Categories
Daily Compliance News

AI Today in 5: August 11, 2026 the Zuckerberg Speaks Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. 5 key takeaways from Zuckerberg manifesto on AI.(Bloomberg)
  2. Can AI help with travel costs? (NYT)
  3. EY launches bid to hold down AI costs. (Bloomberg)
  4. FCA finalizes rules to cut £100MM in reporting costs. (FinTechGlobal)
  5. AI safety in healthcare is everyone’s job. (HealthcareFinance)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 72 – Surviving the Unknown: Risk Management Lessons from “That Which Survives”

In compliance, risk management is more than a checklist. It is the ongoing discipline of identifying threats, assessing their potential impact, and implementing measures to mitigate or neutralize them before they cause harm.

Few Star Trek episodes illustrate the escalating consequences of underestimated risks as effectively as That Which Survives. In it, the Enterprise crew encounters a seemingly lifeless planet guarded by Losira, an alien projection who can kill with a single touch. Her purpose is to protect the planet’s secrets, but her method is indiscriminate, deadly, and poorly aligned to the situation at hand.

For compliance professionals, this episode offers five important lessons on anticipating, assessing, and responding to risks, both known and unknown, within an organization.

Lesson 1: Identify Risks Before Engaging in New Ventures

Illustrated By: The Enterprise arrives at an uncharted planet. Within moments, a mysterious woman materializes and kills a crew member simply by touching him.

Compliance Lesson. Too often, companies rush into new markets, partnerships, or projects without conducting a thorough risk assessment. This can expose the organization to sanctions violations, corruption risks, cybersecurity vulnerabilities, or operational failures.

Lesson 2: Understand That Some Risks Are Intelligent and Adaptive

Illustrated By: Losira targets specific individuals and adapts her approach to their vulnerabilities.

Compliance Lesson. Not all risks are static. Fraudsters change tactics, cyber threats evolve, and corrupt third parties find new ways to conceal misconduct. A compliance program must anticipate that some risks will actively seek to bypass controls.

Lesson 3: Don’t Dismiss Low-Probability, High-Impact Threats

Illustrated By: At first, the crew assumes Losira’s appearances are isolated incidents, but they quickly realize she poses an existential threat.

Compliance Lesson. Rare events, such as a single high-value bribery transaction, a lone rogue employee, or a targeted cyberattack, can have catastrophic consequences. Organizations sometimes underprepare for these scenarios because they seem unlikely.

Lesson 4: Risk Mitigation Requires Cross-Functional Coordination

Illustrated By: The landing party on the planet and the Enterprise crew in orbit are each facing threats from Losira, but their survival depends on sharing information and coordinating responses. Without clear communication, both groups would be doomed.

Compliance Lesson. Compliance cannot manage risk in isolation. It must work with legal, internal audit, operations, IT, and HR to identify threats and implement controls.

Lesson 5: Address the Root Cause, Not Just the Symptoms

Illustrated By: The crew eventually discovers that Losira is an automated defense mechanism left behind by an extinct race. Once the crew understands her origin and purpose, they can neutralize the threat.

Compliance Lesson. In risk management, addressing surface-level problems without finding the underlying cause only delays future incidents. Compliance should integrate root cause analysis into all investigations.

Final ComplianceLog Reflections

That Which Survives is more than a suspense episode; it is a cautionary tale about the dangers of underestimating risk. Losira was not inherently evil; she was a misunderstood, unexamined part of an environment the crew did not fully assess before engagement.

The compliance officer’s mandate is to ensure the company doesn’t make the same mistake: to scan for threats before beaming in, to adapt to risks that evolve, to prepare for unlikely but devastating events, to coordinate across the enterprise, and to address the root cause when problems arise. Risk management is not just about surviving; it is about ensuring that your organization thrives in any environment, whether it’s an unexplored planet or a rapidly changing market.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI generated voice

Categories
Daily Compliance News

Daily Compliance News: August 11, 2026 the Section 230 Liability Defense Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance related stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest for the compliance professional.

  • Russia’s hottest start up is a sanctions evasion network.  (WSJ)
  • 9th circuit allows lawsuits against big tech to move forward. (Reuters)
  • Compliance alone can’t stop health care fraud. (MedCityNews)
  • Leadership training on change management. (FT)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Innovation in Compliance

Innovation in Compliance: Scaling the RiskCloud and Agentic AI for Enterprise GRC with Diego Panama

Innovation comes in many areas and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance as he visits with top innovative minds, thinkers and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with s Diego Panama, new CEO of LogicGate.

