Categories
Blog

Leadership Lessons from The Changeling

Leadership Lessons for Compliance Professionals from “The Changeling”

Compliance, fundamentally, is about leadership. It is about guiding individuals and entire organizations to act ethically, responsibly, and effectively, even when the path is uncertain or challenging. Today, we venture boldly into the classic episode “The Changeling,” which offers rich lessons in leadership directly applicable to corporate compliance. Here are five key lessons from the episode that illustrate critical skills compliance leaders must master.

Lesson 1: Clarity of Purpose is Essential

Illustrated by: Originally designed as a peaceful explorer, its mission was corrupted following a collision with an alien probe called “Tan Ru,” causing its core directives to merge and mutate dangerously.

Compliance Lesson. Compliance leaders must maintain absolute clarity about their purpose and objectives.

Lesson 2: Effective Communication Prevents Crisis Escalation

Illustrated by: Kirk’s precise, deliberate communication with Nomad slows down its destructive tendencies and provides crucial time to develop a solution.

Compliance Lesson. Communication in compliance crises is similarly critical. Compliance leaders must communicate clearly, calmly, and thoughtfully, particularly in high-stakes scenarios.

Lesson 3: Recognize When Adaptation is Necessary

Illustrated by: Initially, Kirk tries conventional diplomatic approaches. Recognizing that conventional methods have failed, he adapts swiftly and strategically.

Compliance Lesson. In compliance leadership, adaptability is essential. Regulatory landscapes and compliance risks constantly evolve, necessitating quick pivots and agile leadership responses.

Lesson 4: Confront Problems Directly and Courageously

Illustrated by: When Nomad determines Captain Kirk himself to be flawed and thus a threat, Kirk faces Nomad directly, boldly confronting it without hesitation, despite understanding the risk involved.

Compliance Lesson. Compliance leaders must similarly confront compliance issues directly and courageously. Avoiding difficult conversations or deferring tough decisions can magnify risks and vulnerabilities.

Lesson 5: Cultivate Critical Thinking Within the Team

Illustrated by: Throughout the episode, Kirk relies heavily on his team, particularly Spock’s analytical logic, Scotty’s technical skills, and Uhura’s linguistic insights after Nomad erases her memory.

Compliance is a collaborative discipline that requires collective critical thinking from diverse team members.

Final ComplianceLog Reflections

Each leadership lesson in this episode, clarity of purpose, effective communication, adaptability, courageous confrontation, and fostering critical thinking, is fundamental to guiding organizations safely through the complex maze of modern compliance challenges. Compliance leaders today face situations not unlike the Enterprise crew: unexpected challenges, high stakes, and rapidly changing conditions. The effectiveness of compliance hinges significantly on leadership skills that navigate these complexities with clarity, confidence, and ethical fortitude.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

Security, Extortion, and the New Compliance Mandate in Cartel-Driven Markets

This blog continues our series on the ACI Forum on Cartels, TCOs, and Compliance in Latin America and why it is so timely. What we are seeing across the region is not simply another enforcement trend. It is a structural change in the way compliance officers, boards, legal departments, security teams, and business leaders must assess and manage risk. The issue is where security, extortion, compliance, and enterprise risk management now sit at the same table.

The key point is one that every compliance professional has heard after a failure: “We did not see that coming.” In most cases, that statement does not mean the risk was invisible. It means the organization was not looking in the right way. It had a preconceived view of its threat environment. It relied on familiar dashboards. It accepted old assumptions. It conducted a risk assessment that confirmed management’s beliefs rather than testing them. That is not a security problem alone. That is a compliance failure.

Cartel Risk Is Now an Enterprise Risk

The designation of certain cartels and criminal organizations as Foreign Terrorist Organizations and Specially Designated Global Terrorists has changed the risk conversation. Executive Order 14157 established a process for certain international cartels and other organizations to be designated as FTOs or SDGTs and described international cartels as a national security threat beyond traditional organized crime, including through infiltration of governments across the Western Hemisphere. OFAC also lists an alert on international cartels designated as FTOs and SDGTs as part of its counterterrorism sanctions resources. (OFAC)

For CCOs, this means cartel and TCO exposure cannot be treated as a regional security issue or as a one-time sanctions-screening exercise. It must be integrated into risk assessments, third-party management, contract review, internal controls, HR, community relations, logistics, government affairs, and crisis response.

True threat assessment begins by stepping back, looking at the full operating environment, and then breaking the risk down by function. The Department of Justice has made clear that compliance programs must be robust, well-resourced, and empowered, and that companies are expected to continuously review and update compliance programs to account for emerging risk factors. A static, annual, checklist-driven risk assessment is not fit for a cartel-driven operating environment.

