truth." Executives waste time in meetings debating whose figures are correct, rather than what to do about the company's issues. Additionally, they worry about the consequences of making strategic decisions using the wrong information, directly impacting the long-term survival of the organization.

This brief essay by Jeffrey Ritter discusses the compelling forces converging at the beginning of the 21st century that are shaping the need to consider trusted information as a vital asset that should be the priority of any organization:

As the 21st century accelerates, digital devices connected to the Net will continue to be indispensable to modern life. But those devices, and the services provided through them, remain vulnerable to human judgment—the 21st century winners will be those who earn and sustain the trust of those using the devices and the services—whether those are consumers, employees, shareholders, lenders or service providers.

When the law intersects with the validity of information the corporate battle lines are drawn. Think about how much time and dollars are spent proving or disproving the integrity of information in a court of law. Those organizations who know that they are in the "4th Generation Warfare" (4GW) era will survive only if they can grasp this concept. Fourth Generation Warfare removes the front entirely. Attackers rely on a barrage of information salvos and coordinated incidents to paralyze or erode the adversaries political will, rather than seeking decisive hand-to-hand combat. Does this sound familiar to your General Counsel?

We are not talking about Al Qaeda now. We are talking about the class action "Army" that is forming the strategy and the means to wage unconventional battles against your, trusted information. Or is it?

22 June 2007

Private Equity: Nexus of Risk...

In recent comments in the main stream security media we have heard that convergence is over. It means that the arguments are over on whether convergence is a highly debated topic, not that it is still occuring. In fact, it is speeding up with M & A activity and the private equity surge to buy and sell large global enterprises.

Why would a company like Blackstone Group do an MBO with a company like Intelenet Global Services? Convergence in information technology is still happening under the umbrella of Business Process Outsourcing (BPO) at a rapid pace. More layoffs and elimination of redundant data centers, call centers and customer service centers is a tremendous business. Especially when you are trying to gain control, slice up and sell companies like Sungard, Nielson and other significant investments in critical infrastructure. It's going to be a deja vu moment anytime soon. When you are operating a private equity firm with so many facets you require special people with power and to give you advice. That is why Paul O'Neil is only a phone call away from the Senior Managing Directors at BX.

What kind of Operational Risks are happening within the portfolio of private equity firms like Blackstone as they try to achieve economies of scale and convergence? The same kind that exist within any organization that is focused on convergence and divergence of information simultaneously. Centralize telecom and decentralize risk management to the business units. Centralize information processing and decentralize access through mobile devices. The list goes on.

Execution, Delivery & Process Management

Losses from failed transaction processing or process management, from relations with trade suppliers and vendors. This includes Transaction Capture, Execution & Maintenance Miscommunication, Data entry, maintenance or loading error Missed deadline or responsibility, Model / system misoperation Accounting error, entity attribution error, Delivery failure, Collateral management failure Reference data maintenance, Monitoring & Reporting Failed mandatory reporting obligation, Inaccurate external report (loss incurred), Customer Intake & Documentation Client permissions / disclaimers missed Legal documents missing / incomplete, Customer / Client Account Management Unapproved access given to accounts, Incorrect client records (loss incurred), Negligent loss or damage of client assets, Trade partners, non-client vendor misperformance and vendor disputes.

Business Process Outsourcing (BPO) and Business Process Management (BPM) are being hailed as the answer to mitigating much of the operational risk exposures. It is also about creating new found synergies and elimination of redundant systems in order to drive greater return on investment. Yet all of the enterprise architecture, IT reengineering and Six Sigma / Lean will not change the current and impending threat to our interdependent Internet Protocol (IP) linked economy.

John Schwarz from the New York Times highlights the reality of the possibility of an Internet Armageddon. "ANYONE who follows technology or military affairs has heard the predictions for more than a decade. Cyberwar is coming. Although the long-announced, long-awaited computer-based conflict has yet to occur, the forecast grows more ominous with every telling: an onslaught is brought by a warring nation, backed by its brains and computing resources; banks and other businesses in the enemy states are destroyed; governments grind to a halt; telephones disconnect; the microchip-controlled Tickle Me Elmos will be transformed into unstoppable killing machines."

Private sector companies that are owned or controlled by large private equity and alternative investment hedge funds may be even more at risk and the target of both nation state (China) and non-state actors (Al-Qaeda in Europe). Getting access to the information on the future plans, strategy and architecture of protecting critical infrastructure companies is a priority by those who wish to wage a simultaneous salvo of both digital and physical attacks.