They discuss his career from Microsoft product management to scaling Live Ramp to an IPO, building go-to-market at Olo, and joining LogicGate through a planned CEO transition with co-founder Matt Kunkel. Panama describes his focus on scaling operations while preserving a customer-first, values-driven culture, and sharpening the company’s positioning as the leading AI GRC platform for enterprise. The discussion highlights AI’s role in moving GRC from check-the-box defense to real-time, strategic enablement, including holistic risk visibility across silos, third-party risk blind spots, and always-on monitoring. Panama explains LogicGate’s workflow agents and the path toward orchestrated, autonomous GRC with humans setting risk appetite, emphasizes data access, quality, and governance, and outlines product UX evolution from no-code to prompt-driven configuration. He notes boards’ increased attention to GRC due to AI risks and encourages students and practitioners to stay curious and aligned to business outcomes.

Key Highlights

  • Why LogicGate and GRC
  • AI Makes GRC Strategic
  • Holistic Risk and Third Parties
  • Workflow Agents Explained
  • Data Access and Governance
  • Big Tech Lessons on Focus
  • Staying Current in Tech

Resources

LogicGate

Diego Panama on LinkedIn

 

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
Blog

Risk Management in Compliance: Five Lessons from Star Trek’s That Which Survives

In compliance, risk management is more than a checklist. It is the ongoing discipline of identifying threats, assessing their potential impact, and implementing measures to mitigate or neutralize them before they cause harm.

Few Star Trek episodes illustrate the escalating consequences of underestimated risks as effectively as That Which Survives. In it, the Enterprise crew encounters a seemingly lifeless planet guarded by Losira, an alien projection who can kill with a single touch. Her purpose is to protect the planet’s secrets, but her method is indiscriminate, deadly, and poorly aligned to the situation at hand.

For compliance professionals, this episode offers five important lessons on anticipating, assessing, and responding to risks, both known and unknown, within an organization.

Lesson 1: Identify Risks Before Engaging in New Ventures

Illustrated By: The Enterprise arrives at an uncharted planet, scans it briefly, and beams down a landing party. Within moments, a mysterious woman materializes and kills a crew member simply by touching him.

Compliance Lesson. Too often, companies rush into new markets, partnerships, or projects without conducting a thorough risk assessment. This can expose the organization to sanctions violations, corruption risks, cybersecurity vulnerabilities, or operational failures. Compliance should lead or be deeply involved in pre-engagement risk assessments. Before “beaming down” into a new business environment, map potential threats—regulatory, operational, reputational—and identify safeguards. Skipping this step can lead to preventable harm and costly remediation.

Lesson 2: Understand That Some Risks Are Intelligent and Adaptive

Illustrated By: Losira’s ability to appear anywhere, both on the planet and aboard the Enterprise, shows she is not a passive hazard. She targets specific individuals and adapts her approach to their vulnerabilities.

Compliance Lesson. Not all risks are static. Fraudsters change tactics, cyber threats evolve, and corrupt third parties find new ways to conceal misconduct. A compliance program must anticipate that some risks will actively seek to bypass controls. Build adaptive monitoring into your compliance systems. Use continuous transaction monitoring, real-time alerts, and data analytics to detect changes in patterns. A one-time risk assessment is not enough—ongoing vigilance is essential.

Lesson 3: Don’t Dismiss Low-Probability, High-Impact Threats

Illustrated By: At first, the crew assumes Losira’s appearances are isolated incidents, but they quickly realize she poses an existential threat. Even though she is only one individual, her capabilities could destroy the Enterprise if not addressed.

Compliance Lesson. Rare events, such as a single high-value bribery transaction, a lone rogue employee, or a targeted cyberattack, can have catastrophic consequences. Organizations sometimes underprepare for these scenarios because they seem unlikely. Compliance departments should incorporate low-probability, high-impact risks into the risk register. Conduct tabletop exercises to simulate rare but potentially devastating events, ensuring the organization has both prevention and response plans in place.

Lesson 4: Risk Mitigation Requires Cross-Functional Coordination

Illustrated By: The landing party on the planet and the Enterprise crew in orbit are each facing threats from Losira, but their survival depends on sharing information and coordinating responses. Without clear communication, both groups would be doomed.

Compliance Lesson. Compliance cannot manage risk in isolation. It must work with legal, internal audit, operations, IT, and HR to identify threats and implement controls. Silos breed blind spots, and blind spots breed crises. Establish cross-functional risk committees or working groups. Ensure that incident reporting and escalation procedures are well understood across departments. Make compliance the hub of a collaborative risk network, not a separate spoke.

Lesson 5: Address the Root Cause, Not Just the Symptoms

Illustrated By: The crew eventually discovers that Losira is an automated defense mechanism left behind by an extinct race. She’s not malicious—she’s simply executing a program without context or adaptability. Once the crew understands her origin and purpose, they can neutralize the threat.

