Compliance em ambientes altamente regulados | Videocast "Fala, Compliance!" - EP 6
Introduction
The episode discusses compliance in highly regulated environments. The guests for this episode are Geovane Savedra, responsible for compliance and investigations at Savedra & Gotov Advogados, and Albert Bayer, Chief Compliance Officer at WTW Corretora de Seguros.
Compliance in Regulated Markets
- Compliance in regulated markets involves implementing a compliance management system based on international best practices.
- In regulated markets, there are specific obligations and guidelines issued by regulatory bodies that dictate the duties of compliance.
- Compliance includes both objective requirements that must be fulfilled regardless of risk assessment and subjective evaluations based on the regulator's expectations.
- Examples of regulatory bodies include Banco Central, ANS, SUSEP, and CVM, each with their own specific regulations and obligations.
- Compliance in regulated markets extends beyond traditional anti-corruption measures to include considerations such as customer relationships and product offerings.
Differences between In-House and External Council Perspectives
The discussion explores the differences between working as an in-house compliance officer within a regulated market versus being an external consultant providing compliance advice.
In-House Perspective
- In-house compliance officers focus on meeting regulatory requirements and obligations set by the regulatory body.
- They prioritize not only industry best practices but also specific obligations imposed by regulators.
- In-house professionals need to constantly monitor changes in legislation to ensure ongoing compliance.
External Council Perspective
- External consultants must stay updated on relevant regulations to provide accurate advice to clients.
- They assist clients in understanding their obligations towards regulators beyond legal requirements.
- Transitioning from a non-regulated market to a regulated one requires thorough study of the applicable regulations.
Adapting to Regulatory Environments
The speakers discuss the adaptability of compliance professionals when transitioning from non-regulated to regulated markets.
- Compliance professionals possess the necessary skills to understand and navigate regulatory frameworks.
- Adapting to a regulated market requires studying regulations, understanding the specific product or industry, and familiarizing oneself with the working environment.
- Professionals with experience in both regulated and non-regulated markets can bring valuable insights to compliance roles.
Conclusion
The episode concludes by emphasizing the importance of compliance in highly regulated environments and the need for continuous learning and adaptation.
- Compliance plays a crucial role in ensuring adherence to regulations in highly regulated environments.
- Professionals must stay updated on regulatory changes and obligations specific to their industry.
- Transitioning between regulated and non-regulated markets requires thorough study and understanding of applicable regulations.
The Importance of Staying Updated
The speaker discusses the importance of staying updated and how it can prevent one from becoming outdated in their field.
Staying Current with Regulations
- It is crucial to stay updated with regulations, as they are constantly changing.
- Companies often seek external consultants who specialize in compliance to help them navigate complex regulations.
- Consultants provide a deeper understanding of regulations and can alert clients to any changes that may affect their business.
Different Risks in Different Sectors
- Each sector has its own set of risks, and without proper knowledge, one may overlook potential problems.
- For example, the healthcare industry is not regulated in the same way as the insurance industry. Understanding these differences is essential for providing accurate advice.
Shifting Compliance Frameworks
- Compliance frameworks have shifted from a checklist-based approach to a risk-based approach.
- This change requires companies to analyze risks and implement measures accordingly.
- The legislation surrounding prevention of money laundering has also undergone significant updates, leading to a more qualitative approach rather than solely focusing on quantitative requirements.
Challenges Faced by Regulated Companies
The speaker discusses the challenges faced by regulated companies and why they often require external consultants.
Complex Regulations
- Regulations are not always easy to understand or interpret, making it challenging for companies to comply on their own.
- External consultants with specialized knowledge can provide valuable insights into regulatory requirements.
Internal Management Demands
- Compliance officers have multiple responsibilities within an organization, which limits their ability to fully comprehend all aspects of compliance.
- External consultants can fill this gap by dedicating time and resources solely to compliance matters.
