Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance-Episode 84— The Slop Grenades edition

What happens when two top compliance commentators get together? They talk compliance of course. Join Tom Fox and Kristy Grant-Hart in 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Stories This Week Include

  • Former Vitol trader Javier Aguilar sentenced to 4 years.   (Bloomberg)
  • Russia seizes control of Nestle operations.  (WSJ)
  • The Class ceiling in America.   (NYT)
  • SEC rollback puts audit fees at risk. (FT)
  • Must AI companies disclose ‘dangerous events’? (Reuters)
  • OpenAI Discloses Six New Incidents of ‘Concerning’ A.I. Behavior – NYT – HERE
  • Shopify CEO says employees’ ‘slop grenades’ are making more work for everyone else – Fortune – HERE
  • Payments Scandal Rocks LA Clippers – Radical Compliance – HERE
  • Florida man dressed in full jester costume arrested for pulling 12-inch dagger on landscaper over loud mowing  – AOL – HERE
  • The EU AI Act Is No Longer Theoretical – Volkov Law – HERE

Resources

Kristy

Kristy Grant-Hart on LinkedIn

Order Kristy’s updated, at 10-years, new edition of How to Be a Wildly Effective Compliance Officer, by clicking here.

Tom

Check out Tom on LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Daily Compliance News

Daily Compliance News:  September 25,  2026 the PE and Law Firms Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance related stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest for the compliance professional.

  • Creating world AI controls via groupchat.(WSJ)
  • Corruption shaking up Brazilian Presidential election. (NYT)
  • The monster behind Russia sanctions evasion. (NYT)
  • Private Equity will pay out to lawyers. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Balance in Crisis

Balance in Crisis: The Ziglar Wheel and Internal Controls

We live in an age of constant motion. We move faster, communicate more, and accomplish more than ever before, yet many people feel exhausted, fragmented, and quietly unsettled. Our lives are full but are not integrated. In this podcast, Balance in Crisis, Kenneth O’Neal challenges the belief that balance is a myth or something achieved by doing less. True balance is built. It is the result of alignment and the intentional ordering of life around what matters most. When values, beliefs, and daily actions are misaligned, even success carries a hidden cost. Burnout, confusion, strained relationships, and loss of purpose often follow. In this inaugural episode, host Tom Fox and Kenneth O’Neal introduce the topic of “Balance in Crisis” with a discussion of aligning virtues, priorities, and communication.

Tom Fox and Kenneth O’Neal continue their “Balance in Crisis” series by exploring why O’Neal wrote the book and how Zig Ziglar’s “wheel of life” and seven key areas (including mental, spiritual, physical, relationships, family, financial, career/personal care) remain relevant. O’Neal discusses Ziglar’s focus on service to others, Tom Ziglar’s involvement (including writing forwards to O’Neal’s four books), and how COVID accelerated O’Neal’s coaching, speaking, and writing after his Schreiner University program ended. They examine O’Neal’s expanded “wheel of balance” with 15 spokes, including business-oriented spokes such as leadership, marketing, sales, administration/finance, and operations, anchored by a hub focused on body, soul, and spirit. The conversation connects these concepts to compliance-style “systems,” especially internal controls, auditing experience, leadership accountability, and engagement.

Key Highlights

  • Zig Ziglar and His Legacy
  • Why Balance in Crisis
  • Wheel of Balance Explained
  • 15 Spokes and the Hub
  • Internal Controls as a System
  • Overrides and Personal Boundaries

Resources

Kenneth O’Neal

Balance in Crisis

Book a Clarity Call

Categories
AI Today in 5

AI Today in 5: September 25, 2026 the Next Gen Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. Banks warn on AI shopping bots.(Reuters)
  2. AI pushing drug development. (BioSpace)
  3. Hospices have learning curve on AI. (HospiceNews)
  4. The next generation of compliance.  (FinTechGlobal)
  5. AI v. AI is driving up medical costs. (NYT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Compliance and AI

Compliance and AI: Brian Holyfield on Shrinking the Blast Radius

What is the intersection of AI and compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, host Tom Fox visits Brian Holyfield, Chief Product Officer at SendSafely.

Holyfield is the co-founder and Chief Product Officer at SendSafely, where his background in ethical hacking and real-world security testing shapes a practical view of cybersecurity. He believes compliance should reflect how breaches actually happen, especially through vendors and service providers, which means organizations must look beyond their own perimeter. For him, data minimization and retention controls are essential: companies should keep only the data they truly need, delete unnecessary copies, and limit where sensitive information lives. Holyfield also stresses blast radius reduction, arguing that the best defense is to assume a breach will occur and design systems so attackers can access as little data as possible for as short a time as possible.

