Categories
Great Women in Compliance

Great Women in Compliance: AI, Compliance & Thinking Outside the Box

AI is a key topic for all of us these days, and for ethics and compliance professionals, it is a challenge and an opportunity. In this episode, Lisa Fine and Hemma Lomax speak with Mara Senn, founder and CEO of Ethakos, and Audrey Harris, Managing Director at Affiliated Monitors; both have deep experience across investigations, enforcement, in-house compliance, and monitorships. We focus on what AI means for compliance – from how it is changing how companies operate to how it can help us work smarter while keeping humans in the AI loop.

They share insights from their experience on many topics, including:

  • Moving beyond AI as a time-saving tool and thinking bigger about how it can transform compliance.
  • Why compliance needs to understand the business, its systems, and its data.
  • The risks of staying safely inside the “compliance box.”
  • How better data and AI can help compliance see risk differently—and connect the dots.
  • Why tech and data skills are becoming essential for the next generation of compliance professionals.
  • Finding the balance between innovation and risk management.

This is a great discussion for novice AI users and experienced professionals alike. 

Categories
AI Today in 5

AI Today in 5: September 9, 2026, The Wiki Incident Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. AI governance is the real test for compliance. (FinTech Global)
  2. The role of AI in manufacturing. (Deloitte)
  3. AI hacking WeChat. (NYT)
  4. OpenAI has a wiki ‘incident.’ (Reuters)
  5. Is AGI here? (Bloomberg)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Clippers Salary-Cap Circumvention: Sham Endorsements, Contract Red Flags, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for hard-hitting compliance insights? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the NBA’s sanctions against the Los Angeles Clippers for a salary-cap circumvention scheme tied to Kawhi Leonard.

In this delicious set of compliance imbroglios, senior management, including owner Steve Ballmer, allegedly arranged sham endorsement deals with four business partners and offsetting Clippers business to funnel about $18 million in extra compensation, plus improperly pay Leonard’s personal expenses. Tom and Matt review the Wachtell Lipton 36-page investigation detailing sparse contracts, unusual counterparties, rapid deal timing, and incriminating emails (including from Gillian Zucker), as well as recidivism after a similar 2019 violation. Penalties include a $30 million team fine, Leonard’s $700K fine, loss of first-round picks for five years, and suspensions for Ballmer, Zucker, and the basketball operations executive. Meanwhile, Ballmer denies wrongdoing and says the Clippers will file an appeal. They highlight contract-management and third-party due diligence lessons from FCPA-style guidance, the need to analyze patterns across multiple agreements, and the value of strong compliance roles in pro sports.

Key highlights:

  • NBA Scandal Overview
  • How The Scheme Worked and Why Salary Caps Matter
  • Sham Contracts = Red Flags
  • Paper Trail and Intent
  • Recidivism and Tone at the Top
  • Contract Patterns Lessons

Resources:

Matt in Radical Compliance

Tom in the FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has received Davey, Communicator, and w3 Awards, all for podcast excellence.

Categories
FCPA Compliance Report

9/11 Twenty-Five Years Later: Part 4: Eric Feldman – A Wake Up Call

Ed. Note: Five years ago, Tom Fox looked back on 9/11 in a 20-year retrospective. This week is the 25th anniversary of that event. We will be rerunning this award-winning podcast so we never forget.

On the 20th anniversary of the 9/11 terrorist attack, Tom Fox and guests look back on the tragic event and what it meant for them personally, as well as how it impacted the world of compliance. Today Tom’s guest is Eric Feldman. Eric is the Senior Vice President and Managing Director at Affiliated Monitors, a company that monitors large and small companies in government contracting, construction, engineering, manufacturing, and financial services. He also assesses corporate ethics and compliance programs across many countries. Eric joins Tom to discuss how the events of 9/11 changed the role of the Inspector General.

The Impact of 9/11 on the IG’s Role

Eric tells Tom that 9/11 was the most informative time of his career and of many other Inspector General’s. It was a moment of refocusing for everyone. Eric worked within the oversight function, but as part of the mission he was overseeing. “That focus on mission was it for me,” he tells Tom. Eric expresses that understanding the mission helped make him a better Inspector General. IGs worldwide became more concerned with the broader picture of how funds were used at their agencies to fight the war on terror, rather than the minutiae of time-and-attendance reporting.

