Integrating Risk, Legal and Compliance Functions in Large Corporations
Boeing's recent decision to assign its new chief legal officer the responsibility for both global compliance and the law department reflects an emerging interest in integrating the risk, legal, compliance and ethics functions in large corporations.
May 21, 2020 at 11:04 AM
6 minute read
Boeing's recent decision to assign its new chief legal officer the responsibility for both global compliance and the law department reflects an emerging interest in integrating the risk, legal, compliance and ethics functions in large corporations.
According to its press release, the reorientation of Boeing's legal and compliance activities was part of a larger organizational effort to achieve greater cross company integration and continuous improvement; align enterprise services with current business conditions while increasing value; streamline leadership roles and responsibilities, and prepare for a post-pandemic environment.
The decision to combine legal and compliance (as well as trade controls, ethics and business conduct) under the leadership of the CLO is intended to enhance Boeing's existing compliance and governance program through "focused accountability for, and a more integrated approach to, its compliance responsibilities."
Boeing is one of the latest of a number of large corporations that have adopted more administratively integrated approaches to compliance program effectiveness. Another prominent adopter was a large national financial services company that changed its risk and compliance infrastructure following a significant scandal. That company shifted from a decentralized, federated compliance model (with compliance staff reporting to the business units they oversaw) to a more centralized model under a newly created strategic execution and operations office. This change was intended to provide greater oversight and to facilitate a coordinated response to risk and compliance issues.
Last month a major U.S.-based global media and technology company appointed a new chief compliance officer, responsible for oversight of domestic and international compliance. The position reports to the corporate general counsel. In addition, many of the publicly announced general counsel hirings to date in 2020 combine the role of chief compliance officer within the general counsel position. This group includes companies across the commercial spectrum, ranging from technology, private equity, insurance, pharma and mortgage companies to a major motorcycle manufacturer and a global contract logistics supplier.
All of this seems to confirm that there is no "one size fits all" approach to the coordination of corporate legal and compliance functions, to compliance officer/general counsel reporting relationships and to whether the roles of compliance officer and general counsel can be combined into one position. An organizational structure that achieves the greatest degree of effectiveness may depend upon the circumstances of the particular company.
Companies are continuing to adopt structures that offer them the greatest opportunity to achieve enhancements to, and efficiencies arising from, their legal and compliance functions. There is a particular interest by some companies to seek increased horizontal coordination of the various organizational functions involved with enterprise risk. These include the traditional (e.g., legal and compliance) and the non-traditional (e.g., information services, technology, supply chain and human resources).
Especially post-pandemic, increased value will likely be attributed to effective risk based knowledge and information sharing, in order to identify and quantify risk on a more timely basis. Such cross-disciplinary communication is more likely to succeed in the absence of artificial barriers that limit coordination between personnel with risk/legal/compliance/audit duties. In these circumstances, the advantages of a "siloed" approach to such duties become less obvious.
Nevertheless, there are several elements of the legal/compliance relationship that regulatory agencies (such as the Department of Justice) will look for when evaluating the effectiveness of an organization's compliance program. These include, but are not limited to,: the compliance officer holding a senior hierarchical position in the organizational chart; appropriate experience and qualifications of the compliance officer; a direct reporting relationship from the compliance officer to the CEO; a futility bypass right to the board or its audit committee; and board oversight of the hiring, compensation and termination of the compliance officer (and the general counsel).
The presence of these and similar traditional elements is especially important in industries such as health care, and with regulatory agencies such as the Office of Inspector General of the Department of Health and Human Services. OIG is somewhat unique in its single-minded objection to the chief compliance officer reporting to the general counsel. Indeed, in corporate integrity agreements, the OIG not only precludes such reporting to the general counsel, but also the performance of legal functions for the company (and thus presumably could not themselves place an investigation under privilege). The specific CIA language says that the compliance officer "shall not be, or be subordinate to, the General Counsel or Chief Financial Officer or have any responsibilities that involve acting in any capacity as legal counsel or supervising legal counsel functions for" the company under the CIA.
For that reason, efforts by health industry companies to integrate corporate risk, legal and compliance functions should focus on structures that are sensitive to the OIG's concerns. Note in this regard, Boeing's plan is to soon appoint a new compliance officer who, while reporting to the general counsel, would also have a direct reporting relationship to the CEO and to the board's audit committee.
Many companies periodically recalibrate their compliance and risk management practices to adjust to changes in their business model, the environment in which they operate, and the relevant regulatory climate. In that context, it is increasingly likely that a more integrated approach to these practices may be appealing, as long as it reflects an organizational commitment to compliance and to the support of its legal and compliance functions.
Boeing's decisions with respect to legal and compliance integration do not constitute some new "best practice." They may not even suggest a new wave of practice. But they do represent a unique way to achieve effective legal, regulatory and ethical compliance in a rapidly changing risk environment. That's something to be considered by corporate executive and board leadership as they periodically evaluate the effectiveness of their own legal and risk programming.
Michael W. Peregrine, a partner at the law firm of McDermott Will & Emery, advises corporations, officers, and directors on matters relating to corporate governance, fiduciary duties, and officer and director liability issues. His views do not necessarily reflect the views of the firm or its clients.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllAI Disclosures Under the Spotlight: SEC Expectations for Year-End Filings
5 minute readA Blueprint for Targeted Enhancements to Corporate Compliance Programs
7 minute readThree Legal Technology Trends That Can Maximize Legal Team Efficiency and Productivity
Trending Stories
- 1Orrick Loses 10-Lawyer Team to Herbert Smith in Germany
- 2‘The US Market Is Critical’: KPMG’s Former Head of Global Legal Services On the Legal Arm of the Big Four Firm Entering the US
- 3Justice Marguerite Grays Elevated to Co-Chair Panel That Advises on Commercial Division
- 4McDermott Continues UK Growth With Another Partner Hire in London
- 52 Texas Lawyers Vie for Prominent Post: 2025-2026 Election
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250