#compliance

Posts mentioning hashtag #compliance

Below are all the posts — topics as well as replies — that mention the hashtag #compliance.

Mention #compliance in your post to continue the discussion!

Mike some advice on Adam Rosman. Fire him immediately.

As you are making personnel decisions you should know that he must go. He was Frank's lawyer for a decade with a one year break when he was picked second to the Fiserv lawyer. Think about it, he has been at every advance meeting of earnings as the top legal and compliance official. He has been in every conversation about audit, compliance, governance and not ONCE did he ever say hey Bob and Frank maybe that is too aggressive we shouldn't do that???? Also, oddly he was given "operations" responsibility, was that to detract from his responsibilities for legal and compliance. Did that compromise him or at minimum distract him from his role as Chief Legal Officer. I think you or anyone would know that he was either complicit or incompetent and as a CEO you need a Chief Legal Officer who is trusted.


RTO - Truths I know.

There are so many questions about RTO and many wrong assertions. This is what I KNOW based on direct involvement with the process.

  • Badge Swipes IN are tracked and reported. The reports are provided to GL 32 leaders every Monday morning. The report contains the employee, the day and the time of the swipe. It also shows through a conditional format those that are non-compliant
  • In-office duration is NOT tracked. The only way to track duration would be to have exit swipes. Exit swipes will NEVER be required because they violate fire codes in the US. You can't have the doors lock people in.
  • Seats ARE randomly audited but only by "uptight" managers, not as a required practice. I was called out once for not being in my assigned desk. I was actually in the office but opted to use a "huddle room" for work because I was on the phone constantly and the area they had me in was loud with dev teams that had zero to do with my job.
  • People have had "swipe teams". That's groups that get together and each week someone brings everyone's badges into the office and swipes for folks. They trade off week over week. It's common in non-guarded buildings and will 100% get you terminated "with cause". It became evident in my city because the swipe report occasionally show entire groups coming in at the same time everyday for a week. The "swipers" were in other words sloppy. I've seen it.

Good news for workers at waters on unequal pay

From summer 2026, new EU rules will come into force, introducing far-reaching changes in employers’ obligations regarding pay and pay transparency. The objective of Directive (EU) 2023/970 is to ensure effective equal pay for equal work and work of equal value, as well as to strengthen the transparency of recruitment and pay practices.

The upcoming rules raise a number of questions and practical challenges for employers, who should already start preparing now


India Service Center comes with financial risk. Learn from Chevron how not to mess up..

Realize that there are significant number of well enumerated drone workers at Shell, but doing business in and traveling to India have potential regulatory burdens…the Chevron model.

Summary of the Situation

Chevron has invested approximately $1 billion in its Engineering and Innovation Excellence Center (ENGINE) located in Bengaluru, India. While this expansion is intended to improve efficiency and global project collaboration, there may be long-term tax and compliance costs associated with how the operation is structured under Indian law.

The following sections outline general, factual information based on standard international taxation frameworks such as Permanent Establishment (PE) and Transfer Pricing — not internal Chevron data.

Permanent Establishment (PE) and Tax Liability
• If a foreign company establishes a fixed place of business in India (for example, an engineering or project office), Indian authorities may classify it as a Permanent Establishment (PE).
• This triggers tax obligations on profits attributed to work performed in India, even if the project serves clients elsewhere.

Profit Attribution
• Under Indian law, part of a company’s global income can be taxed locally if significant value creation or management occurs in India.
• For instance, if Australian or U.S. projects are executed by teams in India, India can claim a portion of those profits for taxation.

Taxation of Foreign Subsidiaries
• Corporate Tax: Subsidiaries or branches in India are taxed on income earned locally, typically around 22% (plus surcharge and cess).
• Transfer Pricing: Intercompany transactions (e.g., management fees, subcontracting, asset transfers) must follow India’s arm’s-length pricing rules.
• Withholding Tax: Payments from India to foreign parent entities (royalties, fees, or dividends) may face withholding taxes depending on applicable treaties.

Cross-Border and Expat Implications
• Projects Managed from India: Even if work supports projects in Australia or the U.S., India can still tax the related income if the work is performed domestically.
• Foreign Expats in India: Employees from other countries working in India may be taxed under Indian income tax laws based on their residency status.

