Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 47 – Charting Unseen Risks: Investigative Strategies from ‘The Immunity Syndrome’

There is a moment in every compliance professional’s career when you must venture into the unknown: a new country, a new business line, or a merger with a company whose culture, controls, and risks you only dimly perceive. In many ways, this is the compliance professional’s dilemma when launching operations in a new jurisdiction or pursuing a new business venture. Old assumptions may no longer apply—hidden dangers lurk where we least expect. And survival, not just success, depends on investigative skills, adaptability, and a willingness to challenge everything we think we know. Today, we examine the investigative lessons from “The Immunity Syndrome” that every compliance professional should heed when boldly going where their organization has never gone before.

Lesson 1: Question Your Assumptions—The Risks May Be Invisible

Illustrated by: The Enterprise receives a distress call and learns that the Intrepid, a ship crewed entirely by Vulcans, has been destroyed by an unknown force.

Investigative Takeaways:

  • Do not assume that past success in other markets guarantees future safety.
  • Leverage local knowledge just as Spock’s unique connection gave the Enterprise vital early warning.
  • Use multiple investigative approaches: don’t rely solely on established data or processes.

Lesson 2: Conduct a Deep Diagnostic—Surface Scans Are Never Enough

Illustrated by: The Enterprise finds a “zone of darkness” in space. It is a void with no energy, no light, and no readings at all. Standard scans and probes reveal nothing.

Investigative Takeaways:

  • Supplement traditional due diligence with on-the-ground investigations and “boots on the ground” audits.
  • Look for the absence of evidence as well as the presence—missing records, unusual silence, or gaps in documentation can be just as telling as a smoking gun.
  • Enlist specialists (just as Kirk uses Spock and McCoy’s unique skills) to delve into complex risks, whether legal, cultural, or operational.

Lesson 3: Trust but Verify—Local Expertise Is Essential, But Not Infallible

Illustrated by: Kirk is forced to choose between Spock and McCoy for a dangerous reconnaissance mission into the organism’s interior.

Investigative Takeaways:

  • Respect local expertise, but always cross-check against independent sources.
  • Build diverse investigative teams, including insiders and outsiders, as well as headquarters and field personnel, such as lawyers and auditors.
  • Establish clear escalation protocols when local advice contradicts global standards.

Lesson 4: Monitor for Emerging Risks—What Starts as a Small Threat Can Escalate Rapidly

Illustrated by: Once inside the organism, the Enterprise is quickly overwhelmed.

Investigative Takeaways:

  • Establish early-warning systems for compliance and operational risks.
  • Monitor not just for violations but for near misses, rumors, and signs of stress within the local business.
  • Use “pulse checks”—quick, frequent assessments—to catch emerging issues before they escalate.

Lesson 5: Have an Exit Strategy—Sometimes the Best Move Is to Retreat and Reassess

Illustrated by: As the Enterprise is nearly destroyed, Kirk orders a desperate gambit.

Investigative Takeaways:

  • Continually assess the risk/reward calculus of continuing versus exiting.
  • Prepare senior management for “no-go” recommendations, supported by clear evidence and risk assessments.
  • Document your investigations, findings, and decision rationale thoroughly, especially when choosing to walk away.

Final ComplianceLog Reflections

In every new venture, there is a “zone of darkness.” It is a realm of unknown risks and unexpected threats. The only way to navigate it is through rigorous investigation, humility in the face of uncertainty, and the courage to act, whether that means pushing forward or pulling back.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Hill Country Treasures

Hill Country Treasures: Inside the Appraisal Process for Coins, Bullion, Jewelry, and Estates

This is a podcast from MR Mint Coins & Collectibles in Kerrville, Texas, exploring the value, history, and stories behind coins, currency, gold, silver, jewelry, bullion, sports cards, memorabilia, and family collections. Whether you are a lifelong collector, a curious beginner, or someone who just inherited a box of old coins, this show helps you understand what you have, what makes it valuable, and how to make smart, confident decisions. Join host Tom Fox and MR Coin owner Mike Russ for a show that celebrates local expertise, honest conversations, and the treasures hiding in plain sight across the Hill Country.

