Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 66 – Warp-Speed M&A Risks: Hidden Lessons from “Wink of an Eye”

Today, we’re setting our sensors on one of Star Trek: The Original Series’ most thought-provoking episodes—“Wink of an Eye.” While this story may not feature the grand courtrooms or battlefields you might expect for compliance lessons, it’s a goldmine for any compliance officer, in-house counsel, or business leader navigating the perilous and rapidly accelerating world of mergers and acquisitions.

In the world of M&A, deals can go from zero to warp speed in the blink of an eye, and those left operating in “normal” time often find themselves blindsided by risks, unseen motives, and cultural misalignments. Today, we use the lens of “Wink of an Eye” to explore five critical M&A lessons for today’s compliance professional.

1. Beware the Dangers of Unseen Agendas

Illustrated By: The Scalosians are present, but moving too fast to be detected; observing, manipulating, and acting without the crew’s awareness.

Compliance M&A Lesson. In every M&A transaction, some risks and agendas may not be immediately visible.

2. Speed Kills—Or at Least, Blindsides

Illustrated By: Captain Kirk and his crew are thrust into a reality where the Scalosians’ actions occur at warp speed.

Compliance M&A Lesson. Pressure to “get the deal done” quickly is endemic in today’s market. Boardroom bravado, aggressive timelines, or fear of losing out to a competitor can push compliance to the back burner.

3. Cultural Misalignment Can Doom Even the Smartest Teams

Illustrated By: Kirk, once accelerated, finds himself isolated, unable to communicate or coordinate with his crew, who remain “out of phase.” The gulf between realities leads to mistrust, confusion, and near-catastrophe.

Compliance M&A Lesson. One of the most underestimated risks in any deal is cultural misalignment.

4. Technology—Friend, Foe, or Trojan Horse?

Illustrated By: The Scalosians secretly tamper with the Enterprise’s environmental systems, seeking to convert the crew and ship to their needs.

Compliance M&A Lesson. Every acquisition brings a technology integration challenge and, with it, a potential compliance nightmare. Legacy systems may be vulnerable, riddled with security holes, or subject to data localization rules you never anticipated.

5. Communication Is the Antidote to Chaos

Illustrated By: As chaos mounts, Kirk finds creative ways to bridge the communication divide—leaving clues and working with Spock to slow himself down, eventually restoring balance to the ship.

Compliance M&A Lesson. All too often, compliance is left out of critical conversations during a deal or brought in too late, when the train has already left the station. Information silos, unclear chains of command, or poor stakeholder engagement leave gaps where risk thrives.

Final ComplianceLog Reflections

“Wink of an Eye” is more than a sci-fi tale of hyper-acceleration and hidden threats. It’s a vivid parable for compliance officers tasked with shepherding organizations through the labyrinth of mergers and acquisitions. When the pace picks up and risks move faster than you can see, it’s easy to lose sight of the fundamentals. But as Star Trek teaches us, it’s precisely at these moments that discipline, vigilance, and creativity matter most.

In the ever-accelerating world of M&A, compliance is the brake that allows your ship to arrive safely, whatever the speed of your journey. So, the next time your organization beams into a new deal, ask yourself: Are you seeing the whole picture or missing the real action because it’s moving at the speed of a wink?

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
AI Today in 5

AI Today in 5: August 5, 2026 the Hallucinations Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. Hallucinations global business: compliance risks.(CCI)
  2. How do you prove what happened-AI and document retention. (CCI)
  3. The EU AI Act implications for financial institutions. (PYMNTS)
  4. AI is creating an existential crisis for HR. (Bloomberg)
  5. Turning prompts into repeatable workflows. (DemandGen)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Compliance Into the Weeds

Compliance into the Weeds: FinCEN’s $125MM UBS AML Order: A Culture and Resourcing Failure

The award winning, Compliance into the Weeds is the only weekly podcast which takes a deep dive into a compliance related topic, literally going into the weeds to more fully explore a subject. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss a newly issued FinCEN consent order sanctioning UBS Financial Services, the U.S. broker-dealer subsidiary of UBS.

 It is a $125 million penalty, the largest FinCEN fine against a broker-dealer, for extensive anti-money laundering failures. They highlight weak transaction monitoring and suspicious activity reporting (SAR) processes, poor customer due diligence, inadequate wire-transfer data collection, and data governance gaps that led to under-reporting and hindered FinCEN’s ability to build a complete money-laundering picture. The order notes UBS failed to monitor more than 50,000 foreign-currency wires totaling over $10 billion and did not disclose ongoing deficiencies discovered after a 2018 $14 million FinCEN action requiring fixes by 2021, with problems traceable back to 2004 and not addressed until 2023. They frame the matter as a tone-at-the-top and resourcing failure, compare it to other enforcement actions (including a recent SEC fine against Merrill Lynch), and suggest a future deeper dive after reviewing the full order.