Compliance Lesson. In risk management, addressing surface-level problems without finding the underlying cause only delays future incidents. For example, punishing an employee for violating a policy without examining why the policy was ignored leaves the organization vulnerable to repeat violations. Compliance should integrate root cause analysis into all investigations. Whether it’s a process flaw, cultural issue, or oversight gap, solving the real problem is the only way to reduce recurrence.

The Enterprise as a Risk Management Model

Captain Kirk and his crew succeed not because they are lucky, but because they adapt quickly, share intelligence, and dig deeper to understand the nature of the threat. These are precisely the attributes a corporate compliance department needs to lead risk management:

  • Proactive assessment before engagement.
  • Adaptive controls that respond to evolving risks.
  • Preparation for rare but high-impact events.
  • Collaboration across organizational functions.
  • Root cause remediation for lasting solutions.

Practical Compliance Takeaways

From That Which Survives, compliance professionals can draw these operational insights:

  1. Integrate Compliance Early—Risk management starts before contracts are signed or operations begin, not after.
  2. Invest in Technology—Data analytics, AI monitoring, and continuous auditing tools make adaptive risk management possible.
  3. Conduct Scenario Planning—Practice responding to “Losira-like” threats: targeted, intelligent, and hard to predict.
  4. Build Risk Alliances—Partner with all departments to create a unified threat picture.
  5. Close the Loop—Use each incident to strengthen your program against future threats.

Final ComplianceLog Reflections

That Which Survives is more than a suspense episode; it is a cautionary tale about the dangers of underestimating risk. Losira was not inherently evil; she was a misunderstood, unexamined part of an environment the crew did not fully assess before engagement.

The compliance officer’s mandate is to ensure the company doesn’t make the same mistake: to scan for threats before beaming in, to adapt to risks that evolve, to prepare for unlikely but devastating events, to coordinate across the enterprise, and to address the root cause when problems arise.

In other words, risk management is not just about surviving; it is about ensuring that your organization thrives in any environment, whether it’s an unexplored planet or a rapidly changing market.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

THE BERKO TRIAL – PART TWO: The Missing Last Mile: How the Defense Challenged the Berko Case

Yesterday in Part One of our series on the Asante Berko FCPA trial and conviction, we examined the prosecution’s mosaic. Today in Part 2 we ask the defense question that cut across every category of proof: Where was the bribe?

The Department of Justice (DOJ) had more than 300 emails, payments to intermediaries, financial-flow charts, compliance concerns, and a secretly recorded lunch. The defense argued that the case still lacked its last mile. No alleged recipient testified. No Ghanaian witness took the stand. No eyewitness described a bribe. No bank record showed money reaching a public official. None of the participants in the email chains explained their meaning to the jury.

That position did not prevail. For only after approximately three hours of deliberation, the jury convicted Asante Kwaku Berko on conspiracy to violate the FCPA, a substantive FCPA violation, and money laundering conspiracy. But a fair account of the trial requires more than repeating the result. It requires understanding why the defense believed suspicious conduct and compliance red flags did not add up to proof beyond a reasonable doubt.

Red Flags Are Not the Elements of a Crime

The defense began with the burden of proof. A high-risk intermediary, personal email, opaque invoices, and cash discussions may justify enhanced diligence, an internal investigation, or a decision to exit a transaction. They do not, standing alone, prove corrupt intent or participation in a bribery agreement. Defense attorney Robert Boone told jurors that the government had years to find a witness or record connecting the money to an official. The courtroom presentation, he argued, was impressive, but the underlying proof was missing. The government’s financial charts traced money from Aksa accounts in Turkey to Tricorp, Berko, and others. According to the defense, those charts stopped before showing a transfer to any alleged public-official recipient.

Prosecutors answered that cash completed the path and concealed the payments. The defense response was that an explanation for missing evidence is not the same as the evidence itself. The last-mile gap was not necessarily a claim that a bank receipt was required for every charged theory. It was an attack on the inferences the government asked the jury to draw about agreement, knowledge, purpose, and authorization.

A Scam, Not a Conspiracy

The defense supplied an alternative explanation for the intermediaries’ demands. Tricorp’s principals, Boone argued, saw outsiders pursuing a valuable project and used claims of political access and urgent payment needs to extract money. They were running a shakedown, not carrying out a bribery agreement.

The emails gave that theory something to work with. In one April 2015 message, a Tricorp principal demanded $500,000 immediately and insisted that unspecified necessities had to be handled. Other exchanges reflected disagreements over amounts, timing, and what had supposedly been promised. Boone characterized the demands as exaggerated and unreliable, comparing them to familiar advance-fee scams.

That distinction was critical. If an intermediary falsely claimed that officials had been or needed to be paid, an email repeating that claim might document the intermediary’s sales pitch rather than an actual bribe. Even the reported statement that Parliament had been paid by Berko came from a Tricorp principal. The defense asked the jury to consider whether the speaker was reporting a fact or using the language of a scam to justify another reimbursement.

