1
00:00:00,450 --> 00:00:02,009
Compliance.

2
00:00:02,009 --> 00:00:05,040
Compliance is the critical aspect of any organization

3
00:00:05,040 --> 00:00:07,800
ensuring adherence to laws, regulations,

4
00:00:07,800 --> 00:00:09,960
guidelines and specifications

5
00:00:09,960 --> 00:00:12,180
relevant to its business processes.

6
00:00:12,180 --> 00:00:15,390
It is a broad field that encompasses various components

7
00:00:15,390 --> 00:00:18,630
including compliance reporting, and compliance monitoring.

8
00:00:18,630 --> 00:00:21,240
In this lesson, we are going to dive into these aspects,

9
00:00:21,240 --> 00:00:23,430
providing examples and discussing the role

10
00:00:23,430 --> 00:00:25,740
of automation and compliance.

11
00:00:25,740 --> 00:00:28,020
First, compliance reporting.

12
00:00:28,020 --> 00:00:31,350
Compliance reporting is a systematic process of collecting

13
00:00:31,350 --> 00:00:33,780
and presenting data to demonstrate adherence

14
00:00:33,780 --> 00:00:35,580
to compliance requirements,

15
00:00:35,580 --> 00:00:37,770
can be categorized into two types -

16
00:00:37,770 --> 00:00:40,860
internal and external compliance reporting.

17
00:00:40,860 --> 00:00:43,470
Now, internal compliance reporting involves the collection

18
00:00:43,470 --> 00:00:44,820
and analysis of data

19
00:00:44,820 --> 00:00:46,980
to ensure that an organization is following

20
00:00:46,980 --> 00:00:49,470
its internal policies and procedures.

21
00:00:49,470 --> 00:00:52,320
It is typically conducted by an internal audit team

22
00:00:52,320 --> 00:00:54,180
or a compliance department.

23
00:00:54,180 --> 00:00:56,850
For example, a financial institution may have

24
00:00:56,850 --> 00:00:59,640
an internal policy that requires all transactions

25
00:00:59,640 --> 00:01:01,950
above a certain threshold to be reviewed

26
00:01:01,950 --> 00:01:04,410
and approved by a compliance officer.

27
00:01:04,410 --> 00:01:06,600
The compliance department will then have

28
00:01:06,600 --> 00:01:10,110
to generate a report detailing all such transactions,

29
00:01:10,110 --> 00:01:12,720
including whether they were appropriately reviewed

30
00:01:12,720 --> 00:01:14,520
and approved.

31
00:01:14,520 --> 00:01:17,580
Next, external compliance reporting.

32
00:01:17,580 --> 00:01:19,680
External compliance reporting on the other hand

33
00:01:19,680 --> 00:01:22,770
involves demonstrating compliance to external entities

34
00:01:22,770 --> 00:01:26,400
such as regulatory bodies, auditors, or customers.

35
00:01:26,400 --> 00:01:30,480
This type of reporting is often mandated by law or contract.

36
00:01:30,480 --> 00:01:32,490
For instance, pharmaceutical company

37
00:01:32,490 --> 00:01:34,200
must submit regular reports

38
00:01:34,200 --> 00:01:37,290
to the Food and Drug Administration, or the FDA

39
00:01:37,290 --> 00:01:40,440
detailing their adherence to good manufacturing practices

40
00:01:40,440 --> 00:01:41,700
or GMP.

41
00:01:41,700 --> 00:01:44,340
These reports include data on product quality,

42
00:01:44,340 --> 00:01:47,460
safety measures, and process controls.

43
00:01:47,460 --> 00:01:49,590
Now onto compliance monitoring.

44
00:01:49,590 --> 00:01:53,880
Compliance monitoring - the process regularly reviewing

45
00:01:53,880 --> 00:01:57,180
and analyzing an organization's operations

46
00:01:57,180 --> 00:01:59,940
to ensure compliance with laws, regulations,

47
00:01:59,940 --> 00:02:01,680
and internal policies.

48
00:02:01,680 --> 00:02:05,250
It involves several key components, including due diligence

49
00:02:05,250 --> 00:02:08,070
and due care, attestation and acknowledgement

50
00:02:08,070 --> 00:02:11,039
and internal and external monitoring.

51
00:02:11,039 --> 00:02:13,410
Due diligence and due care.

52
00:02:13,410 --> 00:02:15,330
Due diligence in compliance monitoring

53
00:02:15,330 --> 00:02:17,730
involves conducting an exhaustive review

54
00:02:17,730 --> 00:02:19,500
of an organization's operation

55
00:02:19,500 --> 00:02:22,530
to identify potential compliance risks.

56
00:02:22,530 --> 00:02:25,560
Due care on the other hand refers to the steps taken

57
00:02:25,560 --> 00:02:27,390
to mitigate these risks.

58
00:02:27,390 --> 00:02:29,100
For example, a company planning

59
00:02:29,100 --> 00:02:32,610
to expand its operation overseas would conduct due diligence

60
00:02:32,610 --> 00:02:35,610
by researching the foreign country's business laws

61
00:02:35,610 --> 00:02:37,020
and regulations.

62
00:02:37,020 --> 00:02:40,710
They would then exercise due care by implementing measures

63
00:02:40,710 --> 00:02:42,930
to ensure compliance with these laws,

64
00:02:42,930 --> 00:02:45,600
such as training employees on the new regulations

65
00:02:45,600 --> 00:02:48,630
or hiring a local legal advisor.