The Importance of the IG Now

Tom asks Eric to elaborate on how the IG’s role rose in prominence post-9/11. Eric explains that government IGs became “part of the team” in different ways. There is more collaboration now across the agencies that IGs oversee. There is also independence: Eric expresses that there must be a balance between collaboration and independence. IGs are especially important because they ensure the dollars spent on the war and mission are spent properly.

A Wake-Up Call of Unity

Eric reflects that 9/11 was a wake-up call for the United States. The country came together, and unity, patriotism, and a sense of duty overtook politics. Eric hopes that the people can return to that unity without another catastrophe. 

Resources:

Eric Feldman | ⁠LinkedIn⁠ | ⁠Twitter⁠

⁠Affiliated Monitors

Categories
Daily Compliance News

Daily Compliance News: September 9, 2026, The Huawei (Finally) Goes to Trial Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Ukraine Prosecutor General resigns over corruption allegations. (KYIV Post)
  • Huawei wanted a trial; now it’s getting one. (Reuters)
  • Score one for Team Torre. (WSJ)
  • What’s next, no more maple syrup? (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

The NBA/Clippers Investigation: Part 3 – Paper Compliance Is Not an Internal Control: Substance, Procurement, and the Audit Trail

The Clippers investigation shows why contracts, approvals, and carefully drafted emails cannot substitute for controls that test economic reality. In Part 3 of a five-part series, we explore why and how a transaction can have a contract, an approval, an invoice, and an email trail and still pose a serious compliance problem. Documentation proves that a process occurred. It does not prove that the process was legitimate.

That distinction sits at the center of the investigation into the LA Clippers and Kawhi Leonard. The independent investigators’ report (Wachtell Report) concluded that the Clippers initiated and facilitated endorsement arrangements between Leonard and four companies doing business with the team, induced those arrangements by offering business to the companies, paid impermissible personal expenses, and failed to meet improper demands made on Leonard’s behalf.

The alleged conduct crossed organizational boundaries. It touched business operations, basketball operations, procurement, sponsorships, consulting arrangements, accounts payable, expenses, legal review, and executive management. That makes this an internal controls case.

The Difference Between Evidence and Control

One of the report’s most important findings concerned introduction emails sent by Clippers President of Business Operations Gillian Zucker. The emails were written as if Boingo, Daktronics, Lockton, and later Aspiration had requested introductions to Leonard’s representatives. NBA rules permitted a narrow response when a commercial partner initiated such a request. They did not permit the team to create the opportunity for the player. The investigators concluded that the emails did not reflect the true sequence of events and, in Aspiration’s case, were created after deal development was already underway.

This is a classic paper-compliance problem. The communication used the language of the rule without satisfying its substance. A control cannot merely ask whether an introduction email contains the approved wording. It must test who initiated the contact, what discussions preceded the email, who proposed the economics, and whether team personnel remained involved afterward. Checklists confirm the form. Effective controls challenge reality.

Fragmented Transactions Hid a Common Purpose

The Wachtell Report described multiple agreements that could have appeared unrelated in separate systems. Vendors entered consulting or services agreements with the Clippers while also entering endorsement agreements with Leonard. Aspiration had sponsorship, sustainability, investment, forum, and player-endorsement relationships involving overlapping parties.

Investigators connected those transactions through timing, matching amounts, communications, and business leverage. Two companies reportedly received $10 million in consulting payments before entering endorsement agreements with Leonard. A third received a $2 million consulting payment one day after making its first payment to him.

The Forum agreement initially contemplated $7 million in annual business for Aspiration. That figure matched the annual cash component of Leonard’s endorsement agreement. Investigators further reported that the underlying carbon analysis did not generate the $28 million budget. Instead, the consultant said the Clippers supplied that budget.

The control failure was fragmentation. Procurement reviewed one agreement, marketing another, finance a payment, and business leaders the broader relationship. No control appears to have aggregated the transactions and asked whether one funded, induced, or conditioned another.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) tells prosecutors to examine how misconduct was funded, including purchase orders and reimbursements (How was the misconduct in question funded (e.g., purchase orders, employee reimbursements, discounts, petty cash?); what controls could have prevented access to those funds (What controls failed?); whether vendor-selection procedures were followed (If vendors were involved in the misconduct, what was the process for vendor selection and did the vendor undergo that process?); and whether contract terms, payment terms, performance, and compensation were appropriate. Those are precisely the questions an organization should ask before enforcement authorities arrive.