The prosecution had a powerful answer: Berko was not merely copied on one stray message. His communications, payment negotiations, channel choices, and recorded statements appeared throughout the chronology. Still, the defense theory targeted an important evidentiary question. Before accepting an intermediary’s statement as proof, who made it, why, and with what first-hand knowledge?

A Legitimate Project With Commercial Logic

The underlying project was real. Ghana was confronting serious electricity shortages and wanted to add 1,000 megawatts of generating capacity quickly. Aksa later obtained financing from Barclays and a Turkish bank after Goldman withdrew, and its 370-megawatt plant entered commercial operation.

The defense used those facts to challenge motive. Ghana needed available power, Aksa could supply it, and other financial institutions ultimately supported the project. Boone put the point bluntly: Why would a qualified company need to bribe a government that was desperate for electricity?

Commercial merit is not a defense to bribery. Legitimate projects can still be advanced through corrupt means. Yet the project’s reality gave the defense a noncriminal explanation for meetings, urgency, large fees, and intense communications. The government had to prove that the conduct crossed the line from hard-driving project execution into corrupt payment activity.

Hundreds of Emails, but No Voice From the Chain

The prosecution treated the emails as the scheme speaking for itself. The defense treated them as fragments without context. FBI Special Agent Ryan Collins introduced much of the correspondence, but Boone emphasized that Collins did not participate in the exchanges and did not know what the writers meant. No participant in the chains took the stand to explain the language.

That allowed the defense to challenge words such as payment, millions, fees, and cash. Depending on purpose and recipient, those terms can describe legitimate compensation, reimbursement, or financing. Similarly, using Gmail for business after acknowledging that a Goldman account was monitored could demonstrate poor judgment, policy evasion, or concealment. The defense argued that the criminal inference depended on what the communications concerned, not the platform alone. This was also the weakness in the defense position. The messages were numerous, contemporaneous, and aligned with transaction milestones. An alternative interpretation had to explain the full pattern, not merely establish that individual phrases were ambiguous.

Testing the Recorded Lunch

The recorded lunch carried the drama of a direct conversation, but the defense attacked its context and origin. The unnamed source first approached the SEC, later assisted the FBI, and was described at trial as the genesis of the investigation. The defense argued that possible eligibility for an SEC whistleblower award created a financial incentive. According to the reporting, the source did not testify, and defense filings asserted that the source had supplied false information to investigators.

The FBI also identified subjects for the source to raise before the November 2016 meeting. One was cash. The resulting video was grainy, the restaurant was noisy, and the conversation moved among English, Twi, and Ghanaian Pidgin English. Jurors relied in part on a translated transcript.

The defense emphasized that the cash exchange arose during an apparently hypothetical discussion involving investors, Ghanaian stock, and a botanical garden. Berko initially said paying the people under discussion was not a good thing. Only after the source asked for the best way to pay did Berko answer that cash could be used.

The government’s strongest response was Berko’s own reported language, including his statement that “KD got one million” and his assurance that he could obtain a large amount of cash.[4] Source motive did not erase those words. The defense attack went to whether the source’s prompting, translation, and hypothetical setup changed their meaning.

Corporate Withdrawal Was Not a Criminal Verdict

Goldman’s review produced genuine concerns. Amandine Martin testified that Aksa’s explanations for payments to Tricorp did not match earlier information and that months of questions did not produce satisfactory answers. Goldman withdrew and earned nothing from the contemplated financing. For the defense, that corporate decision showed a risk-control judgment, not proof of Berko’s guilt. Businesses act before uncertainty is resolved because they do not apply the criminal standard of proof. Other lenders later financed the project, reinforcing the defense position that the transaction had commercial substance.

The distinction matters. A company may properly stop a transaction when diligence cannot resolve serious red flags. A jury must decide whether the government proved the charged crime beyond a reasonable doubt. Those are different decisions made for different purposes.

The Missing Link and the Complete Pattern

The jury rejected the defense position and returned guilty verdicts on all three counts. The general verdict does not disclose why. It does not tell us whether jurors found the emails decisive, credited the cash explanation, accepted the recorded statements at face value, or concluded that all of the evidence corroborated itself.

The defense nevertheless framed the trial’s central proof contest. The government had to turn red flags into criminal evidence. The defense had to offer an innocent explanation capable of accounting for the complete record: the emails, milestone timing, intermediary payments, off-channel communications, compliance interactions, financial flows, and recorded lunch. Identifying a missing link can create reasonable doubt. But the alternative theory must also explain why every other link appears to point in the same direction. In Berko, the jury concluded that the government carried its burden.

Join us tomorrow for Part 3 where we will consider what those three guilty verdicts legally established, what a general verdict leaves unresolved, and why compliance professionals should resist turning a verdict into factual findings the jury never made.

Resources

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko