Pharmaceutical Compliance and Regulatory Congress 2009

Similar documents
RISK MANAGEMENT OVERVIEW 2011 RISK CONFERENCE SPONSORED BY THE FEDERAL RESERVE BANK OF CHICAGO AND DEPAUL UNIVERSITY

Effective Enterprise Risk Management with ErmsCo ERM Foundation

Breaking Down the Silos: A 21st Century Approach to Information Governance. May 2015

Tying It All Together: Practical ERM Integration. Richard Scanlon Vice President Enterprise Risk Management CIGNA Corporation

ENTERPRISE RISK MANAGEMENT FRAMEWORK

Getting Started with Data Governance. Philip Russom TDWI Research Director, Data Management June 14, 2012

Information Security Program CHARTER

Enterprise Risk Management in Colleges and Universities

White Paper: The Seven Elements of an Effective Compliance and Ethics Program

Vendor Risk Management Financial Organizations

Fraud Prevention and Deterrence

Supply Chain Shared Services (SCSS)

Principled Performance & GRC

Safety Management Program

Aegon Global Compliance

The CIPM certification is comprised of two domains: Privacy Program Governance (I) and Privacy Program Operational Life Cycle (II).

KPMG s Financial Management Practice. kpmg.com

Data Quality Governance: Proactive Data Quality Management Starting at Source

Operations. Group Standard. Business Operations process forms the core of all our business activities

Question: 1 Which of the following should be the FIRST step in developing an information security plan?

UBS presentation Key remediation actions

Fundamentals of Information Governance:

White Paper Achieving GLBA Compliance through Security Information Management. White Paper / GLBA

Framework for Enterprise Risk Management

COMPLIANCE CHARTER 1

Management Update: The Cornerstones of Business Intelligence Excellence

Fortifying the Three Lines of Defense to Combat Compliance Risk

Explore the Possibilities

Blending Corporate Governance with. Information Security

Implementing Information Security Policies and Standards. A Real Life Example

MNsure Compliance Program Strategic Plan. December 17, 2014

Dallas IIA Chapter / ISACA N. Texas Chapter. January 7, 2010

State of Minnesota. Enterprise Security Strategic Plan. Fiscal Years

EURIBOR - CODE OF OBLIGATIONS OF PANEL BANKS

THE SOUTH AFRICAN HERITAGE RESOURCES AGENCY ENTERPRISE RISK MANAGEMENT FRAMEWORK

Fraud Risk Management Procedures

Physician Payments Sunshine Act

RSA ARCHER OPERATIONAL RISK MANAGEMENT

CISM (Certified Information Security Manager) Document version:

Data Governance in a Siloed Organization

WHITE PAPER Third-Party Risk Management Lifecycle Guide

Anti-Money Laundering controls in Mergers & Acquisitions

Audit. In today s constantly changing business. The Relevant

ESKITP Manage IT service delivery performance metrics

Auditor General s Office. Governance and Management of City Computer Software Needs Improvement

Requirements 1/28/2014. First Tier, Downstream and Related Entities (FDR) Compliance Program. Definitions. An overview.

Sparta Systems. Proven Enterprise Quality Management Solutions

Enterprise Risk Management

Final. North Carolina Procurement Transformation. Governance Model March 11, 2011

Metrics by design A practical approach to measuring internal audit performance

Why are PMO s are Needed on Large Projects?

IT audit updates. Current hot topics and key considerations. IT risk assessment leading practices

Data Governance Overview

CLASSIFICATION SPECIFICATION FORM

IT Governance: framework and case study. 22 September 2010

FISCAL PLAN RESPONSE TO THE AUDITOR GENERAL

Regulatory Compliance Management for Energy and Utilities

Risk and Contingency Planning. Today s Topics. Key Terms. A Vital Component of Your ICD-10 Program

Developing a Proactive Compliance Monitoring Program

RISK MANAGEMENT FRAMEWORK. 2 RESPONSIBLE PERSON: Sarah Price, Chief Officer

How To Manage Information Security At A University

Enterprise Risk Management & Information Technology

fs viewpoint

Deputy Chief Financial Officer Peggy Sherry. And. Chief Information Security Officer Robert West. U.S. Department of Homeland Security.

July New Entrants: Charting the Health Industry s Risk and Regulatory Landscape Where Risk Meets Opportunity

Italy. EY s Global Information Security Survey 2013

Compliance. TODAY June Meet Lanny A. Breuer. Assistant Attorney General, Criminal Division, U.S. Department of Justice.

Managing Risk at Bank of America Corporation. Overview

Business Logistics Specialist Position Description

Board of Directors Meeting 12/04/2010. Operational Risk Management Charter

Preparing for the Convergence of Risk Management & Business Continuity

PM Services. Transition Program Management

IT Governance Charter

An Effective Approach to Transition from Risk Assessment to Enterprise Risk Management

How To Manage Risk At Atb Financial

IT Vendor Due Diligence. Jennifer McGill CIA, CISA, CGEIT IT Audit Director Carolinas HealthCare System December 9, 2014

Version: 5 Date: October 6, 2011

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

Third Party Risk Management 12 April 2012

A Best Practice Guide

Imperative. Tim Mohn Industry Principal Sparta Systems

Becoming Reactively Proactive Rethinking compliance risk management in today's environment

