Categories
Compliance and AI

Compliance and AI: Diego Panama on – AI-Driven GRC: The Next Enterprise Standard

What is the intersection of AI and compliance? What about machine learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, host Tom Fox visits with Diego Panama, new CEO of LogicGate.

Panama brings a disciplined, business-focused perspective to the future of AI-driven GRC platform strategy and risk management transformation. He believes AI is turning GRC from a reactive, checkbox exercise into a strategic, board-level capability, where a holistic platform can unify third-party, cyber, supply chain, and enterprise risks in real time. Rather than leaving professionals buried in operational tasks, he sees agentic AI handling assessments, recommendations, and continuous monitoring so teams can focus on risk appetite, governance, and business outcomes. For Panama, the future of GRC is increasingly autonomous but still human-led, with strong data governance, clear priorities, and responsible use of emerging technology enabling faster, more precise, and more valuable risk management.

Key highlights:

  • Scaling Past 100 Customers with Customer-First GRC
  • AI Agents for Real-Time Global Risk Monitoring
  • Enterprise-wide access and intelligent data interaction
  • Conversational no-code UX with Config Newton agent
  • GRC as the Key to Safe AI Adoption

Resources:

LogicGate

Diego Panama on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – September 11, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending September 11, 2026, include:

  1. AI leaders for healthcare. (BankInfo Security)
  2. Continuous monitoring of AI in healthcare. (Computer Weekly)
  3. The black box of clinical AI. (HealthcareITNews)
  4. Pharma doubles down on AI. (Reuters)
  5. Moving to prevention in medicine with AI. (Frontiers)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
AI Today in 5

AI Today in 5: September 11, 2026, The Compliance Must Evolve Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Getting AI right in wealth management. (FinTech Global)
  2. Could AI go ‘all Skynet’?. (WSJ)
  3. Auditing compliance AI. (BitSight)
  4. Legal considerations for AI rollout. (Foley Hoag)
  5. Why compliance must evolve. (Fast Company)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
FCPA Compliance Report

9/11 Twenty-Five Years Later: Part 6: John Lee Dumas – “I Knew I Was Going to War”

Ed. Note: Five years ago, Tom Fox looked back on 9/11 in a 20-year retrospective. This week is the 25th anniversary of that event. We will be rerunning this award-winning podcast so we never forget.

On the 20th anniversary of the 9/11 terrorist attack, Tom Fox and guests look back on the tragic event and what it meant for them personally, as well as how it impacted the world of compliance. Today Tom’s guest is John Lee Dumas. John, host of the award-winning podcast Entrepreneurs on Fire, joins Tom Fox for the final installment of Looking Back at 9/11 to commemorate the 20th anniversary of the 9/11 attacks. He tells Tom how his life changed in that pivotal moment and the big lessons he learned.

A Time of War

John tells Tom that he was in his final year at Providence College and in the ROTC cadets on 9/11. When he saw the towers fall, he knew at once that it would change the trajectory of his career. He and his roommate looked at each other, and they knew “that our next four years of active duty army experience went from being in the peacetime army to looking like we were going to war.” Within hours, they were called to active duty: “We just became officers in the US Army during a time of war,” John recalls.

Leadership Lessons from the Army

Tom asks John what leadership lessons he learned in the Army. John outlines three major takeaways that his time in combat taught him:

  1. To learn from those who went before. “I learned right at the beginning that I needed to stand upon the shoulders of giants,” he remarks.
  2. A good decision now is better than a great decision later. Action is everything. Make the best decision you can with the information you have, take action, then adjust when you know more.
  3. If you discover later on that you made a wrong decision, cut your losses and move on. Don’t compound that mistake by staying in a bad place, John advises. “I kept being willing to pull back and say, let’s try again, until I finally made a great decision. It took six years to make my first great decision, but that great decision has led to the last 10 years of living the exact life that I want to live.”