Key Highlights

  • Preventive AI governance through data minimization
  • Deliberate configuration choices that shrink breach blast radius
  • Aging Out Data Into Secure Backend Archives
  • Native end-to-end encrypted storage for regulated attachments
  • Trust Layer for End-to-End Encrypted Regulated Data

Resources

SendSafely

Brian Holyfield on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories –Week Ending September 25, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust. This week’s stories include:

  1. Trust and AI in the financial sector.  (FinTechGlobal)
  2. AI recordkeeping hurdles for financial services firms. (ACA)
  3. Can financial services overcome barriers to AI adoption.  (FinTechGlobal)
  4. Finance leaders want more proof of and control over AI.(BusinessInsider)
  5. Banks warn on AI shopping.(Reuters)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Blog

Da Vinci Week: Part 5 – Leonardo’s Notebooks and the Defensible Compliance Program

In the first four posts in the Leonardo Compliance Framework, we used Leonardo’s work to explore the compliance disciplines of Refine, Investigate, Innovate, and Monitor.  For our final blog post, the lesson comes not from a single Leonardo masterpiece but to the extraordinary collection of notebooks he created throughout his life. Leonardo recorded observations about anatomy, engineering, mechanics, water, optics, mathematics, architecture, flight, weapons, and the natural world. He drew machines, recorded experiments, posed questions, explored ideas, and returned repeatedly to subjects that interested him.

The compliance lesson is larger than good note-taking. Leonardo externalized knowledge. He created a record of observations, ideas, questions, and reasoning that otherwise would have existed only in his mind. Modern corporations face a similar challenge. A CCO may understand why a particular control exists. An investigator may remember why an inquiry was expanded. A regional compliance officer may know why a distributor received enhanced scrutiny. An Audit Committee may understand why management accepted a particular residual risk. An AI governance committee may know why a particular use case was approved with specific limitations.

Then people leave, responsibilities change, businesses are reorganized, and memories fade. The policy remains, but the reasoning disappears. That is why documentation should be viewed as a component of compliance governance rather than simply an administrative obligation.

If It Is Not Documented, the Organization May Not Know It

Compliance professionals are familiar with the maxim that if something is not documented, it did not happen. That formulation can be overly simplistic, but it points toward a genuine problem. Organizations often know more than their systems preserve.

Consider a high-risk distributor approved five years ago. The compliance file may contain due diligence reports, certifications, contractual provisions, and an approval. Yet the people involved may have known far more. They may have discussed a government relationship, considered terminating the proposed engagement, obtained additional information, imposed enhanced controls, and ultimately concluded that the residual risk was manageable.

If the file contains only the final approval, a future reviewer may know what the company decided without understanding why it made the decision. That distinction matters. Good compliance documentation should preserve significant reasoning, not simply outcomes.

This does not mean every routine decision requires a lengthy memorandum. Documentation should remain proportional to risk. A routine low-risk approval may require little explanation. A significant exception involving elevated corruption risk, a senior executive, a sensitive investigation, or a consequential AI application may warrant considerably more.

Risk-based documentation is part of a defensible compliance program.

Documentation Creates Institutional Memory

One of the most significant vulnerabilities in many compliance programs is the concentration of institutional knowledge in particular individuals. Every organization has employees who know why things work the way they do.

A longtime compliance officer remembers why a control was implemented after an investigation. An Internal Audit executive understands why a particular business unit receives enhanced testing. A Finance employee knows why payments to a particular category of third parties require additional approval. An investigator remembers a series of cases that revealed a recurring management problem.

That knowledge has value. A new CCO should be able to understand why major components of the program exist. A new Audit Committee chair should be able to understand significant unresolved compliance risks. A new investigator should be able to identify relevant historical matters. A new control owner should understand what problem the control was designed to address. Institutional memory should belong to the institution.

Documentation Supports Accountability

Clear documentation also helps answer one of the most important questions in corporate governance: who decided?

Organizations make thousands of decisions involving compliance risk. Most are routine. Some are consequential.

When a significant risk is accepted, the company should be able to identify the person or governance body with authority to accept it.

This is particularly important for exceptions.

If a high-risk third party is approved despite significant red flags, who approved the relationship? If an investigation involving a senior executive is narrowed, who authorized the change in scope? If a remediation deadline is extended, who approved the extension and what interim controls are operating? If an AI system is permitted to influence consequential decisions, who approved the use case and under what conditions?

These are governance questions.

Documentation creates a decision trail.

That trail allows management, Internal Audit, the board, and, when necessary, regulators or enforcement authorities to understand how the organization exercised judgment.

A defensible compliance program does not require perfect decisions. Business decisions involve uncertainty.

It should, however, be able to demonstrate that significant decisions were made through an appropriate process by people with the authority and information necessary to make them.

Remediation Requires Evidence

The Michelangelo series emphasized the difference between closing a project and solving the underlying problem. Leonardo’s notebooks add another dimension: the organization should preserve evidence of what it changed and why.

