Categories
Great Women in Compliance

Great Women in Compliance – The Compliance Influencer with Bettina Palazzo

In this episode of Great Women and Compliance, Lisa speaks with Dr. Bettina Palazzo, a leader in business ethics, the founder of Palazzo Ethics Advisory, and the International Compliance Association Influencer of the Year in 2024. Bettina shares the experiences that led to her entering the field of business ethics and the profession’s evolution, particularly in Europe.

Bettina shares how she defines an ethics influencer and how all of us can become one. She gives ideas and strategies for effectively communicating ethics and compliance using positive messaging and how this can lead to a more ethical workplace and happier employees. She also introduces the “ethics gym,” a training concept designed to help leaders navigate ethical dilemmas and reinforce their commitment to ethical practices.

Two other fun facts: she met her husband, Guido Palazzo, at a business ethics conference and started the “F-Up Festival with Christian Hunt,” where E&C professionals can speak candidly about mistakes and lessons learned—the next one is on Thursday, May 15, at 11 a.m. ET!

Categories
Compliance Into the Weeds

Compliance into the Weeds: Leaving on a (Qatari) Jet Plane

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! With a nod to Peter, Paul, Mary, and John Denver, in this Compliance into the Weeds episode, Tom Fox and Matt Kelly deeply dive into the potential gift of a luxury Qatari jetliner to President Trump.

We discuss the launch of Trump’s meme coins and the Qatari government’s allegedly planned $400 million plane donation to Trump. The conversation examines the compliance and corruption risks these actions pose for U.S. and international businesses. Kelly emphasizes how these incidents challenge ethical standards and underscore the importance for companies to address new forms of corruption proactively within their anti-corruption programs.

Key highlights:

  • Trump’s Alleged Corruption: An Overview
  • The Meme Coins Controversy
  • The Qatari Plane Donation
  • Compliance and Integrity in the Face of Corruption

Resources:

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds, was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, the Top 10 Business Law Podcasts, and the Top 12 Risk Management Podcasts.

Categories
Blog

Data Defense is the New Compliance: What the Data Security Program Means for Compliance

In an age where data is the new oil, the Department of Justice (DOJ) has dropped a regulatory hammer with the release of the Data Security Program (DSP), which was released on April 8, 2025, and was implemented under Executive Order 14117. If you are a corporate compliance officer, this is not simply another acronym to file away; it is a full-blown mandate to build a risk-based compliance infrastructure that treats data the way we’ve historically treated cash: something precious, something dangerous, and something that foreign adversaries are actively trying to exploit. The DSP marks a critical shift in how compliance professionals think about national security, not as the purview of spooks and diplomats but as a living, breathing component of your organization’s third-party risk, data governance, and vendor oversight programs. Equally interestingly, the Trump Administration builds with zero fanfare on the building blocks put in place by the Biden Administration.

DSP Is More Than an IT Issue

The DOJ is not simply aiming at you, your Chief Information Officer (CIO), but rather looking squarely at you, the compliance professional. The new rules require U.S. persons (which includes individuals and corporations) to proactively monitor, restrict, and, when necessary, report data transactions that could expose U.S. Government-related or bulk sensitive personal data to adversarial foreign actors. These rules are about compliance and accountability. DSP enforcement brings with it the full force of the International Emergency Economic Powers Act (IEEPA), meaning penalties can include civil fines exceeding $368,000 per violation and criminal liability with up to 20 years in prison. That should sober up even the most compliance-fatigued executive.

Who’s in the DOJ’s Crosshairs?

The program identifies “Countries of Concern,” including China, Russia, Iran, North Korea, Venezuela, and Cuba. It further defines “covered persons” as not just foreign governments or entities but any individual or company operating under their influence, including contractors and subsidiaries that may be 50% or more owned by such parties. This is not simply a red flag but should be seen as a red carpet for compliance departments to step up and create data-focused due diligence protocols that mirror those already established under FCPA for anti-bribery or OFAC for sanctions screening.

