Categories
Innovation in Compliance

Innovation in Compliance: Brian Holyfield on Reducing Cybersecurity Blast Radius

Innovation comes in many areas and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance as he visits with top innovative minds, thinkers and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom visits with Brian Holyfield, Chief Product Officer at SendSafely.

Holyfield discusses about why the right compliance question on cybersecurity is not whether a breach will happen but when and what data will be exposed, often through vendors. Holyfield explains “blast radius” as the scope of access and data reachable during an incident and argues organizations should prioritize architecture, data minimization, and retention controls alongside prevention. Holyfield highlights risks from accumulated file attachments, over-broad user access, interconnected systems using OAuth tokens, and “standing access” via long-lived machine credentials that can be abused without obvious login anomalies. Holyfield discusses the examples involving ServiceNow and Salesforce illustrate platform vulnerabilities, trusted upstream vendor connections, and end-user compromise. Holyfield advises leaders to inventory connections, define retention/archiving, and move sensitive data out of frontline platforms; SendSafely positions itself as an end-to-end encrypted trust layer, including for AI chatbot attachments.

Key Highlights

  • Assume the Breach
  • Blast Radius Explained
  • ServiceNow and Salesforce Lessons
  • Board-Level Questions
  • AI Changes the Game
  • Compliance and Governance Fit

Resources

SendSafely

Brian Holyfield on LinkedIn

 

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
Daily Compliance News

Daily Compliance News: August 25, 2026, The All Leadership Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • The leadership skill that matters most in the age of AI. (Bloomberg)
  • CEO with ‘no close friends.’ (FT)
  • Keeping top talent in the age of AI. (FT)
  • Becoming a Principled Driven Leader. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Everything Compliance - Shout Outs and Rants

Shout Outs and Rants- AI, Investigations, Kickbacks and Kids

Welcome to a new season of Everything Compliance – Shout Outs and Rants. We have a new host, Adam Turteltaub, new panelist, Rebecca Walker who joins returning regulars Jonathan Armstrong and Karen Moore for the next iteration of Everything Compliance Shout Outs and Rants.

  • Adam shouts out to the Boeing documentary Free Fall and Peter Robison’s book Flying Blind for lessons on culture, whistleblowers, and safety, and praises United Airlines for returning a plane to address a mechanical issue.
  • Rebecca raises a compliance training dilemma: employees using company AI tools to answer test or “test-out” questions, which may look like cheating and undermine training records in an investigation, yet could mirror desired real-world behavior if employees are expected to consult policies, compliance, or an AI chatbot when issues arise.
  • Jonathan recounts a scandal involving Scotland’s First Minister John Swinney, including FOI-revealed travel costs (about £45,000 in flights and significant car hire) allegedly contrary to policy and justified as meetings in Kentucky.
  • Karen shouts out to the 25 incoming Fordham MSL Introduction to Corporate Compliance students and reflects on the shift from accidental to intentional compliance careers.

Everything Compliance Shout Outs and Rants is a production of the Compliance Podcast Network.

Categories
AI Today in 5

AI Today in 5: August 25, 2026 the Named Accountability Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. AI governance for health services. (YaHoo!Finanace)
  2. AI for email compliance. (NJIT)
  3. AI in quality management. (ARC)
  4. AI governance is becoming a named accountability. (CCI)
  5. Bank grade AI for compliance. (FinTechGlobal)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Blog

Private Company, Public Risk: Building Defensible AI Governance Before the Rules Arrive

For private companies, the central question about artificial intelligence is no longer whether the technology is in the business. It is whether anyone can explain where it is, what it does, what data it touches, and who is accountable when it fails.

That is the warning in “AI Governance for Private Companies,” by Hillary Flynn, Drew Morales, and Courtney Hugger of Wellington Management which was recently posted in the Harvard Law School Forum on Corporate Governance. The authors report that nearly three in four companies plan to deploy agentic AI within two years, while only one in five has a mature governance model for autonomous agents. That is not merely a technology gap. It is a governance gap.

Private ownership does not make AI risk private. The consequences arrive through customers, employees, regulators, investors, lenders, insurers, and business partners. A company may not yet face a single comprehensive AI law, but it can still face a privacy complaint, contract dispute, cyber incident, customer loss, or damaged valuation. For compliance professionals, governance should precede scale.

Private Does Not Mean Exempt

Private companies are moving quickly because AI can increase productivity, improve customer service, accelerate analysis, support coding, and help a growing company scale. The article also identifies a critical lesson from Wellington’s portfolio companies: the largest barriers are often organizational, not technical. Companies making the strongest progress combine AI investment with employee training, clear governance, and defined expectations.

This is where the Chief Compliance Officer can reframe the discussion. AI governance is the discipline that allows useful experimentation without unmanaged legal and business exposure. The goal is not a thick policy on a shared drive. The goal is an operating system for accountable decisions.

