Categories
FCPA Compliance Report

Natural Disaster Expo 2026 Speaker Series: James Caron on Lessons from Winter Storm Uri

Welcome to Natural Disasters Expo Houston! For its fifth year, Natural Disasters Expo USA comes back to Houston on October 14–15, 2026, at the George R. Brown Convention Center. And there’s no better place for it. This city knows what it takes to prepare for disasters, respond, and rebuild afterward. For two days, industry leaders, government agencies, first responders, and resilience professionals will come together with one shared goal: helping communities’ weather the next storm stronger than the last. Explore new solutions and technology, learn from experts who have been on the front lines, and meet the partners who will help you turn preparedness into action. Whether you’re here to learn, share, or collaborate, you are part of the effort to build a more resilient nation.

In this speaker series, Tom Fox interviews James Caron on Lessons from Winter Storm Uri and Business Risk Preparedness

James Caron, is the director of weather operations for North America and  at Atmospheric G2 and owner of Caron Weather Consultancy. He discusses his upcoming Disaster Expo 2026 presentation in Houston, “Storm Ready: Analyzing Winter Storm Uri and Preparing for Future Winter Hazards.” Caron explains forensic meteorology as expert witness work in litigation involving weather-related incidents, then outlines how a displaced polar vortex during Uri placed all 254 Texas counties under winter storm warnings, drove Dallas–Fort Worth to -2°F, nearly collapsed ERCOT, cut power to about 4.5 million customers, and spiked natural gas prices above 1,000 MMBTU. He will use his financial institution lead-time forecasting experience as a case study and offer practical preparedness guidance for emergency management, grid and energy operators, and businesses, noting Uri broadened business awareness of winter risk and that a strong El Niño could elevate winter 2026/27 threats.

Resources:

Natural Disasters Expo USA 

Get your Ticket

Conference Agenda

Speakers 2026

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories –Week Ending October 2, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust. This week’s stories include:

  1. An AI-driven economy.(FinTechFutures)
  2. Should AI agents take on more finance work. (Forbes)
  3. What are banks on intelligence.(Microsoft)
  4. Will AI debt lead to market correction.(FT)
  5. The dark side of banking and AI.(Reuters)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week-October 2

Welcome to AI in Healthcare in 5 Stories. This podcast is a Weekly Briefing of the five most important AI developments shaping healthcare, medicine, and life sciences. Each week Tom Fox breaks down the latest stories in clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation, all through a practical and business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.  The top five stories for the week ending September 25, 2026 include:

  1. Data privacy issues holding patients back from AI. (HealthcareDive)
  2. How AI is changing nursing. (YaleNews)
  3. Pharma doubles down on AI. (Reuters)
  4. AI and medicine. (Barrons)
  5. Rural WVa hospitals to receive AI tech. (WVNews)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Daily Compliance News

Daily Compliance News: October 2, 2026 the Wither Capitalism Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance related stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest for the compliance professional.

  • How badly did Man City fraud distort the Premier League.(Reuters)
  • How high risk is Venezuela. (WSJ)
  • Is capitalism in danger?   (FT)
  • Insider knowledge of a pre-emptive pardon. (NYT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Popcorn and Compliance

Popcorn and Compliance: Frankenstein It’s Alive: Innovation, Governance, and the Responsibility of the Creator

This October we return to one of my all-time favorites, the Universal Picture Classic monsters. Over the years, I have looked at all the classics, Dracula, The Mummy, The Wolfman, The Invisible Man, took detours in the films of Val Lewton and the Hammer Studios. This year, I wanted to return for a deep dive into the first five Frankenstein movies. We will consider the original, the Bride of Frankenstein, Son of Frankenstein, Ghost of Frankenstein and Frankenstein Meets the Wolfman. In this first episode we consider the original and one of the greatest horror movies of all-time, Frankenstein, released in 1931. In this exploration, I have used my AI friends, Timothy and Fiona to provide commentary.

Film Synopsis

James Whale’s Frankenstein remains one of the foundational movies of American horror, with Colin Clive as Henry Frankenstein and Boris Karloff giving us the definitive cinematic image of the Monster. Henry retreats to his laboratory with his assistant Fritz, determined to discover the secret of life. His experiment succeeds, but a crucial mistake has already occurred: Fritz has supplied the brain identified in the film as abnormal rather than the intended brain. Henry brings his creation to life without understanding what he has created, without controls for managing it, and without any real plan for what comes next. The resulting tragedy ultimately sends creator and creation toward their confrontation at the burning windmill.