A major hurdle that nations face in defending their critical infrastructures is working with the entities that actually own their countries' telecommunications networks, electrical grids, and transportation systems. This is a major issue in the United States, given that the private sector owns more than 85% of the critical infrastructure and doesn't take kindly to government demands that shareholder money be invested in protection rather than expansion.

Cooperation between government and private-sector critical infrastructure owners is essential. "When it comes to information warfare, corporations in general are no match for a trained [enemy] intelligence officer," David Drab, a 27-year veteran of the FBI who retired in 2002 and is now principal for information content security with Xerox Global Services, said in an interview. These officers have an objective, they have resources, and often they have the element of surprise on their side, he added.

Acceleration of private equity investments puts control of managing the vital lifeblood of information into the hands of Senior Managing Directors, CIO's and Project Managers at the BPO third parties. The nexus of thinking from these participants is to do what ever it takes to converge operations and eliminate redundancy. One can only hope that they are becoming together to discuss the same topics as other large financial institutions. The East Coast Buildings Plot is just one example of why this is imperative.

In publicly released statements, bin Laden has also stressed his “policy” of “bleeding America to the point of bankruptcy.” And an excerpt from the Al Qaeda publication Sawt al-Jihad states:

“If the enemy has used his economy to rule the world and hire collaborators, then we need to strike this economy with harsh attacks to bring it down on the heads of its owners. If the enemy has built his economy on the basis of open markets and free trade by getting the monies of investors, then we have to prove to these investors that the enemy's land is not safe for them, that his economy is not capable of guarding their monies, so they would abandon him to suffer alone the fall of his economy.”


19 June 2007

FACTA: The Writing is on the Wall...

Now that the financial community is wiping their brow with a sigh of relief on this latest Supreme Court ruling, what can a General Counsel or Chief Risk Officer expect? Will the adversarial train of plaintiff suits slow down and come to a halt. Not likely.

The U.S. Supreme Court's ruling that blocks investors from suing Wall Street investment banks under antitrust laws could save Wall Street firms a bundle by limiting investors to smaller recoveries.

In a case dating back to the dot-com bubble, the high court ruled Monday that antitrust suits would pose a "substantial risk" to the securities market. Damages in antitrust cases are tripled, in contrast to penalties under the securities laws.

The ruling struck down a lower court decision that would have allowed investors to go after Wall Street firms that they say engaged in anticompetitive practices by conspiring to drive up prices on about 900 newly issued stocks in the late 1990s.

Because the well-documented implosion of names like Enron Corp. swallowed any serious money that investors might hope to recover from that and other flame-outs, some investors have turned to the banks and other Wall Street regulars such as accounting firms that did work for such companies.

Wall Street institutions in the case before the Supreme Court were Credit Suisse Securities (USA) LLC, formerly Credit Suisse First Boston LLC; Bear, Stearns & Co. Inc.; Citigroup Global Markets Inc.; Comerica Inc.; Deutsche Bank Securities Inc.; Fidelity Distributors Corp.; Fidelity Brokerage Services LLC; Fidelity Investments Institutional Services Co. Inc.; Goldman, Sachs & Co.; The Goldman Sachs Group Inc.; Janus Capital Management LLC; Lehman Brothers Inc.; Merrill Lynch, Pierce, Fenner & Smith Inc.; Morgan Stanley & Co. Inc.; Robertson Stephens Inc.; Van Wagoner Capital Management Inc.; and Van Wagoner Funds, Inc.

These institutions may not have "Anti-Trust" anxiety from the Supreme Court any longer yet there are plenty of other Operational Risks on their minds. Namely International Fraud.

In an era of data warehousing, metadata management, business process management and the looming BASEL II Accord there are plenty of conversations about what to do about fraud and other regulatory compliance. Multi-factor authentication for online banking systems is not a trivial matter when it comes to Enterprise Risk Management. Is the customer service organization ready for the upgrade? Is the consumer going to be confused on what questions they are being asked to get access to their latest online credit card statement? What is my customer "churn" factor? In other words, how many of my customers are jumping ship as a result of the operational risks that have turned their loyalty into consumer driven class action fraud litigation?

An International Banking Fusion Center is on the horizon and it's not too far from the same justification that addresses Know Your Customer (KYC) and the financing of terrorism.

According to one study respondent, "Organizations are secretive of fraud losses and that inhibits our ability to work together."

