Categories
FCPA Compliance Report

Natural Disaster Expo 2026 Speaker Series: Amy Forsythe on Crisis Leadership and Media Communication

Welcome to Natural Disasters Expo Houston! For its fifth year, Natural Disasters Expo USA comes back to Houston on October 14–15, 2026, at the George R. Brown Convention Center. And there’s no better place for it. This city knows what it takes to prepare for disasters, respond, and rebuild afterward. For two days, industry leaders, government agencies, first responders, and resilience professionals will come together with one shared goal: helping communities’ weather the next storm stronger than the last. Explore new solutions and technology, learn from experts who have been on the front lines, and meet the partners who will help you turn preparedness into action. Whether you’re here to learn, share, or collaborate, you are part of the effort to build a more resilient nation.

In this speaker series, Tom Fox interviews retired US Navy Reserve officer Amy Forsythe ahead of her Disaster Expo keynote, “When Crisis Calls: Leadership, Communication, and Community in the Moments That Matter.”

Forsythe describes her 33 years of service, beginning as a Marine Corps combat photographer and later retiring as a Navy public affairs officer, with extensive experience coaching senior leaders on media engagement and crisis response. She and co-presenter Mandi Fine will combine Fine’s firsthand experience from the Red Hill fuel spill crisis in Hawaii with Forsythe’s lessons on building trust, honest communication, humility, and effective interagency coordination during disasters. Forsythe notes these principles apply to businesses and leaders whose viability can be impacted by crisis communication, including the risk of “one bad interview.” She aims to share hard-learned lessons, including from the 2017 Santa Rosa, California fires, and to connect with practitioners in Houston.

Resources:

Natural Disasters Expo USA 

Get your Ticket

Conference Agenda

Speakers 2026

Categories
Daily Compliance News

Daily Compliance News: October 6, 2026, The No Claims Paid Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Are insurers moving to a ‘no claims paid’ policy? (WSJ)
  • Big Bend don’t need no stinkin’ wall. (Reuters)
  • Does Big Oil own the Supreme Court? (NYT)
  • Slovakia makes testimony of corruption illegal. (Bloomberg)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Innovation in Compliance

Innovation in Compliance: Pamela Gupta on Closing the AI Governance Implementation Gap

Innovation comes in many areas and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance as he visits with top innovative minds, thinkers and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom welcomes Pamela gupta, the author of De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook.

Pamela Gupta, is the founder of Trusted AI and author. She and tom discuss the closing the AI governance implementation gap between high-level frameworks (e.g., NIST AI RMF, ISO 42001) and use-case execution under rapid AI rollout pressure. Gupta argues organizations struggle to translate principles into actionable, risk-based decisions involving many stakeholders (security, privacy, legal, audit, business, IT, data science), leading either to unmanaged risk or stalled innovation. She emphasizes AI-specific risks such as bias, transparency, explainability, and accountability, illustrating with Humana’s nH Predict claims system (alleged bias; 90% reversals) plus Amazon’s scrapped hiring model and Air Canada’s chatbot ruling. Gupta outlines her AI TIPS framework (eight pillars, ~80 controls) and contends AI governance can accelerate adoption by defining intake, evidence, and decision processes, even as agentic AI raises risk and uncertainty.

Key Highlights

  • AI Governance Gap
  • Assessing AI Risk
  • Bias and Ethics Ownership
  • Humana Case Study
  • AI TIPS Framework
  • Governance as Accelerator

Resources

Pamela Gupta on LinkedIn

De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook

Website: TrustedAI.AI

Podcast: Trustworthy AI: De-Risk Business Adoption of AI

Trusted AI Feed: TrustedAI.AI/feed/

X/Twitter: @OutsecureCom

LinkedIn: OutSecure Inc.

YouTube: OutSecure Inc.

Facebook: OutSecure Inc.

 

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

 

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

 

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
AI Today in 5

AI Today in 5: October 6, 2026 the AI Pesonalization Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. Humans must remain in the loop.(HealthcareFinance)
  2. NYC grills AI execs. (WSJ)
  3. What’s next on the AI personalization front? (FinTechGlobal)
  4. The myth behind the AI agent hacks.  (FT)
  5. AI in compliance seen as MSP advantage. (Channele2e)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Blog

Modern Philosophers and Compliance: Part 2 – Simone de Beauvoir and the Conditions for Ethical Action

This week we will conclude our lengthy exploration of the philosophical underpinnings of the modern corporate compliance program. We have looked at Hannah Arendt and her concepts around personal responsibility and how they relate to the modern compliance program. We will look at John Rawls and institutional justice and fairness in a corporate compliance program; Jürgen Habermas and the governance of speaking up and Hans Jonas and the responsibility for the future of corporate compliance. Today we continue by looking at Simone de Beauvoir and the conditions for ethical action in a corporation.