 ·      What UBS Got Wrong

·      Scale Of The Failures

·      Board Oversight And Resourcing

·      Data Governance Breakdown

·      SARs, Metrics And AI Talk

·      Takeaways And Next Steps

 Resources

USB Consent Order

 Tom  

Instagram

Facebook

YouTube

Twitter

LinkedIn

 

A multi-award winning podcast, Compliance into the Weeds was most recently honored as one of a Top 25 Regulatory Compliance Podcast and a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, Communicator and w3 Award, all for podcast excellence. 

Categories
Daily Compliance News

Daily Compliance News: August 5, 2026, The What Were You Wearing Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top AI stories include:

  • Uber goes after sexual assault claimants. (NYT)
  • ABA rejects plans to scrap DEI rules for law schools. (Reuters)
  • The white elephant in the room (of Colombian politics). (The Guardian)
  • FBI agent apparently misses tutorial on corruption. (Gizmodo)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

When Time Accelerates: Five M&A Lessons from Star Trek’s “Wink of an Eye”

Today, we’re setting our sensors on one of Star Trek: The Original Series’ most thought-provoking episodes—“Wink of an Eye.” While this story may not feature the grand courtrooms or battlefields you might expect for compliance lessons, it’s a goldmine for any compliance officer, in-house counsel, or business leader navigating the perilous and rapidly accelerating world of mergers and acquisitions.

For those unfamiliar with the episode, “Wink of an Eye” finds the crew of the USS Enterprise responding to a distress call from the planet Scalos. But as soon as they beam down, most of the away team seem to vanish—or so it appears. In reality, the Scalosians exist in a hyper-accelerated state, moving so quickly that to the Enterprise crew, they’re invisible. Before long, Captain Kirk is forcibly accelerated to join them and quickly discovers the perils of operating at different speeds, hidden agendas, and the catastrophic results of unchecked assumptions.

Sound familiar? In the world of M&A, deals can go from zero to warp speed in the blink of an eye, and those left operating in “normal” time often find themselves blindsided by risks, unseen motives, and cultural misalignments. Today, we use the lens of “Wink of an Eye” to explore five critical M&A lessons for today’s compliance professional.

Lesson 1: Beware the Dangers of Unseen Agendas

Illustrated by: The Enterprise crew responds to a distress signal, only to find an abandoned city. In truth, the Scalosians are present but moving too fast to be detected, observing, manipulating, and acting without the crew’s awareness.

Compliance M&A Lesson. In every M&A transaction, some risks and agendas may not be immediately visible. Target companies may appear transparent, but unseen issues, ranging from latent liabilities to regulatory exposures or even toxic cultures, can operate just out of sight. Compliance professionals must be vigilant for “hyper-accelerated” problems: sudden regulatory changes, emerging enforcement risks, or compliance gaps that could metastasize after closing.

What should you do now? Never assume what you can’t see can’t hurt you. Invest in robust, multilayered due diligence. Do not rely solely on surface-level representations. Engage with local counsel, scrutinize whistleblower hotlines, and dig deep for signs of hidden trouble.

Lesson 2: Speed Kills—Or at Least, Blindsides

Illustrated by: Captain Kirk and his crew are thrust into a reality where the Scalosians’ actions occur at warp speed. The Scalosians manipulate the ship’s systems, jeopardizing the Enterprise, all before the crew can respond.

Compliance M&A Lesson. Pressure to “get the deal done” quickly is endemic in today’s market. Boardroom bravado, aggressive timelines, or fear of losing out to a competitor can push compliance to the back burner. But as the Enterprise learned, speed without visibility or controls can spell disaster. When critical steps are skipped or rushed, whether in compliance, due diligence, or integration planning, the seeds for future crises are sown.

What should you do now? Fight the tyranny of the urgent. If deal velocity is forced, demand appropriate pauses for compliance risk assessment. Build “speed bumps” into the process: no sign-off until compliance and legal due diligence are complete, and clear escalation paths for unresolved red flags.

Lesson 3: Cultural Misalignment Can Doom Even the Smartest Teams

Illustrated by: Kirk, once accelerated, finds himself isolated, unable to communicate or coordinate with his crew, who remain “out of phase.” The gulf between realities leads to mistrust, confusion, and near-catastrophe.

Compliance M&A Lesson. One of the most underestimated risks in any deal is cultural misalignment. Whether it’s differences in compliance cultures, attitudes toward regulation, or simply management style, these differences are often invisible until they aren’t. Like Kirk trying to bridge the gap between two timelines, post-deal integration can become a chaotic, error-prone process if cultural divides aren’t acknowledged and addressed.

What should you do now? Assess and plan for cultural integration from Day One. Compliance must have a seat at the table, not just for “hard” issues like controls and policies, but for the “soft” issues that often determine long-term success. Early joint training, culture assessments, and leadership buy-in are vital.

Lesson 4: Technology—Friend, Foe, or Trojan Horse?

Illustrated by: The Scalosians secretly tamper with the Enterprise’s environmental systems, seeking to convert the crew and ship to their needs. Their subtle manipulations are initially undetectable, nearly leading to disaster.

Compliance M&A Lesson. Every acquisition brings a technology integration challenge and, with it, a potential compliance nightmare. Legacy systems may be vulnerable, riddled with security holes, or subject to data localization rules you never anticipated. “Plug and play” is rarely plug-and-play. Worse, legacy tech can act as a “Trojan Horse,” hiding systemic weaknesses, cyber risk, or even evidence of past misconduct.

What should you do now? Demand comprehensive IT and data risk assessments before closing. Ensure data mapping is part of due diligence. Post-acquisition, prioritize integration of compliance tech solutions, hotlines, monitoring tools, and incident management platforms to avoid inheriting someone else’s problems.

Lesson 5: Communication Is the Antidote to Chaos

Illustrated by: As chaos mounts, Kirk finds creative ways to bridge the communication divide—leaving clues and working with Spock to slow himself down, eventually restoring balance to the ship.

Compliance M&A Lesson. All too often, compliance is left out of critical conversations during a deal or brought in too late, when the train has already left the station. Information silos, unclear chains of command, or poor stakeholder engagement leave gaps where risk thrives. Success in M&A is measured not just in legal agreements but in the effectiveness of communication between all parties before, during, and after the deal.

What should you do now? Champion open, continuous communication throughout the deal lifecycle. Establish clear escalation channels. Engage early and often with all stakeholders—from executive leadership to local compliance officers at the target entity. After closing, maintain the cadence: town halls, FAQs, and feedback loops can help manage uncertainty and set expectations.

Final ComplianceLog Reflections

“Wink of an Eye” is more than a sci-fi tale of hyper-acceleration and hidden threats. It’s a vivid parable for compliance officers tasked with shepherding organizations through the labyrinth of mergers and acquisitions. When the pace picks up and risks move faster than you can see, it’s easy to lose sight of the fundamentals. But as Star Trek teaches us, it’s precisely at these moments that discipline, vigilance, and creativity matter most.

In the ever-accelerating world of M&A, compliance is the brake that allows your ship to arrive safely, whatever the speed of your journey. So, the next time your organization beams into a new deal, ask yourself: Are you seeing the whole picture or missing the real action because it’s moving at the speed of a wink?

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Great Women in Compliance

Great Women in Compliance: Curiosity at the Complexity Café

Career journeys are rarely linear—and sometimes our most valuable lessons come from the unexpected turns.

In this episode of Great Women in Compliance, co-host Dr. Hemma Lomax sits down with Amybeth Garcia-Bokor to explore a career spanning public service, legal and compliance leadership, and an inspiring pivot from law to baking before returning to the profession with a renewed perspective. Together, they discuss how curiosity, resilience, and thoughtful leadership help compliance professionals navigate increasing complexity while building trust and enabling better decisions.

Key Takeaways:

  • Why judgment is one of the most important capabilities in modern compliance.
  • How an unconventional career path can strengthen leadership and perspective.
  • The evolution of compliance from enforcement to strategic business partnership.
  • Building cultures where curiosity, learning, and open dialogue thrive.
  • Leading confidently through ambiguity without sacrificing integrity.
  • Preparing compliance programs—and ourselves—for a future shaped by constant change and AI.
Bio

Amybeth Garcia-Bokor is a leader who helps organizations navigate complexity, build trust, and make sound decisions where strategy, governance, and innovation intersect. Her career spans government, private practice, entrepreneurship, and nonprofit organizations, giving her a distinctive perspective on how organizations grow, manage risk, create lasting value, and innovate responsibly in rapidly evolving environments. She currently serves as Senior Vice President of Legal and Compliance at Emergent, where she helps shape the governance of the emerging global market for forest carbon finance.