The European Union AI Act is being implemented in phases through 2027, with expectations around transparency, human oversight, documentation, risk management, monitoring, and AI literacy. In the United States, NIST guidance,ISO standards, sector rules, state laws, and customer requirements are shaping expectations without one federal AI statute. A private company can therefore face AI governance demands through a contract or transaction long before a regulator knocks on the door.

Begin With the Business Objective

One of the article’s strongest recommendations is also one of the simplest: start with the business problem, not the AI tool. This is precisely what Carl Hahn has continually maintained, which is toe always ask the question ‘What is the Business Value.” Teams should define the desired outcome before selecting a model or vendor. Is it lower cost, faster response, better quality, increased revenue, fewer errors, or reduced risk?

Governance cannot evaluate an undefined promise. A measurable objective gives management a basis for deciding whether the use case works and whether its benefits justify its risks. It also creates stopping rules. Approval should identify what failure, customer impact, control breakdown, or change in scope will trigger redesign, escalation, suspension, or retirement.

Compliance should insist on this discipline, particularly when an AI use case affects payments, eligibility, claims, pricing, employment, healthcare, education, financial products, or customer communications. Those are not ordinary software deployments. They are decisions and interactions with consequences for real people.

Inventory First, Then Tier the Risk

A company cannot govern what it cannot see. The foundation is an inventory of models, vendors, internal tools, embedded features, customer-facing systems, employee-built applications, and known shadow AI. It does not need to be perfect. It needs an owner, an update process, and enough information to support risk decisions.

Each use case should then be placed into a risk tier. Relevant factors include the sensitivity of the data, degree of autonomy, importance of the business process, effect on customers or employees, regulatory exposure, ability to explain the result, and ease of reversing an error. Low-risk uses can follow a streamlined path. High-impact uses should receive enhanced testing, documented approval, human oversight, monitoring, and senior-level escalation.

Risk tiering prevents two failures. Treating every use as equally dangerous overwhelms review and encourages employees to route around it. Treating every use as ordinary technology leaves consequential applications without meaningful controls. Good governance applies greater rigor where potential harm is greater.

Put a Name Next to the Risk

Every AI system should have a business owner who remains accountable for its outcome. Accountability cannot be delegated to the model, the data science team, or the vendor. The owner should understand the intended purpose, approved users, permitted data, performance standard, escalation route, and circumstances under which the system must be paused.

Higher-risk applications should receive cross-functional review involving the business, product, engineering, legal, compliance, privacy, cybersecurity, procurement, and risk functions. This does not require a new bureaucracy. It requires a repeatable process with recorded approvals and clear responsibility.

Agentic AI raises the stakes because the risk moves from a wrong answer to a wrong action. Permissions should be limited, high-stakes actions should require human approval, and activity should be logged. Override and shutdown mechanisms should be tested. The chatbot manipulated into agreeing to sell a vehicle for one dollar shows how weak boundaries turn a novelty into an operational event.

Treat Vendors as Part of the System

Most private companies will rely on external models, platforms, and software. That makes AI governance inseparable from third-party risk management. Traditional security questionnaires are not enough. Diligence should address how vendor data is used, whether customer data trains models, how model changes are communicated, what transparency is available, how performance is tested, who bears liability, and whether data and workflows can be moved if the relationship ends.

The company should monitor model updates, service degradation, changes in terms, and features that expand access or autonomy. A tool approved for summarization should not silently become authorized to send messages, approve transactions, or alter customer records.

Monitor the System in Practice

AI governance does not end at approval. Model updates, new data, and user behavior can alter performance. Companies should monitor accuracy, reliability, bias, drift, misuse, repeated failures, and customer impact. An incident protocol should define how to pause the system, preserve evidence, escalate, remediate harm, and communicate with affected stakeholders.

This is where AI governance meets familiar compliance principles. The DOJ’s Evaluation of Corporate Compliance Programs asks whether a program works in practice. COSO emphasizes control activities, information, monitoring, and accountability. NIST’s AI Risk Management Framework helps organizations govern, map, measure, and manage AI risk. ISO/IEC 42001 offers a management-system approach. A company should select a coherent baseline and produce evidence that its controls operate.

A Practical Agenda for Boards and CCOs

Establish ownership. Name an executive accountable for AI governance and identify the board committee that will oversee material AI risk.

Build the inventory. Capture sanctioned tools, embedded vendor capabilities, customer-facing uses, agentic applications, and known shadow AI.

Tier the use cases. Apply enhanced review where AI affects sensitive data, consequential decisions, critical operations, or autonomous action.

Strengthen the vendor process. Add AI-specific diligence, contractual protections, change controls, exit planning, and ongoing monitoring.

Test the failure plan. Confirm that the company can detect a harmful outcome, stop the system, preserve evidence, assign responsibility, and remediate the impact.

The author’s bottom line is the right one for compliance leaders: the winners will not necessarily be the companies that deploy AI fastest. They will be the companies that combine innovation with accountability, customer awareness, and disciplined execution. For a private company, defensible AI governance is not preparation for some distant regulatory future. It is how management protects value today.