A company that asks employees to act ethically must examine the conditions under which they make decisions. An employee may understand the code of conduct, recognize a problem, and know how to report it, yet reasonably fear that speaking up will jeopardize a livelihood. That fear is a governance issue. Simone de Beauvoir helps compliance professionals understand why.

In Part 1, Hannah Arendt brought personal responsibility into the corporate approval process. We examined whether individuals exercise judgment when organizational routines encourage deference. Beauvoir takes the discussion further by asking how circumstances affect the ability to act on that judgment. Responsibility matters, and so does the distribution of power around the person expected to exercise it.

For the chief compliance officer, this means examining the distance between what a policy permits and what employees believe they can safely do. A reporting mechanism becomes credible when the company understands that distance and takes concrete steps to reduce it.

Freedom Exists Within Real Circumstances

Beauvoir was a French philosopher whose work explored freedom, responsibility, and oppression. In The Ethics of Ambiguity, published in 1947, she examined human beings as both capable of choosing and constrained by circumstances they did not choose. We pursue our own projects while depending on a world shared with other people. Ethical responsibility includes concern for their freedom as well as our own.

Ambiguity, in this sense, does not make every choice equally acceptable. It describes a condition of human life: we act with limited knowledge and within circumstances we cannot fully control, yet our decisions affect others. We must take responsibility without assuming that a simple formula will resolve every conflict.

In The Second Sex, published in 1949, Beauvoir examined how women had been defined in relation to men and constrained through social expectations, institutions, and material dependence. Her analysis of women as the Other challenged the treatment of one group’s experience as the norm against which everyone else was measured.

The compliance application is an interpretation of these ideas. Beauvoir did not prescribe hotline procedures or investigation protocols. Her work asks us to attend to people’s actual circumstances. Inside a corporation, that means considering who controls pay, work assignments, advancement, and access to decision-makers. Those relationships can shape whether an employee sees an ethical option as practically available.

The Employee Who Knows How to Report

Consider this hypothetical. A junior procurement analyst discovers that a supplier has submitted invoices for services that lack supporting documentation. Her manager directs her to process them before the reporting period closes. He says the supplier is important and that asking further questions will make the department look uncooperative.

The analyst has completed compliance training. She knows the hotline number. She also knows that the manager controls desirable assignments and will soon recommend whether her temporary position becomes permanent. A colleague who challenged him previously lost important responsibilities. She does not know whether that change was retaliatory, but she understands its warning value.

From headquarters, the reporting system appears accessible. From her position, the choice carries immediate economic consequences. The uncertainty about those consequences affects her decision even before anyone makes an explicit threat.

Beauvoir helps us examine that difference. The analyst retains responsibility for her conduct, while management remains responsible for the conditions it creates. Telling her to demonstrate courage leaves the governance problem unresolved. The company must examine how managerial discretion, employment insecurity, and prior experience influence the use of its controls.

For the CCO, this requires asking whose perspective informed the policy. A senior employee with financial security and direct access to legal may experience the same reporting procedure very differently from someone whose continued employment depends on the person named in the concern.

The DOJ Connection Through Trusted Reporting

The Department of Justice’s Evaluation of Corporate Compliance Programs (ECCP) examines whether reporting mechanisms are trusted and whether employees feel comfortable using them. It also asks whether organizational practices discourage reporting and whether the company assesses employees’ willingness to raise concerns.

These inquiries create a substantive connection to Beauvoir’s emphasis on circumstances. Publishing a telephone number establishes an available channel. Understanding whether employees can use it requires evidence about their experience. The ECCP’s attention to proactive retaliation prevention reinforces that distinction.

In our hypothetical, the CCO should examine whether the analyst can reach someone outside the manager’s reporting line, whether temporary employees understand the available protections, and how concerns involving powerful managers are routed. The company should also explain the limits of confidentiality. In a small team, the facts themselves may reveal who reported.

An effective response could include an independent contact, a documented protection plan proportionate to the circumstances, and follow-up with the analyst. Those are practical design choices flowing from the identified risk. The organization should explain what it can do and who will act, rather than offer assurances that nobody can reliably deliver.

Whose Experience Shapes the Compliance Program

Beauvoir’s analysis of the Other offers another lesson for policy design. Organizations can mistake the experience of their most influential employees for the experience of the workforce. A policy written around headquarters staff may overlook workers who lack private computer access, work overnight, or depend on a supervisor to interpret company communications.