Specialized Expertise
- Regulatory bodies often require specific expertise in different areas such as insurance (SUSEP), banking (Bacen), or securities (CVM).
- External consulting firms have teams with specialized knowledge in these areas, ensuring comprehensive compliance support.
Identifying Risks
- Different sectors have different types of risks, and without market knowledge, it is challenging to identify potential issues.
- Consultants with industry expertise can help companies assess risks accurately and provide appropriate recommendations.
Transition to Risk-Based Approach
The speaker discusses the transition from a checklist-based approach to a risk-based approach in compliance frameworks.
Regulatory Changes
- Compliance frameworks have shifted towards a risk-based approach due to international standards set by organizations like the Financial Action Task Force (FATF).
- Brazilian regulatory bodies have adopted this approach, starting with Bacen and followed by other sectors such as insurance.
Proportional Due Diligence
- The risk level determines the extent of due diligence required for compliance.
- Companies must demonstrate that they have considered the risk level when implementing their due diligence procedures.
Legal Implications
- The shift to a risk-based approach holds companies and compliance officers legally responsible for conducting adequate due diligence.
- Failure to meet these requirements can result in legal consequences for both individuals and organizations.
Risk-Based Approach Beyond Money Laundering Prevention
The speaker explains that the risk-based approach applies not only to money laundering prevention but also to other aspects of compliance.
Comprehensive Risk Management
- The risk-based approach extends beyond money laundering prevention and applies to various compliance areas.
- Regulated entities must consider risks associated with different aspects of their operations, such as fraud or corruption.
International Standards Influence
- International organizations like FATF influence regulatory frameworks globally.
- As international standards evolve, regulated entities must adapt their compliance practices accordingly.
The Role of Compliance and Risk Management
This section discusses the importance of compliance and risk management in regulated industries, such as finance and insurance. It emphasizes the need for segregation of duties and a risk-based approach to decision-making.
Importance of Segregation of Duties
- In regulated industries, it is crucial to have separate roles for compliance and risk management.
- In unregulated sectors, one person often takes on multiple responsibilities, which can lead to inefficiencies and increased risks.
Risk-Based Approach
- A risk-based approach involves implementing methodologies that go beyond random sampling.
- It requires selecting samples based on objective criteria and justifying the selection process.
- This approach is essential for preventing issues like money laundering or corruption.
Challenges Faced by Compliance Officers
- Compliance officers are responsible for making decisions about potential risks without knowing what will happen in the future.
- It is easier to analyze situations retrospectively than when one has to make real-time decisions.
- Compliance officers must consider various regulatory requirements, including anti-money laundering measures and sanctions.
Risks in Regulated Environments
This section focuses on specific risks present in regulated environments, such as money laundering prevention and sanctions compliance. It highlights the importance of monitoring customer bases and transactions for connections with high-risk countries.
Money Laundering Prevention
- Money laundering is a significant risk in regulated sectors like insurance, healthcare, and finance.
- Regulatory bodies require specific controls to mitigate this risk effectively.
Sanctions Compliance
- Global companies with connections to countries under sanctions face additional challenges related to compliance.
- Multinational corporations need to monitor their relationships with countries like Russia, Cuba, Iran, North Korea, etc., due to potential sanctions violations.
Compliance Obligations in Regulated Industries
This section discusses how compliance obligations can vary depending on the industry and regulatory requirements. It emphasizes that while compliance is often seen as a means to promote ethical business practices, it can also be mandatory in certain cases.
Industry-Specific Compliance Requirements
- Different industries may have specific compliance obligations imposed by regulatory bodies.
- For example, the healthcare sector may require a program of integrity, while trade compliance is more common in international markets.
Mandatory Compliance
- While compliance is often associated with promoting sustainable and ethical business practices, it can also be mandatory.
- Various regulations make certain compliance measures obligatory for businesses operating in specific sectors.
Interconnectedness of Compliance Obligations
This section highlights how different compliance obligations are interconnected and build upon each other. It emphasizes the importance of having a comprehensive compliance program that covers all relevant areas.
