Categories
FCPA Compliance Report

Natural Disaster Expo 2026 Speaker Series: Dr. Joseph Colaco Reducing Hurricane Damage in Houston’s High-Rise Environment

Welcome to Natural Disasters Expo Houston! For its fifth year, Natural Disasters Expo USA comes back to Houston on October 14–15, 2026, at the George R. Brown Convention Center. And there’s no better place for it. This city knows what it takes to prepare for disasters, respond, and rebuild afterward. For two days, industry leaders, government agencies, first responders, and resilience professionals will come together with one shared goal: helping communities’ weather the next storm stronger than the last. Explore new solutions and technology, learn from experts who have been on the front lines, and meet the partners who will help you turn preparedness into action. Whether you’re here to learn, share, or collaborate, you are part of the effort to build a more resilient nation.

In this speaker series, Tom Fox interviews Dr. Joseph Colaco on Reducing Hurricane Damage in Houston’s Expanding High-Rise Environment.

Dr. Colaco is a tenured University of Houston architecture professor and president of Dr. Colaco Engineers. He visits with Tom about his upcoming presentation on reducing hurricane damage in Houston’s growing high-rise environment. Dr. Colaco describes assessing building performance during Hurricane Alicia in 1983, including firsthand observations downtown, documentation of facade damage, and visits to the Galleria area and Galveston. He explains that Houston’s increased density and taller buildings create new wind-flow conditions, making some older wind tunnel results less applicable; he notes Houston began wind tunnel and window-wall facade testing in the 1970s to inform design and construction. Dr. Colaco values conferences for networking and for transferring lessons learned across generations, and cites Chicago’s periodic inspection requirements for tall buildings as a model for improving building safety and living conditions in Houston.

Resources:

Natural Disasters Expo USA 

Get your Ticket

Conference Agenda

Speakers 2026

Categories
FCPA Compliance Report

FCPA Compliance Report – IIA President Anthony Pugliese on the IIA’s Expanding Role in AI, Cybersecurity, and Geopolitical Risk

In this episode, Tom Fox welcomes Anthony Pugliese, President and CEO of the Institute of Internal Auditors (IIA).

We begin with the IIA’s global footprint with boards in 122 countries, its role in setting internal audit standards, certifications, including the Certified Internal Auditor credential with about 225,000 holders, and education. Pugliese describes how internal audit is shifting from primarily financial controls to a broader focus on non-financial risks, including cybersecurity, AI and disruptive technologies, sustainability reporting, business resilience, and geopolitical risk. He emphasizes internal audit’s growing prospective/advisory role, particularly in assessing whether AI governance is keeping pace with rapid adoption and in communicating complex risks to boards and audit committees. Cybersecurity is cited as chief audit executives’ top concern, increasingly requiring continuous monitoring. Pugliese notes members want more industry-specific guidance and expanded GRC resources relevant to compliance and directs listeners to iia.org and the free annual Risk in Focus report.

Key Highlights

  • What the IIA Does
  • Risk Landscape Shifts
  • From Assurance to Advisory
  • Geopolitical Risk in Practice
  • Cyber Threats and Continuous Auditing
  • Why Compliance Pros Should Join

Resources

Anthony Pugliese on LinkedIn

Institute of Internal Auditors

 

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Daily Compliance News

Daily Compliance News: October 5, 2026 the He’s a Busy Boy Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance brings to you compliance related stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest for the compliance professional.

  • Could AI stunt lawyers’ training.(Reuters)
  • Jay Clayton to be named AI Czar. (WSJ)
  • Ex-head of Subway purchasing indicted on $80MM bribery scheme.   (NRN)
  • US yanks visas for Latin American officials over allegations of corruption. (Bloomberg)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
AI Today in 5

AI Today in 5: October 5, 2026 the Legal Risk Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. Could AI stunt lawyers’ training.(Reuters)
  2. Jay Clayton to be named AI Czar. (WSJ)
  3. Compliance purpose built AI. (ThompsonReuters)
  4. Legal risks piling up for OpenAI.  (FT)
  5. Should private AI agents run your life? (WSJ)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Blog

Modern Philosophers and Compliance: Part 1 -Hannah Arendt and Personal Responsibility in Corporate Compliance

This week we will conclude our lengthy exploration of the philosophical underpinnings of the modern corporate compliance program. We will look at Simone de Beauvoir and the conditions for ethical action in a corporation; John Rawls and institutional justice and fairness in a corporate compliance program; Jürgen Habermas and the governance of speaking up and Hans Jonas and the responsibility for the future of corporate compliance. Today we begin by looking at Hannah Arendt and her concepts around personal responsibility and how they relate to the modern compliance program.

