Developing an Effective Consequence Management Process

Developing an Effective Consequence Management Process

Table of Contents

  1. Introduction
  2. About Intuit
  3. The Importance of Consequence Management
  4. Defining Risk Tolerance
  5. Defining Violations and Consequences
  6. The Consequence Management Process
    1. Identifying Stakeholders
    2. Establishing Risk Tolerance
    3. Defining Violations
    4. Determining Consequences
    5. Assigning Responsibility
    6. Setting Expectations
  7. Communicating Findings
  8. Continuous Improvement
  9. Challenges in Implementing a Consequence Management Program
  10. ROI of a Consequence Management Program
  11. Conclusion

🔍 Developing a Consequence Management Process for Effective Compliance

In today's business landscape, compliance with laws and regulations is crucial for companies to thrive. For global organizations like Intuit, ensuring compliance and holding employees accountable for their actions is of paramount importance. In this article, we will explore the concept of consequence management and how it plays a crucial role in effective compliance programs. By developing a robust consequence management process, companies can address compliance findings objectively, consistently, effectively, and efficiently.

About Intuit

Intuit is a leading provider of financial management and compliance solutions, with flagship products like TurboTax, QuickBooks Pro, Connect, and Mint. With offices in the United States, Canada, United Kingdom, India, and other locations, Intuit has a strong global presence. As a compliance manager at Intuit, Melanie Gallagher is at the forefront of back-office technology and plays a vital role in ensuring compliance with laws and regulations worldwide.

The Importance of Consequence Management

Compliance programs rely on effective measurement tools and consequences for policy violations. Measurement enables companies to gauge employee behavior, detect misuse, abuse, fraud, and identify areas for improvement. Robust consequence management allows organizations to address findings objectively, consistently, effectively, and efficiently. It also helps companies demonstrate to auditors and regulators that they have an effective compliance program in place. Moreover, consequence management promotes behavior changes, accountability, policy improvements, and increased awareness and education for employees.

Defining Risk Tolerance

Before implementing a consequence management process, it is crucial to Align stakeholders and define risk tolerance. Risk tolerance varies from company to company, based on factors such as industry regulations and the company's culture. It is essential to assess whether the company encourages innovation and risk-taking or operates in a highly regulated industry. By defining risk tolerance, companies can determine the level of flexibility in their policies, assess the likelihood and impact of potential risks, and establish the boundaries of acceptable behavior.

Defining Violations and Consequences

Defining violations is a critical step in developing a consequence management process. The definition of violations should be agreed upon by key stakeholders, including Human Resources, legal teams, corporate investigations, chief procurement officers, and business leaders. It is important to specify what constitutes misuse, abuse, and fraud, and provide clear examples to ensure consistent understanding across the organization. Moreover, determining the appropriate consequences for violations is essential. Organizations should decide what is considered a warning, a fireable offense, or other disciplinary actions. By setting clear definitions and consequences, companies can ensure accountability and consistency in their compliance programs.

The Consequence Management Process

The consequence management process involves several key steps that enable organizations to address compliance findings effectively and efficiently. It begins with identifying stakeholders and getting their agreement on risk tolerance, violation definitions, and consequences. Once these are established, responsibilities are assigned to specific individuals or teams responsible for implementing the consequence management process. Clear expectations are set, and communication channels are defined to ensure consistent messaging and reporting. This creates an auditable and standardized approach, minimizing subjectivity and potential bias.

Communicating Findings

Communication is crucial in any consequence management process. Clear and effective communication helps employees understand the consequences of policy violations and reinforces company values and expectations. By providing Timely feedback and using templates for approving or rejecting expense reports, organizations can educate employees and drive behavior change. Communication should be consistent, reinforcing policy compliance, and providing guidance on Where To find additional resources or assistance.

Continuous Improvement

A consequence management process should not be static; it should evolve continuously. Regular reviews of policies, controls, and training programs are essential for identifying areas of improvement and enhancing compliance programs. By incorporating feedback from stakeholders and leveraging the data and insights gathered from audits, organizations can bolster their policies, controls, and training to adapt to changing compliance requirements.

Challenges in Implementing a Consequence Management Program

Implementing a consequence management program can pose several challenges. These include aligning stakeholders, establishing risk tolerance, and agreeing on violation definitions and consequences. Working collaboratively with Human Resources, legal teams, and other functional groups is crucial to ensure a unified and effective program. Additionally, overcoming resistance to change and ensuring consistent implementation across different regions or employee levels might pose difficulties. However, the benefits of an efficient consequence management program outweigh the initial challenges.

ROI of a Consequence Management Program

Although developing and implementing a consequence management program requires upfront investment in time and resources, it yields significant returns on investment. Companies can witness behavior change, increased awareness of policies, and a decline in violations, leading to improved compliance and decreased risks. A well-implemented program builds a culture of accountability and responsibility, reducing the likelihood of regulatory issues and enhancing the company's reputation.


A consequence management process is an integral component of any effective compliance program. By aligning stakeholders, defining risk tolerance, violations, and consequences, and establishing clear roles and responsibilities, organizations can address compliance findings consistently and objectively. Effective communication, continuous improvement, and managing challenges contribute to the success of the program. Implementing a consequence management program requires commitment, but the ROI in terms of improved compliance and reduced risks is well worth the effort.


  • A consequence management process enables organizations to address compliance findings objectively, consistently, effectively, and efficiently.
  • Defining risk tolerance is crucial for determining the level of flexibility in policies and assessing potential risks.
  • Clear definitions and consequences for violations promote accountability and consistency in compliance programs.
  • The consequence management process involves identifying stakeholders, defining risk tolerance and violations, assigning responsibilities, setting expectations, and establishing communication channels.
  • Open and consistent communication helps employees understand consequences, reinforces values, and drives behavior change.
  • Continuous improvement and adaptation enhance compliance programs over time.
  • Implementing a consequence management program may face challenges such as stakeholder alignment and resistance to change.
  • A well-implemented program yields a high ROI with behavior change, increased policy awareness, and reduced risks.


Q: What is the purpose of consequence management in compliance programs?

A: Consequence management aims to address compliance findings objectively, consistently, effectively, and efficiently. It promotes behavior change, accountability, policy improvements, and increased awareness and education for employees.

Q: How can organizations define risk tolerance?

A: Risk tolerance is defined by assessing factors like industry regulations, company culture, and the level of innovation and risk-taking encouraged by the organization. It helps determine the boundaries of acceptable behavior and assess the likelihood and impact of potential risks.

Q: Why is communication important in the consequence management process?

A: Effective communication ensures that employees understand the consequences of policy violations, reinforces company values and expectations, and provides guidance on resources and assistance. It drives behavior change and fosters a culture of compliance.

Q: How can organizations ensure continuous improvement in their compliance programs?

A: Continuous improvement involves regular reviews of policies, controls, and training programs. Feedback from stakeholders, Data Insights from audits, and industry developments help identify areas of improvement and adapt to changing compliance requirements.

Q: What challenges may organizations face when implementing a consequence management program?

A: Implementing a consequence management program may require aligning stakeholders, establishing risk tolerance, and overcoming resistance to change. Consistent implementation across regions or employee levels can also be challenging. However, the long-term benefits outweigh the initial challenges.

Note: This article is based on the content of a webinar hosted by Intuit featuring Melanie Gallagher, Senior Compliance Manager at Intuit.

Find AI tools in Toolify

Join TOOLIFY to find the ai tools

Get started

Sign Up
App rating
AI Tools
Trusted Users
No complicated
No difficulty
Free forever
Browse More Content