Categories
Blog

The Scoular DPA Part 3: The Data Was Talking – Data Analytics and the Scoular Bribery Scheme

The Scoular Company bribery scheme was hidden, but it was not invisible. For six years, customs brokers paid Mexican officials approximately $2,000 per train so Scoular Company shipments could cross the border despite adverse inspections. The brokers invoiced the payments back to Scoular as “reinspection fees.” In total, Scoular Company admitted that it authorized $414,351 in bribes and avoided approximately $6.5 million in fees and costs. Those facts describe an FCPA violation. They also describe a data pattern.

In had the opportunity to visit with Vince Walden, CEO of KonaAI about the Scoular Company FCPA enforcement action from a data analytics perspective. He identified the feature that should command every CCO’s attention: people concealing misconduct often record it consistently. They may avoid the word “bribe,” but they still need a repeatable description that allows the payment to be processed, reconciled, and found again. At Scoular Company, that description was “reinspection fee.”

Walden’s observation goes to the heart of modern compliance. Illegal conduct may be concealed from the compliance department while remaining visible in accounts payable, journal entries, invoices, purchase orders, shipment records, and communications. The control failure occurs when those systems hold the evidence but the company never asks the data the right questions.

Consistency Can Become the Fraudster’s Fingerprint

Walden observed that accountants value consistency because consistent classifications support accurate reporting. Fraudsters and their enablers can exploit the same discipline. A bookkeeper cannot label a payment “bribe expense.” The payment still needs a code, description, vendor, amount, approver, account, and business purpose. If the scheme continues, the participants need a method they can repeat. That repetition creates a fingerprint.

Suspicious terms in payment descriptions and journal entries are among the most useful anti-corruption monitoring tests. His examples included phrases such as “friend fee,” “government payment,” and “miscellaneous.” The precise word will vary by company and geography. The analytical principle does not.

The company should identify unusual language, then connect it to the transaction behind it. Even if the language is not unusual, its repeated use might form a pattern worth exploring. A word cloud may provide a useful visual starting point. Keyword searches, natural-language processing, and risk dictionaries can scale the review across thousands of invoices and expense reports. Yet the purpose is not to find one forbidden word. It is to identify language that is unusual for the business, unusually frequent for one vendor, or correlated with a high-risk outcome. “Reinspection fee” was facially plausible. Repetition changed its meaning.

The First Test Was Hiding in Plain Sight

An elementary analytic (As in Elementary, my dear Watson) would have grouped customs-related payments by invoice description, vendor, amount, port, and frequency. That test could have asked:

  • How often does “reinspection fee” appear?
  • Which brokers submit the charge?
  • Is the amount repeatedly near $2,000?
  • Which employees approve it?
  • Does it appear only on trains with an inspection problem?
  • What happens to the shipment immediately after payment?

No single answer proves bribery. Together, the answers can create a compelling reason to investigate. The recurring round-dollar amount matters. Legitimate inspection costs often vary with the service, product, weight, time, port, or government fee schedule. A repeated $2,000 charge across multiple transactions may indicate a fixed unofficial tariff rather than the cost of a legitimate service.

The description also matters. If “reinspection fee” was not found in an approved government schedule, lacked official documentation, or appeared only in broker invoices rather than government receipts, the control should have required escalation before payment. Finally, the outcome matters most. If trains that failed inspection were consistently released after the fee, the company had more than an accounting anomaly. It had a payment linked to a favorable exercise of government discretion.

Connect the Payment to the Business Outcome

Traditional controls often examine whether an invoice matches a purchase order and whether an authorized employee approved it. A bribery scheme can satisfy both tests when employees are participating in the misconduct.

Data analytics must therefore test commercial substance, not merely procedural completion.

For Scoular Company, the decisive data model would connect five sources:

  • Inspection data: date, result, impurity identified, inspector, agency, and reinspection history.
  • Shipment data: train identifier, product, port, broker, delay, release time, and disposition.
  • Payment data: invoice description, amount, general-ledger account, supporting documents, approver, and payment date.
  • Third-party data: broker risk rating, contract terms, bank account, audit rights, ownership, and compensation history.
  • Communications data: relevant emails, WhatsApp records lawfully available to the company, and other business messages.

With those sources joined, compliance could test whether an adverse inspection was followed by a $2,000 broker charge and then by rapid release of the train. It could compare release rates for shipments with and without the payment. It could identify which brokers, ports, and employees produced unusually favorable clearance outcomes. That sequence is the analytic signature of the scheme: failed inspection, unusual payment, successful release.