Key Highlights

  • Innovation without governance is simply uncontrolled risk.
  • The abnormal brain is a third-party and supply-chain failure.
  • Waldman represents credible challenge without sufficient authority.
  • Henry abandons responsibility when responsibility matters most.
  • The catastrophe begins before the Monster escapes.

Popcorn and Compliance takeaway: Do not wait until the Monster is running through the village to conduct the risk assessment.

Timothy and Fiona are AI generated voices courtesy Notebook LM.

Categories
AI Today in 5

AI Today in 5: October 2, 2026 the Going to the Dark Side Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. How much of compliance spend will go to AI.(FinTechGlobal)
  2. Data privacy issues holding patients back from AI. (HealthcareDive)
  3. Google releases the most advanced Gemini model. (FT)
  4. Using AI governance to move compliance to an advantage.  (LewisSilken)
  5. Banks may soon face the dark side of AI. (Reuters)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Balance in Crisis

Balance in Crisis: Using Gumption to Balance Crisis: Daily Choices, Resilience, and Grace

We live in an age of constant motion. We move faster, communicate more, and accomplish more than ever before, yet many people feel exhausted, fragmented, and quietly unsettled. Our lives are full but are not integrated. In this podcast, Balance in Crisis, Kenneth O’Neal challenges the belief that balance is a myth or something achieved by doing less. True balance is built. It is the result of alignment and the intentional ordering of life around what matters most. When values, beliefs, and daily actions are misaligned, even success carries a hidden cost. Burnout, confusion, strained relationships, and loss of purpose often follow. In this inaugural episode, host Tom Fox and Kenneth O’Neal introduce the topic of “Balance in Crisis” with a discussion of aligning virtues, priorities, and communication.

Tom Fox and Kenneth O’Neill explore applying “gumption” in crisis, defining it as the daily choice and initiative to start well through structured morning practices (reflection, devotionals, planning) and focusing on top priorities. O’Neill distinguishes gumption (starting now) from long-term resilience (“grit”/“guts”), emphasizing continuous 1% daily improvement, end-of-day reflection, and virtues such as caring for others, forgiveness, gratitude, and “letting go” of bitterness and anger—especially for leaders who must release what they cannot control while supporting and holding others accountable. They discuss helping people who have lost values by acknowledging reality, listening, reducing bias, and having difficult conversations amid societal division.

Key Highlights

  • Defining Gumption
  • Grit Guts and Growth
  • Grace Forgiveness Legacy
  • Division and Hard Conversations
  • Vision Performance Becoming

Resources

Kenneth O’Neal

Balance in Crisis

Book a Clarity Call

 

 

Categories
Blog

Frankenstein and Compliance: Part 1-It’s Alive: Innovation Without Governance

Ed. Note-This month, over on my podcast series Popcorn and Compliance, I am taking a deep dive into the  first five Frankenstein movies. Over October I will consider the Frankenstein, the Bride of Frankenstein, Son of Frankenstein, Ghost of Frankenstein and Frankenstein Meets the Wolfman. The blog post is a companion to the podcast series.

The most famous moment in Frankenstein (1931) comes when Henry Frankenstein’s experiment succeeds. Electricity surges through his laboratory, the body on the table begins to move, and Frankenstein celebrates what he believes is an extraordinary scientific achievement.

“It’s alive!”

For the corporate compliance professional, however, the critical decisions occurred before Henry ever activated his equipment. He had decided to proceed without an adequate risk assessment, effective oversight, meaningful challenge, or a plan for managing the consequences if his experiment succeeded. Viewed through that lens, Frankenstein is not simply a horror movie about a scientist and the Monster he creates. It is a case study in innovation without governance.

That lesson has particular relevance as companies accelerate the adoption of AI and other emerging technologies. Businesses are appropriately focused on innovation, productivity, efficiency, growth, and competitive advantage. Yet technological capability can develop faster than the governance structures needed to manage the resulting risks. The compliance issue is not whether companies should innovate. They must. The issue is whether governance keeps pace with innovation.

The Business Case Was Clear. The Governance Case Was Not.

Henry Frankenstein has a compelling objective. He believes he can accomplish something no one has accomplished before. He assembles the equipment, obtains the materials, develops the technical capability, and builds a team capable of executing the project. In corporate terms, Henry has a strategy, resources, technical expertise, and executive sponsorship. What he does not have is an effective governance framework.

