Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 68 – The Dangers of Assumption: How “Elaan of Troyius” Proves Due Diligence Is Essential

Today, let’s set our phasers to “analyze” and travel back to one of Star Trek: The Original Series’ most underrated diplomatic dramas: “Elaan of Troyius.” This episode is not just a space opera of culture clashes, hidden agendas, and diplomatic peril; it is a near-perfect parable for compliance professionals wrestling with the eternal question: Why is due diligence mandatory when considering a new business partner?

Let’s get into the heart of the episode and draw out five compliance lessons that every organization should heed before it signs that next contract.

1. First Impressions Are Deceptive: Always Probe Deeper

Illustrated By: Elaan’s arrival is marked by dramatic displays of power, arrogance, and cultural superiority.

Compliance Lesson. How many times have we seen organizations swept off their feet by a potential partner’s surface credentials, market reputation, or charismatic leadership? Due diligence is your organization’s safeguard against falling for the “Elaan effect”: the temptation to trust a partner’s public image without digging into their true character, operational practices, or hidden risks.

2. Cultural Blind Spots: Understand the Landscape Before You Leap

Illustrated By: Misunderstandings abound, from differing customs around authority and gender to fundamental misalignments in values.

Compliance Lesson. Entering into any partnership without understanding your partner’s culture, whether corporate, regional, or national, is asking for trouble.

3. Hidden Agendas and Sabotage: Trust, But Verify

Illustrated By: The mission is sabotaged by Elaan’s retinue, her bodyguard conspires with the Klingons, hiding a device that compromises the Enterprise’s defenses.

Compliance Lesson. When evaluating new partners, you must assume that unseen risks may be lurking just below the surface.

4. Emotional Reactions Cloud Judgment: Stay Objective

Illustrated By: Kirk finds himself emotionally entangled with Elaan after being exposed to her tears, which act as a potent love potion.

Compliance Lesson. In real-world business, emotional bias can cause teams to overlook red flags, downplay risks, or shortcut due diligence.

5. The Price of Ignorance: Remediation Is Harder Than Prevention

Illustrated By: Only after chaos erupts do Kirk and the crew scramble to uncover the source of their problems, a hidden device sabotaging the Enterprise’s engines.

Compliance Lesson. If you do not invest in rigorous due diligence up front, you will inevitably spend much more time, money, and resources cleaning up the mess after something goes wrong.

Final ComplianceLog Reflections

Elaan of Troyius” is a warning to any organization tempted to “wing it” when evaluating a new business partner. Diplomacy, optimism, and trust are essential, but they are not substitutes for due diligence. Hidden risks, cultural misunderstandings, and emotional biases can turn opportunity into disaster in a heartbeat. Kirk and the crew of the Enterprise ultimately succeed not because of luck, but because they confront hard truths, adapt, and persevere. In the world of corporate compliance, the same rules apply.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Timothy is an AI generated voice

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories –Week Ending August 7

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust. This week’s stories include:

  1. Jamie Diamond recruits bankers and IT leaders to tackle AI risks.(Finextra)
  2. When AI overwhelms the humans. (BankingDive)
  3. ROI for banks on AI-redesigned workflows.(AmericanBanker)
  4. AI skills more valuable than MBA.(CFO Brew)
  5. Mandatory AI training at the top of Deutsche Bank.(FinancialNews)
Categories
Daily Compliance News

Daily Compliance News: August 7, 2026 the End of the Jones Act Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance related stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest for the compliance professional.

  • Mike Bloomberg wants to get rid of the Jones Act.  (Bloomberg)
  • Addition by subtraction. (Forbes)
  • Feds probe JPMorgan denial of customer reimbursements. (WSJ)
  • Judge cuts charges against FirstEnergy defendant. (com)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Compliance and AI

Compliance and AI: Deterministic Legal Reasoning, Trust, and Auditability in Compliance Automation with Paul Kelter

What is the intersection of AI and compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. Today I visit with Paul Welter, a German lawyer and former software engineer who co-founded Bayshore AI after research at Stanford Law School’s Codex on automating legal reasoning.

