Categories
Daily Compliance News

Daily Compliance News: April 25, 2025, The Trouble in Travel Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy morning coffee, and listen to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Will Paramount have to drop diversity to merge with SkyDance? (WSJ)
  • Don’t vouch for Huawei at the EU Commission. (WSJ)
  • Trump is now suing law firms for representing clients or issues he does not approve of. (Reuters)
  • Americans are afraid to travel outside the US. (Business Insider)
Categories
Blog

The Future of Continuous Monitoring: AI-Driven Compliance is Here to Stay

The compliance function has officially crossed the Rubicon. Artificial intelligence is no longer an experimental technology on the compliance periphery; it is at the center of forward-thinking compliance programs. We are witnessing a seismic shift in managing risk, detecting misconduct, and maintaining corporate integrity. AI enables real-time monitoring, uncovering subtle anomalies, and delivering the kind of automated oversight previously confined to PowerPoint dreams. As we enter 2025, the question is not whether your compliance function should adopt AI but how quickly you can make it central to your operations.

This blog post explores how compliance professionals can use AI to power a future-ready, continuously monitored compliance program. Today, we will explore five powerful lessons supported by real-world case examples and framed within current regulatory expectations. As Andrew McBride described, we are entering the “Holy Grail” era of compliance, where due diligence, internal and external data, and communications can be monitored holistically through AI agents trained to detect abnormalities and investigate unethical behavior.

Lesson 1: AI Enhances Risk Detection

AI doesn’t just speed up compliance; it sharpens it. Traditional compliance teams have long struggled to keep up with massive amounts of structured and unstructured data. From financial transactions to email threads, vendor records, and chat logs, there are risk indicators that no human team could feasibly monitor in real-time. Enter AI and machine learning.

With natural language processing (NLP), AI systems can read between the lines. They detect shifts in sentiment, keyword patterns, and coded language that may indicate bribery, fraud, or circumvented controls. Matt Galvan emphasizes this as a game-changer, especially when GenAI tools synthesize background due diligence with transactional anomalies to flag red flags early before misconduct manifests.

Better still, AI eliminates the “needle in a haystack” problem. It builds outliers into profiles, detects slush fund behavior, and creates actionable summaries with supporting documentation. You are not simply faster, and you are smarter. But here’s the kicker: the quality of AI outputs depends on the quality of your inputs—poor data = poor detection. AI must be trained on clean, complete, and bias-aware datasets. And AI should never operate in a vacuum. Human judgment remains essential to interpret findings and assess the business context.

The bottom line is that AI transforms compliance from reactive to proactive. It is no longer about catching up; it is about staying ahead.

Lesson 2: Regulators Expect AI-Driven Compliance

If you need a business case for AI, start with the Department of Justice (DOJ) and its 2024 Evaluation of Corporate Compliance Programs (2024 ECCP). The DOJ has moved beyond encouragement and now expects companies to adopt real-time, AI-powered compliance monitoring. Failing to implement these tools could soon be seen as a failure to meet basic compliance standards.

This isn’t just about the DOJ. The SEC, FinCEN, OCC, Federal Reserve Board, and the Financial Action Task Force (FATF) are pushing toward a future where real-time compliance tools are a baseline requirement, not a nice-to-have. What’s more, regulators are now asking companies to explain their AI. What data powers your algorithms? How are decisions made? Can you justify why one transaction was flagged and another was not? Transparency and audibility are no longer optional; they are regulatory imperatives.

Regulators understand that AI can reduce legal risk and enhance oversight. They expect you to understand it, too.

Lesson 3: AI Identifies Emerging Geopolitical Risks

Welcome to the volatility vortex of 2025. What was a low-risk jurisdiction on Friday can be a sanctioned country by Monday. Supply chains bend and sometimes break under the weight of sanctions, tariffs, and political upheaval.

Traditional compliance programs cannot react fast enough. This is where AI earns its keep. AI flags emerging geopolitical risks before they bite by ingesting thousands of data points from news, regulatory alerts, trade databases, and internal procurement systems. Andrew McBride’s example of a virtual bill of materials is especially prescient: imagine knowing exactly where a conflict mineral is buried in your supply chain and being alerted when a regulatory status changes.