The DSP targets four main types of transactions:

1. Data Brokerage Agreements

2. Vendor Agreements

3. Employment Agreements

4. Investment Agreements

Any of these, involving sensitive personal data or government-related data, could trigger a compliance obligation or, worse, a violation. Even anonymized or encrypted data isn’t exempt if it can be aggregated to reveal individual identities. Compliance teams must now incorporate data risk classification and flow mapping into their routine controls and audits.

Restricted and Prohibited Transactions: Not Just Semantics

The DSP distinguishes between “prohibited” and “restricted” transactions. Prohibited transactions, like selling bulk data to a covered person or foreign entity, are off-limits. Restricted transactions, such as engaging a foreign vendor for cloud services, are allowed only if specific due diligence, security protocols, and contractual safeguards are met.

Translation for compliance officers: This is your new playbook. You must tailor contract language to prohibit onward data transfers, track compliance, audit vendors, and report violations within 14 days. Inaction isn’t just a missed best practice; it could also be a statutory violation.

Your New Compliance Infrastructure: Four Pillars

Under Subpart J of the DSP, companies must develop and maintain a robust Data Compliance Program. Here’s what the DOJ expects from you:

1. Risk-Based Due Diligence Procedures: Know your data, vendors, employees, and business model. Map where sensitive data lives and flows. Identify exposure to covered persons or countries of concern.

2. Security Requirements: Implement the Cybersecurity and Infrastructure Security Agency’s (CISA) security standards and document them in a written policy reviewed annually.

3. Audit Program: Conduct an annual independent audit to assess DSP compliance, covering your vendors, data flows, contracts, and internal controls.

4. Training and Certification: Deliver targeted training to frontline staff and compliance officers. Certify the program annually with a sign-off from a senior officer not designated as a covered person.

The Compliance Response

Do not underestimate the power of line managers in operationalizing this program. From procurement officers vetting vendors to HR leads onboarding new hires, your middle managers are now your eyes and ears for potential data risks. Equip them with training, toolkits, and escalation protocols. Empower them to say, “No, we can’t do that,” and back them up when they do. This is where culture meets controls, and a compliance-minded organization distinguishes itself from a liability waiting to happen. DSP violations are serious business, but the program leaves room for good-faith actors. Reporting suspected breaches or rejected transactions within 14 days may mitigate enforcement risks.

What to Do Now: A Compliance  Checklist

For those who want to get ahead of this before the hammer drops, here’s your compliance punch list:

  • Review your current data governance and privacy policies—align them with DSP risk categories.
  • Audit your third-party vendor agreements for exposure to covered persons or countries of concern.
  • Draft contractual clauses that explicitly prohibit data resale or access by covered entities.
  • Set up internal processes for training, audit, and reporting.
  • Engage your board and C-suite on DSP requirements. This is national security compliance, not just privacy.
  • Start building your Data Compliance Program today, as the date of October 6, 2025 (the full implementation date) is not as far off as it seems.

Conclusion: The Age of Data National Security is Here

The DSP marks a sea change for compliance professionals. It transforms data governance from an IT-driven policy concern into a top-tier compliance risk, with reporting deadlines, audit mandates, and hefty penalties. It requires us to think beyond cybersecurity and embrace data risk as a function of geopolitical conflict and corporate accountability. Compliance is not simply about following the rules; rather, it is about being the first line of defense in protecting American data, values, and institutions from adversarial exploitation. And in that mission, every compliance professional is now a stakeholder in national security.

So, as Bette Davis might say, buckle up, tune up your compliance programs, and get ready to evangelize the next great frontier in corporate compliance.

Categories
Upping Your Game

Upping Your Game: Episode 2 – From Reactive to Predictive: How AI is Rewriting the Compliance Playbook

In February, the Trump Administration suspended investigations under and enforcement of the FCPA. Many compliance professionals have since wondered what this will mean for corporate compliance programs. Hui Chen challenged compliance professionals with “It’s time to up your game.” This podcast series, sponsored by Ethico and co-hosted with Ethico co-CEO Nick Gallo, hopes to meet Hui Chen’s challenge for compliance professionals. We will discuss how compliance professionals can ‘Up Their Game’ using currently existing Generative AI (GenAI) tools to improve compliance programs dramatically. As compliance professionals, it is critical to recognize that this moment is not merely about incremental improvements but about elevating our profession to an entirely new level of effectiveness, efficiency, and organizational value.