Tom visits with Mike Russ about how appraisals work when customers bring coins, jewelry, bullion, and collectibles into Mike’s store, especially in estate situations. Mike explains categories (bullion, jewelry, collectible coins, and “run-of-the-mill” items) and how pricing starts with spot prices, then applies purchase percentages: bullion is typically around 95% of spot, with silver sometimes around 90% due to premiums; jewelry value is based on karat purity, weight, and a percentage of spot; collectible coins are evaluated via grading/condition and market tools like Gray Sheet and eBay, factoring in fees, with some coins potentially sent for professional grading. They emphasize transparency, education, trust-building, getting second opinions, and caution against hotel “roadshow” buyers. Mike recommends handling precious metals outside estate sales due to high commissions and suggests keeping collections together for better value.

Highlights:

  • Appraisal Basics and Categories
  • Pricing Collectible Coins
  • Bullion and Jewelry Math
  • Estate Sales and Private Consults
  • Keep Collections Together
  • Testing, Grading, and Timeline

Resources:

MR Mint and Coin Collectibles

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – July 17, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending July 17, 2026, include:

  1. Moving AI from pilot to production in pharma. (Lab Manager)
  2. Autonomous AI and patient safety. (Digital Journal)
  3. Compliance in AI home healthcare. (MedCityNews)
  4. Mark Cuban says AI is making healthcare worse. (BusinessInsider)
  5. Healthcare needs to simplify its AI stack. (HealthCareITNews)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Probing the Unknown: Investigative Lessons from Star Trek’s “The Immunity Syndrome”

Probing the Unknown: Investigative Lessons from Star Trek’s “The Immunity Syndrome”

There is a moment in every compliance professional’s career when you must venture into the unknown: a new country, a new business line, or a merger with a company whose culture, controls, and risks you only dimly perceive. Even with all our policies, controls, and frameworks, nothing can fully prepare us for the complexity, ambiguity, and risks of these new frontiers.

For me, no episode of Star Trek: The Original Series better illustrates the challenge of entering uncharted territory than “The Immunity Syndrome.” In this classic, the USS Enterprise is sent to investigate the mysterious loss of the starship Intrepid. The crew finds itself confronting a massive, deadly space organism—a threat it does not understand, cannot immediately combat, and that operates according to rules entirely foreign to its experience.

In many ways, this is the compliance professional’s dilemma when launching operations in a new jurisdiction or pursuing a new business venture. Old assumptions may no longer apply—hidden dangers lurk where we least expect. And survival, not just success, depends on investigative skills, adaptability, and a willingness to challenge everything we think we know.

Today, we examine the investigative lessons from “The Immunity Syndrome” that every compliance professional should heed when boldly going where their organization has never gone before.

Lesson 1: Question Your Assumptions—The Risks May Be Invisible

Illustrated by: The Enterprise receives a distress call and learns that the Intrepid, a ship crewed entirely by Vulcans, has been destroyed by an unknown force. As they approach the affected sector, Spock, usually calm and logical, is deeply unsettled, sensing the deaths of hundreds of Vulcans—a phenomenon that neither science nor sensors can explain.

Compliance Lesson: When entering a new country or business venture, the most dangerous risks are often the ones you cannot see or do not know how to measure. Local compliance risks, fraud schemes, or cultural taboos may be invisible to standard due diligence or data analytics. Before launch, question your risk map. What don’t you know? Who can help you see the invisible? Consider local partners, whistleblower channels, and open-ended interviews to reveal hidden hazards.

  • Investigative Takeaways:
    • Do not assume that past success in other markets guarantees future safety.
    • Leverage local knowledge just as Spock’s unique connection gave the Enterprise vital early warning.
    • Use multiple investigative approaches: don’t rely solely on established data or processes.