What Americans Should Remember

John wants Americans to appreciate their freedom because it was hard-won. He tells listeners, “So few people have ever experienced what true lawlessness is. And until you’ve experienced that, it’s hard to really appreciate what we do have here. But you know, this is a great country, and it is the home of the free because of the brave. And I hope that’s just something that we will always remember.”

Resources

John Lee Dumas: ⁠Entrepreneurs on Fire⁠ 

Categories
Fox on Podcasting

Fox on Podcasting: Bryan Barletta on Podcast Movement NYC 2026

Join Tom Fox as he explores the world of podcasting and get ready to be inspired to start your own podcast. In this episode, Tom talks with Bryan Barletta about two New York City podcasting events: the Sounds Profitable Business Summit (Monday–Tuesday) and Podcast Movement (Thursday–Friday), plus an affiliated IAB Upfronts after-party (Wednesday).

Barletta emphasizes an industry model that subsidizes broader access: buyers (brands, agencies, and holding companies) attend free, while sellers (Sounds Profitable partners) pay $2,000, helping fund lower-cost creator tickets ($199) and free public access to recorded content. The Business Summit is capped at around 500–600 with short 10-minute sessions and heavy networking; no paid speaking slots are used. Podcast Movement features roughly 84–90 sessions across five stages, with panels chosen by popular vote and a diverse committee, and uses headphone audio to support hallway networking. The expo hall is removed in favor of “guerrilla” demos, with potential plans for a future demo stage.

Key highlights:

  • Business Summit Format
  • Networking and No Payola
  • Creator Event Panels
  • Why New York City
  • Hallway Networking Tips
  • Building the New Model

Resources

Bryan Barletta on LinkedIn

Podcast Movement 2026

Artwork

Elaine Capers

Art by Elaine

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending September 11, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include the following:

  1. FOMO leading bank AI spending. (Banking Dive)
  2. Canada’s big banks embrace AI. (CBC)
  3. ChatGPT for financial services. (OpenAI)
  4. Production AI in financial services. (CIO)
  5. How AI will impact corporate spending. (Forbes)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Daily Compliance News

Daily Compliance News: September 11, 2026, The Always Remember Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Huawei trial begins. (WSJ)
  • Former Ecuadorean President sentenced for COVID-era medical supply corruption. (Reuters)
  • 21 Air and safety. (WSJ)
  • ICAC charges ex-HKEX VP (how’s that for acronym overuse?) (SCMP)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance: The Farewell to Dolly Edition

What happens when two top compliance commentators get together? They talk compliance, of course. Join Tom Fox and Kristy Grant-Hart on 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Stories This Week Include:

  • Meta Settles NYT
  • Dolly Parton Passes Away. NYT
  • Hemma Lomax does it again. FCPA Compliance Report
  • 4 things states can do to combat federal corruption. Just Security
  • AI for email compliance. NJIT
  • JPMorgan Ended Banking Relationship With Polymarket Over Regulatory Concerns – WSJ
  • FTC Warns Retailers on Using Private Consumer Data to Raise Prices – WSJ
  • Why Do Boards Keep Giving Misbehaving CEOs Second Chances? – WSJ
  • Unannounced Compliance Audits: Good, bad or “it depends”? – Ideas & Answers
  • Smokey Bear aids arrest of man accused of stealing, reselling signs of iconic mascot from Florida parks – Click Orlando

Resources:

Kristy

Kristy Grant-Hart on LinkedIn

Order Kristy’s updated 10-year new edition of How to Be a Wildly Effective Compliance Officer by clicking here.

Tom

Check out Tom on LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

The NBA/Clippers Investigation: Part 5 – Lessons for CCOs and Boards

The ultimate measure of a compliance program is whether it can constrain the people the organization believes it cannot afford to disappoint. Most compliance programs are designed for ordinary decisions made by ordinary employees. The real danger lies in extraordinary decisions involving people with unusual economic power. Today we conclude with lessons learned.