Build a Layered Anti-Bribery Analytics Program

A mature program should not depend on one keyword or one dashboard. It should use several complementary tests.

Text analytics. Search invoice narratives, journal entries, purchase orders, and expense descriptions for high-risk terms, euphemisms, spelling variants, and unusual phrases. The risk dictionary should reflect the company’s markets and evolve with investigations.

Transaction analytics. Flag recurring round-dollar payments, duplicate or near-duplicate invoices, payments just below approval thresholds, split payments, weekend postings, manual journal entries, and charges lacking official receipts.

Vendor analytics. Compare customs brokers by fee frequency, payment descriptions, clearance rate, failed-inspection rate, use of subcontractors, changes in bank accounts, and concentration under particular employees or business units.

Outcome analytics. Test whether payments are statistically associated with permits, inspections, releases, tax outcomes, contract awards, or other favorable government actions. This moves the review from what the invoice says to what the payment accomplished.

Sequence analytics. Measure the time between an adverse event, a payment request, approval, payment, and favorable resolution. Short, repeated intervals can reveal a designed process.

Communications analytics. Where lawful and consistent with company policy, match high-risk transactions to messages about urgency, guarantees, officials, inspections, exceptions, or payments. A suspicious invoice can corroborate a message, and a message can explain the invoice.

Network analytics. Map relationships among employees, brokers, bank accounts, ports, approvers, and government touchpoints. Shared bank accounts, common addresses, unusual subcontractors, or recurring approval chains can expose concealed connections.

These tests should create ranked alerts, not automated accusations. Analytics identifies anomalies. Trained reviewers determine whether the transaction has a legitimate explanation, requires more evidence, or warrants an investigation.

Continuous Monitoring Is a Governance Choice

Walden’s closing advice was simple: keep innovating and keep running the analytics. The word “running” matters. As in continuously. A one-time review performed after a subpoena is forensic reconstruction. A risk-based test operating monthly, weekly, or at the point of payment is a compliance control.

Continuous monitoring does not mean surveillance of every employee or review of every transaction. It means that known high-risk processes receive repeatable testing at a frequency aligned with the risk. Customs payments, government-facing third parties, failed inspections, and manual financial entries deserve more attention than ordinary low-risk purchases.

The program also needs governance. Compliance and internal audit should agree on data ownership, alert thresholds, reviewer responsibilities, escalation standards, documentation, privacy requirements, and feedback loops. Finance must help validate legitimate payment patterns. The business must explain operational outcomes. Technology must maintain data quality and access. Legal must ensure that communications monitoring is lawful.

Most importantly, the board should ask whether compliance has direct access to the data. A dashboard built from incomplete information can create false assurance. If broker invoices sit in one system, inspection results in another, shipment releases in a third, and WhatsApp messages outside company retention, the organization sees fragments while the scheme operates across the seams.

Internal Controls Must Learn From Every Alert

Data analytics is not a substitute for internal controls. The supplement each other as data analytics is a way to test whether those controls work and where they fail. An alert concerning a reinspection fee should trigger questions about official documentation, approved fee schedules, broker contracts, audit rights, segregation of duties, approval thresholds, and the economic rationale for the charge. If the review confirms misconduct, root-cause analysis should determine why the payment passed through accounts payable, why the broker remained active, why inspections and payment data were not connected, and whether incentives rewarded shipment clearance over compliance.

Every closed alert should improve the system. Confirmed concerns should add new keywords, vendor attributes, transaction patterns, and outcome measures. Legitimate transactions should help refine thresholds and reduce noise. This is how a compliance program becomes adaptive rather than static.

Questions for CCOs

CCOs should ask:

  • Which payment descriptions recur in our highest-risk government-facing processes?
  • Can we connect invoices to inspections, permits, customs outcomes, and shipment releases?
  • Which third parties generate unusually favorable results after unusual payments?
  • Are alert reviewers trained to investigate commercial substance, not merely paperwork?
  • How quickly does a confirmed issue change our controls and analytics?

The Bottom Line

Scoular Company’s bribery scheme did not require a sophisticated algorithm to detect. It required the company to notice a repeated phrase, a recurring amount, a high-risk broker, an adverse inspection, and a favorable government outcome. Walden’s lesson is that concealment often creates consistency, and consistency creates data. The task of compliance is to convert that data into a question early enough to matter.

Follow the words. Test the amount. Connect the outcome. Then channel your inner Sherlock Holmes investigate what the pattern is telling you.