Video: From Detection to Documentation: Case Management in Motion | Duration: 1812s | Summary: From Detection to Documentation: Case Management in Motion | Chapters: Webinar Introduction (29.07s), Platform Overview (141.07501s), CCO Exam Challenges (280.745s), Compliance Continuous Cycle (509.225s), Case Management Tools (672.435s), Marketing Rule Violation (980.015s), Policy Management Tools (1195.25s), Trade Rule Violations (1374.9049s), Closing and Feedback (1567.6649s), Closing and Next Steps (1626.4751s)
Transcript for "From Detection to Documentation: Case Management in Motion":
Hey, everyone. I'm Allison. Welcome today's to today's webinar, from detection to documentation, case management in motion, which is a fancy way of saying that David, who's joined me today, our chief product officer, and I are going to be walking y'all through some best practices with policy violations and documentation and being regulatory regulator ready in that process, and we're gonna show you some examples here. Before we get into things, I am going to take care of a few housekeeping pieces. So a copy of recording rather of today's webinar is gonna be shared out with all of you who registered or attended today. And so look out for an email from our team. And with that, I'm gonna just run through the agenda. So we've, of course, taken care of our introductions. David's gonna do a really brief Comply overview. I know we've got some clients and some different folks exploring the Comply platform and things of that nature. So really quick overview of who we are and what we do. We're gonna get into some data points. So we recently conducted a market survey, our twenty twenty six CCO and compliance leader report, and it uncovers a lot of interesting information that we think would be valuable to this group in kind of shaping how we approach our products and our services and things of that nature. And then we're gonna get into, case management. So identifying, documenting, and reporting out policy violations and making sure that your firm and your employees are understanding the policies that you've got in place, that they're clear, and that you have a very strong way of kind of managing that, documenting it, and being able to prove that to regulators if and when they come knocking. And then we're gonna get into a demo of the product. So three different scenarios within case management that you could be using, the product for, and then we'll wrap things up. So with that, I'm gonna toss it over to David who's gonna go through a few things first. Thank you so much, Allison, and welcome everyone. Thanks for joining us. So I will cover a couple of quick setup slides and hand it over to the, most exciting part of the session today, which is the demos that Allison has prepared and will walk us through. So just by means of, setting context, this is a very high level view of everything that we do as as a firm in the one comply platform. Everything from broker dealer and SEC and state registration, as well as ongoing filing support all the way through creating policies and procedures with our clients, helping them with the annual review and risk assessment, running their entire program with an overall compliance calendar, communications, e comms archiving, obviously, conflicts of interest, code code of ethics, personal account dealing in The UK, and, political contribution monitoring through control room and conflicts checking there as well. So, there's a lot here, but there is one element that really helps tie all these things together. And so what you're gonna see in the demo is Allison closing the loop across a number of these bullet points using case management to help tie those threads together. So let's jump to the next one, Allison. Alright. So as Allison already mentioned, we recently got great results from a very comprehensive, CCO survey across, The US, North America, The UK, and Europe as well. And here are a couple of key stats that we think, will be most interesting for the audience today. 68% of the respondents have been audited by a regulator in the last couple of years. 45% of them use software, compliance specific software for preparing for exams and audits, and 40% site documentation, as issues on exam day. Right? So still plenty of room for improvement around preparing all those documents and reports that you may be asked for by an auditor or a regulator. A top exam issues or concerns for those same CCOs, almost half said marketing materials and how they oversee and manage all of their, marketing material reviews. Almost half, again, 43% inconsistent supervision, so proving how they manage the entire supervisory requirements across the whole firm, obviously, with limited compliance resources. And another big one which will be very relevant today as well, documentation gaps. 40% said they struggled to get all of the documents necessary ready to go upon request by those regulators. I think part of that issue is because of what you'll see here, which is 36% managed documents and other materials, lists, violations, logs as an example in spreadsheets. We often say that one of our biggest competitors in the comply world is the Microsoft Office three sixty five suite because a lot of compliance programs are keeping documents in OneDrive or SharePoint. It's via email, all of their communications, using, again, spreadsheets to keep track of lists of violations and issues, word documents for all of the policies and procedures. And 45% of the respondents said they do use dedicated compliance software for a lot of the documentation. So that's good, but still, you know, a pretty big chunk of folks that are managing these more manually. Okay. So, a couple of other, weaknesses that the CCOs called out in their, regulatory exam prep that overall compliance concerns. One of the biggest, cybersecurity and data handling. So I think, in the survey that covered a number of things. But it was not just how compliance manages documents, but how the entire firm oversees vendors, manages cybersecurity holistically, prevents phishing attacks, and making sure that all of their client data is held in a safe, secure way and is not exposed to bad actors. Another very top contender for most common issues, employees understanding policies. I hear quite often that up to half of compliance team member, time is spent answering questions from the employee base, from the supervised users, the the advisors, the broker dealers, the the partners, what the the firm's