66
00:02:48,630 --> 00:02:51,720
Next, attestation and acknowledgement.

67
00:02:51,720 --> 00:02:53,640
Attestation in compliance monitoring

68
00:02:53,640 --> 00:02:57,030
involves a formal declaration by responsible party

69
00:02:57,030 --> 00:02:58,800
that the organization's processes

70
00:02:58,800 --> 00:03:00,690
and controls are compliant.

71
00:03:00,690 --> 00:03:03,990
Acknowledgement refers to the recognition and acceptance

72
00:03:03,990 --> 00:03:07,740
these compliance requirements by all relevant parties.

73
00:03:07,740 --> 00:03:10,290
For instance, IT company might require

74
00:03:10,290 --> 00:03:13,740
its software developers to attest that they have followed

75
00:03:13,740 --> 00:03:16,200
all necessary data security protocols

76
00:03:16,200 --> 00:03:18,210
when creating a new applications.

77
00:03:18,210 --> 00:03:20,940
The developers would also acknowledge these protocols

78
00:03:20,940 --> 00:03:23,910
by signing a compliance agreement.

79
00:03:23,910 --> 00:03:26,970
Finally, internal and external monitoring.

80
00:03:26,970 --> 00:03:29,610
Internal monitoring involves regularly reviewing

81
00:03:29,610 --> 00:03:32,820
an organization's operations to ensure compliance

82
00:03:32,820 --> 00:03:35,700
with internal policies and procedures.

83
00:03:35,700 --> 00:03:39,390
External monitoring conversely involves third party reviews

84
00:03:39,390 --> 00:03:41,550
or audits to verify compliance

85
00:03:41,550 --> 00:03:44,280
with external regulations or standards.

86
00:03:44,280 --> 00:03:46,560
For example, manufacturing company

87
00:03:46,560 --> 00:03:48,150
might conduct internal monitoring

88
00:03:48,150 --> 00:03:50,820
by regularly reviewing the production processes

89
00:03:50,820 --> 00:03:54,120
to ensure that they meet internal quality standards.

90
00:03:54,120 --> 00:03:57,180
The company might also undergo external monitoring

91
00:03:57,180 --> 00:03:59,820
by a third party auditor to verify compliance

92
00:03:59,820 --> 00:04:04,050
with ISO 9001 quality management standards.

93
00:04:04,050 --> 00:04:07,440
Next up, the role of automation in compliance.

94
00:04:07,440 --> 00:04:09,900
Automation is increasingly playing crucial role

95
00:04:09,900 --> 00:04:11,100
in compliance.

96
00:04:11,100 --> 00:04:14,520
Automated compliance systems can streamline data collection,

97
00:04:14,520 --> 00:04:18,600
prove accuracy, and provide real-time compliance monitoring.

98
00:04:18,600 --> 00:04:20,610
For instance, a healthcare provider

99
00:04:20,610 --> 00:04:22,320
might use an automated system

100
00:04:22,320 --> 00:04:24,960
to monitor patient data privacy compliance.

101
00:04:24,960 --> 00:04:28,230
The system could automatically flag any unauthorized access

102
00:04:28,230 --> 00:04:30,810
to patient records, enabling the provider

103
00:04:30,810 --> 00:04:32,820
to quickly identify an address

104
00:04:32,820 --> 00:04:35,070
any potential HIPAA violations.

105
00:04:35,070 --> 00:04:37,830
Similarly, a bank might use an automated system

106
00:04:37,830 --> 00:04:39,120
to monitor transactions

107
00:04:39,120 --> 00:04:41,520
for potential money laundering activities.

108
00:04:41,520 --> 00:04:44,610
The system could automatically generate reports

109
00:04:44,610 --> 00:04:47,010
detailing any suspicious transactions,

110
00:04:47,010 --> 00:04:50,790
simplifying the bank's compliance reporting process.

111
00:04:50,790 --> 00:04:53,160
So remember, compliance is a critical aspect

112
00:04:53,160 --> 00:04:55,200
of any organization's operations,

113
00:04:55,200 --> 00:04:57,540
ensuring adherence to both internal policies

114
00:04:57,540 --> 00:04:59,580
and external regulations.

115
00:04:59,580 --> 00:05:02,610
Compliance reporting both internal and external

116
00:05:02,610 --> 00:05:05,700
is a key part of this, providing evidence of compliance

117
00:05:05,700 --> 00:05:09,300
to both the organization itself and external entities.

118
00:05:09,300 --> 00:05:12,714
Compliance monitoring, including due diligence and due care,

119
00:05:12,714 --> 00:05:14,430
attestation and acknowledgement,

120
00:05:14,430 --> 00:05:16,800
and internal and external monitoring

121
00:05:16,800 --> 00:05:18,750
is another crucial component

122
00:05:18,750 --> 00:05:22,560
helping to identify and mitigate compliance risks.

123
00:05:22,560 --> 00:05:26,370
Finally, automation is increasingly important in compliance,

124
00:05:26,370 --> 00:05:28,920
streamlining processes, improving accuracy

125
00:05:28,920 --> 00:05:31,650
and providing real-time monitoring capabilities.

126
00:05:31,650 --> 00:05:33,810
By understanding and effectively implementing

127
00:05:33,810 --> 00:05:37,320
these aspects of compliance, organizations can ensure

128
00:05:37,320 --> 00:05:40,140
they meet their legal and ethical obligations,

129
00:05:40,140 --> 00:05:41,640
protect the reputation

130
00:05:41,640 --> 00:05:44,463
and provide assurance to stakeholders.