Before activating his creation, Henry conducts nothing resembling a meaningful risk assessment. He does not identify potential failure scenarios or establish control requirements. He does not define stopping criteria or determine who has authority to challenge the project. There is no meaningful contingency plan for an adverse outcome. This is precisely where Compliance should enter the business process.

An effective compliance function should not first encounter a significant new technology when the business seeks approval immediately before deployment. Compliance needs to participate sufficiently early to understand the business objective, identify the associated risks, and help determine what controls are appropriate.

That does not mean Compliance should own innovation or assume responsibility for the underlying business decision. Risk ownership should remain with the business. Compliance should help ensure that management understands the legal, regulatory, ethical, and control implications of the decision before significant commitments are made.

For the CCO, this raises a practical question: At what point in our company’s innovation process does Compliance become involved? If the answer is immediately before launch, the organization may already be too far downstream.

AI Has Made the Frankenstein Problem Immediate

Artificial intelligence makes the governance issue in Frankenstein particularly relevant. Companies are deploying AI to analyze information, generate content, assist customer service, support investigations, screen candidates, evaluate transactions, enhance due diligence, identify suspicious activity, and improve decision-making. These applications can generate significant business value. They also create governance questions that need to be addressed before deployment.

Organizations need to understand what data an AI application uses, how that information was obtained, who approved the use case, and which regulatory requirements apply. They should determine how outputs are validated, where human review is required, how confidential information is protected, and what happens when a system produces an unexpected or inappropriate result.

There must also be clear accountability. Someone should own the business risk associated with the use case, and the organization should understand who has authority to suspend or terminate the application if circumstances warrant.

The NIST AI Risk Management Framework provides one useful approach through its Govern, Map, Measure, and Manage functions. ISO/IEC 42001 similarly treats AI through a management-system framework emphasizing governance, accountability, risk management, and continual improvement.

Both approaches reinforce a broader compliance principle: technology risk needs governance throughout the lifecycle. Henry Frankenstein has no lifecycle governance. His approach is essentially to build the system, activate it, and evaluate the consequences afterward. That is not an acceptable corporate control environment.

The Abnormal Brain and the Importance of Validating Inputs

One of the film’s most useful compliance scenes occurs before the Monster comes to life. Henry needs a brain for his creation. His assistant Fritz obtains one, but the intended specimen is destroyed. Rather than report what happened, Fritz substitutes another brain, identified in the film as abnormal, without telling Henry. (AbbyNormal-if you know, you know.) The project therefore proceeds after a critical input has changed without the project leader’s knowledge.

For compliance professionals, the scene provides a useful analogy for third-party risk, supply-chain controls, due diligence, and data governance. Organizations routinely rely on information supplied by others. A distributor provides beneficial ownership information. A vendor completes a compliance certification. An employee submits an expense report. An acquisition target makes representations during due diligence. A supplier certifies compliance with contractual obligations. An AI application relies upon data obtained from multiple sources.

The relevant control question is not simply whether the required information was received. It is whether important information was appropriately validated based on risk. Fritz completed his assignment in the narrowest sense. He returned with a brain. The process failed because nobody verified that he returned with the correct brain.That distinction is important for compliance program effectiveness. A completed checklist demonstrates that an activity occurred. Appropriate validation provides assurance that the control achieved its purpose.

Dr. Waldman and Credible Challenge

Henry is not entirely without oversight. Dr. Waldman understands what Henry is attempting and recognizes the potential danger. He raises objections. Henry proceeds anyway. This takes the film from risk assessment into the effectiveness of the challenge function. Many companies can demonstrate that compliance participated in a significant decision. That does not necessarily establish that a compliance professional had meaningful influence over the outcome. A CCO can attend meetings, review proposals, identify concerns, and recommend additional controls. If commercial leadership can routinely disregard those concerns without escalation, the company may have consultation without credible challenge.

This is why the authority, stature, resources, independence, and access of the compliance function matter. The effectiveness of a corporate compliance program becomes most visible when it disagrees with an important business proposal. Boards should therefore look beyond whether your compliance function was consulted. They should understand what happens when a compliance officer disagrees with the business. They need to ask such questions as: Can the CCO escalate a significant concern? Does the CCO have appropriate access to the Audit Committee or board? Are material disagreements documented? Who has authority to accept significant compliance risk? Can commercial management override a compliance objection without further review?