Every approval in a compliance process represents a decision. Someone is accepting an explanation, authorizing a payment, resolving a concern, or allowing business to proceed. The central question is whether that person understands and takes responsibility for the decision. Hannah Arendt gives compliance professionals a powerful way to examine what happens when organizational routines weaken that connection.

Our examination of ancient and Enlightenment thinkers established the importance of inquiry, ethical habits, institutional order, and evidence. We now turn to twentieth-century philosophy, beginning with responsibility inside complex organizations. Arendt asks us to consider the individual who operates within the system. What happens when that person stops examining the meaning and consequences of the work?

For a Chief compliance officer, this question reaches directly into third-party approvals, internal investigations, management conduct, and board oversight. A company can assign responsibilities in a policy while its employees learn to defer judgment to someone else. An effective compliance program must address that gap.

Thinking and Judgment as Compliance Responsibilities

Arendt was a German-born Jewish political thinker who fled Nazi Germany and eventually settled in the United States. Her experiences of persecution and displacement informed her examination of totalitarianism, political life, and personal responsibility. In essays including “Personal Responsibility Under Dictatorship” and “Thinking and Moral Considerations,” she explored the relationship between independent thought, moral judgment, and conduct.

Her account of Adolf Eichmann and the phrase “banality of evil” remain controversial if not one of the most well-known phrases to describe Nazi Germanyevalu. The phrase did not mean that the crimes were ordinary or insignificant. Her interpretation emphasized his failure to think critically about what he was doing, although scholars have challenged her assessment of his motivations. The historical crimes she examined must retain their specificity and gravity.

The application to compliance is a narrower one: institutional roles do not eliminate the need for personal judgment. Arendt was not writing a corporate governance manual. Her work nevertheless provides a basis for asking whether employees examine what their actions enable, particularly when organizational language makes questionable conduct appear routine.

That question builds on Socrates. Socratic inquiry tests assumptions through questioning. Arendt directs our attention to the person who must decide whether to accept the answer and participate in the conduct. For compliance professionals, that is where inquiry becomes responsibility.

When Approvals Divide Responsibility

Consider this hypothetical. A multinational manufacturer proposes hiring an intermediary to help secure business with a state-owned customer. The commission is unusually high. The description of services is vague, and the intermediary requests payment to an account outside its home jurisdiction.

Sales confirms the commercial opportunity. Procurement verifies that the vendor record is complete. Legal reviews contractual provisions. Finance checks that the required approvals appear in the payment system. Compliance previously reviewed the intermediary, but the proposed payment arrangement has changed since that review. Each function assumes another has addressed the remaining concern. The payment proceeds.

No single feature establishes bribery. Together, these facts warrant further inquiry. The governance failure is that nobody takes responsibility for obtaining a satisfactory explanation before payment. Each participant can describe a completed task. The organization cannot explain who assessed the unresolved risk.

This is where Arendt becomes useful to the CCO. Division of labor is necessary in a large company. It must be accompanied by clear obligations to recognize concerns, communicate them, and seek an appropriate decision. Otherwise, specialization can allow important facts to disappear between functions.

The practical response is to specify what each approval means. Does the approver confirm budget availability, verify services, resolve due diligence findings, or authorize an exception? What changes require renewed review? Who owns the decision when concerns remain? These questions turn personal responsibility into an operating requirement.

The DOJ Connection Through Gatekeepers and Escalation

The Department of Justice’s Evaluation of Corporate Compliance Programs (ECCP) addresses this issue directly. Under policies and procedures, the ECCP asks about guidance and training for gatekeepers with approval or certification responsibilities. It examines whether they recognize misconduct and understand when and how to escalate concerns.

This is a substantive connection to Arendt’s work, rather than a claim of philosophical influence on DOJ. The compliance question concerns whether an employee’s assigned role includes meaningful judgment. An approval control is weakened when its operator understands the mechanics but cannot identify the circumstances requiring further review.

Return to our hypothetical. The finance employee should understand whether the changed bank account requires renewed diligence. The business sponsor should be responsible for explaining the services and commercial rationale. Compliance should receive material changes to the information on which its earlier review depended. The final decision should record how identified concerns were resolved.

The CCO can test this through a sample of actual transactions. Interview the approvers. Ask what they believed their approval represented, what information they reviewed, and what would have caused them to stop. Compare those answers with the procedure. The difference between intended and understood responsibility is a control issue requiring attention.