Suppose an investigation identifies weak approval controls over distributor discounts. Management agrees to remediate the issue by modifying system permissions and requiring additional review.

The compliance record should identify the deficiency, remediation owner, planned corrective action, expected completion date, and evidence required for closure. When management reports that remediation is complete, the record should support that conclusion.

Was the system actually modified? Were users informed? Did testing confirm that the revised control operates as intended? Were similar vulnerabilities evaluated elsewhere? This creates a defensible chain from problem to solution.

Finding → Root Cause → Remediation → Ownership → Validation → Closure

That chain is valuable to the CCO because it demonstrates that compliance findings lead to management action. It is valuable to Internal Audit because it supports assurance. It is valuable to the board because it provides evidence that identified risks are being addressed. Documentation converts remediation from a promise into an accountable process.

AI Makes Documentation More Important

Artificial intelligence may make the documentation principle more important than at any previous point in the modern compliance program. AI governance involves decisions that may be difficult to reconstruct after the fact if they are not documented when made.

A company evaluating a significant AI use case should preserve enough information to understand the system’s intended purpose, business owner, risk classification, relevant data, identified risks, testing, required controls, human oversight, approval conditions, and monitoring expectations.

The record should also reflect material changes.

An AI application approved as a low-risk productivity tool may later gain access to sensitive internal data. A vendor may change the underlying model. A system may become integrated into a consequential business process. An application initially used to recommend actions may eventually be authorized to take them. The governance record should evolve with the system.

This is particularly important because AI can complicate traditional assumptions about decision-making. When a human employee makes a decision, organizations generally know who made it. When an AI system influences or takes an action, accountability can become less obvious.

Documentation should prevent that ambiguity from becoming an accountability gap. The company should be able to reconstruct what the system was authorized to do, who approved that authority, what controls applied, and who was responsible for monitoring its operation.

NIST AI RMF and ISO/IEC 42001 both reinforce the broader value of structured governance, risk management, documentation, monitoring, and continuous improvement. For the CCO, the important point is not simply alignment with a framework. It is the ability to demonstrate how the organization governed the technology in practice.

Documentation Should Feed Organizational Learning

Documentation becomes most valuable when the organization uses it. Investigation records can reveal recurring root causes. Exception records can identify controls employees routinely struggle to follow. Third-party approval records can reveal recurring risk patterns. Remediation documentation can show which corrective actions are effective. AI governance records can identify use cases generating repeated incidents or overrides.

The organization can analyze these records to improve the compliance program. This closes the loop between all five Leonardo principles.

  • Documentation captures what monitoring reveals.
  • Monitoring identifies issues requiring investigation.
  • Investigations generate lessons that drive refinement.
  • Refinement can support responsible innovation.
  • Innovation creates new risks that require monitoring and documentation.

The framework is therefore not a linear sequence. It is a learning cycle. That is perhaps the most important Leonardo lesson for the modern CCO.

Completing the Leonardo Compliance Framework

With Leonardo’s notebooks, we complete our five-part framework:

Refine-> Investigate-> Innovate-> Monitor-> Document

Together, these principles describe compliance as an organizational learning system. Effective programs learn from experience, investigate failures to understand root causes, support innovation within appropriate governance, monitor whether controls continue to work, and preserve what the organization learns so that knowledge informs future decisions.

The Mona Lisa taught us to Refine. Compliance programs should improve because organizations learn from experience, changing risks, investigations, employee feedback, and data. Leonardo’s anatomical studies taught us to Investigate. Misconduct should be examined beneath the surface so the organization understands root causes, control failures, incentives, management behavior, and systemic vulnerabilities. His flying machines taught us to Innovate. Compliance should help the company capture the value of emerging technology while maintaining risk-based governance, meaningful human oversight, and clear accountability. The Last Supper taught us to Monitor. Controls can deteriorate as the environment changes, making testing, analytics, ownership, remediation, and continuing oversight essential to program effectiveness. Leonardo’s notebooks teach us to Document.

That provides the essential contrast with Michelangelo. His framework of Challenge, Execute, Defend, Build, and Govern taught a CCO how to construct and operate an effective compliance program. Leonardo teaches a CCO how to keep that program learning and adapting. The modern compliance function needs both disciplines because strong controls can become obsolete if the organization fails to recognize changes in its business, technology, and risk environment.

That combination is particularly important in 2026. AI is accelerating business change, geopolitical developments can alter risk rapidly, third-party ecosystems continue to expand, and boards need evidence that compliance systems work in practice. The CCO cannot administer yesterday’s compliance program while the business builds tomorrow’s operating model.

Leonardo’s notebooks leave us with a simple compliance mandate: learn from what the organization does, preserve what it learns, and use that knowledge to make the organization better.