"The sharing of intelligence is key to being able to take advantage of the predictability of fraud," First Data's Barwell continues. "Banks are sitting on valuable data that, if analyzed innovatively, could provide fraud intelligence worth sharing. One major bank has shown that if their internal client databases across business lines and geographies are analyzed using sophisticated link analysis tools, spurious networks of accounts can be uncovered and, when fully investigated, could uncover organized networks of first-party fraud accounts."

Barwell adds that several U.S. banks have expressed interest in taking the "quantum leap" to true data sharing.

The International Language of Fraud

"In the last eight to 10 years, fraud has really gone international," says Steve Baker, director of the Midwest region of the Federal Trade Commission (FTC). The FTC maintains a Consumer Sentinel database that includes more than 3.5 million consumer fraud complaints and is accessible to more than 3,000 law enforcement agencies internationally. In 2006, 22 percent of the reported fraud was cross border.

So What? What does information sharing have in common with:

International fraud, Identity Theft and the risk of litigation within the banking or credit card industry. Now the bankers want to sue the retailers and recover losses for the lack of privacy and security controls at the retailers. Since December 2006, plaintiffs’ class action firms in California and elsewhere have filed over 200 nationwide class actions in federal court against a broad spectrum of retailers and restaurants alleging violations of the Fair and Accurate Credit Transactions Act ("FACTA"). In addition to California federal courts, FACTA cases have been filed recently in federal courts in Pennsylvania, Illinois, New Jersey, Nevada, Maryland and Kansas.

13 June 2007

ID Theft: The Innocent Insider...

If you were a betting person you might think that the threat of 1 Million Botnets is a greater Operational Risk than a "lone wolf insider". What is the likelihood that one person will impact your business and disrupt your operations vs. the power of thousands of rogue computers unleashing a salvo of malicious code or denial of service attacks on your institution?

A botnet is a collection of compromised computers under the remote command and control of a criminal “botherder.” Most owners of the compromised computers are unknowing and unwitting victims. They have unintentionally allowed unauthorized access and use of their computers as a vehicle to facilitate other crimes, such as identity theft, denial of service attacks, phishing, click fraud, and the mass distribution of spam and spyware. Because of their widely distributed capabilities, botnets are a growing threat to national security, the national information infrastructure, and the economy.

“The majority of victims are not even aware that their computer has been compromised or their personal information exploited,” said FBI Assistant Director for the Cyber Division James Finch. “An attacker gains control by infecting the computer with a virus or other malicious code and the computer continues to operate normally. Citizens can protect themselves from botnets and the associated schemes by practicing strong computer security habits to reduce the risk that your computer will be compromised.”

Yet there are individuals within your own organization who lie in wait, innocently. For the right timing and the right vulnerability to be exploited. They have been unknowingly planning and operating under cover for years and are masters at evading detection. In the Executive Suite, the "Bot" may operate in the background or under the radar of management audits and risk management control mechanisms. So how do you catch them or at least detect their presence? Send everyone on vacation.

When was the last time you had the fraud investigators training the internal auditors? When did you last utilize a "True" Independent outside advisor, investigator or consultant to assist your CISO in early detection. If you have 10,000 employees, 99.x% of these employees are hard working and honest people without any hidden agenda to bring harm to the organization or individuals inside the company. However, not all who would bring harm to you are stealing money or other physical assets from the warehouse. We aren't talking about a few items from the office supplies closet or a case of beer from the 7-11.

We are talking about the one employee who is operating a "Botnet" from behind the walls of your Fortune 50 company. Do you have anyone sharing pictures or music in the executive suite? Without you detecting it.

We define peer-to-peer, bot, and botnet below.

  • peer-to-peer - A peer-to-peer network is a network in which any node in the network can act as both a client and a server.
  • bot - A bot is a program that performs user centric tasks automatically without any interaction from a user.
  • botnet - A botnet is a network of malicious bots that illegally control computing resources.

Some definitions of peer-to-peer networks require no form of centralized coordination. Our definition is more relaxed because the attacker may be interested in hybrid architectures. Our definition of a bot is not inherently malicious. However, the malicious nature of a bot is implicit under some contexts. Finally, we do define a botnet to be malicious in nature.

The case study of the Trojan.Peacomm bot demonstrates one implementation of peer-to-peer functionality used by a botnet. That "Lone Wolf" in your organization could be your innocent administrative secretary and they don't even know it.