Control Environment

The control environment begins with leadership and accountability. According to the report, the most senior business and basketball executives participated in or knew about key parts of the conduct. Investigators concluded that Ballmer failed to create conditions in which the organization followed rules it had previously violated. When senior leaders create the risk, lower-level approvals are unlikely to function as meaningful controls. Employees may view an executive request as authorization to proceed, even when the transaction presents obvious concerns.

Risk Assessment

The Clippers had a prior circumvention violation and were investigated over Leonard’s free-agency negotiations. The NBA had then provided specific training and imposed a mandatory reporting obligation. That history should have produced a targeted risk assessment covering player representatives, sponsor introductions, endorsement arrangements, personal expenses, vendor spend-back programs, and benefits flowing through third parties. Prior misconduct is not simply history. It is risk data.

Here, the ECCP asked some direct questions, including, “Were there prior opportunities to detect the misconduct in question, such as audit reports identifying relevant control failures or allegations, complaints, or investigations?” Additionally, it notes that critical factors in evaluating any program include whether the program is adequately designed to maximize effectiveness in preventing and detecting employee wrongdoing and whether corporate management enforces the program or tacitly encourages or permits employees to engage in misconduct.

Control Activities

The Wachtell Report suggests potential gaps in segregation of duties, conflict review, procurement approval, contract benchmarking, expense reimbursement, and related-transaction analysis. High-risk transactions should require independent approval outside the requesting executive’s chain of command. Controls should compare compensation with deliverables, confirm actual performance, flag advance payments, and identify common counterparties across procurement and non-procurement systems.

Information and Communication

The organization reportedly had information that should have triggered escalation: demands for $10 million in annual off-court income, unusual endorsement economics, concerns from Aspiration executives, internal descriptions of a Forum deal as “shady,” and explicit threats connecting the Forum and Leonard agreements. Indeed, Uncle Dennis’s presence alone was enough of a red flag based on his prior conduct. The issue was not the absence of information. It was the failure to move that information to a function with the independence and authority to act.

Monitoring

Hundreds of personal expenses were reportedly paid without the required deduction or reimbursement. Multiple vendors signed unusual endorsement arrangements, with minimal public activation or performance. These were recurring patterns, not one-time exceptions. Monitoring should identify patterns across time. If a control repeatedly approves exceptions without examining their cumulative effect, it is not monitoring risk. It is normalizing it.

Designing Controls for Substance

An effective control architecture should include three layers. Preventive controls should require documented business rationale, competitive sourcing, conflict disclosures, independent approval, clear deliverables, market benchmarking, and legal and compliance review before committing funds.

Detective controls should compare related transactions, test payment timing, examine overrides, confirm performance, and monitor expense exceptions. They should search for patterns across legal entities and business functions. Responsive controls should define who receives red flags, when compliance can stop payment, when issues reach the audit committee, and how remediation is tracked to completion. The most important design principle is independence. The DOJ asks whether compliance has adequate authority, stature, resources, and direct access to the board. (Where within the company is the compliance function housed (e.g., within the legal department, under a business function, or as an independent function reporting to the CEO and/or board?)

If executives can bypass or overrule the control function without documented challenge, the program is not empowered.

Practical Takeaways

Compliance, audit, and risk leaders should take the following actions:

  • Inventory all systems containing vendor, contract, payment, expense, sponsorship, and conflict information.
  • Build monitoring systems that identify common parties and beneficiaries across those systems.
  • Require proof of services and measurable deliverables before releasing significant payments.
  • Review advance payments, matching amounts, compressed timelines, and executive overrides as elevated-risk indicators.
  • Treat prior violations and mandatory reporting duties as subjects for recurring control testing.
  • Give internal audit authority to examine commercial substance, not merely procedural completion.
  • Report control failures involving senior management directly to an independent board committee.

The Clippers salary cap circumvention demonstrates that an audit trail can document a failure as easily as it documents compliance. The question is whether the organization has controls that can interpret what the records mean.

In tomorrow’s blog post, we will turn from detection to accountability and examine how cooperation, credibility, seniority, prior misconduct, and supervisory failure should shape consequence management.