They may be founders, controlling owners, senior executives, rainmakers, celebrity endorsers, critical customers, or star performers. Their value to the organization can become a reason to bypass controls, reinterpret rules, or treat prohibited requests as business problems requiring creative solutions.

The investigation into the LA Clippers and Kawhi Leonard demonstrates what happens when that pressure enters the commercial ecosystem. The independent investigators’ report (Wachtell Report) concluded that Clippers leaders helped create outside-income opportunities for Leonard through companies doing business with the team, linked vendor business to endorsement arrangements, paid impermissible personal expenses, and failed to report prohibited demands.

The lessons reach well beyond professional sports. They reach into all businesses. Finally, they apply wherever commercial urgency can overwhelm governance.

Lesson One: Power Is a Compliance Risk Factor

Traditional risk assessments organize risk by geography, business unit, transaction type, or regulatory subject. They often overlook individual power.

Organizations should identify people whose economic importance, ownership position, revenue contribution, reputation, or personal relationship with leadership could weaken ordinary controls. This is not an accusation against those individuals. It is recognition that employees may respond differently when a request comes from someone perceived as indispensable.

The DOJ’s Evaluation of Corporate Compliance Programs asks whether risk management is proactive, whether resources follow risk, and whether senior leaders persist in their commitment to compliance when facing competing business objectives. A power-risk assessment helps answer those questions.

Lesson Two: Prior Misconduct Must Change the System

The Clippers had a prior circumvention violation. The NBA later investigated improper demands associated with Leonard’s 2019 free agency, established a reporting requirement, and trained the team’s senior leadership. Yet the Wachtell Report concluded that similar risks materialized again.

Training is not remediation unless the organization can demonstrate changed behavior. After an incident, compliance should identify the root cause, assign control owners, establish deadlines, test effectiveness, and report results to the board. The inquiry should continue until the organization can show it has materially reduced the opportunity for recurrence. DOJ expressly asks whether companies incorporate lessons from their own misconduct and from similar problems at peer organizations. The Organizational Sentencing Guidelines likewise make prior history relevant to risk assessment, program design, and organizational culpability.

Lesson Three: Compliance Must Have Independent Authority

The question is not whether the organization employs compliance professionals. It is whether those professionals can challenge a powerful executive, suspend a transaction, obtain complete information, and reach an independent board committee without management permission.

The DOJ evaluates whether compliance has adequate qualifications, seniority, stature, resources, autonomy, and direct board access. These are operational requirements, not organizational-chart preferences. A CCO who can advise but cannot stop or escalate is not empowered. A compliance committee dominated by the executives sponsoring the transaction is not independent. A board that receives only management-filtered information is not exercising informed oversight.

Lesson Four: Follow the Entire Commercial Relationship

The Clippers investigation involved sponsorships, consulting agreements, sustainability services, an owner’s investment, player endorsements, vendor payments, and personal expenses. Reviewing each transaction separately could obscure the common purpose. Compliance needs a consolidated view of the relationship. That requires common identifiers across procurement, contracts, accounts payable, expenses, conflict disclosures, gifts, sponsorships, and third-party systems.

The most useful question may be simple: What other business do we have with this person or entity? Make that question mandatory when a transaction involves a significant vendor, executive relationship, personal investment, public official, customer representative, agent, or other high-risk beneficiary.

Lesson Five: Test Economic Substance

According to the Wachtell Report, several endorsement arrangements had unusual economics, limited performance obligations, little public activation, and compressed negotiation timelines. Consulting agreements involved substantial advance payments. Separate agreements contained matching or closely connected amounts. The COSO Internal Control–Integrated Framework reminds organizations that controls support compliance and operational objectives, not simply accurate accounting. A payment can be correctly recorded and still serve an improper purpose.

Controls should test business rationale, market value, deliverables, proof of performance, payment timing, ultimate beneficiary, and connections to other transactions. Internal audit should be authorized to ask whether a contract makes commercial sense, not merely whether an authorized person signed it.