10 June 2007

The New New Math: Corporate Responsibility...

The "New New Math" (N2M) is the evolution of economics and return on investment in the modern day organization. Is it a hybrid equation of a previously published and patented algorithm? An upside down or inside out way of justification for new resources or or just new emphasis on the latest shareholder suit. The N2M is something all too often found in the most successful corporations across the globe and it's starting to see the light of day as a result of increasing Operational Risks.

Another way of looking at and understanding the "New New Math" for investment can be found in the roots of what some would say is just good old fashioned Corporate Social Responsibility (CSR):

Corporate Social Responsibility (CSR) is a concept that organizations, especially (but not only) corporations, have an obligation to consider the interests of customers, employees, shareholders, communities, and ecological considerations in all aspects of their operations. This obligation is seen to extend beyond their statutory obligation to comply with legislation.

CSR is closely linked with the principles of Sustainable Development, which argues that enterprises should make decisions based not only on financial factors such as profits or dividends, but also based on the immediate and long-term social and environmental consequences of their activities.


So the N2M on Return on Investment is now being considered across the enterprise and the Board of Directors meetings. ROI discussions are shifting away from the typical GAAP dialogue and more directed at whether new strategic initiatives are "The Right Thing To Do." When you have executives nodding their heads in the meeting about making positive decisions to invest millions of dollars in corporate initiatives based upon it's "The Right Thing To Do" justification, you are experiencing the "New New Math" (N2M)

Making strategic decisions on CSR and N2M is quickly becoming the emotional reasoning and rationale for many corporate enterprise investments. Measuring the ROI doesn't always come in a percentage of dollars invested or a normal way of thinking about getting a return. Many times the executives who champion these initiatives have an underlying reason for doing so that reaches into their personal lives. So when you invest in more robust security for the company or significant programs to increase the protection for key employees, that ultimate driver could be as simple as losing a fellow colleague to kidnapping or the latest law suit.

How your organization is perceived internationally may dictate the degree of risk for your traveling executives. The attack on an employee may be an attack on your "Brand" and what the general public believes that you stand for, in the "minds eye" of the media blur.

Why us?
Where businesses are the target of terrorism, it is usually because of what they represent, rather than anything they do or don’t do themselves. Global brands can assume symbolic significance for terrorists. The US National Counterterrorism Center’s list of significant terrorist events describes 24 attacks on McDonald’s restaurants between 1993 and 2005 worldwide.

Of the minority where responsibility was claimed, motivation for the attacks included nationalism, anti-globalisation, religion and Marxism – but in each case the perpetrators objected to the restaurant as a symbol of America, not a purveyor of products. Mr Jenkins notes that, before 9/11, the two best correlated predictors of whether a US firm would suffer an attack were size and familiarity to the public – corporate behaviour, even philanthropy, was inconsequential. Added to this is the very real possibility of risk displacement: business targets are often easier to hit than government facilities or sites.

Attacks on your organziation or employees don't always have to take a violent twist. Many times these are orchestrated under the cloak of a "personal scandal" or even the filing of a civil Intellectual Property litigation. Legal Risk is a consistent threat to the enterprise and is far often the most effective way of bringing down the house in terms of putting a cloud of uncertainty and speculation about a company that may be in, a competitors "cross hairs."

A week after the public learned of Qualcomm Inc.'s bombshell admission that it withheld potentially thousands of important documents in a high-stakes patent trial against Broadcom Corp., many in the intellectual property community are still buzzing about the gaffe.

The case is even more striking because the attorney who has publicly apologized for Qualcomm's error has a strong reputation in his field, as does his firm. Yet several attorneys say it's still too early to assign blame for the error.

"Whenever there are accusations of concealment of evidence and they prove to be true, there definitely is going to be harm to the lawyers and the parties," said Anup Tikku, an IP associate with Kirkpatrick & Lockhart Preston Gates Ellis, who has followed the case closely. "What I find difficult to understand is how Qualcomm interviewed witnesses, put them on the stand and did not realize these documents existed."

Corporate Social Responsibility extends to Enterprise Litigation Governance and goes well beyond just understanding electronically stored information (ESI). The "New New Math" on doing the right thing in preparation for legal risk are taking on new dimensions as the implications of judgements in favor of the plaintiff set new legal precedence and case law. The Board of Directors and executive management are getting the message that protecting their employees from violence and politically motivated terrorism is just as imperative as preparation for adversarial law suits.