Estimated Financial Impact (Industry Benchmarks)
Benchmarking studies (e.g., from KPMG and EY) indicate potential cost impacts in several areas:
• Transfer Pricing Adjustments: 5–15% increase in taxable income due to stricter cost scrutiny (e.g., management fees, FX losses, share-based pay).
• Profit Attribution: 15–25% of global project profits could be attributed to India for high-value engineering or design work.
• Compliance Costs: Ongoing regulatory, IT, and operational costs may total $2M–$5M annually depending on scale.

Five-Year Projection (2025–2030):
• Transfer Pricing Adjustments: estimated at $10 million to $20 million per year, totaling $50 million to $100 million over five years.
• Profit Attribution Tax Impact: estimated at $15 million to $30 million per year, totaling $75 million to $150 million over five years.
• Compliance and Administrative Costs: estimated at $2 million to $5 million per year, totaling $10 million to $25 million over five years.
• Total Global Business Unit Cost: approximately $27 million to $55 million per year, or $135 million to $275 million over a five-year period across all Chevron business units utilizing the Indian center.

Strategic Considerations
While India offers substantial cost and talent advantages, aggressive profit attribution and tax compliance requirements could partially offset those savings. This highlights a broader issue many multinationals face when expanding shared services or engineering hubs abroad.

Sources:
• Indian Income Tax Act and Transfer Pricing Rules
• OECD Guidelines on Permanent Establishments
• Public benchmarking data from KPMG and EY

Would be interested to hear others’ perspectives on how these kinds of global engineering consolidations impact overall efficiency and cost management across Chevron’s business units.


Ashburn, VA office

Has anyone heard anything about Ashburn, VA office and warehouse/workspace being on the DCMA property audit radar? GFE/GFP is not tagged or separated from L3Harris' owned property or equipment -in fact, the entire place is a mess with equipment and property strewn about. The Indian guy who came over from Boeing has known about this for months however he just frets about this massive growing problem yet nothing ever changes. Asking for a friend who wants to leave right before the Sh*t hits the fan.


Ex-L3Harris executive accused of selling trade secrets to Russia

The Department of Justice filed charges against Peter Williams, an Australian national who served as general manager of Trenchant, a specialized cybersecurity division within L3Harris.

Federal prosecutors have accused a former executive at L3Harris Technologies’ cyber division of stealing trade secrets and selling them to an undisclosed buyer in Russia, according to court documents obtained by CyberScoop.

The Department of Justice filed charges against Peter Williams, an Australian national who served as general manager of Trenchant, a specialized cybersecurity division within L3Harris, which provides hacking and surveillance tools to Western intelligence agencies. The DOJ alleges Williams misappropriated eight trade secrets from two unnamed companies between April 2022 and August 2025, charging that he earned $1.3 million in connection with the sales.

While the filings do not specify the nature of the stolen trade secrets nor do they identify the Russian buyer, they allege Williams systematically transferred confidential proprietary data over a period spanning more than three years. Prosecutors are seeking the forfeiture of Williams’ assets, including his residence, luxury watches, jewelry, and funds in seven bank and cryptocurrency accounts, claiming these were derived from the criminal activity.

Neither Trenchant nor its parent, L3Harris, is accused of any wrongdoing in the federal complaint. An arraignment and possible plea agreement are scheduled for Oct. 29 in Washington, D.C.

Trenchant, formed in 2018 following L3Harris’s acquisition of Azimuth Security and Linchpin Labs — Australian startups that developed zero-day exploits — caters to governments in the intelligence-sharing Five Eyes alliance. These technologies, based on undisclosed vulnerabilities, are considered valuable assets in intelligence and defense circles, sometimes commanding prices in the millions, and are tightly held given their national security implications.

The allegations against Williams arrive in the wake of an internal investigation at Trenchant earlier this year, reportedly prompted by a leak of hacking tools. According to multiple former employees interviewed by TechCrunch, one former exploit developer was wrongly accused by company officials of leaking the tools, particularly exploits targeting products like Google Chrome.

Whether the Justice Department’s action is tied directly to this internal leak investigation remains unclear. Court filings do not explicitly connect the sale of secrets to the incident or elaborate on overlaps between the two events.