THIRA as a Compliance Tool

One of the most useful concepts in the attached article is the use of Threat and Hazard Identification and Risk Assessment, or THIRA. THIRA began in the public-sector preparedness world, but its discipline translates well into corporate compliance. FEMA describes THIRA as a three-step risk assessment process that helps communities identify the risks of greatest concern and determine the capabilities needed to address them. FEMA also notes that identifying and assessing risk should be a key input into planning and that plans must be risk-informed.

For compliance professionals, that is the point. Do not begin with the control. Begin with the threat. What could happen? Who could exploit the business model? What routes, facilities, vendors, unions, brokers, security providers, customers, or local officials create exposure? What happens if a logistics route becomes unsafe, a vendor is coerced, a local union is compromised, a government permit is delayed unless a payment is made, or a security provider is connected to criminal actors?

THIRA-style analysis forces a company to model realistic scenarios, assess consequences, and then determine whether it can respond. That means authority, communications, escalation, training, legal review, security protocols, financial controls, and board reporting must all be stress-tested before the crisis.

Continuous Monitoring Is Not Optional

In ordinary compliance discussions, “continuous monitoring” can sound like a best practice phrase. In a high-threat environment, it is an operating necessity. The attached article notes that threats can change by the hour, routes can become unsafe, infrastructure can fail, and misinformation can spread intentionally.

The compliance parallel is direct. A company cannot rely only on lagging indicators, annual certifications, or publicly available reports. In cartel-influenced markets, yesterday’s intelligence can create today’s exposure. The risk function must have access to live operational data, hotline reports, security intelligence, payment anomalies, logistics disruptions, vendor changes, law enforcement alerts, and local business intelligence.

This also requires delegated authority. If compliance or security sees a threat but lacks authority to pause activity, reroute shipments, reject a vendor, escalate a payment, or stop a transaction, the program is underpowered. Policies without authority are not controls. They are artifacts.

The Board’s Role: Oversight, Not Assumption

Boards must also recalibrate. Duncan’s point that boards often understand risk exists but do not always understand their lane should resonate with every CCO. The board’s role is not to manage routes, approve security plans, or second-guess local threat intelligence. Its role is to ensure that management has identified the risk, defined risk tolerance, resourced the response, assigned authority, and created reliable reporting.

In cartel-driven markets, the board should ask, “Where are we operating in areas of criminal influence?” Which third parties are essential to those operations? How do we know they are not compromised? What payments, donations, sponsorships, logistics arrangements, or security relationships create exposure? What is our escalation protocol if an employee, vendor, union representative, community leader, or government official signals coercion?

Risk tolerance must be written, debated, approved, and revisited. Silence is not neutrality. It is permission.

Security Is a Compliance Function

The attached article makes another crucial point: security is not just physical. Insider threats, personal vulnerabilities, substance abuse, coercion, espionage, poor training, and cultural dysfunction all create compliance exposure. Employees must understand not only what the rules are but also why the rules matter and how criminal organizations exploit weak points.

In Venezuela, the State Department’s June 27, 2026, advisory tells travelers to reconsider travel because of crime, kidnapping, terrorism, poor health infrastructure, and natural disaster risk, and it identifies Tren de Aragua and Cartel de los Soles as FTOs that started in Venezuela and continue to operate. The same advisory states that the U.S. government has extremely limited capacity to provide emergency services to U.S. citizens, especially outside Caracas.  That is a board-level fact pattern. It affects duty of care, insurance, crisis response, employee travel, third-party security, incident reporting, and operational continuity.

Build the Threat Hub

The most practical recommendation is to create a threat hub. It should be a cross-functional forum where legal, finance, operations, security, compliance, and other functions review threats, vulnerabilities, and operational changes. This is precisely what mature compliance should look like in a high-risk market.

The threat hub should review incidents, routes, payments, vendor changes, customer anomalies, government interactions, community demands, employee reports, and security intelligence. It should have the authority to escalate. It should report to management and the board. It should test crisis plans through realistic exercises.

Practical takeaways

First, refresh the risk assessment now. Second, add THIRA-style scenario planning to cartel and TCO risk. Third, empower compliance and security to act in real time. Fourth, review third parties, major contracts, customers, logistics providers, unions, community intermediaries, and security vendors. Fifth, educate the board on its oversight role and require explicit risk tolerance.

The final lesson is simple. In high-threat markets, static programs fail. Assumptions kill preparedness. Authority matters. Culture is defined by what leaders tolerate. The choice for every company is whether to learn before or after the crisis.

This conversation makes clear that security, compliance, and risk are not separate disciplines. They are different lenses on the same problem: how organizations survive and succeed in uncertain environments. Security has taken on even greater importance in Venezuela as President Trump has announced the US will not provide any security to US companies returning to the country.

For compliance professionals, the takeaway is simple but uncomfortable. Static programs fail. Assumptions kill preparedness. Authority matters. Culture is shaped by what leaders tolerate. And boards must be educated partners, not distant overseers. In high-threat environments, failure is immediate and unforgiving. In corporate compliance, it is slower, but no less certain.