In today’s ‘Upping Your Game’ episode, Nick and Tom discuss moving from reactive to predictive compliance. They discuss how artificial intelligence revolutionizes compliance by shifting from reactive measures to predictive analytics. They highlight how regulatory bodies like the SEC and DOJ have led the charge in data analytics, emphasizing the importance of having access to data silos. Nick shares his experiences and stresses the need for compliance officers to integrate predictive models into business operations. They also explore the iterative process of refining these models and the significance of speaking the language of business to achieve better compliance outcomes and business impacts. The episode concludes with practical advice for compliance officers seeking to educate themselves and effectively pitch their initiatives to executives.

Key highlights:

  • The Regulatory Wake-Up Call
  • The Power of Predictive Analytics
  • Key Lessons for Compliance Professionals
  • The Iterative Approach
  • Meeting with the CEO

Resources:

Upping Your Game: How Compliance and Risk Management Move to 2030 and Beyond on Amazon.com

Nick Gallo on LinkedIn

Ethico Workshop on EV Workshop: Calculate, Track & Articulate Return on Integrity (ROI). For registration and information, click here.

Ethico

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Red Flags Rising

Red Flags Rising: S01 E11 – Point-Counterpoint – U.S. Export Controls Policy

Mike & Brent return with a point-counterpoint episode on U.S. export control policy. After discussing the latest news about U.S. AI export controls (01:03), they discuss the points and counterpoints related to whether we should have export controls at all (04:57), the relevance of the national security justifications offered by the U.S. Department of Commerce in promulgating its regulations (06:52), the lessons of Ukraine battlefield recoveries (09:59), the views of Anthropic’s CEO, Dario Amodei, on risk and how to push any industry to a more-compliance mindset (rather than acquiesce to the race to the bottom) (10:44), why Brent shouldn’t talk about the old days of corruption (12:08), and how not only the export controls’ design but also their enforcement by government and compliance efforts by industry are all relevant factors to consider in assessing export controls’ effectiveness (14:53). They conclude with the latest installment of Brent’s “Managing-Up” segment (23:04).

Resources:

Brent LinkedIn

Mike LinkedIn

Mike & Brent’s “Fresh Looks” Series

Categories
Innovation in Compliance

Navigating Regulatory Changes and Compliance in Trade and Data Privacy with Stephanie Font

Innovation comes in many areas, and compliance professionals must be ready for and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. Today, we begin a 3-part podcast series sponsored by Diligent with Clint Palermo, Kristy Grant-Hart, and Stephanie Font. Part 2 discusses navigating regulatory changes and compliance in trade and data privacy.

In this episode, host Tom Fox converses with Stephanie Font, Director for Operations Optimization Group at Diligent, to discuss the ever-evolving landscape of economic sanctions, trade policies, and data privacy. Font shares insights on how businesses can stay compliant amidst rapid regulatory changes, emphasizing the importance of continuous monitoring, thorough due diligence, and understanding one’s business partners. The conversation also touches on new regulatory trends such as BIS address specifications, Mexican cartels being designated as FTOs, and the implications of the Uyghur Forced Labor Prevention Act.

Key highlights:

  • Economic Sanctions and Trade Policy
  • Compliance and Business Operations
  • Staying Updated on Regulatory Changes
  • Cartels and Foreign Terrorist Organizations
  • Data Privacy and Cybersecurity
  • Human Rights and Business Culture

Resources:

Stephanie Font on LinkedIn

Visit Diligent Website

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Daily Compliance News

Daily Compliance News: May 13, 2025, The Leaving on a Jet Plane Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News—all from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Is the gift of a jet plane corruption? (NYT)
  • Will the SEC overturn bans and suspensions? (Reuters)
  • GOP wants to ban state regulation of AI. (Bloomberg)
  • What is risk paralysis? (FT)
Categories
Compliance Tip of the Day