Lesson 2: Conduct a Deep Diagnostic—Surface Scans Are Never Enough

Illustrated by: The Enterprise, it finds a “zone of darkness” in space—a void with no energy, no light, and no readings at all. Standard scans and probes reveal nothing. Kirk, Spock, and McCoy debate theories and send increasingly sophisticated diagnostics before realizing they are up against a living, immune organism of unprecedented scale.

Compliance Lesson: Too many compliance failures occur because companies mistake a clean policy review or background check for a full investigation. New ventures require deep diagnostics that probe beneath the surface to understand not only what is there but also what is missing. Design investigative protocols that go beyond checklists: site visits, employee interviews, unannounced audits, and third-party verification. The darker the zone, the deeper you must probe.

  • Investigative Takeaway:
    • Supplement traditional due diligence with on-the-ground investigations and “boots on the ground” audits.
    • Look for the absence of evidence as well as the presence—missing records, unusual silence, or gaps in documentation can be just as telling as a smoking gun.
    • Enlist specialists (just as Kirk uses Spock and McCoy’s unique skills) to delve into complex risks, whether legal, cultural, or operational.

Lesson 3: Trust but Verify—Local Expertise Is Essential, But Not Infallible

Illustrated by Kirk, who is forced to choose between Spock and McCoy for a dangerous reconnaissance mission into the organism’s interior. Both men are experts, but each brings different strengths, blind spots, and biases to the investigation. Kirk weighs their counsel but ultimately makes his call.

Compliance Lesson:

Local advisors, consultants, and employees are critical assets when entering new regions. However, their perspective is necessarily shaped by local norms and may not fully align with your organization’s risk appetite or ethical standards. Seek out a variety of perspectives, and always keep “tone from the top” and corporate values as your North Star. Investigative rigor means striking a balance between trust and verification at every turn.

  • Investigative Takeaways:
    • Respect local expertise, but always cross-check against independent sources.
    • Build diverse investigative teams, including insiders and outsiders, as well as headquarters and field personnel, such as lawyers and auditors.
    • Establish clear escalation protocols when local advice contradicts global standards.

Lesson 4: Monitor for Emerging Risks—What Starts as a Small Threat Can Escalate Rapidly

Illustrated by: Once inside the organism, the Enterprise is quickly overwhelmed. The ship’s energy is drained, the crew is incapacitated, and the threat escalates far faster than anticipated. Kirk and his team must improvise and respond dynamically as new threats emerge.

Compliance Lesson:

When operating in new markets, small, manageable issues can quickly become existential threats if left unchecked. Corruption, weak controls, or legal ambiguities that seem minor at first can balloon if they are not caught early. Design your investigations and monitoring to see not only current misconduct but also early signs of trouble. Do not wait for the threat to fully materialize before taking action; by then, the momentum in your program may have been lost.

  • Investigative Takeaways:
    • Establish early-warning systems for compliance and operational risks.
    • Monitor not just for violations, but for near-misses, rumors, and signs of stress within the local business.
    • Use “pulse checks”—quick, frequent assessments—to catch emerging issues before they escalate.

Lesson 5: Have an Exit Strategy—Sometimes the Best Move Is to Retreat and Reassess

Illustrated by: As the Enterprise is nearly destroyed, Kirk orders a desperate gambit: injecting antimatter into the organism to destroy it, even if it means risking the ship. The plan works, but only after carefully considering—and ultimately rejecting—the possibility of a strategic withdrawal.

Compliance Lesson: Not every business venture or market entry can (or should) be salvaged. Sometimes, the risk is too great, the red flags too numerous, or the compliance gaps too wide to close. A good investigator knows when to recommend pulling back or declining to proceed. The hallmark of an effective compliance investigation is the willingness to tell leadership when the risk is not worth the reward. Better a temporary retreat than a catastrophic loss.

  • Investigative Takeaways:
    • Continually assess the risk/reward calculus of continuing versus exiting.
    • Prepare senior management for “no-go” recommendations, supported by clear evidence and risk assessments.
    • Document your investigations, findings, and decision rationale thoroughly, especially when choosing to walk away.