Training Employees to Recognize the Decision

Arendt’s emphasis on thinking also offers a practical lesson for training. Employees need opportunities to examine a situation before organizational habit supplies the answer. A course can explain a prohibition accurately while leaving participants uncertain about how to respond when a manager presents a questionable request as urgent and routine.

The ECCP examines whether training is tailored to relevant employees and risks, whether employees can ask questions, and how the company evaluates learning and the effect of training on behavior or operations.[4] Those inquiries support training that develops judgment within defined responsibilities.

Use the hypothetical intermediary payment as an exercise. Give participants the initial facts, then introduce the changed bank account after approval. Ask them to identify what requires renewed attention, which function should act, and what must happen before payment. Require an explanation for the proposed response.

Include the manager who says the transaction has already been approved. That intervention tests whether employees understand the limits of an earlier decision. The training should leave them with a usable escalation route and a clear account of their authority. Asking people to exercise judgment carries a corresponding obligation to equip them to act.

Leadership Determines Whether Judgment Is Welcome

Employees learn what management expects by watching what happens when someone raises a concern. A company may encourage questions in training while a business leader treats delay as disloyalty. Over time, employees may conclude that completing the transaction is safer than examining it.

The ECCP assesses how senior and middle management demonstrate commitment to compliance. It also examines whether employees feel comfortable reporting concerns and whether the company maintains an effective approach to preventing retaliation.[5] These are relevant tests of the environment in which personal judgment operates.

For the CCO, the practical inquiry should include decisions under pressure. When did a manager support an employee who paused a transaction? What happened to an unresolved concern near quarter-end? Did a policy exception receive appropriate scrutiny when the business sponsor was influential? Such examples help explain whether the stated expectations survive commercial pressure.

Boards have a role here as well. The ECCP examines compliance access to governing authorities and opportunities for private discussions. It also cites the Sentencing Guidelines’ expectations concerning governing authority knowledge and oversight.[5] Directors should use that access to ask where management pressure is weakening escalation and whether the compliance function can obtain timely decisions on unresolved concerns.

Investigations Must Examine the Approval Chain

When misconduct emerges, Arendt’s focus on personal responsibility should sharpen the investigation without prejudging anyone’s culpability. The inquiry must establish what individuals knew, what their roles required, what authority they possessed, and how they responded. Participation in a process alone does not establish intentional wrongdoing.

In our hypothetical, investigators should trace the changed payment instructions through the approval chain. Who received them? Did the system alert compliance? Did anyone ask for an explanation? Was a concern overridden, misunderstood, or never transmitted? Those facts distinguish deliberate avoidance from inadequate training, poor system design, or reasonable reliance on incomplete information.

The ECCP asks whether investigations identify system vulnerabilities and accountability failures, including those involving supervisory managers and senior executives. Its remediation questions address failed controls, missed opportunities, and accountability for supervisory failures.[6] An investigation that stops at the person who released the payment may leave the conditions that enabled the problem intact.

Fair accountability therefore requires attention to both conduct and context. Discipline should reflect established facts and relevant responsibilities. Remediation should repair the information flows, authority gaps, and incentives that shaped the decision. The organization must be able to explain what it learned and how that learning changes future approvals.

Five Key Arendt Takeaways for the Compliance Professional

  1. Define the responsibility within each approval. Identify what the approver must assess, the evidence required, and the conditions that trigger escalation. Test whether employees understand these obligations in actual transactions.
  2. Train for judgment under realistic pressure. Use scenarios involving changed facts, urgent requests, and influential sponsors. Assess whether employees can explain a concern and identify the appropriate response.
  3. Make challenge operationally possible. Give employees clear escalation routes and appropriate authority to pause decisions. Examine how managers respond when employees use those mechanisms, including whether adverse consequences follow.
  4. Follow accountability through the management chain. Investigate who knew what, who exercised authority, and where supervision failed. Apply fair standards to senior leaders and high performers as well as frontline employees.
  5. Give the board evidence of independent judgment. Report material overrides, unresolved concerns, and lessons from investigations. Explain where employee challenge changed a decision and where management action is still required.

Arendt helps us see that personal responsibility must remain visible inside institutional processes. The CCO’s task includes designing controls that preserve that responsibility and creating conditions in which employees can exercise it. A useful board question follows: Where could our processes allow every participant to believe that someone else was responsible for examining the risk?

Join us tomorrow in Part 2, as we turn to Simone de Beauvoir and discuss the conditions that make ethical action possible. If Arendt asks individuals to exercise judgment, Beauvoir helps us examine how unequal power, dependence, and vulnerability affect their ability to act on it. That inquiry takes us directly into reporting culture, retaliation prevention, and the lived experience of corporate compliance.