Interconnected Compliance Obligations
- Compliance obligations are interconnected, meaning that one requirement often leads to others.
- For example, having a code of ethics may necessitate the establishment of an ethics committee and a designated compliance officer.
Comprehensive Compliance Program
- To ensure full compliance, businesses need to address all relevant areas simultaneously.
- Neglecting any aspect of compliance can result in fragmented efforts and incomplete adherence to regulations.
New Section
This section discusses the connection between governance and risk appetite in different companies and business phases. It also highlights the evolving nature of risk appetite and the regulatory environment.
Connection between Governance and Risk Appetite
- The speaker emphasizes that governance is closely related to risk appetite in companies.
- Different companies have different levels of risk appetite based on their market presence, business phase, and growth strategies.
- Risk appetite may vary depending on market conditions, with some companies adjusting their strategies during times of crisis.
- Compliance regulations play a role in defining what is allowed or prohibited, but there has been a shift from a strict compliance approach to a more nuanced evaluation of risks.
New Section
This section explores how risk appetite evolves over time and its relationship with market movements. It also discusses the impact of compliance regulations on risk management.
Evolution of Risk Appetite
- Risk appetite tends to decrease as markets mature, but new entrants can still exhibit high-risk appetites.
- Market fluctuations can influence risk appetite, leading to adjustments in company strategies.
- Compliance regulations often focus on prohibitions and permissions, resembling an old-fashioned policing approach.
- Modern risk management involves more complex evaluations with conditional permissions rather than binary decisions.
New Section
This section highlights the increasing regulatory requirements for reporting and self-declaration. It emphasizes the need for justified justifications when presenting reports to regulators.
Reporting Obligations
- Many legislations now require companies to submit annual reports that include self-declarations about various aspects such as training effectiveness or risk assessments.
- There is a shift from a police-like mentality to one focused on transparency and cooperation between regulators and companies.
- Companies should provide well-founded justifications for their reports instead of simply presenting positive outcomes.
- Merely copying and pasting previous reports without any changes is not acceptable, as regulators expect to see progress and evolution.
New Section
This section discusses the importance of demonstrating progress and evolution in reports. It also mentions the flexibility in entry requirements for regulated markets, allowing smaller companies to participate.
Demonstrating Progress in Reports
- Reports should demonstrate the evolution and improvement of risk management programs over time.
- Simply presenting a report that appears perfect without any changes or improvements will not be effective.
- Regulated markets have introduced more flexible entry requirements, allowing smaller companies to participate alongside larger ones.
- Examples include FinTech sandboxes and regulatory frameworks that enable small businesses to operate within highly regulated environments.
New Section
This section explores how holding companies with multiple licenses face compliance challenges. It highlights the need for specialized teams to manage different licenses.
Compliance Challenges for Holding Companies
- Holding companies often have multiple licenses from different regulatory bodies such as SUSEP, CVM, or BACEN.
- Each license requires dedicated compliance teams to ensure adherence to specific regulations.
- Compliance responsibilities become more complex when dealing with various licenses within a single company structure.
Partnership with Business and Compliance
The speaker discusses the changing dynamics of partnerships between businesses and compliance, highlighting the shift from a "police and thief" mentality to a more collaborative approach. Compliance by design is emphasized, along with the need for understanding the product before commercializing it.
Changing Dynamics in Business-Compliance Partnership
- In the past, there was a "police and thief" mentality regarding compliance.
- Nowadays, businesses actively seek compliance expertise to ensure regulatory adherence.
- Compliance by design is an important aspect of product development.
Importance of Understanding the Product
- It is crucial to have a deep understanding of the product before commercializing it.
- Digital platforms play a significant role in this process.
- Regulatory sandbox provides an experimental environment for innovative products.
Demonstrating Controls to Regulators
- Regulatory sandbox allows showcasing controls for new products.
- Various regulatory bodies like CVM, SUSEP, and Banco Central oversee experimentation.
- Products like credit on PIX require considerations such as cybersecurity and data sharing.
Role of Sandbox in Regulatory Experimentation
The speaker explains how regulatory sandboxes serve as environments for regulatory experimentation. They discuss the importance of demonstrating controls for innovative products and highlight specific examples like pet insurance or credit on PIX.
Regulatory Sandbox as an Experimental Environment
- Sandbox facilitates regulatory experimentation for innovative products.
- It allows companies to demonstrate their controls and risk management strategies.
Examples of Innovative Products in Sandboxes
- Pet insurance or other unique insurance offerings can be tested in sandboxes.
- Credit on PIX is another example that requires considerations like cybersecurity.
Collaboration with Regulators and Planning
The speaker emphasizes collaboration with regulators during sandbox experiments. They discuss the importance of planning, validating screens, and ensuring system integrity. Overlapping regulations and the objective of making compliance more challenging are also mentioned.
Collaboration with Regulators in Sandbox Experiments
- The website of regulatory bodies like BACEN and CVM provides information on sandboxes.
- Collaborative meetings with regulators help validate screens and identify potential flaws.
Overlapping Regulations and Making Compliance Challenging
- Overlapping regulations make compliance more complex.
- The objective is to ensure a robust financial system by scrutinizing new products.
Risks Associated with Innovative Products
The speaker discusses the risks associated with innovative products in regulatory experimentation. They mention the importance of understanding potential risks and complying with regulations from entities like CVM, SUSEP, and Banco Central.
Understanding Risks for Innovative Products
- Credit on PIX is an example of a new product that involves aspects like cybersecurity.
- Compliance professionals need to assess potential risks associated with innovative products.
Compliance Requirements from Regulatory Entities
- Regulatory bodies like CVM, SUSEP, and Banco Central have specific compliance requirements.
- Demonstrating controls for risk management is essential during sandbox experiments.
Importance of Data Security in New Products
The speaker highlights the significance of data security in new products. They use examples like credit on PIX to illustrate how data sharing and secure transactions are crucial considerations for compliance professionals.
Data Security Considerations for New Products
- Credit on PIX involves immediate payment transactions, requiring secure data sharing.
- Compliance professionals need to address data protection measures during product development.
Sandbox Registration Process
The speaker explains the registration process for participating in a regulatory sandbox. They mention the need for thorough planning, validation, and coordination with regulators to ensure system integrity.
Sandbox Registration Process
- The website of regulatory bodies provides information on sandbox registration.
- Thorough planning and validation are required during the registration process.
- Coordination with regulators helps identify potential flaws in the financial system.
Multidisciplinary Approach in Compliance
The speaker emphasizes the importance of a multidisciplinary approach in compliance. They discuss the need for diverse expertise, including legal knowledge, management skills, and understanding business processes.
Importance of Multidisciplinary Approach
- Compliance professionals need to have diverse expertise beyond legal knowledge.
- Management skills and understanding business processes are crucial for effective compliance.
Collaboration between Legal and Compliance Teams
- Law firms should have a broader skill set beyond legal expertise to assist businesses effectively.
- Understanding both legal requirements and business transformation is essential.
Layers of Compliance in Modern Business Environment
The speaker discusses how compliance has evolved into multiple layers within the modern business environment. They mention privacy concerns, internal controls, and the impact of compliance on innovation.
Evolving Layers of Compliance
- Compliance now encompasses various aspects like privacy regulations and internal controls.
- Privacy concerns have become an integral part of compliance practices.
Impact on Innovation
- Traditional compliance approaches can hinder innovation by creating bottlenecks.
- Balancing compliance requirements with innovative practices is crucial for success.
Importance of Cross-Disciplinary Knowledge
The speaker highlights the significance of cross-disciplinary knowledge in compliance. They emphasize that relying solely on legal expertise is insufficient and stress the need for collaboration between different disciplines.