Compliance Tip of the Day – Multiplying the Influence of Compliance

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Use multipliers to extend the influence of your compliance regime.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing Your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
Blog

Declinations, Disclosure, and National Security: Key Lessons from the 2024 NSD Enforcement Policy

Yesterday, I wrote about a Declination issued by the Department of Justice issued a Declination to the Universities Space Research Association (USRA), a nonprofit organization working with NASA on advanced scientific research. The Declination is found here. Today, I want to dive deeper into the March 2024 update to the National Security Division’s (NSD) Enforcement Policy for Business Organizations. This document is a must-read for every compliance officer handling export controls, sanctions, or any business with potential national security implications. It was a policy update and a blueprint for navigating one of the highest-risk areas in global business today.

The NSD is central in safeguarding the United States from national security threats, particularly by enforcing export control and sanctions laws. Businesses and their employees are vital partners in this mission, given their roles as custodians of sensitive technologies and financial systems. NSD strongly encourages companies to voluntarily self-disclose potentially willful violations of key U.S. statutes, such as the Arms Export Control Act, Export Control Reform Act, and the International Emergency Economic Powers Act, alongside related offenses like money laundering and false statements. Such violations can pose serious risks to national security, and the NSD’s approach to corporate enforcement seeks to strike a balance between encouraging cooperation and deterring harmful conduct.

The updated Enforcement Policy outlines how the NSD, in collaboration with U.S. Attorneys and other DOJ components, determines appropriate resolutions for companies that self-disclose misconduct related to export controls and sanctions. It also sets parameters for how acquiring companies can qualify for protections under the Mergers and Acquisitions (M&A) Policy when disclosing violations by an acquired entity. While the policy’s primary focus is on export and sanctions laws, its principles are designed to guide enforcement decisions in other national security-related matters, such as FARA violations and CFIUS-related conduct. The overarching message is clear: companies should proactively report potential criminal conduct under the NSD’s jurisdiction to help mitigate legal exposure and protect national security.

Here are five key lessons compliance professionals should take away from the updated policy.

1. Voluntary Self-Disclosure Must Be Early, Unprompted, and Specific

In NSD’s world, timing is not just everything; properly seen, it is the thing. To earn credit, disclosure must happen before an imminent threat of exposure or investigation, and it must be made directly to NSD. That means you cannot sit on a problem while deciding whether to tell OFAC, BIS, or your outside counsel. If NSD doesn’t know, your organization does not even qualify for full credit.

The disclosure must include all relevant non-privileged facts, including those about individuals inside and outside the company involved in the misconduct. If your disclosure is vague, partial, or delayed, it may be too little, too late. NSD puts the burden squarely on the company to prove that the disclosure was voluntary and timely.

Compliance Lesson: Build your compliance playbook around immediate, well-documented self-reporting protocols. Simulate drills. Define who makes the call to NSD. Because once the clock starts, hesitation can cost you the deal.

2. Full Cooperation Means More Than Not Obstructing

NSD has redefined “full cooperation” in practical, prosecutorial terms. It is not enough to say your organization will assist. Instead, your organization must provide full assistance, and you must proactively help. That includes sharing key facts as you uncover them, providing timely updates, disclosing foreign-located documents, and making employees (even those overseas) available for interviews.

It also means identifying every opportunity where NSD could obtain relevant evidence, even when they have not yet asked for it. That may seem like a high bar, especially for multinationals operating in jurisdictions that block statutes or data privacy laws. The bottom line is that your organization bears the burden of showing why documents can’t be produced—and you must offer alternatives.

Lesson: Compliance teams should revisit their internal investigation protocols to ensure they enable real-time, proactive engagement with government investigators. This is no place for passive risk management.

3. Remediation Is Not Window Dressing—It’s Root Cause Surgery

NSD isn’t interested in cosmetic compliance. They want to see a thorough root cause analysis and real efforts to remediate the misconduct and the control failures that allowed it to occur. That includes changes to reporting structures, testing compliance effectiveness, employee discipline (up to and including termination), and even clawbacks when appropriate.