The choice, as always, is whether to learn before the crisis or after it.

The Cartels, TCOs & Compliance in Latin American conference will feature these topics and many more. For information and registration, click here. For the complete agenda, click here. You can receive 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
AI Today in 5

AI Today in 5: July 2, 2026, The Bank of the Future Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Does AI workflow matter more than the model? (FinTechGlobal)
  2. BoE says AI agents may need their own regs. (BankingExchange)
  3. Employers already rue laying off humans for AI. (CNBC)
  4. JPMorgan Chase is building the bank of the future. (Forbes)
  5. Human healthcare in the age of AI. (HospitalNews)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: July 2, 2026, The Is Bribery Good Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Judges urge prosecutors to drop corruption charges against Netanyahu. (TimesofIsrael)
  • Can bribery be a good thing? (ProMarket)
  • Google ordered to pay $2bn in Swedish antitrust case. (FT)
  • After the scandal, McKinsey shakes up the Board. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Kerr250 Podcast

The Kerr250 Podcast: 4 Books on the Continental Congress

Kerr250 is a community-focused podcast dedicated to celebrating America’s 250th birthday through the people, businesses, traditions, and events of Kerr County. As our nation marks this historic anniversary on July 4, 2026, Kerr250 will highlight the local celebrations and community efforts that bring this milestone to life. Each episode will feature conversations with local leaders, business owners, organizers, volunteers, and proud citizens who are helping make Kerr County a vibrant part of this national moment. The podcast will explore how history, patriotism, service, and community pride come together in one county that believes America’s strength has always come from its people. Kerr250 is where Kerr County honors the past, celebrates the present, and helps inspire the future. In this episode, we look at 4 Books on the Continental Congress.

  1. The Story of the First Continental Congress by CL Gammon
  2. American Legends by the Charles River editors
  3. Party Politics in the Continental Congress by James Henderson
  4. Reluctant Rebels by Lynn Montross

Resources:

Kerr250 website

GoodreadsTop Books on the Continental Congress

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 32 – Leadership Lessons from The Changeling

Compliance, fundamentally, is about leadership. It is about guiding individuals and entire organizations to act ethically, responsibly, and effectively, even when the path is uncertain or challenging. Today, we venture boldly into the classic episode “The Changeling,” which offers rich lessons in leadership directly applicable to corporate compliance. Here are five key lessons from the episode that illustrate critical skills compliance leaders must master.

Lesson 1: Clarity of Purpose is Essential

Illustrated by: Originally designed as a peaceful explorer, its mission was corrupted following a collision with an alien probe called Tan Ru, causing its core directives to merge and mutate dangerously.

Compliance Lesson. Compliance leaders must maintain absolute clarity about their purpose and objectives.

Lesson 2: Effective Communication Prevents Crisis Escalation

Illustrated by: Kirk’s precise, deliberate communication with Nomad slows down its destructive tendencies and provides crucial time to develop a solution.

Compliance Lesson. Communication in compliance crises is similarly critical. Compliance leaders must communicate clearly, calmly, and thoughtfully, particularly in high-stakes scenarios.

Lesson 3: Recognize When Adaptation is Necessary

Illustrated by: Initially, Kirk tries conventional diplomatic approaches. Recognizing that conventional methods have failed, he adapts swiftly and strategically.

Compliance Lesson. In compliance leadership, adaptability is essential. Regulatory landscapes and compliance risks constantly evolve, necessitating quick pivots and agile leadership responses.

Lesson 4: Confront Problems Directly and Courageously

Illustrated by: When Nomad determines Captain Kirk himself to be flawed and thus a threat, Kirk faces Nomad directly, boldly confronting it without hesitation despite understanding the risk involved.

Compliance Lesson. Compliance leaders must similarly confront compliance issues directly and courageously. Avoiding difficult conversations or deferring tough decisions can magnify risks and vulnerabilities.

Lesson 5: Cultivate Critical Thinking Within the Team

Illustrated by: Throughout the episode, Kirk relies heavily on his team, particularly Spock’s analytical logic, Scotty’s technical skills, and Uhura’s linguistic insights after Nomad erases her memory.

Compliance is a collaborative discipline that requires collective critical thinking from diverse team members.

Final ComplianceLog Reflections

Each leadership lesson in this episode, clarity of purpose, effective communication, adaptability, courageous confrontation, and fostering critical thinking, is fundamental to guiding organizations safely through the complex maze of modern compliance challenges. Compliance leaders today face situations not unlike the Enterprise crew: unexpected challenges, high stakes, and rapidly changing conditions. The effectiveness of compliance hinges significantly on leadership skills that navigate these complexities with clarity, confidence, and ethical fortitude.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Timothy and Fiona are AI-generated voices.