Showing posts with label regulation. Show all posts
Showing posts with label regulation. Show all posts

Friday, June 20, 2008

Bear Stearns and the Tour de France

There is another case of email messages being used to identify possible wrongdoers in the financial services industry (see “Prosecutors in Bear Case Zero In On Email”, Wall Street Journal).

Anyone in the US financial services industry should be well aware that regulatory compliance requires that employee email, IMs and file uploads are tracked and cached. Over the last decade when prominent cases emerged where old emails were used as evidence I thought that this common knowledge would not so much improve ethical standards as push unethical behavior to other forums, such as the phone, face-to-face meetings and the use of allusions.

So it is surprising to see people make the same mistake as recently as mid-2007, as the Bear Stearns employees’ old emails may show that they acted contrary to their clients’ interest. My take is that as long as enough money was being made, sketchy actions that improved performance did not attract notice, but once the market tanked, it became a matter of assigning responsibility. Electronic messaging supervision (the active monitoring and spot-checking of emails by compliance personnel) helps catch problematic behavior, but not even the best system can catch every ethical lapse as it occurs.

Breaking the rules in sports is similar. In ultra-competitive contests such as the Tour de France, cyclists have used doping in order to qualify and perform above their natural peak. Again, this strategy calls for breaking the rules to improve performance. Doping is not used by all competitors, but one must assume that all competitors have the ability to use it. Prize money is high. Some are caught and some not. And in the Tour de France, this has been going on for the last century.

Hence the paradox: there are industries and contests so competitive that it can be necessary to break the rules in order to compete. Governance bodies then often eventually identify and ban these same rule-breakers, but only after they have done the damage. A behavior may be prohibited (insider trading, options backdating, doping) but the means to catch the behavior often lags behind the means to evade detection.

Perhaps the only means to reduce these types of unethical behavior is to reduce the dramatic temptation that huge compensation gives to the competitors, whether in the form of a massive annual bonus or prize money and future sponsorship contracts.

Thursday, May 1, 2008

Mechanical conscience

I’ve been thinking about how businesses react to ethical transgressions. Some types of transgressions, such as those recorded by electronic messaging (email, file uploads, IMs etc), contributed to a number of large corporate court cases in the US since 2000 and came to influence the way companies store and monitor data.

Messaging supervision is a series of processes and tools put in place by organizations to monitor employee electronic communications with the goal of catching problematic communications either in real time or soon afterwards. Businesses (often those in financial services) implementing messaging supervision are often required, or influenced by regulations including NASD Rule 3010 and SEC Rule 17a-4 when they put such systems in place. Businesses also implement these systems in order to protect intellectual property and catch undesirable employee behavior, hopefully before it gets out of hand. Transgressions are caught by the system’s mechanical conscience.

But really, businesses just want to automate compliance and adhere to regulations efficiently. While no regulatory body requires a software-based system to check for possible transgressions, the sheer volume of email is too large for anything but spot checks from compliance staff. Nor should an organization want to actively review all communications traffic. Instead, the bulk of email communication, website visits, IMs and file downloads are scanned by rule-based software platforms. That means that if compliance staff look at a fixed number of tracked communications daily, use of these systems should increase their probability of finding something problematic without adding extra content volume to view.

What the mechanical conscience cannot do is account for context, intent, or employees who write for the censor’s eye. Also, these supervision systems are used at a corporate level primarily in the US. Interestingly Americans, who are normally considered to be privacy conscious, accept the right of their employers to look at their email. In France, for example, employees are allowed to set up private email folders which cannot legally be read by corporate compliance supervisors, should there be any. Further, employee knowledge of messaging supervision also pushes potential transgressors to other means of unmonitored communication: the cell phone conversation or meeting for a drink, which an industry worker once told me is just what the presence of the system is supposed to do.

Does regulatory compliance lead to a different approach to ethics in organizations?