Categories
Compliance Tip of the Day

Compliance Tip of the Day – Real-Time Compliance Scoring

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at how organizations are leveraging APIs to get real-time compliance scoring of their operations.

Categories
Daily Compliance News

Daily Compliance News: March 20, 2025, The Fluid Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen to the Daily Compliance News—all from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Business execs call Trump’s trade policy ‘fluid’. (NYT)
  • Ex-Credit Suisse head of risk and compliance fined in Switzerland. (Bloomberg)
  • DOJ enforcement outlook in healthcare under Trump. (Reuters)
  • 4 arrested in the EU Huawei scandal. (Politico)
Categories
Compliance and AI

Compliance and AI: Ali Khan on Implementing AI Risk Management Systems

What is the role of Artificial Intelligence in compliance? What about Machine Learning? Are you using ChatGPT? We will explore these three questions in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, Tom is joined by Ali Khan, Head of Governance Risk & Compliance at Kandji and an Advisory Board Member (CAB) at Drata.

This episode discusses the essential steps to effectively implement an artificial intelligence management system, as defined by ISO 42001. They start by understanding the standard requirements and expectations, performing a scoping exercise and gap assessment, and securing management’s commitment to the project. Key steps include revamping the risk assessment process to align with ISO 23894, which guides managing AI-related risks and using the NIST AI risk management framework. The design and implementation phase involves creating various AI policies, integrating AI deployment plans, and performing impact and risk assessments. They also discuss Kandji’s internal audit plan, third-party vendor assessment processes, and security awareness training to include AI-specific considerations. The beauty of ISO 42001 is its applicability to organizations of any size and industry that develop, produce, or use AI products or services.

Key highlights:

  • Understanding the Standard Requirements
  • NIST AI Risk Management Framework
  • Design and Implementation
  • Creating AI Policies and Procedures
  • Performing AI Impact and Risk Assessments
  • Steps Taken for ISO 42001 Implementation

Resources

Ali Khan on Linkedin

Kandji Website

Kandji on LinkedIn and X

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Red Flags Rising

Red Flags Rising: S01 E02 – Lutnick: “We Have Had Enough”

Mike and Brent discuss remarks at the Bureau of Industry & Security’s “Update” Conference that started today in Washington, DC (00:00), specifically Secretary of Commerce Howard Lutnick’s statement that he would take a hard line against China (02:18), including a “dramatic increase” in enforcement (04:01) and fines (13:45). In the returning segment “Brent Carlson’s Managing-Up,” Brent identifies key takeaways for trade compliance professionals to share with stakeholders, management, and boards (15:31).

Resources:

The New York Times’ initial report by Ana Swanson about Secretary Lutnick’s Statements 

Ian Cohen’s Subsequent Reporting for Export Compliance Daily 

Brent LinkedIn

Mike LinkedIn

Mike & Brent’s “Fresh Looks” Series

Categories
Blog

Compliance by Design: Future-Proofing Your Product Oversight and Governance

The US and the world financial services sector have entered a race of disruption and evolution unlike any other. While companies scramble to launch innovative solutions, be it instant payment technologies, crypto offerings, or AI-driven platforms, compliance professionals must ensure that regulatory rigor and consumer protection never become afterthoughts. Enter “Compliance by Design,” a proactive methodology that integrates compliance principles right into the DNA of product creation and governance.

As noted in a KPMG white paper entitled Compliance by Design, authors Gillian Kelly, Shane Garahy, and Donata Halpin explain that these strategies are not abstract considerations; they represent your daily battlefront. More importantly, these same challenges provide valuable compliance lessons. As compliance professionals, our responsibility lies in managing the fallout from regulatory lapses and actively preventing them. It is about embedding good governance into every aspect of product design and operational lifecycle. I have used the KPMG article as a starting point to review Compliance by Design for Compliance Professionals.

A Shift from Reactive to Proactive Compliance

The authors highlight a crucial compliance lesson: Moving from a reactive to a proactive approach significantly enhances consumer outcomes. (As Carsten Tams continually reminds us, it’s all about the UX.) Companies often adopt reactionary compliance strategies, acting primarily after issues surface. However, Compliance by Design necessitates embedding consumer protection requirements and regulatory oversight from the very beginning.