Lesson Six: Mandatory Reporting Requires a Closed Loop

The Wachtell Report found that Clippers leaders did not report improper solicitations made on Leonard’s behalf, despite a rule requiring reporting even if a request was rejected. A mandatory reporting policy needs more than a sentence in the code of conduct. It requires defined triggers, responsible owners, escalation deadlines, documentation, non-retaliation protection, and verification that the report reached the required recipient.

Organizations should test the reporting control. Present leaders with realistic scenarios and ask what they would do, whom they would contact, and how quickly. If answers vary, the control is not operating reliably.

Lesson Seven: Red Flags Must Reach Someone Who Can Act

The Wachtell Report described unusual payment structures, internal concern about the Forum transaction, resistance from Aspiration executives, and explicit communications linking Clippers business to Leonard’s endorsement agreement. Red flags do not protect an organization merely because they exist in an email archive. They must reach a person with authority, independence, and responsibility to act.

Boards should identify mission-critical compliance risks and establish reporting systems that deliver meaningful information. The Delaware Supreme Court’s decision in Marchand v. Barnhill emphasizes the board’s obligation to make a good-faith effort to establish and monitor reporting systems for central compliance risks. That does not make every control failure a Caremark violation. It does mean that silence at the board level is not a defensible oversight model.

Lesson Eight: Investigation Conduct Is Compliance Conduct

Investigators assessed not only the underlying transactions but also witness credibility and cooperation. They distinguished between witnesses who accepted responsibility and those whose accounts conflicted with documents or changed over time.

Organizations should prepare for investigations before a crisis. Document preservation, witness instructions, privilege protocols, anti-retaliation protections, escalation duties, and cooperation standards should already be in place. Outside counsel should defend legitimate interests without impairing the organization’s ability to learn the truth. An investigation is not solely a litigation event. It tests culture and governance.

Lesson Nine: Accountability Must Reach Supervisors

The NBA’s penalties included a $30 million organizational fine, forfeiture of five first-round draft picks, individual suspensions, a payment by Leonard, a five-year restriction on Robertson, and a five-year compliance and monitoring program.

The sanctions reached individuals based on different forms of responsibility, including direct conduct, approval, supervision, and organizational leadership. Corporate consequence management should do the same. Employees who participate directly should be accountable, but so should managers who ignore red flags, approve unsupported exceptions, or fail to supervise. Enforce compliance consistently, regardless of commercial value or title.

Lesson Ten: The Board Must Oversee the Pressure Points

Boards do not need to approve every sponsorship, vendor agreement, or expense report. They do need visibility into the areas where incentives, power, and mission-critical compliance risks intersect.

The board should receive reporting on high-risk transactions, control overrides, related-party relationships, significant investigations, repeated policy violations, executive discipline, and remediation testing. It should meet privately with the CCO and internal audit leader and confirm both functions have the information and resources they need. Board oversight is not passive dashboard receipt. It is an informed challenge followed by documented action.

Practical Takeaways: A 90-Day Agenda

CCOs and risk leaders can translate these lessons into action:

  • Identify the organization’s most powerful internal and external stakeholders and assess where their requests could bypass controls.
  • Review prior investigations, violations, and audit findings to confirm that remediation was implemented and tested.
  • Map all relationships involving high-risk vendors, personal investments, sponsorships, consulting arrangements, and individual beneficiaries.
  • Establish independent review for transactions involving controlling owners, senior executives, or conflicts of interest.
  • Test procurement, payment, expense, and reporting controls using real transaction data.
  • Give compliance documented stop-work and escalation authority.
  • Define investigation cooperation and consequence-management standards before the next allegation.
  • Provide the board with targeted reporting on control overrides, repeat issues, and high-risk relationships.

The final lesson from the Clippers investigation is straightforward. Compliance fails when the organization treats the rule as an obstacle and the desired outcome as nonnegotiable. An effective program reverses that order. The rule defines the boundary, and the business must operate within it. The true measure of compliance is whether the organization can say no when yes would be more profitable, more convenient, or more popular. That is where governance becomes real.