Articles

Articles

GUTTIEREZ-CRESPIN, Antoinette

Audit of Compliance Systems

Full reference : Gutierrez-Crespin, A., Audit of Compliance systems, in Frison-Roche, M.-A., "Compliance Tools" , in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 151-158.   Read a general presentation of the volume in which the article has been published   - Summary of the article (by Marie-Anne Frison-Roche) The author identifies what characterizes a "Compliance audit". Different from a "Compliance program", which is an instrument of constraint, and even from an internal investigation, which aims to detect breaches, the Compliance audit aims to measure the risks of discrepancy in relation to Compliance requirements. or even identify areas for improvement. From this definition, it is explained how concretely a Compliance audit is carried out, by a risk-based approach, and who are the actors (internal and external to the company).   Read the other summaries   -

Articles

BURLINGAME, COPPENS, Karen, Roger, POWER, Noel & LEE, Dae Ho

Anti-Corruption Compliance: Global Dimension of Enforcement and Risk Management

Full reference : Burlingame, R., Coppens, K, Power, N. & Lee, D.H., Anti-Corruption Compliance: Global Dimension of Enforcement and Risk Management, in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 199-208.   Read a general presentation of the volume in which the article has been published. -   Summary of the article (by Marie-Anne Frison-Roche) The authors show that the authors certainly face a diversity of legal systems due to their multiple localization, but in reality in terms of fight against corruption the French authority, the English authority and the American authority develop similar requirements in a common spirit. Indeed by reading the texts, in particular soft law, issued by the French Anticorruption Agency, the Department of Justice and the Serious Fraud Office, it appears that the primary concern is in the effectiveness of the compliance program adopted by companies. The authorities of the three countries also stress the need for the company's governing bodies to actively promote and disseminate the culture of anti-corruption compliance. For the three authorities, it is more precisely necessary that this program be adapted and tailor-made, that the governing body commits itself to its effective compliance and that a code of conduct, effective training and communication actions, the program to be based on structural internal investigation and whistleblowing mechanisms, and refer to an evaluation. The authors show that beyond the specificities of each of the systems, the three authorities are united in the fight against corruption, which reduces the insecurity of internationally exposed companies.   Consult the summaries of the other articles composing the book.   -

Articles

PAILLER, Ludovic

Technological Tools, Compliance by Design and GDPR: the Protection of Personal Data from Design

Full reference : Pailler, L., Technological Tools, Compliance by Design and GDPR: the Protection of Personal Data from Design, in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 299-306   Consult an overview of the volume in which the article was published.   - Summary of the article (by Marie-Anne Frison-Roche) The author considers that the GDPR has changed the "paradigm" of data protection for the bearer in Compliance, in that the data controllers must ensure the effectiveness of the rules defined by the Regulation, which they make accounts. In addition, the data, processed by the algorithm, is a “means of compliance” described and is used for vigilance plans and all the other tools, this brick being common to all Compliance Law. To respect Law, and in particular to protect people, Compliance by design continues to integrate "compliance" from the design of its tools through standard techniques (Privacy Enhancing Technologies – Pet's), legalized by the GDPR. The author analyzes the technological means of data protection from the design of the tool, which complement Law and the contract. They are part of the "measures" required to protect people, for example transfers to third countries, these technological means being classified according to their degree of effectiveness. If the principle is free in the choice of technology, but Law requires and controls that it be not only effective but also robust, easy to use and compatible with the tools of use. The author emphasizes that the notion of "effectiveness" encompasses these particular requirements. This effectiveness, which must be proven a priori ("documented") is checked by the Authorities in the appropriateness of the measurement techniques, their effective implementation and their concrete effect. Even if this is only subject to the state of the art, it must develop its technical resources, helped by the authorities (cf. "compliance pack" of the CNIL (French data regulator)). Even if the powers were aimed at optimizing costs, he must bear them, the context and the purpose of the processing do not ultimately become proportional. So if the risk is very high for people, it will be necessary to insert techniques and protectors other than those of Compliance Law. -   Consult the summaries of the other articles composing the book.   -

Articles

KOENIGSBERG, S. and BARRIERE, F.