For compliance officers, the core takeaway is clear: You must anticipate and integrate. Proactivity in compliance is not simply a nice-to-have; rather, it is now a must-have. By defining positive user outcomes upfront and aligning them with clear product performance metrics, firms create built-in guardrails that help identify and mitigate risks from day one. Such an approach fosters not only stronger compliance but also greater consumer trust.

Addressing the Digital Transformation Risks

One significant issue identified by KPMG is the rapidity of innovation and its attendant risks. Product oversight frequently suffers when speed-to-market becomes the overriding priority. Compliance professionals must recognize that innovation, while exciting and essential, can inadvertently introduce new categories of consumer harm and regulatory exposure.

For example, artificial intelligence (AI) brings significant benefits and new risks, such as algorithmic bias, lack of transparency, and unanticipated operational vulnerabilities. Compliance by Design underscores the importance of integrating robust governance, rigorous testing, and continuous monitoring into the product development lifecycle, particularly when new technologies like AI and algorithmic trading are concerned.

Managing Regulatory Expectations

The regulatory landscape, especially in the financial services sector, is in constant flux, as the post-pandemic world has clarified. Whether adapting to the European Banking Authority’s guidelines or navigating the complexities introduced by the Senior Executive Accountability Regime (SEAR), compliance officers are increasingly called upon to demonstrate agility and clarity. For compliance, the arena is currently in a state of extreme flux as well.

By implementing automated compliance checks at early stages and continuously throughout a product’s lifecycle, compliance teams create a strong narrative of responsibility and preparedness, which is precisely what regulators demand. Such preemptive compliance strategies resonate positively during regulatory reviews and audits, making Compliance by Design a strategic advantage for any organization.

Enhancing Consumer Protection through Automation

Manual assurance approaches often falter due to limitations in scope and visibility, potentially allowing consumer detriment to go undetected. Compliance by Design advocates embedding automated testing into the product design, thereby vastly increasing detection capabilities across a consumer population rather than merely targeted subsets.

Automating compliance monitoring enhances consumer protection and significantly boosts operational efficiency. It reduces the manual labor burden on compliance teams and allows compliance officers to refocus their valuable time and expertise away from repetitive tasks towards more strategic compliance initiatives.

Leveraging Data for Compliance Effectiveness

Data collection and analytics remain underutilized resources in compliance circles. According to KPMG, integrating automation and harnessing data insights throughout the product lifecycle enable compliance professionals to establish early-warning systems based on accurate Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs). These data-driven indicators facilitate proactive rather than reactive measures, preventing compliance issues before they escalate.

Compliance professionals must champion analytics integration within their governance frameworks, ensuring data accuracy and completeness. Organizations willing to invest in robust data strategies will find themselves more agile and responsive to regulatory shifts and better positioned to demonstrate robust oversight and accountability.

Tackling Legacy Systems and Knowledge Gaps

The authors identified one significant obstacle for compliance departments as legacy systems and inadequate documentation. Aging IT systems, compounded by incomplete data and inconsistent documentation, create significant barriers to effective compliance monitoring.

Compliance by Design calls for comprehensive understanding and documentation of products from inception, tackling potential legacy problems head-on. Regression testing and systematic IT reviews are crucial steps compliance officers can adopt to prevent future operational fallout from legacy system constraints. Addressing these problems upfront streamlines compliance oversight and mitigates the risk of hidden vulnerabilities resurfacing later in product lifecycles.

Establishing Clear Accountability Structures

An integral part of Compliance by Design is clarifying and enforcing accountability lines within organizations. The Senior Executive Accountability Regime (SEAR) emphasizes this principle, requiring senior leaders to have clear oversight and accountability for consumer outcomes and regulatory adherence. Compliance officers must seize this opportunity to embed accountability into their compliance culture.

This does not merely entail assigning responsibility; it is about fostering a corporate environment where compliance responsibilities are understood, embraced, and enforced at all organizational levels. A strong accountability framework helps organizations swiftly address emerging risks and assures senior executives and regulatory bodies that the firm is proactively managing its compliance obligations.

