Categories
Creativity and Compliance

Creativity and Compliance – Reinventing Compliance: Lauren Thal on Improv, Humor, and Approachable Messaging at Tolmar

Tom Fox and co-host Ronnie Feldman interview Lauren Thal, VP of Compliance at mid-size pharma company Tolmar, about building an in-house compliance program after external partners previously ran it.

Lauren describes her background in healthcare compliance and earlier consulting at Ernst & Young and Navigant and explains why Tolmar’s legal/compliance team used improv training at a retreat to strengthen soft skills, bonding, and collaboration in a remote, cross-location environment. They discuss how exercises like “Red Ball” and role-playing highlight communication styles, active listening, adaptability, and managing competing priorities, helping compliance partner with the business without appearing “finger-waggy” or like the “police.” Lauren also explains her training/communications strategy using short, playful compliance videos on topics such as Speak Up and Code of Conduct to disarm fear, increase attention and recall, and encourage engagement, offering practical ideas for deployment and emphasizing that humor reinforces rather than undermines compliance messages.

Key Highlights

  • Lauren’s Compliance Journey
  • Why Improv at Retreat
  • Red Ball and Styles
  • Partnering Without Fear
  • Handling the Chaos
  • Business Feedback and Impact
  • Advice to Sell the Idea

 

Resources

Ronnie

  • Learnings & Entertainments (Website)
  • Compliance Confessions – inspired by “Mean Tweets” these 90-second commercials address misconceptions and excuses to promote speak up culture and the E&C team as positive and helpful.
  • E&C Training Jams – a soulful singer banters with ethics & compliance explaining policies, sharing examples and debunking excuses. 
  • Tales from the Hotline – Real speak up-themed stories about workplace behavior gone wrong.
  • Workplace Tonight Show! – E&C meets SNL Weekend Update explaining corporate risk topics and why employees should care.
  • 60-Second Communication & Awareness Shorts – A variety of short, customizable, music and multimedia, quick-hitter “commercials” promoting integrity, compliance, speaking up and the E&C team as helpful advisors and coaches.
  • Custom Live & Digital Programing – Custom creative programming that balances the seriousness of the subject matter with a more engaging delivery. After all, you can’t bore people into learning.

Lauren Thal

On LinkedIn

 

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Creativity and Compliance is a multiple podcast award winner show and was recently honored as one of the Top 35 Podcasts on Creativity by Feedspot.

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending July 31, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include the following:

  1. Using traditional legal frameworks to regulate AI. (Reuters)
  2. HSBC opens AI center of excellence. (FinTech Global)
  3. The 60-25-15 rule is reshaping AI compliance pilots. (FinTech Global)
  4. Banks appointing Chief AI Officers. (FinTech Magazine)
  5. BaFin to monitor AI use at banks and insurers. (Reuters)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI Today in 5

AI Today in 5: July 31, 2026 the 60-25-15 Rule Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. 8 compliance changes under the EU AI Act.(Orrick)
  2. Agentic AI in banking in APAC. (CFO Tech)
  3. The 60-25-15 rule is reshaping AI compliance pilots.(FinTechGlobal)
  4. 5 key issues for AI in healthcare. (HealthExec)
  5. 5 top AI in fintech stories from July. (FinTech Futures)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week-July 31

Welcome to AI in Healthcare in 5 Stories. This podcast is a Weekly Briefing of the five most important AI developments shaping healthcare, medicine, and life sciences. Each week Tom Fox breaks down the latest stories in clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation, all through a practical and business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.  The top five stories for the week ending July 31, 2026 include:

  1. 5 key issues for AI in healthcare. (HealthExec)
  2. FDA rulebook for AI in drug trials. (Clinical Trial Vanguard)
  3. Healthcare needs to lean on security and integrity. (HealthITNews)
  4. AI to help in chronic disease research.(HealtcareITNews)
  5. AI in Healthcare still has a trust problem.(HealthcareInnovation)

Welcome to AI in Healthcare in 5 Stories. This podcast is a Weekly Briefing of the five most important AI developments shaping healthcare, medicine, and life sciences. Each week Tom Fox breaks down the latest stories in clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation, all through a practical and business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world. The top five stories for the week ending July 31, 2026 include:

1. 5 key issues for AI in healthcare. (HealthExec)
2. FDA rulebook for AI in drug trials. (Clinical Trial Vanguard)
3. Healthcare needs to lean on security and integrity. (HealthITNews)
4. AI to help in chronic disease research. (HealtcareITNews)
5. AI in Healthcare still has a trust problem. (HealthcareInnovation)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Blog

Connected Compliance: Part 5 – From Signals to Trust: Why Compliance Must Operate as One System

We conclude our series on various components of connected compliance by pulling them all together in an integrated whole. An effective compliance program is often described through its components: policies, training, risk assessment, reporting channels, investigations, discipline, and monitoring. That description is accurate, but incomplete. It tells us what the program contains. It does not tell us how the program works.

The deeper lesson from this series is that compliance effectiveness lives in the connections. Communication, risk sensing, investigations, and whistleblower programs are not separate workstreams that happen to sit under the same organizational chart. They are parts of one information-and-accountability system. Each part produces information that another part must receive, interpret, and convert into action.

That is the integrated argument. Compliance is truly connected because risk moves through an organization as a signal before it becomes an event. An employee question, customer request, control exception, supplier problem, unusual payment, new technology use, or hotline report may be the first indication that the company’s risk profile has changed. The program succeeds when it can move that information through a disciplined cycle: listen, assess, assign, investigate, remediate, communicate, and learn.

The program fails when the signal dies at a handoff.

The Seams Are Where Compliance Breaks

Most companies do not lack compliance activity. They lack reliable movement between activities. Training may be completed, but recurring questions never reach the risk assessment. A hotline may capture an allegation, but intake and investigation teams may use different priorities. An investigation may identify a control weakness, but the remediation owner may not be named. A new policy may be issued, but compliance may never test whether employees understand the change. Each function can report progress while the overall system remains ineffective.

This is why silos create more than inefficiency. They create control risk. A program can look mature by function and still fail as a system because no one owns the transfer of information, the decision deadline, or the feedback loop. Compliance professionals should therefore examine the seams: Who receives the signal? Who decides what it means? Who owns the response? What evidence confirms completion? Who tests whether the response worked? How does the lesson return to employees, managers, controls, and the risk assessment? Those are not administrative questions. They are the architecture of effectiveness.

Compliance Is an Information System

Communication is the first connection because it moves information in both directions. It tells employees what the organization expects, but it also tells compliance what employees are experiencing. Questions, requests for advice, training discussions, manager escalations, surveys, and workplace observations are all risk data. Communication becomes a control when it does more than broadcast. It creates a dependable exchange.

That information must then enter a dynamic risk process. Risk assessment is not merely a periodic exercise that ranks known categories. It is the organization’s method for deciding which signals require monitoring, immediate containment, deeper review, new controls, or additional resources. The quality of that decision depends on access to operational information across functions.

The Department of Justice (DOJ) makes this connection explicit in its 2024 Evaluation of Corporate Compliance Programs (ECCP). The ECCP asks whether periodic risk review is limited to a point-in-time snapshot or is based on “continuous access to operational data and information across functions.” It also asks whether the results lead to updates in policies, procedures, and controls. The enforcement lesson is straightforward: information must move, and it must change the program.

Compliance Is Also an Accountability System

Information alone does not create effectiveness. The organization must make decisions and assign responsibility. When a risk signal becomes an allegation, the investigation process establishes reliable facts. A credible investigation determines scope, protects evidence, preserves independence, treats witnesses fairly, reaches a supported conclusion, and identifies root causes. Its value is not limited to deciding whether one person violated a policy. It should reveal what the organization must change.

This is the point where accountability often weakens. A case may close when a report is issued, even though the control failure remains. Discipline may address the individual without addressing incentives, supervision, access rights, third-party oversight, or prior warnings. Recommendations may be accepted without an owner, deadline, testing plan, or escalation route.

A connected program treats investigation closure as the beginning of remediation. Findings should feed risk assessment, control design, training, management reporting, and resource allocation. Remediation should then be tested, and the result should be documented. If the company cannot show how a material finding changed the program, it has created a record of the past, not a control for the future.

Trust Is Both an Input and an Outcome

The whistleblower program completes the system because it determines whether critical information enters at all. A hotline provides access, but employees decide whether the reporting system is credible. Their decision is shaped by manager behavior, confidentiality practices, investigation quality, anti-retaliation protection, communication during the process, and what they observe after a concern is raised.

