Categories
AI Today in 5

AI Today in 5: September 2, 2026, The Farmers Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Streamlining compliance reviews with AI. (Business Wire)
  2. Musicians sue Suno. (WSJ)
  3. Consultants heading for a showdown with clients. (FT)
  4. John Deere to create a chatbot for farmers. (Bloomberg)
  5. USDA to use AI and satellites for crop estimates. Farmers are not amused. (Reuters)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Broken Execution in Day-to-Day Compliance Operations – The BAE Enforcement Action

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent BAE export control enforcement action.

Matt views the BAE export control enforcement action as a strong example of how ITAR compliance failures often stem from routine breakdowns in day-to-day operations rather than dramatic smuggling schemes. He notes that BAE’s U.S. subsidiary sent technical information and services overseas without proper licenses, including to China and even some allied countries, showing that export controls apply to both data and services, not just physical weapons. Kelly argues that the case reveals common compliance weaknesses such as poor training, unclear procedures, weak system warnings, and employee turnover that can leave staff unsure of the rules. His broader point is that companies in export-controlled industries must maintain current licenses and build strong, monitored compliance programs because governments will continue using export controls as an important geopolitical tool.

Key highlights:

  • ITAR data shipments trigger BAE’s $36 million penalty
  • Broken execution in day-to-day compliance operations
  • Export-control warnings before sensitive file transmission
  • Missing Red-Flag Prompts in Export Control System
  • Self-Disclosed, Cooperated, Remediated, Monitored by Another Name

Resources:

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
Daily Compliance News

Daily Compliance News: September 2, 2026, The Be Careful, Be Very Careful Out There Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Former Ecuadorian president jailed for corruption. (BBC)
  • Head of Polish POC arrested for corruption. (The Block)
  • Corruption issues abound in the Venezuela oil deal. (FT)
  • FTC sues Amazon over secret ad pricing system. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Odyssey Week: Leadership: Telemachus and the Succession Problem

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Tom Holland was great as Telemachus.

Odysseus is away. That is the fact around which Ithaca slowly comes apart. He is not merely on a long business trip. He is not delayed in a regional office because the quarterly review ran over. He has been gone for years. In his absence, the household becomes a leadership vacuum. Penelope holds the center as best she can. Telemachus grows up surrounded by uncertainty. The suitors occupy the palace, consume resources, abuse hospitality, and become more comfortable with every passing day. No one is quite sure who has authority.

And when authority is unclear, misconduct finds a chair at the table. That is Telemachus’s compliance lesson. He is not just the son waiting for his father’s return. He is the next generation of leadership inheriting a control environment weakened by absence, ambiguity, and tolerated abuse.

For modern companies, Telemachus represents the succession problem: what happens to governance, compliance, and accountability when the founder, CEO, general counsel, CFO, chief compliance officer, regional president, or other key executive is absent, distracted, replaced, or functionally unreachable? The company may still have policies. It may still have a code of conduct. It may still have approval matrices, committees, workflows, and board decks.

But the practical question remains: who owns compliance when the person everyone used to ask is no longer there?

The Corporate Translation

Every organization has formal authority and informal authority. Formal authority lives in charters, org charts, delegations of authority, board committee mandates, policy ownership tables, and job descriptions. Informal authority lives in the hallway, the inbox, the founder’s instincts, the CFO’s raised eyebrow, the general counsel’s quiet warning, and the compliance officer everyone calls before doing something adventurous.

The trouble begins when the company depends too heavily on informal authority. The founder knows where the risks are. The CFO knows which regional numbers smell funny. The general counsel knows which agents should never be used. The chief compliance officer knows which managers say all the right things and do something else entirely. The regional leader knows which customer relationships require special scrutiny.

Then one of them leaves, retires, burns out, gets promoted, goes on leave, is distracted by a transaction, or becomes unavailable during a crisis. Suddenly the company discovers that what it called “governance” was partly memory, personality, and habit. That is Ithaca without Odysseus.

Succession Is a Compliance Issue

Succession planning is often treated as a leadership development topic. That is too narrow. Succession is also a compliance issue.

When key people leave, the company can lose risk knowledge, control discipline, escalation history, and institutional memory. Open investigations may drift. Third-party concerns may be forgotten. Exceptions may remain unresolved. Sensitive approvals may migrate to people who do not understand the underlying risks. Business units may exploit the transition. Bad actors may test boundaries. The suitors always notice when the house is lightly supervised.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a company’s program is well designed, adequately resourced and empowered, and working in practice. It also asks whether policies and procedures are integrated into day-to-day operations, who is responsible for that integration, and whether gatekeepers know what misconduct to look for and when to escalate concerns. Those are succession questions as much as compliance questions. A program that works only when one heroic executive is present does not work in practice. It works in person. That is a very different thing.

Delegation of Authority: Who Can String the Bow?