The ECCP asks about language and other barriers to accessing policies, as well as how the company confirms that employees know where to find them. Compliance professionals can use those questions to investigate whether the program works across different employment conditions.

Review a reporting process with employees who actually use it. Can a warehouse worker obtain guidance without leaving a visible record on a shared terminal? Can an employee working through a staffing agency identify the correct reporting route? Does the policy clearly explain where a concern about a supervisor should go? Answers should inform the design of the process.

This work requires listening without assuming that a category determines someone’s experience. Employees facing similar constraints may make different choices. The objective is to identify specific barriers and address them. Participation in policy testing gives the company evidence that a headquarters review cannot supply.

Protection Must Extend Beyond the Initial Report

A report begins a period of heightened responsibility for the organization. Once the analyst raises her concern, management decisions about her assignments, evaluation, and employment status may require additional scrutiny. The practical risk extends beyond formal dismissal.

Retaliation can take forms that appear routine when viewed separately: exclusion from meetings, reduced access to training, undesirable shifts, or a sudden change in performance assessments. Such actions require fact-specific investigation. Their occurrence after a report does not automatically establish retaliation, but it can justify closer review.

The ECCP examines retaliation policies, training, complaint handling, and follow-up. It also asks whether investigations are independent, objective, appropriately conducted, and documented.[3] A company should translate those expectations into assigned responsibilities for protecting reporters and assessing concerns about adverse treatment.

In our hypothetical, compliance and human resources could arrange an independent review of material employment decisions concerning the analyst during an appropriate monitoring period. The review should consider existing performance evidence and legitimate business reasons. Protection should preserve fair management processes while reducing the risk that discretionary decisions become instruments of punishment.

The analyst should also have a named contact and a realistic explanation of what follow-up to expect. A company can communicate that it has addressed a concern without disclosing confidential personnel information. Silence after intake can leave a reporter uncertain about both the investigation and personal safety within the organization.

Power Must Be Part of the Investigation

Beauvoir’s perspective also changes the questions investigators ask. If the analyst processed unsupported invoices before reporting, the investigation should establish the instructions she received, her understanding of them, the authority she possessed, and the options she believed were available. Pressure is relevant evidence. It does not predetermine the outcome.

Investigators should examine the manager’s conduct with the same care. Did he discourage inquiry? Had employees raised similar concerns? Did commercial targets reward the removal of inconvenient checks? Were previous complaints dismissed because his department delivered strong results?

The ECCP examines whether managers encouraged unethical conduct or tolerated greater compliance risk in pursuit of business objectives. It also addresses consistent discipline and accountability for supervisory failures. These expectations support an investigation that follows power and responsibility through the organization.

A Board should receive enough information to assess whether influential managers are obstructing the program. Relevant reporting might identify repeated concerns within a business unit, unresolved retaliation allegations, or exceptions involving senior personnel. Aggregate results should be interpreted carefully. Few reports can reflect confidence in local management, fear of reporting, or other conditions requiring inquiry.

A useful governance discussion therefore asks what the company knows about the employees least able to challenge authority. The answer should connect employee experience with management action, including who owns unresolved issues and when the board will receive an update.

Five Key Beauvoir Takeaways for the Compliance Professional

  1. Assess the conditions surrounding ethical choices. Examine who controls an employee’s income, assignments, evaluation, and future opportunities. Use that understanding to identify situations where dependence may discourage questions or reporting.
  2. Test policies with employees in different circumstances. Include workers with limited access to technology, language barriers, insecure employment, or little access to senior leaders. Ask them to demonstrate how they would obtain guidance or report a concern.
  3. Treat reporter protection as an assigned responsibility. Establish independent contacts, appropriate follow-up, and proportionate review of potentially adverse treatment. Explain confidentiality limits and avoid promises the organization cannot keep.
  4. Investigate power alongside individual conduct. Determine what instructions, pressures, and authority shaped decisions. Preserve fair accountability for employees while examining the actions and supervisory responsibilities of managers.
  5. Give the board evidence about barriers to ethical action. Report material retaliation risks, repeated concerns involving influential leaders, and progress on corrective action. Explain what remains uncertain and how the company will investigate it.

Beauvoir’s contribution to compliance is practical: ethical expectations must be considered alongside the conditions in which people are asked to fulfill them. The CCO should ask which employees face the greatest personal cost when they follow the code. The board should ask what management has done to reduce that cost.

In Part 3, we turn to John Rawls and the twin concepts of institutional justice and institutional fairness. Having considered responsibility with Arendt and the conditions for ethical action with Beauvoir, Rawls shows a compliance professional how a company can design policies, investigations, and discipline that employees can regard as fair regardless of their position or influence.