When you hire a defense firm and they get blindsided about eDiscovery or Enterprise Content Management (ECM) and your own Records Management and IT personnel are scratching their heads, your "Brand" is going to take hit. The operational risks associated with a lack of preparedness and a limited strategy for preemptive action calls for the "New New Math." It's coming to a board room near you and when it does, don't be surprised that the investment decisions are based more on emotion than on your controllers 27 pages of hard numbers.

28 May 2007

Memorial Day: The Courage to Serve...

Today is Memorial Day in the United States and Spencer is on his way to Airborne "Jump School" in Ft. Benning, GA as a proud member of the US Army. He gave up going to a nice University of California campus and a few years of fraternity fun to serve his country and took a risk by joining a life long fraternity of men and women who have defended our country. Simultaneously Keith is risking his life serving the US again for the "nth" time in Afghanistan as US Army Lt. Col. (Ret) on another important and vital mission. He gave up a hunting, fishing and teaching lifestyle to help secure certain important real estate utilizing his diplomatic and training skills learned from decades of real-time experience in South East Asia with the Central Intelligence Agency.

Having spent some time with both of these brave and courageous men makes you wonder what they both have in common. What are the attributes of a person who makes a selfless sacrifice to protect and to serve? Whether it's in the military or in public safety, there is something that is in their DNA and not yours. It's something that many of us think about and end up not doing anything about it. When you fill up your gas tank this week or stroll down the outdoor mall you might ask yourself who made all of this possible? The answer is those who have served and those who are serving right now.

Millions across the country will pause Monday afternoon to honor the sacrifices of the American military in observance of the National Moment of Remembrance.

Crowds at Major League baseball stadiums, NASCAR tracks, train stations, malls, stores and even the astronauts aboard the International Space Station will participate in the “National Moment of Remembrance,” which is observed at 3 p.m. every Memorial Day.

"The national Moment of Remembrance is a time for Americans to contemplate those things that bind us together by remembering the legacy of those who died to better our country," Carmella LaSpada, executive director of the White House Commission on Remembrance, said.

"We encourage all Americans, no matter where they are and what they are doing, at 3 p.m. local time on Memorial Day, to stop and give thanks."

The observance is an initiative of the White House Commission on Remembrance, which Congress established in 2000.

The commission encourages Americans to remember the sacrifices of fallen troops and the families they left behind.

So when you return to work tomorrow after your Memorial Day holiday, hopefully you will have had a chance to say a prayer or to at least acknowledge those brave individuals. And it's also a time to evaluate your own work ethic or duty serving as leader of your organization. Are you putting your employees in harms way? What steps or measures are you taking to make sure that they are training and preparing to mitigate operational risks on a daily basis. To have the courage to do the right thing and to keep the organization out of jeopardy. Beware of the cowboy.

From Leadership Lessons of the Navy SEALS


The Cowboy

Neither of us knows if such a thing has ever been tolerated in modern commando teams. Yes, sometimes you need to charge forward. But, there are simply too many potential casualties and too much political currency resting on commando missions to entrust one to a cowboy. Authorization for an operation depends on the accurate calculation of operational risk. This requires an assessment of proven forces ability to perform a task. All this is contrary to the cowboy philosophy of depending on experimentation, pluck, and luck in order to succeed.

"The problem with being a cowboy is that your bosses won't employ you if they can't trust you, and they can't trust you if they don't know what you'll do. And then you're stuck with the reputation." --LT. CMDR. Jon Cannon


Believe it when he says that people who try to be cowboys in your organization are operating without regard to risk. Now multiply the number of cowboys by the number of people that they surround on their team who think that this is the way to operate. It doesn't take long to find out that these are the root causes of many of the operational risks in your organization. And it starts out with the basics:

> Revenue is not booked according to the rules. Products sit in the warehouse yet revenue ends up on the sales reps commission report because (s)he had a signed order.

> Assets are not valued correctly. Bank accounts are not validated to make sure they actually exist and accounts receivables are inflated.
These are just two of the many facets of fraud that starts with a few cowboys who have little regard for managing risk and all the incentives to line their pockets with new found cash or bonuses.

You might think that the reason is greed. However, the real motive may not be so clear. More than likely, the motive is fear. And that fear is something that grows until it gets to the point of creating harm, loss and destruction. You have to find the cowboys in your organization and you have to follow the mantra of quality gurus from years past, "Drive out Fear".