Final ComplianceLog Reflections

The Immunity Syndrome is more than a science fiction adventure; it is a meditation on the perils of confronting the unknown. For compliance professionals entering new countries or launching new ventures, the lessons are clear: question assumptions, dig deep, leverage local knowledge while scrutinizing it, monitor constantly, and know when to cut your losses.

In every new venture, there is a “zone of darkness.” It is a realm of unknown risks and unexpected threats. The only way to navigate it is through rigorous investigation, humility in the face of uncertainty, and the courage to act, whether that means pushing forward or pulling back.

May your investigative journeys be bold, your questions relentless, and your commitment to integrity unwavering. As the crew of the Enterprise discovered, survival in the unknown depends on never accepting the status quo, never ceasing to probe, and always being ready to chart a new course if the facts demand it.

Boldly investigate where no compliance professional has gone before.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

The Odyssey and Compliance, Part 5 – Peace in Ithaca: Building the Program After the Crisis

Today, we conclude our five-part series on some of the intersections of. On Monday, we began with the Trojan Horse as a control failure. On Tuesday, we looked at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we reviewed The Cattle of Helios, Non-Negotiables, and Control Breaches. Today, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Odysseus finally makes it home. After ten years of war and ten more years of wandering, he returns to Ithaca, confronts the suitors, reclaims his house, and restores his position. The bow is strung. The suitors are defeated. The great crisis is over. Roll credits, cue heroic music, and let everyone go back to normal. Except, of course, that is not how governance works.

The story does not really end when Odysseus wins. Ithaca still has to be governed. The household has to be restored. Trust has to be rebuilt. Loyalties have to be sorted out. The damage done by years of disorder has to be addressed. Penelope, Telemachus, the servants, the suitors’ families, and the broader community all have to live with what comes next.

That is the overlooked compliance lesson at the end of The Odyssey: winning the confrontation is not the same as rebuilding the system. For corporate compliance, Ithaca is the company after an enforcement action, a scandal, a cyber breach, a restatement, a leadership crisis, a whistleblower investigation, a failed audit, or a major control breakdown. The dramatic event may be over. The press release may be issued. The investigation may be closed. The bad actors may be gone. But the real question remains: what changes must be made so that the same story does not happen again?

The Corporate Translation

Every organization wants to believe that removing the wrongdoer solves the problem. Terminate the employee. Discipline the manager. Replace the vendor. Restate the numbers. Settle the matter. Announce new leadership. Launch a refreshed values campaign. Hold a town hall. Add a slide to the annual training deck. All of those may be necessary.

None of them is sufficient. A crisis reveals more than individual misconduct. It reveals how the organization enabled the misconduct, overlooked it, tolerated it, rationalized it, or failed to respond sooner. It exposes weaknesses in governance, incentives, supervision, reporting, monitoring, controls, culture, and accountability.

That is why post-crisis remediation cannot be treated as corporate housekeeping. It is not the ceremonial sweeping of the hall after the suitors have been removed. It is the hard work of rebuilding Ithaca so the suitors do not return wearing different badges. The corporate lesson is simple: winning the investigation is not the same as rebuilding trust.

“Works in Practice” Is the Hard Question

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks three core questions: whether the program is well designed, whether it is adequately resourced and empowered to function effectively, and whether it works in practice. The ECCP makes clear that prosecutors consider how a company’s program performed at the time of misconduct and at the time of a charging decision or resolution.

That third question—does it work in practice? —is the Ithaca question. It is one thing to have a Code of Conduct. It is another thing to know whether employees believe it. It is one thing to have a hotline. It is another thing to know whether people trust it. It is one thing to discipline misconduct. It is another matter to know whether discipline is consistent across ranks, geographies, and revenue contributions.

A compliance program does not work because it is beautifully documented. A compliance program works when it changes decisions, identifies risks, encourages escalation, supports ethical behavior, and improves when reality proves that the initial design was not enough. Odysseus could reclaim the palace in a day. Rebuilding confidence in the palace would take longer. So it is with compliance.