If a CCO can raise a concern but nobody with decision-making authority has to address it, the organization has created the appearance of challenge without its substance. Dr. Waldman had a voice. What he lacked was sufficient influence to change the decision.

Maria and the Risk of Unintended Consequences

Next we consider one of the most poignant scenes in the movie. It is the encounter between the Monster and young Maria provides another important business lesson. This is certainly one of the most unforgettable and indeed tragic scenes in all of the Frankenstein movies. If you have ever seen it, you have not nor will you ever forget it. A small child, Maria shows the Monster how flowers float on the lake. He imitates what he observes. When the flowers are gone, he throws Maria into the water, apparently expecting her to float as the flowers did. The consequences are tragic. The Monster recognizes a pattern without understanding its context.

That distinction has obvious relevance for artificial intelligence and automated decision-making. A system may identify patterns, generate recommendations, and produce technically consistent outputs without understanding their broader legal, ethical, or business implications. A technically accurate output can still create an inappropriate result.

This is why human oversight cannot exist merely as language in an AI policy. Companies need to determine where human judgment is required, who provides that judgment, what qualifications reviewers need, when automated recommendations can be overridden, and how significant exceptions are documented.

Management should also understand whether human review is substantive or simply procedural. An employee clicking an approval button after an automated recommendation does not necessarily constitute meaningful oversight. The relevant control question is not simply whether the technology performed as designed. It is whether the resulting decision was appropriate.

Innovation Requires Accountability

Henry eventually discovers that creating something and controlling it require different capabilities. Corporate leaders should understand the same distinction. Management establishes incentive structures, sales strategies, compensation plans, technology deployments, acquisition strategies, third-party relationships, and performance expectations. Those decisions shape employee behavior and create risk. Leadership accountability therefore does not begin only after misconduct occurs. It begins with the decisions that establish the operating environment.

For the CCO, this means compliance risk should be integrated into strategic business decisions. For management, it means risk ownership remains with the business. For the board, oversight should focus on whether management has reasonable systems to identify, manage, monitor, and escalate significant risks. Compliance does not own a business risk simply because the compliance function identifies it. Management remains responsible for the business decision and the risks created by that decision.

That principle becomes particularly important with emerging technology. The CCO should contribute expertise regarding regulatory requirements, ethical considerations, controls, monitoring, and escalation. Technology leaders should contribute technical expertise. Legal, Privacy, Information Security, HR, Internal Audit, and other functions may have roles depending on the application. Business leadership remains accountable for the decision to deploy the technology and the resulting business risk.

Practical Actions for the CCO

Frankenstein suggests a practical agenda for compliance leadership. Compliance should move upstream and identify significant business processes where its participation is most valuable before commitments are made. Emerging technology, acquisitions, market entry, compensation design, significant third parties, and new products are obvious candidates.

Risk assessment should occur before deployment and should address foreseeable legal, compliance, ethical, operational, and reputational consequences. High-risk inputs supplied by employees, vendors, third parties, acquisition targets, or technology systems should receive risk-based validation.

The organization should also define what credible challenge means in practice. Escalation procedures should be clear when Compliance and business leadership disagree about significant risk.

Finally, approval should be treated as the beginning of governance rather than its conclusion. Controls should be tested, outcomes monitored, exceptions analyzed, and risk assessments updated as the business and technology evolve. The objective is not to slow innovation. It is to make innovation governable.

The Compliance Lesson

Frankenstein is not an argument against innovation. It is an argument for governance.

Henry Frankenstein’s failure was not that he attempted something extraordinary. His failure was that his technical ambition moved faster than his ability to identify, understand, govern, and control the resulting risk.

Companies face the same challenge today. Technology will advance. Business models will change. New markets will open. Competitive pressure will accelerate decision-making. New risks will emerge. The role of Compliance is not to stand outside the laboratory and demand that the electricity be turned off.

It is to help ensure that management has assessed the risk, validated critical inputs, established appropriate controls, defined accountability, created meaningful challenge, and determined how the organization will respond if the initiative produces an unexpected result. The best time to build that governance structure is before deployment.

Our next installment moves the compliance analysis forward. In Bride of Frankenstein, Henry no longer faces an unknown risk. He has already experienced the consequences of his original experiment and understands what can go wrong. Then Dr. Pretorius persuades him to return to the laboratory.

The compliance issue is no longer whether leadership identified the risk. It is what happens when leadership knows better but pressure, ambition, and rationalization push the organization toward the same risk again.

Check out Timothy and Fiona’s commentary on Frankenstein here.