Welter explains Bayshore’s approach: extracting legal decision logic into deterministic, conventional code for predictable, explainable outcomes, while using large language models to gather scenario facts and handle vague legal terms. They discuss regulation as infrastructure for trust and economic activity, and how today’s complexity creates bottlenecks that AI can alleviate by providing legal and compliance advice “in abundance.” Welter describes tailoring assessments to each customer’s policies and risk appetite, embedding them into workflows, and building trust through transparency, second-line control, and auditability for regulators. He highlights automation candidates (e.g., gifts/hospitality, third-party reviews) and advises teams to centralize request intake, measure frequency and effort, and automate iteratively.

Key Highlights

  • Predictable Legal AI
  • Regulation Enables Progress
  • Encoding Policies Not Laws
  • Building Trust in AI
  • Explainability and Audits
  • Agentic AI Use Cases

Resources:

Bayshore

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week-August 7

Welcome to AI in Healthcare in 5 Stories. This podcast is a Weekly Briefing of the five most important AI developments shaping healthcare, medicine, and life sciences. Each week Tom Fox breaks down the latest stories in clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation, all through a practical and business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.  The top five stories for the week ending August 7, 2026 include:

  1. Millennials, GenZ turn to AI for healthcare. (BusinessJournalDaily)
  2. Benefits of medical AI assist vary.(MIT)
  3. Pharma safety teams still worried.(Pharmalive)
  4. AI in hospitals-data trust issues.(HealtcareITNews)
  5. Health systems prefer hybrid AI approach.(HealthcareFinance)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Hill Country Treasures

Hill Country Treasures: Understanding Gold, Silver, Bullion, and Collectible Coins

This is a podcast from MR Mint Coins & Collectibles in Kerrville, Texas, exploring the value, history, and stories behind coins, currency, gold, silver, jewelry, bullion, sports cards, memorabilia, and family collections. Whether you are a lifelong collector, a curious beginner, or someone who just inherited a box of old coins, this show helps you understand what you have, what makes it valuable, and how to make smart, confident decisions. Join host Tom Fox and MR Coin owner Mike Russ for a show celebrates local expertise, honest conversations, and the treasures hiding in plain sight across the Hill Country.

In this episode Mike and Tom discuss how he explains gold and silver to everyday customers, emphasizing this is not investment advice. Russ describes how pricing differs for jewelry, scrap, bullion, and numismatic (collectible) coins: jewelry values depend on karat purity, typically paid as a percentage of spot because it must be refined, while bullion and coin pricing reflects spot plus spreads/premiums, and collectible coins depend on key dates, mint marks, condition, and grading. He notes using XRF testing for purity and a projector to show coin details. Russ outlines store offerings (bullion, collectibles, currency, gems/minerals) and highlights the importance of listening to customer stories, including estate and end-of-life situations.

Highlights

  • Gold & Silver Basics
  • Pricing Jewelry Scrap
  • Collectible Coin Factors
  • Bullion Forms Explained
  • Testing Broken Jewelry
  • Inside the Shop
  • Listening to Stories

Resources

MR Mint and Coin Collectables

Categories
AI Today in 5

AI Today in 5: August 7, 2026 the Perfect Pringle Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. Talk, don’t type to prompt.(FT)
  2. China AI surging in Africa. (NYT)
  3. The quest to make the perfect Pringle. (WSJ)
  4. Compliance for government contractors using AI. (NationalLawReview)
  5. The voice compliance challenge. (FinTechGlobal)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Blog

Scoular DPA Part 5: From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

From Reinspection Fees to Executive Signatures: Final Lessons from Scoular

The Scoular Company FCPA enforcement action began with a deceptively simple fact pattern. Customs brokers allegedly paid Mexican officials approximately $2,000 per train so agricultural shipments could cross the border despite adverse inspection findings. The brokers invoiced the payments to Scoular as “reinspection fees.” That description, however, was only the first layer of the case.

Across this blog post series, Scoular Company became a study in third-party risk, internal controls, cartel exposure, off-channel communications, facilitating payments, data analytics, voluntary disclosure, remediation, DOJ oversight, and executive accountability. Each article examined one part of the control environment. Taken together, they tell a larger story about how bribery becomes normalized inside an operating process and what a company must do when that process fails.