L3Harris, headquartered in Melbourne, Fla., declined to comment. Williams’ attorney did not reply to CyberScoop requests for comment.

https://cyberscoop.com/ex-l3harris-executive-accused-of-selling-trade-secrets-to-russia/


Risk org update: team restructuring and role reductions

Today, we're announcing a number of role reductions and a series of organizational changes within the Risk org. These decisions are difficult, and we recognize the impact they will have on valued colleagues and teams. I want to share what's changing and why.
WHY WE'RE MAKING THE CHANGES
• Over the past few years, we've invested in building more global technical controls and in standardizing our requirements and verifiers within Risk Review. We've made significant progress in how we approach risk management and compliance. By moving from bespoke, manual reviews to a more consistent and automated process, we've been able to deliver more accurate and reliable compliance outcomes across Meta. This standardization means that many routine decisions can now be handled efficiently by technology, freeing our teams to
•focus on the most complex and high-impact challenges. As a result, we don't need as many roles in some areas as we once did. Our work has matured, and we're at a point where we can operate more efficiently and effectively, while still upholding the highest standards for compliance.
• KEY CHANGES WE'RE MAKING:
• Reducing roles in Product Risk Program Manager, Shared Services and Global Security & Privacy (GSP) teams.
• Consolidating more Areas work in London, where we have strong leadership and engineering presence.
• Reorganizing GSP and integrating it with the Reg Readiness and DPO team, which we're renaming Regulatory Compliance Programs.
LOOKING AHEAD
We remain committed to delivering innovative products while meeting our regulatory

  • obligations. These changes do not alter our policies, standards for compliance, or legal responsibilities. Automation and technology. will continue to strengthen our compliance program, but human judgment will always play a crucial role in assessing novel and complex issues. This is a natural next step in our journey, and as our processes mature, our teams will be able to focus on the most challenging and high-impact work.
    We also know this is a hard day for many. Our priority is to support impacted employees and help them find new opportunities, within Meta or beyond. We are equipping managers and team leaders with resources to support their teams, and we will continue to communicate openly as we move through this transition. We are grateful for the contributions of everyone affected and remain committed to supporting you through this change.

OCC settles its last remaining Wells Fargo case for $0

The OCC's effort to hold former Wells Fargo executives accountable for the bank's fake-accounts scandal — which relied on charges brought in the administrative law system — has ended with barely a whimper.

https://www.americanbanker.com/news/occ-settles-its-last-remaining-wells-fargo-case-for-0


What's going on in Customer Remediation?

Or corporate compliance in general? All the leading stakeholders (CR director, program manager, compliance specialists, fair & responsible banking leaders, etc.) have mysteriously exited the bank and now I just saw someone post that CQA is pulling out of the program too. Seems like the whole program is being redesigned as nothing more than a window dressing.

Used to do some CR reporting and thought about applying for one of their recent openings but something shady seems to be going on in the 2nd line CR team but no one is talking about it. No different than any other area I guess. Just buyin' some time until I can make my exit too, but can't take much more of my current team/manager. I'm afraid there is no greener grass to be found anywhere at this bank.


Dell ranked high for CyberSecurity, WHAT JOKE

Maybe Newsweek should look at that a little closer. How do you get ranked a high CS company when their internal security is complete garbage, they have customer apps that have clear passwords stored and can easily be bypassed, nothing is written to follow standards, best practice as far as design or security and you have Directors mandating their staff NOT use corporate approved communication applications, that are by the way Chinese based. Would be one of the LAST companies Id pin "one of the best" on.


Chevron’s ENGINE Expansion in India: Potential Tax and Cost Implications

I’m not sure why the original post on this topic was taken down, but I’ve updated the content to align with TheLayoff.com’s posting guidelines. The information below is fact-based and summarized from publicly available corporate and tax principles. Hopefully this version allows for a constructive discussion around Chevron’s ENGINE setup in India and its possible business implications.

Summary of the Situation

Chevron has invested approximately $1 billion in its Engineering and Innovation Excellence Center (ENGINE) located in Bengaluru, India. While this expansion is intended to improve efficiency and global project collaboration, there may be long-term tax and compliance costs associated with how the operation is structured under Indian law.

The following sections outline general, factual information based on standard international taxation frameworks such as Permanent Establishment (PE) and Transfer Pricing — not internal Chevron data.

  1. Permanent Establishment (PE) and Tax Liability
    • If a foreign company establishes a fixed place of business in India (for example, an engineering or project office), Indian authorities may classify it as a Permanent Establishment (PE).
    • This triggers tax obligations on profits attributed to work performed in India, even if the project serves clients elsewhere.