Importance of Cross-Disciplinary Knowledge
- Complying with laws alone is not enough; cross-disciplinary knowledge is essential.
- Collaboration between legal and non-legal professionals enhances compliance practices.
Enhancing Compliance with Diverse Skill Sets
- Law firms should have professionals with management and process transformation skills.
- Understanding both legal requirements and business processes is crucial for effective compliance.
Transforming Legal Knowledge into Business Processes
The speaker discusses the importance of transforming legal knowledge into practical business processes. They highlight the need for lawyers to understand accounting, management, and other disciplines to effectively support businesses.
Transforming Legal Knowledge into Business Processes
- Lawyers need to expand their expertise beyond legal matters to support businesses effectively.
- Understanding accounting, management, and other disciplines helps in process transformation.
Collaboration between Legal Professionals and Businesses
- Law firms should provide comprehensive support by integrating legal knowledge with business processes.
- Effective collaboration between lawyers and businesses leads to better compliance outcomes.
Importance of Interdisciplinary Skills in Compliance
The speaker emphasizes the importance of interdisciplinary skills in compliance. They discuss the need for non-lawyers to appreciate legal aspects while highlighting the potential risks of disregarding legal considerations.
Importance of Interdisciplinary Skills
- Non-lawyers should appreciate legal aspects to
The Changing Landscape of Compliance
In this section, the speaker discusses how the field of compliance has evolved and emphasizes the importance of understanding the market in order to work effectively in compliance.
Understanding the Market
- Compliance professionals need to have a deep understanding of the market they operate in.
- General knowledge is not enough; one must grasp the specific dynamics and intricacies of the industry.
- The speaker highlights the importance of lawyers having a genuine interest in business and companies they work with.
Importance of Operational Understanding
This section focuses on the significance of operational understanding for compliance professionals and how it can prevent errors and inefficiencies.
Operational Insight
- To effectively work with companies, compliance professionals need to understand their operations.
- The speaker shares an example where a previous misunderstanding led to incorrect procedures being followed.
- Having a clear understanding of how operations function helps avoid unnecessary complications.
Open Finance and Privacy Challenges
Here, the speaker discusses open finance, open insurance, and open banking as emerging trends. They also highlight privacy challenges associated with these developments.
Open Finance and Privacy Concerns
- Open finance, open insurance, and open banking are new concepts that bring about various regulatory challenges.
- These developments often conflict with privacy regulations and anti-money laundering (AML) norms.
- The speaker mentions portability rights for users but raises questions about data sharing between competitors.
Portability Rights and Security Considerations
This section explores portability rights for users in regulated markets. It also addresses security concerns related to data mobility.
User Data Portability
- Users now have increased rights regarding data portability across different institutions.
- The process of switching between banks or insurance companies has become more accessible and streamlined.
- Compliance professionals face challenges in determining which data can be shared and ensuring the security of such transfers.
Benefits of Working in a Regulated Market
The speaker expresses their satisfaction with working in a regulated market and highlights the advantages it offers.
Solidity and Security
- Working in a regulated market provides stability, security, and confidence due to established norms and regulations.
- Compliance professionals appreciate the solidity that comes with having clear guidelines to follow.
- Even those not directly involved in regulated markets can benefit from studying regulatory frameworks for insights on conflict resolution and best practices.
Conclusion: Changing Perspectives on Compliance
In this concluding section, the speaker expresses gratitude for changing perceptions about compliance. They encourage further study of regulatory frameworks for both regulated and non-regulated markets.
Changing Perceptions
- The speaker acknowledges that their perspective on compliance has been positively influenced by working with compliance experts.
- They emphasize the importance of understanding regulatory frameworks even for those not directly involved in regulated markets.
- Studying compliance can provide valuable insights into conflict resolution, best practices, and improving operations.
Timestamps have been associated with relevant sections as per the transcript provided.