policies are on whatever topic. Am I allowed to trade these these, securities? What is our gifts and entertainment policy on this? How do I alert you to an outside business, activity or affiliation? Am I allowed to do this thing? So that that is a a constant refrain from our clients. Almost 50% executive accountability. The awareness and the tone from the top, for compliance across the firm and the executive leadership. Again, marketing rule awareness and making sure that they have very strong evidence of their marketing reviews. And, of course, a rapidly growing topic in the compliance world is not just AI, but how the compliance department is governing the use of AI in the firm and even adding it to specific policies and procedures. So I mentioned, case management earlier around closing the loop. But, very quickly, and then Allison will show this in practice. If you remember all of those bullet points on the horizon slide or the semi circle at the beginning, there are a lot of elements of a comply, compliance program that we assist with. But But at the end of the day, I like to think about it as a continuous cycle where you've got your policies and procedures. You ask your employees to follow those policies and procedures. You ask them to certify that they will follow them and that they understand them. Then you monitor how you're doing against those policies and procedures, and that includes personal trade monitoring or personal account dealing, gifts of entertainment, conflicts of interest, a myriad of things in The UK, individual accountability and SMCR regimes. And and then you ask yourself on a regular basis, is the monitoring program effective? Is it doing what we thought it would do? And is it living up to the standards that we set out for ourselves in our policies and procedures? And I'm going to document that those findings in things like annual reviews. I'm going to document all of the the times where the policy or the process didn't work in a violations log. I'm gonna take, lessons from those shortcomings or those issues that are found during an exam or a mock audit, or when a regulator comes. And then I'm going to put all of this into my risk assessment and update my risk assessment, which then leads to changes to my policies and procedures and around and around it goes. Right? I think that's a pretty good encapsulation at a very high level of the challenges and the ongoing evolution of the compliance function. And so we are going to now show a couple of examples of where these things are connected. Do the policies and procedures work? How do we implement them in practice, including in automating some of those supervisory things in software? How do we assess the the effectiveness on a regular basis? And what do we do with those findings to improve it the next quarter or year or decade? So I think, Allison, we're about done with the slides. Well, I think that we are. I think you did a great job just showing how that's all connected through and just the importance even with the low level kind of known slap on the wrist little things could, if you're not documenting them the right way and you have been, uncover a larger problem, which might be unclear policies around something, and you're spending a lot of time, you know, with that. So we're gonna show you a few things here. While I get into it, you know, I think everyone on this call is a compliance professional, so we don't need to drain this slide. But there's different levels of risk within a firm, and even the low risk at a high velocity is a challenge and and can be a concern of the SEC and other regulators. So as I walk through these next three examples, you know, depending on your firm type, your risk profile, your structure, think about how this could apply to you, and, and kind of be creative about about how this all works together. So the first example is is just the the one that drives us all nuts. Right? So this is late certifications and failure to preclear guest entertainment. And so this could be anything from, oops, I forgot, to an intentional thing. Regardless, it's still a a breach of policy, and it needs to be investigated. So in this scenario, an employee has missed a couple of different certification deadlines, then it's flagged that they didn't preclear a gift. And so it's on the compliance team. They've gotten the alerts. They see the unmatched data within the compliant platform, and then they're going to start to investigate. So if you give me one moment, I'm gonna navigate to this for the team, and I've constructed this in a way that's gonna highlight things for you so it can draw attention to the screen. So if you wanna read them, you can. I'm also gonna explain it. So, you know, if you're new to the Comply platform or if you are an existing client, what you're looking at right now is a sneak sneak brand new employee three sixty profile. And so this is something that I know excites me and David. It is a complete overhaul in all of the best ways of how we're displaying individual employee data, in it reminds me a lot of our dashboards. And so if you think about the compliance dashboard as this jumping off point to get into communications and trade rule violations, this is another area we can drill down into an individual within the firm and check out what's going on. And so this is the user profile. Just taking a look here, you see a lot of visual things. The groups, there's new things that you might not know about. We're gonna walk through that now. And so here, you can see everyone's data in one place. You can see their groups. We have a new thing called tagging, which I'm gonna get into shortly. You can drill down, see their timeline. You can also notice here where it says that they've got four overdue certifications. Certifications. And so you're looking at Ethan, and you're like, okay, Ethan. What's going on? Why are you not doing these certifications? We're sending you the reminders. Like, what's happening here? So because they are overdue and it is a violation, we've gotta create a case. And so what's beautiful about the employee three sixty profile is you're investigating someone, and right from there, you can click this create case button, and it'll open up case management. And if you're new to case management as a client or if you're new to this, there's a lot of different ways that you can configure the forms. We love to give you guys the opportunity to customize them on your own. We also have some prebaked, case type