Policy : Enterprise Risk Management Policy

Transcription:

Pharmaceutical Compliance and Regulatory Congress 2009 Compliance Program Elements Track I: How Program Management Can Keep You On Track Edward H. Leskauskas Director, Compliance and Ethics Operations and Program Management Bristol-Myers Squibb Leila A. Daiuto Director CCH AXENTIS a Wolters Kluwer business

2 In This Session Guide attendees on the what and how of compliance program operations What is Program Management? Skill Set of an Effective Program Manager Keep on Track What? Keep on Track How? How Technology Can Help Challenges & Remedies Key Takeaways

3 What is Program Management? Program Management brings structure and follow through to your compliance initiatives Oversee multiple projects that may be related by: Compliance area (i.e. Sample Accountability, Interactions with HCPs) System (CRM system) Mandate (Corporate Integrity Agreement) Program View = Consolidated view of all projects within the program Overseeing multiple projects means balancing: Differing priorities Differing timelines Differing sponsors

4 What is Program Management? Project Management & Planning Timing Scope Resources Budget Tracking and follow through Issues management Measurement Risk & Contingency Management Procurement Management (e.g. vendor selection) Reporting Budget Management Resource Management (internal and external) Manage dependencies within and across projects

5 Program Manager s Responsibilities Oversee the program, which may include managing multiple project plans Know the right resources to engage & leverage these resources and their capabilities Track progress and report status both at the project and program level Escalate and manage issues Manage change (e.g. scope creep, change control) Maintain focus on the overall compliance program Accountability for the successful execution of the program

6 Skill Set of an Effective Program Manager Relationship building & People management Influence without authority Provide guidance to team members and business partners Manage communications Facilitator Workplan management Understand dependencies across initiatives Drive resources and tasks to completion Problem solving Know when to escalate and who to work with when issues arise Risk management Know how to identify risks and make sure they are mitigated or escalated Experience in process improvements, technology implementations, and other similar programs within the organization

Keep On Track What? 7 Elements of an Effective Compliance Program 1. Policies and procedures 2. Compliance Officer and Compliance Committee Steering committee (e.g. CIA) Compliance Council/ committee 3. Training and education 4. Lines of communication 7 Internal External 5. Internal monitoring and auditing Beware of silos! 6. Enforcing standards and disciplinary guidelines 7. Responding to detected problems and corrective actions

8 Keep On Track What? Compliance requirements CIA Board/Management (SBCE) External audits Mergers/acquisitions (compliance impact) New / changed regulation Compliance risk management Key projects Finances

9 Keep On Track How? Project Management Right resources on hand with the right skill sets Analysis and trending Compare and tie together silos of information Reporting When monthly, quarterly, real time How periodic summaries/metrics all areas of 7 elements Manual vs electronic/system Observation/ Discussion Direct line to Chief Compliance Office Interaction with other experienced resources Technology Automation of compliance processes Monitoring and reporting Consistency and repeatability Relationships and proactive interactions are key to effective program management!

10 Keep On Track How?

11 Keep On Track How?

12 Keep On Track How? Key Metrics* Procedural Documents Training # of documents, by type proposed/ approved monthly/ quarterly % of employees completing mandatory training by deadline Auditing and Monitoring % of repeat observations from monitoring % of appropriately executed HCP Agreements Communications % of employees reached by communications Responding to detected problems and corrective actions Other # and % of disciplinary actions resulting in terminations $ loss averted because of misconduct detection # reduction in compliance incidents due to training Total spend on compliance vendors and systems Select metrics that are insightful, actionable, and relevant *Sources: Compliance and Ethics Leadership Council (CELC), Open Compliance and Ethics Group (OCEG)

13 Technology Implement technologies that drive consistency, efficiency, and repeatability across your 7 elements

14 Technology Governance, Risk & Compliance Mgt Policy, Training & Certification Policy Management Policy Distribution & Certification Learning & Surveys Risk & Control Management Risk & Control Inventory Monitoring Risks & Controls Exception Management Incident Management Investigations & Corrective Action Reports and Audit Results

15 Challenges & Remedies Challenges 1. Staying on track in an ever changing environment (mergers/acquisitions, changing regulations, internal reorganization, budgets) 2. Satisfying all stakeholders whose priorities may be different (Business, IT, Legal, Compliance, Internal Audit) 3. Tracking and identifying problems (e.g. legal liability) 4. Involvement in many efforts at once 5. Maintaining a high level of participant engagement 6. Reporting the appropriate level of detail 7. Accountability Remedies 1. Report to CCO and have a seat at the table. Function as part of compliance team, not as an independent 2. Relationships, relationships, relationships! 3. Discuss before documenting 4. Prioritize, plan, define owners, communicate, and get others involved 5. Be proactive! Establish regular meetings, make reporting a standard monthly procedure. Have senior management continuously engage participants to reenforce roles and contribution to overall engagement. Align to objectives/corporate strategy. 6. Know your audience. Understand the needs and define options 7. Remember your role and clarify with project leadership. Define owners and decision makers within the business

16 Key Takeaways Don t do this alone involve management and business up front Gauge tolerance level of the organization for oversight and structure Relationships, relationships, relationships Continuously evaluate value add Reiterate to management their responsibility to remove barriers to ensure successful outcome of program Use technology for consistency & sustainability, if appropriate Standardize processes Continuous Improvement