The Development of Attorney’s Compliance Expertise

Full reference : Koenigsberg, S. et Barrière, Fr, Th., The Development of Attorney's Compliance Expertise , in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 159-164.   Consult an overview of the volume in which the article was published.   - Summary of the article (by Marie-Anne Frison-Roche) The authors observe that many law firms are now developing expertise in compliance, either in departments or in teams. They emphasize that this expertise is achieved through specialization, which makes it possible to support companies, in Ex Ante (for example in mergers) and in Ex Post (in litigation) in continuum between the two. Moreover, this expertise is built in a collaborative way between the team of lawyers and the company concerned, which reinforces this necessary continuity. -   Consult the summaries of the other articles composing the book.

Articles

LAROUER, Marion

The Manifestation of Incentives Mechanisms in French Compliance Law

Full reference : Larouer, M., The Manifestation of Incentives Mechanisms in French Compliance Law, in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 113-122. Consult an overview of the volume in which the article was published. - Summary of the article (by Marie-Anne Frison-Roche) The author develops in the introduction the idea that Law itself accepts the notion of incentive as being consubstantial with it, relying in particular on codes of conduct. Then the article develops demonstrations of incentive Law as a tool of complicity, first of all in the fight against corruption: the decision of the Sanctions Commission of the Agency Française Anticorruption (French Anti-Corruption Agency) shows that the recommendations of this Agency encourage the company to comply, protecting it from a sanction if it submits to it but does not prevent it from organizing in any other way. In addition, the judgment of the Commercial Chamber of the Court de Cassation (cassation court) stated that the breach of a contractual obligation which is however only the resumption of a constraint lodged in a compliance program which targets a third party justifies the termination of the contract. . More generally, the author shows that the legal system encourages companies to integrate Compliance by publishing vigilance plans and extra-financial performance, while noting that companies do not always do so. The article also concludes that French Compliance Law in its use of incentives is only at its "beginnings".   Consult the summaries of the other articles composing the book.   -

Articles

TARDIEU, Hubert🕴️

Data Sovereignty and Compliance

Full reference : Tardieu, H., Data Sovereignty and Compliance , in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 123-130. Consult an overview of the volume in which the article was published.   - Summary of the article (by Marie-Anne Frison-Roche) After having considered that Europe had in terms of power "lost the battle" of personal data, the author asks for the same error, linked to a lack of interest at the start, not be repeated concerning "company data". The European Commission having affirmed its will in 2020, it is now necessary to build a "European ecosystem" for the sharing of industrial data in confidence. For this, the author explains that it is necessary to develop "incentives for the sharing of company data", in order to increase their available volume and fuel common progress in Artificial Intelligence between European companies and to use common complementary data, which 'none could generate alone, allowing the creation of new services. These incentives can be new and adapted "regulations", but also the adoption by the industry of a "common data model". But the author stresses that it is necessary to go, by experiments allowed by the "regulatory sandboxes". This will allow the deployment of data sharing, with Compliance being able to contribute to it, a path for a sovereign Europe of shared industrial data, a monumental objective which can thus be achieved. - Consult the summaries of the other articles composing the book.   -

Articles

MERABET, Samir

Morality by Design

Full reference : Merabet, S. La morale by design , in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 307-318. Consult an overview of the volume in which the article was published.   - Summary of the article (by Marie-Anne Frison-Roche) After having wondered about the relationship between Law and Morality, for which it is difficult to find points of contact, the author advances the hypothesis that the latter could find a space of concretization in the technology of artificial intelligence, even though many are worried about the deleterious effects of it. The author considering that Compliance is only a method while ethics would be the way in which morality is incorporated in a relaxed way in Law, the technology known as Artificial Intelligence could therefore express the moral rule ("compliance by design could be the appropriate tool to ensure the effectiveness of moral rules without falling into the excesses envisaged"). The author draws on examples to estimate that thus technology for on the one hand expressing the moral rule and on the other hand making it effective. The moral rule can thus be drawn up in a balanced way since it is jointly developed between the State and the economic operators, this collaboration taking the form of general principles adopted by the State using the means chosen by the company. Its content would also be characterized by the search for a "right balance", which would be found by this distribution between the primary moral principles whose expression would be the act of the State and the secondary moral principles whose expression would be delegated to companies. Taking therefore what would be the principles of Compliance, the author applies them to Artificial Intelligence, showing that these technologies include not only the principle of neutrality but also the ethical principles of non-maliciousness, even of benevolence. (first principles) that companies then decline into secondary principles. Therefore, "compliance can usefully be used to convert these fundamental moral principles into derived moral rules, a source of greater effectiveness.". Thus resulting in a "moral by design", the overall system has an additional effectiveness tool. This supposes that the fundamental and derived rules are of an acquired moral quality because for the moment the technological tool can only ensure their effectiveness and not the moral quality of the implemented rules. In determining the "moral rules of application", the company has margins of freedom, used through technological tools.   -   .       Consult the summaries of the other articles composing the book.   -