A delegation of authority matrix is not the most poetic corporate artifact. No one has ever said, “Gather the children by the fire while I tell the thrilling tale of approval thresholds and signature authority.” But delegation of authority matters. It defines who can approve payments, hire third parties, sign contracts, override controls, accept risk, access systems, certify reports, settle disputes, and bind the company.

When delegation is unclear, people improvise. And improvisation is where compliance problems breed. A regional manager approves a vendor because the usual executive is unavailable. A finance employee processes a payment because “someone senior said it was fine.” A business sponsor signs off on due diligence exceptions without understanding the risk. A system administrator grants access because the request came from an important person. A commercial leader commits the company before legal review because the customer needed an answer by Friday.

Each step may feel practical. Each may be defensible in isolation. Together, they reveal a governance weakness. Delegation of authority should answer three basic questions: who can decide, what can they decide, and under what conditions? It should also answer the question most likely to matter in a crisis: who decides when the usual decider is gone?

Control Ownership Cannot Be a Family Secret

In Ithaca, too much depends on Odysseus’s eventual return. That is not a control framework. That is a weather forecast with sandals. Modern companies make the same mistake when control ownership is unclear or overly personalized. Everyone assumes “finance owns that,” “legal handles that,” “compliance reviews that,” “the business manages that,” or “the board knows about that.” Assumption is not ownership. Control ownership should be specific. The owner should understand the risk the control addresses, how the control operates, what evidence demonstrates performance, when exceptions must be escalated, and who serves as backup.

This is especially important in operationally integrated compliance programs. The ECCP emphasizes that compliance policies and procedures should be reinforced through internal control systems and that employees with approval authority or certification responsibilities should receive guidance on what misconduct to look for and when to escalate. That means compliance cannot sit outside the business like a wise statue waiting to be consulted.

It must be embedded into approvals, workflows, reviews, certifications, access rights, vendor onboarding, financial controls, investigations, and reporting channels. Otherwise, when leadership changes, compliance becomes a scavenger hunt.

The Telemachus Problem in Business

Telemachus is not weak. He is inexperienced. That distinction matters. Many next-generation leaders inherit messy control environments. They did not create the old habits. They did not approve the questionable third parties. They did not design the incentive plan. They did not tolerate the difficult executive. They did not ignore the aging audit findings. But they inherit all of it.

That is the Telemachus problem. New leaders often face a painful choice. They can preserve the comfortable ambiguity that made the prior regime work, or they can impose clarity and risk making everyone uncomfortable. Compliance should help them choose clarity.

A new leader should ask, “What are the top compliance risks in this business?” Which controls depend on specific individuals? Which approvals have weak backup coverage? Which investigations or remediation items are open? Which third parties are high risk? Which exceptions have been granted? Which business units have recurring audit findings? Which employees are afraid to speak up? Which senior people are treated as untouchable?

Those questions do not undermine leadership. They establish it. Telemachus cannot govern Ithaca by pretending the suitors are merely enthusiastic guests.

Board Oversight During Transition

Boards of Directors should pay special attention during leadership transitions. A CEO departure, founder transition, CFO replacement, compliance leadership change, merger integration, restructuring, or sudden executive absence can create real compliance vulnerability. It may not appear on the face of the financials. It may not show up immediately in hotline data. But the risk is there.

The board should ask whether interim authority is clear, whether compliance has direct access to leadership, whether key controls remain staffed, whether open issues are being tracked, and whether employees understand where to escalate concerns.

A transition plan should not be limited to investor messaging and organizational charts. It should include compliance continuity. Who owns active investigations? Who signs certifications? Who approves high-risk third parties? Who can grant policy exceptions? Who reports to the board? Who monitors retaliation risk? Who tracks remediation? Who protects records and data? Who communicates expectations to employees? If those answers are unclear, the suitors are already choosing seats.

The Compliance Takeaway

Telemachus teaches us that compliance continuity matters. A company cannot rely on heroic founders, all-knowing executives, indispensable compliance officers, or informal networks of people who “just know how things work.” That may function for a while. It may even feel efficient. But when the key person is gone, the weakness becomes visible. Governance must survive absence.

Authority must be clear. Control ownership must be documented. Delegation must be practical. Oversight must continue. Compliance must be integrated into operations, not dependent on personalities. Because when authority is unclear, misconduct does not wait politely outside the palace. It pulls up a chair, pours the wine, and starts acting like it owns the place.

Join us Tomorrow

Telemachus teaches that governance must survive absence: authority must be clear, ownership documented, and compliance embedded deeply enough that Ithaca can operate without Odysseus in the room. Penelope carries that lesson into the next test, showing what ethical leadership looks like when authority is contested, pressure is relentless. Everyone wants a decision before the facts are ready. If Telemachus asks who owns compliance when the key leader is gone, Penelope asks whether the person with authority has the discipline to say “not yet” to a questionable vendor, weak certification, incomplete investigation, or rushed transaction. Together, they move the leadership arc from succession and continuity to integrity under pressure: first making governance clear, then proving it can hold the line when the suitors demand an answer.