The Compliance Professional’s Call to Action

Compliance professionals occupy a unique position as custodians of regulatory integrity and consumer trust. By championing the Compliance by Design approach, compliance officers are empowered to transition their organizations from reactionary and issue-prone to proactive and resilient compliance frameworks.

Embracing the principles outlined by the authors means compliance officers can confidently navigate the complexities of regulatory landscapes, rapidly evolving technologies, and consumer-centric expectations. Such an approach will position organizations for immediate compliance successes and sustainable long-term integrity and operational excellence.

The path forward for compliance is clear. You should integrate compliance rigorously into product design from the outset, automate your oversight, harness your data, address legacy challenges proactively, and establish clear accountability. Compliance by Design is an essential business imperative for our digital age. It offers not only a road map but an opportunity. You can build stronger, fairer, and more resilient companies prepared to face any future challenge.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Compliance By Design

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at how Compliance by Design can improve your organization’s overall product and service offerings.

Categories
Blog

Compliance Lessons from Uber’s AI Playbook

Uber is no stranger to innovation. The ride-sharing giant has consistently embraced artificial intelligence (AI) to streamline operations, enhance customer satisfaction, and mitigate risks. An article in Digitalefynd discussed these strategies. The article explored how Uber employs AI, not simply transportation or tech. I have adapted the insights for the compliance professional by reviewing five ways Uber leverages AI. I also discuss how compliance practitioners can adapt these strategies to progress their compliance programs.

1. Efficient Matching and Allocation: Enhancing Your Resource Deployment

Uber uses advanced AI algorithms to match drivers to passengers rapidly. The system integrates data points such as rider location, traffic conditions, and driver availability to minimize wait times and maximize efficiency.

Compliance professionals face similar challenges, allocating compliance resources where they’re needed most precisely and promptly. By adopting data-driven AI models, compliance teams can better assess risks, prioritize actions, and assign resources efficiently. AI analytics can synthesize multiple data streams, like whistleblower reports, audit findings, or third-party due diligence information, ensuring that the compliance team’s attention and resources are allocated effectively. The result is reduced compliance risk, more responsive interventions, and ultimately, a more robust compliance posture

2. Dynamic Pricing: Adaptive Risk Assessment and Prioritization

Uber’s dynamic pricing model, known widely as surge pricing, uses AI to adjust prices in real-time to balance supply and demand. By analyzing historical data, real-time demand, and external factors like local events, Uber ensures availability and responsiveness during peak times.

A dynamic, AI-powered approach to risk assessment in corporate compliance can significantly enhance effectiveness. Compliance risk is dynamic. It fluctuates with new markets, regulatory changes, and emerging threats. Leveraging AI to adjust your risk scoring or prioritize compliance initiatives dynamically can enable teams to proactively respond to evolving circumstances, such as emerging sanctions, regulatory updates, or market-specific risks. Like Uber’s model, compliance functions could employ AI algorithms to identify heightened compliance risk periods and adapt their monitoring, investigations, and training accordingly. This ensures that your organization is always ready to respond to changing risk environments.

3. Route Optimization: Streamlining Investigations and Responses

Route optimization allows Uber to identify the most efficient routes in real time, considering factors such as traffic congestion and road closures. This proactive approach reduces delays and increases reliability.

Applying this calculus, compliance professionals can benefit from AI-driven optimization of investigations, audits, and compliance activities. AI can predict potential compliance bottlenecks and inefficiencies by analyzing historical compliance data and integrating real-time signals from various parts of the organization. Such intelligent route mapping ensures compliance investigations follow the most efficient path, avoiding unnecessary delays, repetition, or resources wasted on low-risk issues. As Uber guides drivers through traffic, AI can navigate compliance teams through complex data, reducing response times and enhancing investigative quality.

4. Fraud Detection: Proactive Risk Mitigation and Ethical Safeguarding

Uber deploys AI to detect and prevent fraud by analyzing transactional patterns, user behaviors, and anomalies, addressing threats before significant harm occurs.