Articles

RAPP, Lucien

Incentive Theory and Governance of Space Activities

Full reference : Rapp, L., Incentive Theory and Governance of Space Activities, in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 83-100   Consult an overview of the volume in which the article was published.   - Summary of the article (done by the author) The article studies the conditions for an application of the theory of incentives to the problems currently posed by the governance of space activities. These activities have been enriched by the presence of numerous private operators, without the market that is being set up having yet been properly regulated. The accumulation of debris in close space highlights the difficulty of maintaining a situation where only national laws govern in the absence of a specialized international organization and in the insufficiency of the international treaties in force. This article shows the contributions of the behavioral approach in Law and economics and the interest that there would be in developing it. - Consult the summaries of the other articles composing the book.   -

Articles

Compliance Training: Through and Beyond Traditional Legal Training

Full reference : Causse, H., Compliance Training: Through and Beyond Traditional Legal Training , in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 231-244.   Read a general presentation of the volume in which the article has been published   - Summary of the article (by Marie-Anne Frison-Roche) The author emphasizes that not only Compliance training is required by Law but also that it is necessary. To conceive and practice it, it is certainly necessary to integrate new knowledge, often outside Law, but it is also necessary to preserve the qualities of the classical teaching of classical Law. This is why training is an essential aid and asset for companies. The article shows that the international dimension specific to the subject and that the cultural confrontation it translates must be inserted into traditional legal systems, training succeeding by highlighting the practical imperatives of which Compliance relays the concern. To achieve this, the author maintains that it is above all the classical qualities of the lawyer and the teacher that are required; classical Law thus finding a revival, as teaching methods are revitalized by this new Compliance Law. Its teaching must therefore be anchored both in traditional legal principles and in techniques specific to Compliance mechanisms.   -     Read other summaries   -

Articles

THOURET, Théo

Training and Compliance, Two Correlated Information Transmission Tools

Full reference : Thouret, Th., Training and Compliance, Two Correlated Information Transmission Tools, in M.-A. (dir.), Compliance Tools, série "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 265-274. Consult an overview of the volume in which the article was published.   - Summary of the article (by Marie-Anne Frison-Roche) The article is based on the fact that in general Compliance Law aims to circulate Information and that Training, by nature, is a process for transmitting information, bringing both together. Insofar as Compliance Law internalizes in "crucial operators" the obligation to circulate information (within it, vis-à-vis its stakeholders and the authorities, but also between crucial operators) , it is therefore logical that they develop training programs, not in an adjacent way but in a main way, because of this identity. Indeed, training is a means of obtaining that information is "well received", that is to say understood, assimilated and used by its recipient for what it was transmitted. The regulatory and supervisory authorities therefore control the effectiveness of obtaining this effect. The author finally takes two examples, one of spontaneous adoption of a Compliance training program, operated by Total group, the other of forced adoption, operated by Johnson & Johnson group, to illustrate its general demonstration.   -   Consult the summaries of the other articles composing the book.   -

Articles

GALLAND, Maxime

The Regulator’s Inspection of the Effectiveness of the Compliance Tools Implemented by the Company, in Frison-Roche, M.-A. (ed.), “Compliance Tools”