The source distinction matters. I have now posted two series on the enforcement action. The first series relied on the DOJ Press Release, which announced the resolution and described the government’s allegations and conclusions. The second series relied on the formal Deferred Prosecution Agreement (DPA), in which Scoular admitted, accepted, and stipulated that the facts were true. The DPA did not merely add detail. It changed the evidentiary foundation of the analysis.

I.              Series One: Lessons From the DOJ Press Release

a.     A Small Payment Became an Enterprise Control Failure

The Press Release series began with the mechanics of the scheme. According to the DOJ announcement, the conduct ran from 2013 through 2019, involved more than $400,000 in bribes, and enabled Scoular to avoid more than $6.5 million in fees and costs. Scoular entered a three-year DPA and agreed to pay a $9,769,521 criminal penalty and $414,351 in forfeiture.

The compliance lesson was never the size of one payment. It was repetition. A recurring round-dollar charge, submitted by customs brokers, approved over six years, and recorded under a plausible description became part of the company’s operating model.

The phrase “reinspection fee” demonstrated why invoice controls must examine commercial substance. A three-way match can confirm that an invoice, purchase order, and approval agree. It cannot establish that the underlying service was legitimate. For a high-risk customs payment, the control must ask what government action occurred, who received the money, whether an official fee schedule supports the amount, and what happened to the shipment after payment.

This also exposed the limits of onboarding due diligence. Screening a broker and obtaining an anti-corruption certification are only the beginning. Effective third-party management connects onboarding to invoices, transaction monitoring, business outcomes, periodic review, audit rights, and termination decisions.

b.    Cartel Risk Expanded the Compliance Perimeter

The Press Release stated that a portion of the bribe payments ultimately benefited individuals associated with a cartel operating at the U.S.-Mexico border, although the DOJ said Scoular Company and its employees did not know of that connection.

In an episode of the FCPA Compliance Report,  Matt Ellis discussed a broader question. Traditional anti-corruption diligence focuses on government-facing intermediaries, ownership, political exposure, adverse media, and government relationships. Organized-crime connections may not appear in a corporate registry or screening database.

The lesson was not that every cross-border transaction benefits a cartel. It was that companies must understand the environment in which their money, goods, and third parties move. Customs brokers, trucking companies, warehouses, security providers, labor contractors, and subcontractors can create overlapping corruption, money-laundering, sanctions, trade, security, and organized-crime risks.

c.     WhatsApp Was Part of the Control Environment

The Press Release series also examined WhatsApp and other communications used to discuss shipments and payments. The critical point was not that employees selected an unapproved application. It was that the substantive business decision could occur in a private message while the formal system recorded only the resulting invoice. Ellis emphasized that enforcement priorities may change, but evidence does not. A WhatsApp message can establish knowledge, authorization, concealment, or control circumvention even without a standalone off-channel communications charge.

A defensible program must identify the applications employees actually use, define which business activities may occur there, preserve relevant records, address local privacy and employment law, and enforce violations consistently. The company must also be able to connect communications with payment records, inspection results, shipment identifiers, approval logs, and bank data.

Facilitation Payments Did Not Fit the Facts

The Press Release series then addressed why the payments were not protected as facilitating payments. The FCPA exception is narrow. It may cover a payment intended to expedite a routine, nondiscretionary governmental act that the company is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not. The alleged Scoular payments did not change timing. They changed the outcome and enabled shipments to cross despite findings of dirt, soil, and other impurities.

Amount, urgency, local custom, invoice wording, and use of a third party do not create the exception. Nor does the exception authorize a false accounting entry. A company that permits facilitating payments must still confront local law, accurate books and records, approval controls, and the practical difficulty of asking employees to make a narrow legal distinction under commercial pressure.