statuses and things like that. So in this example, you know, we're classifying this as case type late certifications. It's the first violation. The severity is low. You can put in the incident date and the discovery date. You can add your description here. Maybe you have one up front. Maybe you need to edit it later. You can do both. And then you'll go ahead and click that create a new case button. Once you do that, you'll be able to go over to your case management part of the platform and see all of your open cases. And so you can see here, here's Ethan's open case. He's got these late certifications. We are in the remediation part of that case. But taking it a step up and what you can now do or soon can do in the employee three sixty profile is you can start tagging. So groups are these big overarching things like I'm an employee and I'm on the financial analyst team. Tagging gives the compliance team a little bit more flexibility to put some identifying factors on maybe things you wanna heighten supervision on or trends or things that you're seeing within the team. And so for this example, the combined teams, like, we need to flag this person as overdue certifications. They've missed four. We need a little more heightened supervision. We need to make sure we're keeping the finger on the pulse there. So this is already preloaded in the system. They can select that one, and then you click save. And you'll see over here that they are now tagged with overdue certifications. And from there, that is this portion of kind of the example. I'm gonna get into the next one in in a second. But, let me just actually do that right now. I'm rambling. So back to the deck. This one example, I think, is, you know, super relevant right now is marketing rule violation. It is, like, the favorite thing the SEC likes to go after firms for. It's an easy thing to slip up intentionally or unintentionally. And so in this scenario, we've got a social media post, was published without approval from the compliance team. And what went wrong in that scenario is that the, marketing team member decided to use an AI plug in as marketing team members will do because it makes things sound more fabulous. And upon using that plug in, it ended up introducing a lot of misleading claims, which will put the firm in hot water. And so, you know, an unintentional way of, you know, driving more business and momentum from marketing has then landed the compliance team in a little bit of hot water. So let's kinda look at what that might look like in the system, from a bunch of different capabilities that the Comply platform has. So we're gonna look at archiving, and this is the Comply's archiving portal. And here, we're just taking a peek at social media. So you can see all these different posts, needs further reviewed, not reviewed, flagged keywords, bunch of different capabilities here. But what we're gonna hone in right on right now is an individual post. And so this one right here that you see is a LinkedIn post from Summit Partners. It's a made up firm, and everything is by the book. The compliance team approved it. It had their blessing. It went out. Wonderful. But an alert then told the compliance team, hey. That same person two days later posted a different LinkedIn post from the company profile, and that's the post in question that used that AI plug in. And so we've got double digit returns and exponential growth. Like, we all know this is, you know, very not by the book with the s e David's like, no. Absolutely not. You know? You know? And so that's gonna land everyone in hot water. The SEC will, you know, do the what the SEC does. And so, obviously, because this is a highly find and highly risky scenario, it is a perfect use of the case management portal. So we're gonna go back over to case management, and then we'll create that case. I've already walked you through kind of the logistics of it, so I'm not gonna, you know, walk you through those pieces. But, actually, I'll stay right here for a second. So the you go through the case and, you know, you're documenting it all. You're putting your your investigation happens. Your investigation is not just gonna happen when you open the case file and click a few buttons and comply. You're gonna have to do some work on your end. But during this process and in this scenario I'm explaining to you, the compliance team did some research, did some digging, and found out that it was, in fact, the AI plug in that was responsible for it. It was an innocent but big mistake. And so they had to take a look and say, well, what do our policies and procedures even say about AI? And when they went and looked at their policies and procedures, they realized their AI policies and procedures were from 2022 when we were talking about GenAI in in its infancy, and it's not as heavily used at the firm. And so the compliance team's like, yes, that was a mistake, but, also, we need to cover AI policies and procedures. And so, you know, the case is is documented and followed up on, but the really important part in how we close the loop is how are we going to take this violation and turn it into the next step that we followed to say to the SEC, hey. You know, we did this did happen, but here's how we fixed it. And so now you're looking at the Comply Intelligent Policy Builder. And from here, you can see that there are multiple sections within this policy builder. I'm not gonna do a full demo of that, but you have the ability to add sections policy section. And not only do we need to create an AI policy section, we actually need to be reviewing this on a quarterly basis at minimum because of how much the, AI is evolving and how many different people within the firm are using it. And so they're gonna go ahead and they're gonna use the intelligent policy builder to create their AI policy, which you'll see here. It's all tracked. There's version control. It's fully auditable. Lots of powerful capabilities within there. And you'll see, great. The policy has been created. But as David alluded to earlier, the next step there is certifying and attesting that all employees will follow that policy. And that's how that loop kind of comes to fruition. Right? And so you'll go simply over your certifications area of the platform, and you'll said we need to create a new event. It might not be in that linear order, but the next time you go for your quarterly certifications or monthly or however you decide to, as a firm, do this, you would then create that