Full reference : Galland, M., The Regulator's Inspection of the Effectiveness of the Compliance Tools Implemented by the Company, in Frison-Roche, M.-A. (ed.), Compliance Tools, serie "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 211-224.   Read a general presentation of the book in which the article has been published.    - Summary of the article (done by Marie-Anne Frison-Roche) The author underlines the complexity of the measure of the effectivity of compliance tools because the measure of the risks cannot be mechanical, the exercise is a cost whose the advantage does not appear immediately, the essential is in the behaviors that the firm masters with difficulty while these are results that are evaluated, because Compliance tools must be effective and produce tangible results.  To do that, the regulator intervenes in Ex Ante in order to the applicable texts are understandable by the firm and in order to the tool is working. When a noncompliance occurs, the regulator must beyond the sanction build on this measure of ineffectiveness to lead operators to improve their systems. Thus, it is in terms of "Compliance effort" that the regulator's control works, especially through the observation of an "embodied exemplarity".    Read the summaries of the other articles of the book.    -

Articles

GRANIER, Cécile

The Normative originality of Compliance by Design in Frison-Roche, M.-A. (ed.), “Compliance Tools”

Full reference : Granier, C., The Normative originality of Compliance by Design, in Frison-Roche, M.-A. (ed.), Compliance Tools, serie "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 287-298.   Read a general presentation of the book in which the article has been published.    - Summary of the article by Marie-Anne Frison-Roche: The author develops the idea that Compliance by design represents a "normative originality", in that it aims, through a complex relationship between the obligatory and the voluntary, to ensure the effectiveness of the "primary standards" contained in the "monumental goals" set by public authorities. The normativity of Compliance by design is original because these processes are situated since the implementation of technical processes, what is referred to by the expression "by design", which reinforces the Ex Ante dimension of Compliance Law, IT embedding this normativity in the structures themselves, by a marriage between technology and Compliance. It results from that an "automatized" application of the norm, integrated in an IT program, which for example blocks the access to some data if the user has nor correctly expressed his or her consent, chain of events mechanically caused by the effect of previous events (or non-events) (as in smart-contracts), a whole functioning in total Ex Ante, outside any feared state sanction perspective, the constraint being reinstated in technical aptitude. This primacy of the technique asks the question of the interpretation of norms thus incorporated, question that the authors let opened because it could lead to machines which interpret themselves the norms.  This automatized application is presented as more "efficient", essential quality in the Compliance atmosphere since like that the norm does not depend on private actors and can benefit from their technical power. But we measure now the author of secondary technical norms inserts itself norms that should be only at the first level, the firm integrating its own practices and values, Compliance by design being related to auto regulation.  Moreover, the author shows that in the conception of the norm, in its design, the question is to designate the author of the norm's integration in the algorithm and the modalities of the integration. The author being intern to the firm, this would constitute a privatization of the norm, since the norm, even secondary, cannot be totally deprived of value's integration, Compliance overwhelming the organization of Law sources. In a situation that the author calls an "unknown", except that "jurists-coders" appear, the lawyer is disqualified by its technical inability because it is about a technological integration, the transfer of the legal toward the algorithm, by the translation in a coding and then by the integration in the IT architecture of the firm, transforming the legal rules. For example, through the choice of the severity of the mechanical sanction chosen at the secondary level to give effectivity to an interdiction educated at the primary level. The author shows thus that this effectivity control of primary level norms, effectivity control that is implemented at the second level, directly impacts primary level norms. For example, deciding to ask the authorization, or the expression of a consent, or forbidding the access, when a content has been reproved by a primary level norm which does not precise the mode of control of this reprobation that Compliance by design must associate to it. But Compliance by design being not an auto regulation, public authorities control its implementation, as did the CNIL (French Data Regulator) for Androïd. This type of control will be developed.              Read the summaries of the other articles of the book.  -

Articles

BANCK, Aurélie

The maturity of the Compliance tool’s user, first criterion of the choice of the salient tool, in Frison-Roche, M.-A. (ed.), “Compliance Tools”

Full reference : Banck, A., The maturity of the Compliance tool’s user, first criterion of the choice of the salient tool, in Frison-Roche, M.-A. (ed.), Compliance Tools, serie "Régulations & Compliance", Journal of Regulation & Compliance and Bruylant, 2021, pp. 225-228.   Read a general presentation of the book in which the article has been published.    - Summary of the article (written by Marie-Anne Frison-Roche) The author insists on the practical necessity for the firm to show immediately the documents attesting of the reality of Compliance mechanisms. IT tools helps companies to do that, but the crucial point is that everyone in the firm appropriates these tools.  To obtain it, it is necessary that the Compliance officer does not necessarily choose the tool which suits him or her best and pleases him or her the most but rather suits the one who will handle it, for example commercial teams on the ground, monitoring that the tool integrates the specificity of the sector and of the firm. The adjustment of the softwares must meet a maturity of its users in the firm, which must have a "culture of compliance" to take advantage of its tools. Thus more rudimental tools can be more efficient if the culture of Compliance is still weak, sophisticated tools could be unuseful if a prior minimum basis is not reach.  The author thus shows the link to be made between the maturity of the users and the technicality of the tools, the two having to progress together.   Read the summaries of the other articles of the book.    -