II.   Lessons From the DPA and Admitted Facts

a.     The DPA Showed How the Scheme Became Normal

The DPA blog post series began by distinguishing allegations in the Press Release from facts Scoular Company admitted. The Statement of Facts showed that stricter Mexican inspections created operational pressure (IE., more or new/different risks) in 2013. A broker proposed a fee on every train and promised that Scoular Company would “not have a single risk of adverse determinations.” The proposal was discussed at Scoular Company’s Kansas office and then replicated through additional brokers and border crossings.

The communications removed ambiguity. Employees discussed soil findings, special payments, trains released after inspections, and situations in which “normal procedures are not working.” By 2018, a communication referred to offering officials more than was normally given. These facts showed normalization. The scheme was not simply a broker’s unauthorized act. It became a repeatable process linking operational pressure, management knowledge, third parties, communications, invoices, approvals, and favorable business outcomes.

b.    Stopping the Conduct Was Not Self-Disclosure

The DPA disclosed that internal reports emerged in 2019 and Scoular Company changed its practices and ended direct engagement with the brokers. Yet the company did not receive voluntary self-disclosure credit because it did not voluntarily and timely report the conduct. The DPA does not reveal the company’s internal debate, so speculation would be inappropriate. It does establish a governance lesson. An internal report starts two clocks: the investigation clock and the disclosure-decision clock. Stopping the conduct is remediation. It is not a substitute for a documented, timely decision about disclosure.

Scoular later received cooperation and remediation credit, including a 25 percent reduction from the bottom of the applicable Sentencing Guidelines range. That outcome demonstrates that missing voluntary-disclosure credit does not make later cooperation irrelevant. It also demonstrates that the two forms of credit are not interchangeable.

c.     Executive Signatures Became the Final Control

The DPA’s attachments translated compliance expectations into personal executive responsibility. They required compliance access to the board, adequate authority and resources, incentives and discipline, third-party business-rationale documentation, verification of services, reasonable compensation, data access, root-cause analysis, and remediation.

They also required two distinct certifications. The CEO and CFO must certify disclosure obligations. The CEO and Chief Legal Officer must certify the truth and completeness of DOJ reports and the design of the anti-corruption compliance program. The certification language references potential exposure under 18 U.S.C. §§ 1001 and 1519 for materially false statements or records.

The signature is therefore not ceremonial. It requires an evidence chain from front-line controls through management testing to board oversight.

d.    Data Analytics Connects Both Series

Vince Walden’s analysis supplied the final detection lesson. No single anomaly proves bribery. The stronger signal is a sequence: an adverse inspection, an unusual recurring broker payment, and a favorable shipment release.

The words “reinspection fee” were searchable. The approximately $2,000 round-dollar amount was testable. The brokers, routes, inspection outcomes, timing, and releases were linkable. Communications could then provide context. Analytics should rank anomalies for human investigation, not declare guilt by algorithm.

This is where internal controls become dynamic. The company should test transaction text, payment amounts, vendor concentration, duplicate descriptions, approval patterns, inspection results, clearance timing, and user access together. Every substantiated alert should improve the next rule, risk model, training decision, and control test.

e.     Compliance Takeaways

  1. Treat the process as the risk unit. Review the third party, payment, message, inspection, route, approval, accounting entry, and business outcome together.
  2. Test substance, not labels. Require evidence of the service performed, the lawful basis for the fee, the recipient, the calculation, and the official result.
  3. Expand third-party risk beyond corruption screening. Integrate organized-crime, sanctions, anti-money-laundering, trade, security, and supply-chain intelligence where the risk profile requires it.
  4. Govern communications as business records. Know which channels employees use, restrict substantive approvals to controlled systems, preserve records, and test retrieval before an investigation.
  5. Create a disclosure decision protocol. Define who evaluates material facts, what information is needed, when senior management and the board are briefed, and how the decision is documented.
  6. Use analytics to connect events. Build monitoring around sequences and outcomes, then route alerts to trained investigators with access to operational, financial, and communications data.
  7. Make certifications evidence-based. Executive signers and boards should demand documented control testing, root-cause analysis, remediation status, and unresolved exceptions before signing.

The final lesson from Scoular Company is that bribery rarely sits in one control. It moves through an operating system. An effective compliance program must see that system, test it continuously, and ensure that the people who oversee it can stand behind the evidence.