Trust is therefore not a soft cultural benefit sitting outside internal control. It is an operating condition for detection. Employees who believe that reporting is unsafe or futile will withhold information. The company then loses the opportunity to address misconduct early, protect people, preserve evidence, and reduce loss. Trust is also an outcome of the company’s response. A respectful intake, timely triage, fair investigation, consistent accountability, active anti-retaliation monitoring, and appropriate closure communication strengthen the next employee’s willingness to speak. A mishandled matter does the opposite. Every case affects the future supply of risk information.

The ECCP captures this end-to-end logic. It calls for an “efficient and trusted mechanism” for anonymous or confidential reporting, asks whether reporting and investigation information is analyzed for patterns and compliance weaknesses, and asks whether the company tests hotline effectiveness by tracking a report from start to finish. That is a systems test. It examines the full journey, not the existence of a vendor platform.

Think in Loops, Not Lines

Compliance professionals should stop viewing the program as a sequence that ends when a task is completed. Training does not end with completion. Risk assessment does not end with a heat map. An investigation does not end with a finding. A report does not end when the case is closed.

Each activity must create an output for the next decision and a feedback path to the earlier controls. Communication produces risk intelligence. Risk assessment prioritizes that intelligence. Reporting channels supply allegations and weak signals. Investigations convert allegations into facts and root causes. Remediation changes controls and accountability. Communication then explains the change, and monitoring tests whether it worked. The experience shapes culture and determines whether employees will use the system again.

This loop also changes the role of the compliance professional. The CCO does not need to own every business risk or perform every task. The CCO must help design and steward the system that connects them. That means establishing decision rights, information-sharing protocols, escalation thresholds, common taxonomies, remediation ownership, testing standards, and reporting that shows whether the loop is moving.

The practical objective is not centralization. It is coordinated accountability. Legal, human resources, internal audit, finance, security, procurement, technology, and business leaders may own different decisions. Compliance should ensure that the handoffs are explicit and that no material issue disappears between functions.

Measure the Health of the Cycle

Traditional metrics often count isolated activity: training completions, policy attestations, number of reports, cases closed, or risk assessments performed. Those measures remain useful, but they do not show whether the system is connected. A stronger dashboard measures movement and learning. How long does it take to move a material signal to a decision? What percentage of remediation actions has a named owner, deadline, evidence requirement, and testing plan? How often do investigation findings change the risk assessment? Which recurring employee questions lead to policy or training changes? Are reporter updates timely? Are retaliation concerns monitored after closure? Do repeat issues decline after remediation?

These measures test whether compliance converts information into action and action into improved performance. They also expose stalled handoffs. A long delay between investigation closure and remediation, for example, is not simply a case-management issue. It is a weakness in the connected program.

From Culture to Credibility

The best compliance programs do not eliminate uncertainty, misconduct, or failure. They create a reliable way to identify change, surface concerns, establish facts, make accountable decisions, and learn. That reliability is what turns stated values into operating culture.

Compliance is truly connected because culture affects reporting, reporting affects risk visibility, risk assessment affects resource allocation, investigations affect accountability, remediation affects controls, and communication affects whether employees trust the system enough to use it again. No element can be fully effective on its own.

The final question for compliance professionals is therefore not whether every component exists. It is whether the components exchange information, preserve accountability, and improve one another. When they do, compliance becomes more than a collection of requirements. It becomes a business system that turns signals into decisions, decisions into controls, and controls into credibility.

Bonus Questions for Compliance Professionals

  1. Where are material compliance signals most likely to stall or disappear in the current program?
  2. Who owns the transfer from employee concern to risk decision, and from investigation finding to tested remediation?
  3. Can the organization trace a recent issue from first signal through final control improvement?
  4. Which functions use different taxonomies, priorities, or case thresholds in ways that weaken handoffs?
  5. What evidence shows that reporting and investigation data changed risk assessment, resources, policies, or controls?
  6. Do current metrics reveal system delays and repeat weaknesses, or only completed activity?
  7. How does the organization communicate lessons without compromising confidentiality?
  8. What recent employee experience strengthened or weakened trust in the compliance system?