Skip Navigation
Close Btn

Global Workforce Risk & Culture Assessment Program

Regulatory Compliance & Investigations

Global Workforce Risk & Culture Assessment Program

A fixed-term, relationship-based assessment that surfaces compliance, fraud, workforce, and operational risks that hotlines, surveys, and audits may not reach.

Led By
A former federal prosecutor
Built For
GC, CCO & Audit Committee chairs
Designed To
Reach what hotlines cannot

See risk earlier. Give every team a voice.

KINVERITY™ works alongside your existing compliance program. The name combines kin, reflecting connection and belonging, with verity, meaning truth. Hotlines and culture surveys capture only what employees choose to report. KINVERITY™ builds relationships with respected people in each region, giving remote employees a trusted voice, strengthening their connection to the organization, and surfacing issues while there is still time to act.

The practice is led by Kevin R. Brenner, a former federal prosecutor with two decades of investigative leadership experience, and sits within FCPA & Anti-Corruption and Investigations. Each engagement is tailored to the company’s operational footprint, regulatory exposure, workforce, and existing compliance posture.

Problems rarely come out of nowhere. Misconduct often develops over months or years, and the people closest to it usually know first. Few hotline reports may reflect silence and disconnection. KINVERITY™ helps organizations hear those employees earlier, act on what they know, and build a more connected and resilient global workforce.

Chapter 01

The Risk

  • The cost of getting it wrong
  • Three kinds of exposure. One root cause.
  • Where this risk is concentrated

The cost of getting it wrong

Selected FCPA enforcement penalties, total U.S. government resolutions.

$2.9B
Goldman Sachs
2020
Bribery of officials in Malaysia and Abu Dhabi to win bond mandates connected to the 1MDB sovereign wealth fund fraud.
$1.06B
Ericsson
2019
Payments to government officials in China, Vietnam, Indonesia, Kuwait, and Djibouti to win telecom network contracts.
$282M
Walmart
2019
Payments to local officials in Mexico, Brazil, India, and China to expedite permits for retail store openings.
1 / 3
Source: U.S. Department of Justice, FCPA enforcement actions.

Three kinds of exposure. One root cause.

FCPA gets the headlines. Fraud, discrimination, and harassment carry comparable exposure, and are just as invisible when employees do not trust the channels.

$282M to $2.9B
Anti-corruption
Per resolution, recent range
Undisclosed payments, intermediary conduct, and pressure surrounding permits or public contracts. Penalties range from $282M (Walmart, 2019) to $2.9B (Goldman Sachs, 2020). The fine is typically the floor. Disgorgement, monitorship costs, and reputational damage run for years after the resolution date.
5% of revenue
Internal fraud
Median annual loss, ACFE 2024
Procurement manipulation, conflicts, invoice patterns, and misuse of approval authority. The typical occupational fraud scheme runs 12 months before anyone formally detects it. At $1B in annual revenue, 5% is $50M. These losses are often absorbed invisibly until patterns emerge or a regulator asks the question.
$54M to $215M
Workforce conduct
Recent headline settlements
Harassment, discrimination, retaliation, and local practices that employees do not trust formal channels to address. McDonald’s ($26M, 2022), Riot Games ($100M, 2023), Activision Blizzard ($54M, 2023), Goldman Sachs ($215M, 2023). Direct legal exposure is consistently the smaller number. Turnover, recruiting drag, leadership churn, and brand damage compound for years after.
Sources: ACFE 2024 Report to the Nations; DOJ FCPA enforcement data; publicly reported settlements.

Where this risk is concentrated

Five regions account for the vast majority of FCPA enforcement actions, per Stanford FCPA Clearinghouse data.

India

Complex licensing regimes, multi-layer intermediary networks, and persistent pressure to facilitate permits through unofficial channels. Customs, labor, and regulatory officials are common exposure points.

China

State-owned enterprise counterparties, opaque government decision-making, entrenched gift and entertainment expectations, and party-affiliated officials embedded in supplier and distribution chains.

Latin America

Public contract bribery, customs and inspection official payments, and deep dependence on local agents whose government relationships are rarely disclosed or monitored.

Middle East

Mandatory local partner structures, opaque beneficial ownership, and normalized facilitation payment expectations across sectors, particularly in energy, construction, and government procurement.

Africa

Energy and extractive sector corruption in oil-producing states. Nigeria, Gabon, and Angola rank in the top 15 countries globally by FCPA enforcement action count. Government procurement and agent networks are the primary exposure points.

Chapter 02

Why It Stays Hidden

  • What we see in practice
  • Why people stay quiet
  • Already have a program? Here is what it does not cover.
  • Why the truth is hard to surface

What we see in practice

01

Issues Rarely Come Out of Nowhere.