Critically, NSD recognizes that what counts as a “well-resourced” program depends on the size of your company, but the policy still requires evidence of authority, independence, and a clear line from the compliance function to senior leadership.

Lesson: Expect little sympathy if your root cause analysis is weak or superficial. Effective remediation means digging deep, taking hard actions, and documenting every step for potential DOJ review.

4. Compliance Programs Must Be More Than Just Policies

Your program must exist, be effective, and be tested to avoid monitoring and achieve declination eligibility. NSD’s standards align with the DOJ’s broader 2023 and 2024 guidance around program evaluation: Do your controls work in practice? Are they tailored to your risk profile? Are they embedded into day-to-day operations?

NSD also scrutinizes how you retain business records, especially regarding ephemeral messaging platforms and personal devices. If your team uses WhatsApp, Signal, or iMessage without proper controls, you could be viewed as undermining your compliance system.

Lesson: Modern compliance programs must integrate surveillance, technology, and behavior-based controls, especially where national security risks are involved. “Set it and forget it” programs will not fly.

5. There’s a Path for Acquirers—If You Act Quickly

One of the more notable additions to the 2024 policy is its treatment of M&A-related misconduct. If your company acquires an entity and discovers criminal export control or sanctions violations after the deal closes, the NSD offers a pathway to protection, but only if you act fast.

You have 180 days from the closing date to disclose the misconduct and 1 year to remediate it. Do that, and NSD will generally not seek a guilty plea, criminal fine, or asset forfeiture from the acquirer. And the kicker? The misconduct also won’t count as a strike against your compliance track record in future matters.

Lesson: Build post-acquisition compliance reviews into every integration plan. Don’t wait for a surprise; audit for red flags early and be ready to disclose. In today’s world, inherited risk is your risk.

Declinations Are Earned, Not Given

The 2024 NSD Enforcement Policy is a strong step toward encouraging ethical corporate behavior in a world where the risks are real, and the stakes are high. It rewards companies that do the right thing early, thoroughly, and transparently.

But it’s also a warning: the margin for error is razor-thin. Delayed disclosures, half-baked investigations, or weak compliance programs won’t cut it. And don’t forget, NSD still retains full authority to prosecute individuals, even if your company gets a pass.

Today, the compliance officer’s job is to prevent misconduct and design systems that respond effectively when things go wrong. The new NSD policy gives us the roadmap. We must ensure the car is gassed up, the brakes work, and the driver knows where to go.

Final Compliance Evangelist Tip:

Use this policy as a stress test for your program. Would your controls hold up if misconduct occurred tomorrow? Would you disclose it in time? Could you cooperate fully? If you’re unsure, now is the time to find out before the DOJ does.

Categories
Corruption, Crime and Compliance

LRN’s 2025 Compliance Program Effectiveness Report

Are you running a compliance program that’s making a real impact—or just checking the boxes? In this episode, Michael Volkov dives into LRN’s 2025 Program Effectiveness Report, an annual benchmark that separates the truly impactful compliance programs from those that are merely operational. Based on insights from 1,500 global ethics and compliance professionals, this year’s report draws a clear line between high-impact and medium-impact programs—and what it takes to bridge the gap. The conversation highlights urgent risks, cultural disconnects, and the strategic value of automation, data, and leadership alignment in shaping tomorrow’s compliance functions.

You’ll hear him discuss:

  • How high-impact programs are defined by their strategic use of automation, data analytics, and benchmarking tools to drive measurable compliance outcomes
  • Why third-party risk management—including due diligence and supply chain oversight—is a defining trait of the most effective programs today
  • The growing trust gap between Gen Z employees and middle managers, and why this generational shift poses a cultural red flag
  • The continued dominance of outdated internal systems, regulatory complexity, and budget pressure as top operational challenges facing compliance leaders
  • How high-impact programs are integrating AI into both their codes of conduct and employee training, preparing teams for emerging tech risks
  • What medium-impact programs can do to evolve: focus on training, automation, and peer collaboration to elevate impact and resilience

Resources

Michael Volkov on LinkedIn | Twitter

The Volkov Law Group