3.5 Internal and External Collaboration: Benchmarking, Professional Networks, and Engaging Outside Expertise
Key Takeaways
- The Detailed Content Outline lists collaborating internally and externally to institute best practices — expressly including benchmarking and networking — as its own Domain 2 task, and recognizing the need for external expertise as another.
- Internal collaboration means compliance operates through the functions that own the controls: legal, HR, finance, internal audit, procurement, IT, and the business itself, formalized through shared charters and standing forums rather than ad hoc requests.
- Benchmarking compares program inputs and outputs against peers, but a peer metric is a hypothesis to investigate, never a target to hit; a hotline rate below the benchmark can mean either low misconduct or suppressed reporting.
- Professional networks such as SCCEnet, industry compliance roundtables, and regulator guidance forums are how compliance officers learn what peer enforcement actions actually required, and CCB expects candidates to use them.
- External expertise should be engaged for independence, specialized capability, surge capacity, or credibility with a regulator, and the engagement decision must address privilege structure, scope, and who receives the findings before work begins.
3.5 Internal and External Collaboration
A compliance function of twelve people cannot control the conduct of forty thousand employees, and no one expects it to. The program works through other functions, and the Detailed Content Outline treats that as testable competency: one Domain 2 task is to collaborate internally and externally with others to institute best practices (e.g., benchmarking, networking), and another is to recognize the need for external expertise (e.g., consultant, counsel).
1. Internal Collaboration: Compliance Runs on Other People's Controls
Nearly every compliance control is physically operated by someone outside the compliance department. Payment controls sit in finance. Screening sits in HR. Access controls sit in IT. Contract clauses sit with legal and procurement. Compliance designs, monitors, and escalates — but the function that owns the process owns the control.
| Partner Function | What compliance needs from them | What they need from compliance | Formalization |
|---|---|---|---|
| Legal | Regulatory interpretation, privilege structure, contract clauses, enforcement analysis | Early notice of issues; factual clarity; escalation criteria | Joint escalation protocol; defined privilege boundaries |
| Human Resources | Screening, discipline execution, exit data, culture survey infrastructure | Disciplinary consistency standards; investigation handoff rules | Joint disciplinary review committee; written intake split |
| Finance / Accounting | Transaction data, expense analytics, payment approval controls, vendor master | Red-flag definitions; testing scope; materiality thresholds | Data access agreement; standing analytics feed |
| Internal Audit | Independent testing of compliance controls, workpaper discipline | Risk assessment output; audit universe input; findings routing | Coordinated annual planning; Three Lines role definition |
| Procurement | Third-party inventory, onboarding gates, contract flow-down | Risk tiering criteria; screening service levels | Onboarding workflow with a compliance gate |
| IT / Security | System access, monitoring tooling, retention configuration, device policy | Data requirements; retention rules; investigation preservation | Preservation and access protocol |
The failure mode is collaboration by email. If the only connection between compliance and finance is a request each quarter for a data extract, the relationship collapses the moment finance is busy. Durable collaboration is structural: a standing cross-functional forum with a charter, named delegates, a recurring agenda, and decisions recorded — which is also why the management compliance committee exists.
Exam Watch — Consulting subject-matter resources is a Domain 1 task too. The blueprint separately requires consulting appropriate subject-matter resources (legal, HR, finance) when developing policies. A scenario in which compliance drafts a data-retention policy alone, without IT or legal, is testing that item. The right answer is almost never "compliance decides"; it is "compliance convenes."
2. External Collaboration: Benchmarking and Networking
Using Benchmarks Correctly
Benchmarking compares program inputs (budget, staffing ratios, training hours) and outputs (reporting rates, substantiation rates, cycle times) against peers of similar size, industry, and geographic footprint. Used well, it tells the board whether the program is in a defensible range. Used badly, it becomes a target that corrupts the metric.
| Metric | What a peer comparison suggests | Why it is a hypothesis, not a target |
|---|---|---|
| Reports per 1,000 employees | Whether people are speaking up at a normal rate | Below benchmark can mean low misconduct or fear of retaliation. Only culture data distinguishes them. |
| Anonymous share of reports | Trust in confidentiality | A rising anonymous share can signal deteriorating trust even while total volume looks healthy |
| Substantiation rate | Intake and investigation quality | Driving it up can simply mean screening out ambiguous reports that deserved review |
| Investigation cycle time | Responsiveness and capacity | Cutting it can mean faster triage or shallower investigations |
| Compliance FTE per 1,000 employees | Resourcing adequacy | Meaningless without risk weighting — a domestic services firm and a defense exporter are not comparable |
The governing principle: a benchmark gap is a question to investigate, not a number to close. The compliance officer who raises the hotline reporting rate by running an awareness campaign has done something useful; the one who raises it by counting IT helpdesk tickets as reports has produced a number and no information.