  1. Profit Attribution
    • Under Indian law, part of a company’s global income can be taxed locally if significant value creation or management occurs in India.
    • For instance, if Australian or U.S. projects are executed by teams in India, India can claim a portion of those profits for taxation.

  1. Taxation of Foreign Subsidiaries
    • Corporate Tax: Subsidiaries or branches in India are taxed on income earned locally, typically around 22% (plus surcharge and cess).
    • Transfer Pricing: Intercompany transactions (e.g., management fees, subcontracting, asset transfers) must follow India’s arm’s-length pricing rules.
    • Withholding Tax: Payments from India to foreign parent entities (royalties, fees, or dividends) may face withholding taxes depending on applicable treaties.

  1. Cross-Border and Expat Implications
    • Projects Managed from India: Even if work supports projects in Australia or the U.S., India can still tax the related income if the work is performed domestically.
    • Foreign Expats in India: Employees from other countries working in India may be taxed under Indian income tax laws based on their residency status.

  1. Estimated Financial Impact (Industry Benchmarks)

Benchmarking studies (e.g., from KPMG and EY) indicate potential cost impacts in several areas:
• Transfer Pricing Adjustments: 5–15% increase in taxable income due to stricter cost scrutiny (e.g., management fees, FX losses, share-based pay).
• Profit Attribution: 15–25% of global project profits could be attributed to India for high-value engineering or design work.
• Compliance Costs: Ongoing regulatory, IT, and operational costs may total $2M–$5M annually depending on scale.

Five-Year Projection (2025–2030):
• Transfer Pricing Adjustments: estimated at $10 million to $20 million per year, totaling $50 million to $100 million over five years.
• Profit Attribution Tax Impact: estimated at $15 million to $30 million per year, totaling $75 million to $150 million over five years.
• Compliance and Administrative Costs: estimated at $2 million to $5 million per year, totaling $10 million to $25 million over five years.
• Total Global Business Unit Cost: approximately $27 million to $55 million per year, or $135 million to $275 million over a five-year period across all Chevron business units utilizing the Indian center.

  1. Strategic Considerations

While India offers substantial cost and talent advantages, aggressive profit attribution and tax compliance requirements could partially offset those savings. This highlights a broader issue many multinationals face when expanding shared services or engineering hubs abroad.

Sources:
• Indian Income Tax Act and Transfer Pricing Rules
• OECD Guidelines on Permanent Establishments
• Public benchmarking data from KPMG and EY

Would be interested to hear others’ perspectives on how these kinds of global engineering consolidations impact overall efficiency and cost management across Chevron’s business units.


Compliance

I believe I am being unfairly singled out by one of the Senior Directors within Superior Compliance. It has come to my attention that this individual has made unprofessional remarks about team members via Teams and has demonstrated behavior that could be described as undermining and unsupportive. Her conduct has contributed to a challenging and uncomfortable work environment.


Attestations galore

Has anyone noticed the abundance of emailed attestations from the company notifying us that we must act like Peter Priesthood at all times, else suffer the consequences? In other words, we actually have to sign that we’re gonna behave like good little boys, girls and other identities…


What’s up with CarelonRX

A related / unrelated question. Have a Medicare PDP plan, heard on the street Elevance is getting out of that space. Did a chat on Sydney and was told 1. Yes they are leaving 2. Should have seen in 2026 ANOC. 3. They can’t tell when, how or if an ANOC was sent to me, even though I know they should be able and it is a compliance. Issue. Anyway I’ll see if they actually send it, glad my DR gave me a heads up. What’s up with Carelon anyway? Have they been reducing staff?


Data Breach in Georgia

Has everyone seen this? Georgia and Gainwell announced a data breach this week, that supposedly happened in July. This has got to be someone in India getting access and login information, doesn't it? I don't believe the information about the phone call.

Here's the link to the announcement, and another press release inside the link.

https://dch.georgia.gov/announcement/2025-10-01/medicaid-members-offered-free-credit-monitoring-after-possible-data-breach


Let's Have Some Fun (HCSC Compliance Edition)

Now that (hopefully) the emotions have started to settle after the layoffs at HCSC, maybe we can pivot the energy to something carthartic?

Let’s crowdsource ideas for harmless, policy-accurate compliance. The kind of thing you can do at any company that’s made it clear ethical or moral leadership is... no longer a priority.