event. And you'd create your form, and you'd customize it, and you'd be able to do your notification emails and your reminder emails and all of these things and say, hey. You know, we've discovered this. We have an AI policy. Everyone has attested to it. We've educated the firm, and we're gonna be doing this ongoing, which leads us then into what David and I were sharing earlier is the risk assessment. So, you know, savvy tech savvy firms and are constantly assessing risk, quarterly, monthly, maybe yearly, depending on your firm size. And so, you know, part of the risk assessment tool within the Comply platform is going to offer a lot of underlying details about things that have gone wrong and let you flag that risk on, you know, low, medium, high scale. So if we just jump into one part of the 100 and, I think, 60 questionnaire risk assessment, we've got misrepresentation of services offered, and that is where we have documented the AI content tool, caused this issue. We've written added policies and procedures. It's all there. So it's not living in email. It's not living in conversations. It's not living in outside data. It's outside data. It's living within the platform. Every single thing that's happened has a time stamp. It is compliant. It is something that, you know, will be able to be produced to the regulators if and when and how they ask, and gives you, like, something that's way more buttoned up than the end of your fire drills of let's get all these spreadsheets and messages and conversations going through there. So that is that example. And then I've got one more for the group, which is just your simple trade rule violation. All this know all too well. It's probably one of I think I was talking to someone on David's team, one of the most common cases that are, that are in the system of of different compliant, clients. And so let's just go in normal routine. You go to the dashboard. You look at your open communications in the Comply platform, and you see here something that's a little interesting. So we've got Claire Donovan who has an unmatched trade of buying 3,000 shares of Amazon, and then it flags a trade rule violation. So here we go. We're gonna go look into it. So you're looking at the communication details. And, you know, as you thumb through it, you see that the trade was not pre cleared and that Amazon is on the restricted list. So this is a massive, massive no no. This there is a lot of different layers of I can't ever say that word. There are a lot of layers of of things that could go wrong with with something of this nature, and so it naturally opens up that need to create a case. What I'm showing you here so if you remember earlier, you could create a case from the employee three sixty profile. You can create a case from the case management area, or there's a third way, maybe a few others I might not know about, is you can open the case directly from the communication portal by just clicking this button right here. And that's when you can do again, you'll see it preloaded because I did this myself. It's just the trade violation, restricted list, severity of it, you know, and then the resolution. Hey. You issued clear warning. This is additional training attached to the communication, you know, and so what. Little deeper here. So you've got that case. You see it in your area. But let's say that you don't discover the case, investigate the case, and find the resolution all in one workday. You can always go back to the case details. You can edit the case. I mean, heaven forbid you need to delete it. Maybe there's a duplicate. That is possible in the platform. But here's where you're gonna see all the details here, everything that you would need, the resolution, the linked communication, the documents. So I've uploaded the written warning that she received from the compliance team, the history of the different things that have gone on. And so that's just a different way to be able to make sure that you are taking all of the data that you've got in the Comply platform and leveraging it across different things. And case management really does become that, fluidity throughout of being able to take these massive pieces of very critical compliance data and put it into a format that is very easy for the stakeholders, the ELT, the board members, and the regulators to understand exactly what's going on in your programs and exactly how you're following up. So that ends my case management demo part of, today's session. Excuse me while I accidentally share the wrong screen. But, you know, I've had a lot of conversations with clients, and David has as well. You know, curious to hear from customers how you're using case management. I'm also curious, you know, talking to someone at Convent and just understanding, like, maybe best practices and how to structure cases. So if you guys are hearing this and you've attended this webinar and you find this stuff valuable and you want more, like, please let me know. I've put my email address up here. Let me know in the comments. Like, we would love nothing more to give you guys and and our clients and our prospects more insights and ideas and strategies on how to really create this document defensible documentation within your firm using case management. So I'm gonna pause there. David, do you have any final comments? I do not. I think you did a great job with the the demo and showing how case management connects the dots across a variety of of use cases, marketing review, code of ethics, trade, violations, gifts and entertainment, and tying it all back to your your annual review, your risk assessment, and updating your policies and procedures, and then certifying. And around it goes. So Then I thought it would be. Yeah. It's it's a lot in a short time frame, but hopefully, everyone found it, helpful. And I certainly think it's a a good way of quickly highlighting the value of, closing a loop and managing, your Mhmm. Your compliance program comprehensively. Yeah. I think also if this is something totally new that you're you're thinking about considering starting to do at your firm, like, tackling it literally case by case. Right? So figuring out how you how you wanna roll it out is really important, and, hopefully, this serves as kind of inspiration to think about as you as you develop those programs. But in the meantime, thank you all for joining. We will be following up with a bunch of materials, and we hope to catch you on our next webinar. Thank you. Thank you.