They accumulate over months, sometimes years, before reaching a hotline, an auditor, or a regulator. The problem existed long before anyone formally found out.

02

People Know Before They Report.

Employees in the field, managers, intermediaries and local staff, often have direct knowledge of pressure and misconduct long before it surfaces formally. They carry it quietly.

03

The Silence Is the Signal.

Regions with low hotline reporting and strong culture survey scores are often not clean. They are quiet.

Why people stay quiet

Employees often recognize pressure or misconduct before it reaches a hotline, auditor, or regulator. Fear of retaliation, distrust of reporting channels, and normalization of local practices can suppress reporting. Low complaint volume may therefore reflect limited trust rather than limited risk.

Fear of Retaliation

Employees in high-risk regions rarely trust that reporting will be handled confidentially. The calculus is straightforward: the perceived risk of speaking up outweighs any likely benefit.

Distrust in the Channel

Hotlines and ethics portals are viewed as corporate surveillance, not genuine safety valves. When employees do not trust the channel, they do not use it. Zero reports can mean zero trust.

Cultural Normalization

In many markets, payments to officials or informal facilitation are treated as ordinary business costs. Employees do not report what they do not recognize as wrongdoing. The compliance program never sees it.

Already have a program? Here is what it does not cover.

A well-built compliance program handles what gets reported. The limitation is not the program, it is structural. It cannot reach what employees know but have not said.

Your Channels Capture What Gets Reported.

Hotlines and ethics portals are passive infrastructure. They measure who chose to submit something. They cannot measure the gap between what employees know and what they disclosed, and that gap is where most misconduct lives before it becomes a government matter.

Culture Metrics Measure Stated Beliefs, Not Behavior.

A region scoring 4.2 out of 5 on an annual culture survey can be running systematic payments through a local agent. Both facts are true simultaneously. The survey does not know, because it can only record what employees chose to say.

Ground-Level Truth Requires Relationships, Not Infrastructure.

The employees most likely to know about misconduct are often least likely to use a hotline. Getting to them requires months of trust, the kind built through repeated personal contact, not a portal and a policy. Your program cannot build that at scale. We can.

Why the truth is hard to surface

The most important information rarely surfaces through formal channels, not because programs are broken, but because surfacing it requires trust.

What Programs Capture Well

  • Reported hotline complaints
  • Annual ethics survey responses
  • Training completion rates
  • Disclosed conflicts of interest
  • Gifts and expenses reports filed

What Is Harder to Reach

  • Misconduct that employees know about but have not reported
  • Pressure being felt at the operational level
  • Informal practices that do not register as violations
  • Silence driven by fear rather than absence of issues
  • What agents and intermediaries are doing in the company’s name
Chapter 03

How Works

  • Our approach
  • How KINVERITY™ works
  • What this uncovers
  • Where risk actually hides

People tell the truth where trust exists. We build that trust before problems start.

Not a survey. Not a hotline. Not an audit.

Book a Discovery Call →

How works

Four steps, within a defined assessment period.

Step 01 · Focus

Focus

Select the markets, offices, and risk themes where leadership needs better visibility.

Step 02 · Connect

Connect

Through colleague recommendations, on-site training sessions, and other appropriate channels, identify respected employees across functions and invite them to participate in a scheduled series of private, structured conversations.

Step 03 · Assess

Assess

Evaluate reported concerns, pressure signals, silence patterns, and operational anomalies.

Step 04 · Deliver

Deliver

Provide findings, recommended actions, escalation protocols, and supporting documentation for management or board review.

What this uncovers

Signals your existing program may not capture.

Pressure indicators

Employees being pushed toward questionable conduct, before it becomes misconduct. This is the moment a compliance program can prevent something.

Unreported patterns

Conduct that is known internally but has not been disclosed, through fear, normalization, or distrust of channels. The gap between what happened and what the program saw.

Cultural risk conditions

Leadership behaviors, regional norms, and silence patterns that reliably precede problems. Early data on where the next issue is most likely to originate, and when.

Operational concerns

Supplier, workforce, or management issues that may affect performance as well as compliance.

Where risk actually hides

Culture surveys tell you what employees are willing to say. Trust determines what they are willing to disclose.

The gap between the two is where problems accumulate.

← Trust Score (Low to High)
High trust · Low culture score
Visible Risk

Low Culture Score, but Employees Will Speak Up.

Problems tend to surface through normal channels.

High trust · High culture score
Clean

High Culture, High Trust. Issues Surface.

Your program works here.