Articles

The horror series “Industry” is just a documentary; as was “The Wolf of Wall Street”; watch a series or read a thesis, it’s the same

Academics did a study on how people who work in investment banks kill themselves on the job. The death of a 21-year-old intern, having worked three days without sleeping, in the Goldman Sachs bank, the testimonies of young people explaining that they work non-stop, undoubtedly contributed to testimonies, relayed in the press, specialized or generalist, but also university studies. Indeed, two academics published a research no longer on the rules applicable within investment banks, which took measures to force their employees and their interns (since the victim was an intern) to rest on Sundays but on journeys based on data accessible by taxi companies. As a result, the reaction of the people was not to rest: it was to increase the daily working time, to leave even later after dark. Research shows that this phenomenon increases during the summer, that is to say precisely when the people who work are more trainees, that is to say those who want to "prove themselves": As the authors say: "Cette analyse, menée avec mon ex-collègue de doctorat de la Aalto University School of Business (Finlande), montre que, lorsque les banques ont mis en place des politiques de travail sans samedi, cela a incité les employés à travailler tard le soir en semaine pour compenser. Ces résultats sont plus marqués pendant les semaines de stages d’été, lorsque les banques d’investissement emploient un grand nombre d’étudiants désireux de faire leurs preuves en travaillant dur." (“This analysis, conducted with my ex-doctoral colleague from Aalto University School of Business (Finland), shows that when banks implemented work policies without Saturday, it prompted employees to work late nights on weekdays to compensate. These results are most marked during the summer internship weeks, when investment banks employ large numbers of students eager to prove themselves by working hard. ") -   Let's go back to the Industry series. An expert has shown all the points on which it does not correspond to "reality", on such and such a point. The cinema is reality — not even in the reconstitution of such or such a point, it reproduces it by throwing on the screen what is the idea which moves in the facts. This series begins with the death of a trader, who died of work. It tells exactly the life, how to qualify it …, let's say "the crazy life" of those who work there. It is hardly bearable to watch. In any case, it is exactly the image of what these two academics are saying.    

Articles

Why do we regulate? If it is to prevent systemic risks, systemic “family offices” must be subject to it (Archegos case) (Pourquoi régule-t-on? Si c’est pour prévenir les risques systémiques, les “family offices” systémiques doivent y être soumis (cas Archegos))

Full reference: Frison-Roche, M.-A., Why do we regulate? If it is to prevent systemic risks, systemic "family offices" must be subject to it (Archegos case) (Pourquoi régule-t-on? Si c'est pour prévenir les risques systémiques, les "family offices" systémiques doivent y être soumis (cas Archegos)), Newsletter MAFR – Law, Compliance, Regulation, 30th of March 2021 Read by freely subscribing other news of the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news:  Archegos was a wealth management company whose activity consisted mainly in managing funds that were not themselves from the financial markets (hence its title of "family office"). Obviously, Archegos was proving to be too fragile financially in view of the highly speculative commitments it made on the financial markets and systemic banks were particularly deeply affected by the liquidation of large amounts by Archegos to be able to respond to margin calls. As the mandate of the financial regulatory authorities is aimed almost exclusively at the protection of public savings, Archegos completely escaped the regulation and supervision of the Securities and Exchange Commission (SEC). However, Regulation Law also aims to prevent and manage systemic risks, which are often multi-sectoral and even trans-sectoral, and this in a teleological way. In view of this and the increasingly important place taken by speculative behavior in the financial markets, the financial regulatory authorities must give up the condition of using public savings in their consideration of operators which should be regulated because even an operator not handling public savings can threaten the existence of financial markets. From this perspective, "family offices", not handling public savings but having a systemic dimension, must come under the regulation and supervision of financial regulatory authorities.