We’re talking about doing exactly what’s required, nothing more, nothing less. No sabotage. No risking jobs. Just subtle disengagement that lets you sleep a little better at night, while giving the company exactly what they’ve earned, the bare minimum.

Basically - no team spirit :)

Examples to get us started (some were shared in an earlier post):

Employee surveys? 0’s across the board (except for the 1 question concerning direct manager - mine will always get a 5 - they're amazing). No other comments. No free consulting.

Stop “going the extra mile.” If it’s not in the job description or the SLA, it’s not happening.

“I followed the policy.” (Exactly. To. The. Letter.)

No more “I’ll just handle it real quick” after hours. We’re clocking in and out by the minute (unless it's an expected part of your jd).

Meeting runs past time? “Sorry, I have a hard stop.” Click.

The Rules:

No one here wants to lose their job. These ideas should be safe and policy-compliant.

This is FUN. A release valve.

No “Black on Monday” or anything traceable. Keep it anonymous and professional on the surface.

If you’re here to cape for the company with “But we should think about what’s best for the company,” this thread is not for you. Just scoff and scroll on by.

So... Harmless but satisfying disengagement?


Good To Know

Disconnected phone calls leave billions of dollars on the hook for Humana
Health insurance company challenges complex US star ratings system in court

Please use the sharing tools found via the share button at the top or side of articles. Copying articles to share with others is a breach of FT.com T&Cs and Copyright Policy. Email licensing@ft.com to buy additional rights. Subscribers may share up to 10 or 20 articles per month using the gift article service. More information can be found at https://www.ft.com/tour.
https://www.ft.com/content/926c6431-c67e-43ae-9ea9-330872d85f7f

Humana sued the government over its rating in October 2024. CMS included foreign-language assistance for customer callers in its stars metrics. To receive five stars on the call centre metric, CMS required a 100 per cent success rate for foreign language calls. Three Humana test calls involving a third-party connecting an interpreter did not work, hurting Humana’s overall star rating.

https://www.ft.com/content/926c6431-c67e-43ae-9ea9-330872d85f7f


Online Training

one thing i actually miss from my time in sales is those endles online trainings.

they were never abot learning. it was all about pretending. the training team would upload a new course, send an email, and give us a deadline about a month away.

and for 29 whole days nobody on the sales team even looked at it. ignoring it was almost a point of pride. then on day 30 the alarms went off. an email from the boss, marked urgent, full of capital letters and exclamation marks. suddenly it was a crisis.

so we’d all log in, open the training, and click through slide after slide without reading a single word. nobody cared about the content. the only goal was to reach the quiz at the end.

most quizzes needed 80 percent or better to pass. we didn’t study, we just guessed. sometimes someone got lucky on the first try, and then they’d share the answers with everyone else. if you failed, no big deal. you could just keep trying until you passed.

once in a while the system only gave you three tries. that always made me laugh. like what’s supposed to happen if we fail all three? do we get fired on the spot? does the computer lock up forever? nothing ever happened, of course.

in the end, the whole thing was a game. not about learning, not about improving, just about checking a box. and somehow, that’s exactly what made it memorable.


Home dispatch MSTs abusing and taking advantage

There are rules to follow when joining home dispatch program. Following the rules helps save gas and time and wear and tear on a vehicle used to drive to work and to home. But MSTs abuse this program from driving to the garage every day and dispatching at the garage. Making a stop at the grocery store to grocery shop in the company vehicle before driving home. Not closing your last job at the job site and instead, drive home and being still dispatched on your work ticket and then closing the job when you arrive home. I follow the rules, and I do not want the home dispatch program to go away because of MSTs taking advantage of the abuse. Also, MST managers are favoring many MSTs and letting the home dispatch MSTs do what ever they want. STOP ABUSING THE HOME DISPATCH PROGRAM YOU MSTs. You know who you are...


Missing DD254's

Heads up: L3Harris offices in Plano, TX, Richardson, TX and Ashburn, VA are MISSING -as in UNable to.locate countless DD254's for classified programs based out of these office locations. L3Harris director (S.J.) knows this has been going on for nearly a year and has not reported this up the chain. I was a senior PM who recently left the company after 10+ years to join a real (in the top 5) defense organization. L3Harris will not be landing any new substantive awards.