Low trust · Low culture score
Critical Risk Zone

Elevated Risk

Weak culture and low trust increase the risk that material concerns remain undisclosed.

What your program misses
Low trust · High culture score
The Blind Spot

Strong Survey Scores. No Hotline Reports. Leaders Say Everything Is Fine.

This is where issues accumulate, and where conventional programs cannot look.

 
← Culture Score (Low to High) →
Illustrative. Not based on specific client data.
Chapter 04

Proof

  • Case study
  • Why a strong program is not enough
  • Benefits beyond compliance
  • In practice
Illustrative scenario

Global manufacturer · $4B revenue · Southeast Asia operations

The Situation

Strong compliance metrics. Few hotline reports across Southeast Asian subsidiaries in 18 months. Annual culture survey rated the region 4.2 out of 5.0. The program showed nothing unusual.

What We Found

Trust scores told a different story. Through structured relationship conversations, practitioners identified a pattern: systematic payments to customs officials, known to regional management, treated as a normal cost of operations, and never reported.

The Outcome

The company evaluated voluntary disclosure, implemented targeted remediation, and strengthened board oversight. The matter illustrates how earlier visibility can preserve more response options.

Why a strong program is not enough

DOJ guidance focuses on whether compliance programs function effectively in practice. KINVERITY can help create evidence of risk-based outreach, employee access to reporting channels, escalation discipline, and documented remediation. It is designed to complement, rather than replace, the existing compliance framework.

01

The DOJ Compliance Bar Has Shifted

Regulators now evaluate whether a compliance program actually detects things, not whether policies exist and training was completed. A program that produces clean survey scores but never surfaces anything is not passing that test anymore.

02

FCPA Enforcement Continues, Despite What Some Assume

A change in administration is not the same as a change in enforcement. Foreign regulators, the UK SFO and European authorities among them, operate entirely independently of U.S. political cycles. Companies that have quietly lowered their guard are taking on real, unpriced exposure.

03

The Risk Is Where You Already Operate

India, China, Latin America, the Middle East, Africa. The same regions in the Stanford FCPA data are the regions you are already in. You have exposure. The question is whether you find it, or the government does.

04

This Program Generates the Evidence a DOJ Review Asks For

The updated Evaluation of Corporate Compliance Programs guidance asks whether your program is “adequately resourced and empowered to function effectively.” Documented relationship networks, structured intelligence conversations, and early detection records answer that question directly. Your hotline logs alone do not.

1 / 4

Benefits beyond compliance

What a defined assessment produces, beyond the compliance record.

Earlier escalation

Operational and workforce concerns reach leadership sooner, while response options are still open.

Clearer communication

Better communication between headquarters and regional teams, in both directions.

Employee confidence

Stronger employee confidence in internal reporting, including in markets where hotlines see little use.

Operational visibility

Better visibility into supplier, management, and market risks that affect performance as well as compliance.

Board-level clarity

Clearer information for executive and board decision-making, supported by documentation.

Illustrative scenarios

Three examples of what trust infrastructure produces, beyond the compliance record

Market Intelligence

East Asia manufacturing operation. Regional staff flagged a supplier quality issue in month 3 of the program. The same type of issue had previously run 11 months before surfacing in a customer complaint, at roughly 8x the remediation cost. The intelligence existed. The trust to share it did not.

Workforce Stability

LATAM regional leadership transition. When the regional GM departed unexpectedly, established relationships kept local staff stable and productive throughout the 90-day transition. Comparable offices without trust infrastructure typically see 20 to 30% key-person attrition in similar transitions, knowledge that often takes years to rebuild.

Fraud Detection

UK global distribution company. A regional manager, trusted, high-performing, never flagged, had been running a procurement fraud scheme for years. A local participant surfaced it through a relationship conversation. The manager had seniority and the benefit of the doubt. The source had trust.

Chapter 05

Engage

  • What engagement looks like
  • The client playbook
  • Three ways to engage
  • Procurement red flags in the data

What engagement looks like

Four phases within a defined engagement. Each engagement has a defined scope, schedule, and conclusion. Any follow-on work is separately agreed.

Weeks 1 to 2

Scope and Discovery

One conversation about your footprint, risk profile, and the regions where you have the least visibility. No materials required. No prep.

Weeks 3 to 6

Regional Engagement

We enter each market as compliance trainers, running small-group sessions of no more than 20 people. That format is deliberate: people speak candidly in small groups. Together, we identify one or two employees per office to serve as compliance ombudsmen. These will be employees who are respected and trusted by colleagues.

Months 2 to 5

Structured Conversations

Follow-up visits, structured as training refreshers or working sessions, create repeated personal contact over months. The training is substantive. The relationships that form around it are what make honest disclosure possible.