Fraud detection parallels one of the core missions of any corporate compliance professional: proactively preventing misconduct. By adopting similar AI-powered detection mechanisms, compliance departments can enhance their ability to spot anomalies and unethical behavior within the enterprise, such as improper transactions, conflicts of interest, or insider threats. Machine learning models trained on historical compliance incidents can flag unusual activities early, allowing compliance officers to intervene before issues escalate. Enhanced fraud detection capabilities strengthen organizational integrity and build stakeholder confidence in your compliance ecosystem.

5. Predictive Maintenance: Shifting from Reactive to Predictive Compliance

Uber’s predictive maintenance strategy uses AI to forecast vehicle issues before they occur, scheduling maintenance proactively. This approach reduces downtime and improves reliability.

Compliance professionals can mirror this predictive mindset, moving from reactive firefighting to proactive risk management. AI can analyze extensive compliance datasets, like training completions, past violations, regulatory changes, employee feedback, and market trends, to anticipate compliance failures or lapses before they materialize. Predictive compliance modeling enables your team to schedule targeted interventions, training, or policy updates strategically and proactively, significantly reducing the likelihood of compliance breaches. Proactive maintenance of compliance systems enhances organizational resilience, reduces overall compliance costs, and bolsters stakeholder trust.

Uber’s commitment to artificial intelligence has gone beyond simply revolutionizing urban mobility. Its development offers a powerful example of how AI-driven techniques can transform compliance functions. AI empowers compliance teams to anticipate problems, streamline processes, optimize resource allocation, dynamically adapt to risks, and detect misconduct proactively. These approaches shift compliance from a cost center reacting to issues to a strategic asset proactively safeguarding organizational integrity.

As Uber continues to set new industry standards with AI, compliance professionals should admire these innovations and actively embrace their applications. Adopting an AI-enabled compliance approach positions your organization ahead of emerging risks and regulatory expectations, proving once again that compliance is not simply about responding to problems but anticipating and outpacing them.

After all, the road ahead for compliance is paved not just with good intentions but with strategic foresight, precise execution, and the intelligent use of technology. Uber’s journey underscores the power of AI to redefine operational excellence, and for compliance professionals, this is one ride worth taking.

Categories
Daily Compliance News

Daily Compliance News: March 19, 2025, The Why CISOs Quit Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen to the Daily Compliance News—all from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

Categories
Great Women in Compliance

Great Women in Compliance – Hearing the Unheard: Leading with Courage When the News Isn’t Good

There is a lot to unpack in this roundtable episode hosted by Sarah Hadden and Ellen Hunt. Listen as they flip the script on delivering bad news to explore how to educate our leaders to hear and act on bad news. Our experts Elaine Lin Hering and Deb Hennelly share and explore strategies on how to:

  • Build a trusting relationship before the crisis;
  • Incorporate role play as an anchor for the desired behavior when bad news needs action;
  • Understand that emotions are data that you need to leverage.
  • Address the “silence” that hinders ethical behavior, and
    Create real psychological safety.

🎧 Listen now on your favorite platforms, the Compliance Podcast Network and Corporate Compliance Insights

♥️ Thanks as always to our wonderful #GWIC community for your support. Have an idea or suggestion? Drop a note to Lisa Fine or Hemma Lomax.

Categories
Compliance Into the Weeds

Compliance into the Weeds: A Deep Dive into Employee Leaks and Corporate Culture

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode, Tom Fox and Matt Kelly discuss the issues surrounding employee leaks of confidential information, drawing on insights from a recent SCCE Europe event.

They also consider the motivations behind such leaks, including dissatisfaction with corporate culture and ineffective internal reporting channels, exemplified by the recent leaks at Facebook. The episode reviews measures compliance officers can take to prevent leaks, such as implementing tight access controls, encryption, and improving communication during investigations. Practical tips for reducing leaks and the importance of trust in internal reporting are also highlighted.

Key highlights:

  • Discussion on Employee Leaks
  • Facebook’s Toxic Culture (or not) and Leaks
  • Addressing Internal Speak-Up Culture
  • Practical Tips to Prevent Leaks
  • Modern Communication Challenges

Resources:

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Compliance into the Weeds was recently honored as one of the Top 25 Regulatory Compliance Podcast.