Remediation Is Not a Memo

One of the great corporate temptations after a crisis is to confuse activity with remediation. There will be committees. There will be project plans. There will be executive updates. There will be dashboards in shades of green, yellow, and red. There will be a new policy with a title long enough to require its own table of contents. But the question is not whether the company became busier. The question is whether the company has become better.

Effective remediation begins with root cause analysis. What happened? Why did it happen? Who was involved? Who should have known? Which controls failed? Which controls did not exist? Were employees trained? Were managers supervising? Were incentives distorting behavior? Were prior warnings ignored? Were similar issues found elsewhere?

Then, remediation must move from diagnosis to design. Policies may need to change. Controls may need to be strengthened. Reporting channels may need to be rebuilt. Training may need to be targeted. Third-party relationships may need review. Compensation systems may need adjustment. Governance committees may need clearer authority. Data analytics may need to identify patterns earlier.

And then comes the part companies sometimes skip: testing and ongoing monitoring. A control is not considered remediated just because someone wrote that it was. A control is remediated when it has been implemented, tested, validated, and shown to work. Otherwise, Ithaca has merely repainted the door.

Monitoring and Testing: Trust, but Verify Ithaca

After a crisis, leadership often wants to move on. That impulse is understandable. No one wants to live forever in the investigation report. Employees are tired. Managers are defensive. The board wants assurance. Customers want stability. Regulators want evidence. The business wants to get back to business. But moving on too quickly is how organizations repeat themselves.

Monitoring and testing are the tools that keep memory alive without keeping the organization trapped in the past. Monitoring asks, “What are we seeing now? Testing asks, “Do the controls actually work?” Together, they turn compliance from a promise into evidence.

This is where ISO 37301 offers a useful management-system lens. ISO describes ISO 37301 as a compliance management systems standard for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive compliance management system. That language matters because it treats compliance as a cycle, not a shrine. Establish. Implement. Evaluate. Maintain. Improve.

Culture Reset Requires More Than New Words

After misconduct, companies often rediscover culture with the enthusiasm of a traveler who has just realized the map was upside down. Suddenly, everyone wants to talk about values. Tone at the top. Speak-up culture. Accountability. Transparency. Trust.

But a culture reset requires more than new words from senior leadership. Employees are sophisticated consumers of corporate messaging. They know when a town hall is sincere and when it is theater. They know whether leaders who caused the pressure are still being rewarded. They know whether people who raised concerns were protected or isolated. They know whether the company wants the truth or merely closure.

A real culture reset asks hard questions. Are managers rewarded for ethical leadership? Are employees comfortable escalating concerns? Are investigations fair and timely? Are lessons learned communicated without unnecessary secrecy? Are senior leaders held accountable? Are compliance and audit findings taken seriously? Are business goals achievable without cutting corners? Culture is not reset by announcing that trust has been restored. Trust is restored when employees see different behavior over time.

Governance After the Storm

Ithaca’s problem was not only that the suitors behaved badly. It was the governance structure that allowed them to occupy the house for too long. That is a corporate issue as well.

After a crisis, boards and executive teams should examine whether governance failed. Did the right committees receive the right information? Did compliance have sufficient independence? Were risk owners clearly identified? Did internal audit, legal, HR, finance, security, and compliance coordinate effectively? Were red flags escalated? Did leadership understand the risk, or were they receiving sanitized reporting?

Governance redesign is not glamorous. It lacks the narrative thrill of Odysseus stringing the bow. But it is what prevents the next group of suitors from discovering that no one is really watching the door.

The Compliance Takeaway

The end of The Odyssey is not just about return. It is about restoration. That distinction matters for compliance officers and business leaders. After a crisis, the organization must resist the urge to declare victory too soon. The investigation may identify what happened. Discipline may address who was responsible. But remediation must answer the deeper question: what will be different? A mature compliance program uses a crisis as evidence. It monitors. It tests. It learns. It redesigns governance. It strengthens controls. It resets culture through action. It measures whether the program works in practice, not merely whether it exists on paper.

Odysseus came home and won back Ithaca. The compliance challenge is harder. You have to make Ithaca governable again.