Month 6

Findings and Action Plan

Deliver the final assessment, recommendations, supporting documentation, and escalation plan. The client may elect a separate follow-on engagement for another region or a targeted reassessment.

1 / 4

The client playbook

Five steps that determine how much the program can surface.

01

Name a Single Internal Owner.

The GC or CCO who owns the program, receives our memos, and can grant access without escalation. Without one, requests get rerouted and findings get managed by committee.

02

Align Regional Leadership Before We Arrive.

Regional leadership needs more than an introduction. They need to understand the program and actively back it. Staff take cues from local managers. If leadership is skeptical, that skepticism travels down before we arrive.

03

Share Your Existing Risk Intelligence.

Prior audit findings, hotline data, known issues in target regions. We use that as a baseline. Withholding it does not protect anyone. It costs time and occasionally costs accuracy.

04

Decide Who Sees What Before We Find Something.

Who receives our memos? Who gets briefed on a significant finding? Who approves escalation? Make these calls before the program starts. Decisions made under pressure, with a live finding already on the table, are rarely the right ones.

05

Keep the Framing Clean.

We enter each market as compliance trainers. That framing is deliberate. It is what makes honest conversations possible. Internal communications about the program need to reinforce it, not undercut it.

1 / 5
engagement tiers

Three ways to engage

Scope and intensity scale with your footprint. Pricing is scoped after a no-commitment discovery conversation.

All tiers personally led by Kevin R. Brenner: in-country, not delegated to junior staff or third-party vendors.

6-month engagement

Targeted Assessment

One office or market, typically completed within six months.

Regions: 1
Offices: 1
Cadence: Monthly
Deliverables: Quarterly memo plus ECCP brief for DOJ documentation
Crisis: Available as add-on

Defined 12-month assessment · Most requested

Regional Assessment

Two to three countries, with a defined assessment period and a consolidated regional report.

Regions: 2 to 3
Offices: 2 to 3
Cadence: Bi-weekly
Deliverables: Quarterly plus ECCP brief and GC briefing
Crisis: On-call

Phased annual assessment

Multi-Market Assessment

A phased review of selected jurisdictions, with executive and board-level reporting.

Regions: 4 to 6
Offices: 4 to 6
Cadence: Bi-weekly
Deliverables: Quarterly plus ECCP brief, Board and Audit committee
Crisis: Designated crisis-response availability

1 / 3

Procurement red flags in the data

For clients seeking a data-supported review, KINVERITY can assess vendor, invoice, payment, and approval data for anomalies requiring human review. The analysis identifies patterns for further investigation; it does not determine that misconduct occurred.

Vendor Concentration

One vendor absorbing a third of regional spend, priced well above comparable bids, with no competitive process on file.

Threshold Gaming

Multiple invoices from the same vendor, each sized just under the approval limit, filed within days of each other.

Payment Timing

Payments clearing within 48 hours of a customs or licensing deadline, in a market where standard terms run 30 to 45 days.

Employee and Supplier Ties

An approving employee sharing an address, phone number, or bank detail with a vendor they repeatedly approve for payment.

The agent surfaces the anomaly. We decide what it means, alert you, and investigate. Scoped to your footprint. Priced after a discovery conversation.

Illustrative patterns, plus other deviations from normal activity. Not based on specific client data.

Get better visibility into one market.

Start with a defined assessment of the region or operation where leadership has the least confidence in existing reporting. Fixed scope. Defined deliverables. No commitment beyond the agreed engagement.

Practice Lead
Kevin R. Brenner
FCPA & Anti-Corruption · Investigations · Former Federal Prosecutor

THEIR SIDEYOUR SIDE
THEIR SIDEYOUR SIDE

Strategic Legal Counsel for Healthcare & Health Technology

Your organization faces legal and regulatory complexity that demands more than outside counsel. It demands a partner who has sat on your side of the table.

From government investigations and FCPA matters to healthcare M&A and payer contracting, we’ve handled it from the inside and from the courtroom.

Whether you need fractional leadership, transactional support, or a defensible compliance framework, we deliver counsel built around what the business actually needs. What sets us apart is real-world in-house experience. Our partners have served in senior legal roles within large and publicly traded companies, giving them a direct understanding of what business leaders and boards actually need from legal counsel.

Book a discovery call now

Schedule a Consultation

Finding what your compliance program can’t see. A relationship-based intelligence program for surfacing FCPA, fraud, and culture risk in the operations where your hotline goes quiet.

Connect With
Global Link Law

"*" indicates required fields

This field is for validation purposes and should be left unchanged.