is the system in compliance with applicable law? 3. **Assess the gap between compliance and ethics** — where does the law fall short of ethical requirements? 4. **Evaluate existing governance mechanisms** — does the organization have an ethics program, impact assessments, audit processes?