Professional Networks
CCB's own guidance to candidates points here: it recommends attending compliance events, learning from industry experts and agencies about current guidance, and using SCCEnet to ask questions and network with other compliance and ethics professionals and certification holders. The exam is described as being based largely on compliance work experience, and networks are how that experience is broadened.
- Peer roundtables and industry associations. How comparable organizations solved a control problem you are facing — usually faster and more candidly than a published survey.
- Regulator and enforcement forums. Agency guidance sessions and published resolutions reveal what remediation regulators actually accepted, which is more instructive than what guidance documents describe in the abstract.
- Cross-industry learning. The ECCP expects programs and training to evolve based on lessons learned from the company's own prior issues and from issues at other companies in related industries and geographies. Peer enforcement analysis is not optional curiosity; it is an expected input.
Two guardrails: never share competitively sensitive information in a peer forum without antitrust guidance, and never share the details of an open internal investigation.
3. Recognizing the Need for External Expertise
Engaging outside help is a judgment call, and the blueprint tests the judgment rather than the mechanics. Four legitimate triggers:
- Independence. The subject is a senior executive, the general counsel, the CCO, or the board itself. Internal investigators cannot credibly investigate the people who set their compensation.
- Specialized capability the organization does not have. Digital forensics, foreign-law analysis, sanctions or export-control interpretation, complex financial reconstruction, actuarial or clinical review.
- Surge capacity. A multi-jurisdiction matter that would consume the entire compliance function for six months while routine program work stops.
- Credibility with an external audience. A regulator, an audit committee, or a litigation counterparty that will discount an internal conclusion.
| Situation | Internal is appropriate | External is warranted |
|---|---|---|
| Expense-policy violation by a mid-level manager | ✔ | |
| Allegation against the CFO or a board member | ✔ (independence) | |
| Recurring low-severity policy breaches | ✔ | |
| Suspected FCPA conduct in a foreign subsidiary | ✔ (privilege, forensics, foreign law) | |
| Annual program self-assessment | ✔ | |
| Periodic independent program assessment (3–5 years) | ✔ (objectivity) | |
| Routine policy drafting | ✔ (with SME input) | |
| Interpreting a novel regulation with no agency guidance | ✔ (outside counsel) |
Structuring the Engagement Before Work Begins
Four decisions must be made up front, because they cannot be retrofitted:
- Who retains the firm. Counsel-directed engagements can support privilege; a consultant retained directly by the business generally cannot. If privilege matters, the structure has to reflect that from the first day.
- Scope and independence. Written scope, stated independence from the subject of the review, and a conflicts check — including whether the firm currently performs other work for the organization.
- Reporting line. Who receives the findings: the CCO, the general counsel, or the audit committee. For an investigation into senior management, the answer must be the board or a board committee.
- Knowledge transfer. What the organization retains when the engagement ends. An external review that leaves behind a report but no capability has purchased a document, not a control.
Exam Watch — Governance cannot be outsourced. Engaging a consultant to run risk assessments, a vendor to host the hotline, or outside counsel to conduct an investigation is normal and often best practice. Delegating oversight is not. The governing authority's duty of oversight and the CCO's accountability for the program remain in-house regardless of who does the work, and a distractor offering to hand program responsibility to an external provider is wrong every time.
A compliance officer reviews benchmark data showing that peer organizations of similar size and industry average 12 internal reports per 1,000 employees annually, while her organization records 4. She proposes to close the gap by counting IT helpdesk tickets and routine HR benefits inquiries as compliance reports, which would bring the figure to 13. What is the fundamental error?
An anonymous report alleges that the Chief Financial Officer directed the improper recognition of revenue across two quarters and pressured a controller to stay silent. The Chief Compliance Officer reports administratively to the CFO. What is the most appropriate approach to the investigation?
A mid-size company has never conducted a compliance risk assessment. Its board approves funding for an external consulting firm to build a risk assessment methodology, run the first assessment, and produce a risk register. As the engagement is scoped, which provision most directly protects the organization’s long-term interest?