AI makes it possible. Galvan pointed out that the same data sets used to optimize supply chains can be re-leveraged for compliance risk analysis. In other words, compliance teams should not operate with less information than procurement or logistics. If you are waiting for geopolitical risk to reach your front door, sadly, you are already behind. AI enables a proactive posture to protect your business from international surprises.

Lesson 4: Automating Compliance Reduces Costs and Increases Efficiency

Efficiency is often an underappreciated outcome of effective compliance. But let’s be clear: automation isn’t just about doing things faster; it is about doing them better and cheaper. AI automates transaction monitoring, scans for real-time anomalies, and triages cases for deeper review. No more relying on random audits or static checklists. AI helps compliance programs scale, especially for global companies managing thousands of vendors and counterparties.

Consider regulatory reporting: AI can automate data collection and reporting preparation, ensuring timely submissions and reducing the burden on internal teams. These efficiencies translate directly into cost savings while improving quality.

McBride’s point about AI-driven NLP catching potential bribery schemes in real-time is a glimpse into what’s already possible. Emails, Teams messages, and Slack conversations are goldmines of risk insight when monitored responsibly and legally. Just-in-time risk flags make compliance not only real-time but also real-impact.

AI is your accelerator if you want a leaner, faster, and smarter compliance function.

Lesson 5: Early Adoption of AI Is a Competitive and Ethical Advantage

Finally, we come to the business case. Early adopters of AI-driven compliance are already reaping the rewards. Not just in regulatory peace of mind but in market leadership.

AI enables transparency, consistency, and accountability. It allows organizations to demonstrate good governance, not just say they care about it. That builds trust with investors, customers, and regulators alike. It also helps embed a culture of integrity. By quickly catching issues and addressing them, AI empowers ethics to be lived, not laminated on a wall. And companies that bake ethics into their business model outperform over the long term.

The inverse is also true: those who delay AI adoption will soon find themselves scrambling to catch up, facing increased regulatory scrutiny and higher costs. The future of compliance is not five years away. It’s now. Organizations that embrace AI today will be tomorrow’s industry leaders in ethics, governance, and profitability.

AI is not simply a tool; rather, it is transformational. It allows compliance professionals to do more, do it faster, and do it better. But success requires more than just buying technology. It requires thoughtful integration, rigorous oversight, and a strategic mindset. Continuous monitoring is the future, and the future has arrived. Together, let us build compliance programs that are not only compliant but also resilient, efficient, and ethical.

The above is from my latest book, Upping Your Game: How Compliance and Risk Management Move to 2030 and Beyond, available from Amazon.com.

Categories
FCPA Compliance Report

Ellen Hunt on Compliance ROI and on a Due Diligence and the US Sentencing Guidelines

In this episode of the Diligent Compliance Week 2025 Speaker Preview Podcasts series, Ellen Hunt discusses her two presentations at Compliance Week 2025, “Culture Effectiveness and ROI: How to Move the Needleand “Assessing Effectiveness: Do the 30-Year-Old Federal Sentencing Guidelines Still Work? “

In her first panel presentation, they will discuss the following:

  • Demonstrate measurable and quantifiable ROI
  • Build psychological safety that drives ethical decision-making and engagement.
  • Navigate matrix environments to expand the influence.
  • Use data to tell compelling compliance success stories.
  • Partner with the C-suite to help them navigate disruptive changes, including deregulation and major economic geopolitical shifts.

In her second presentation, she and Carrie Penman, the Chief Risk and Compliance Officer at Navex, will debate whether the US Sentencing Guidelines should be updated.

I hope you can join us at Compliance Week’s 20th Anniversary National Conference. This year’s event will be held April 28-30 at The Mayflower Hotel, Autograph Collection, Washington, D.C. The lineup is first-rate, with some top ethics and compliance practitioners around.

Drop by the Diligent booth for some Compliance Podcast Network coffee to gain insights and make connections at the industry’s premier cross-industry national compliance event, offering knowledge-packed, accredited sessions and take-home advice from the most influential leaders in the compliance community. Back for its 20th year, compliance, ethics, legal, and audit professionals will gather safely face-to-face to benchmark best practices and gain the latest tactics and strategies to enhance their compliance programs.

Categories
Red Flags Rising

Red Flags Rising: S01 E09 – Tariffs: Navigating Uncertainty & Mitigating Enforcement Risk

Mike & Brent jump into tariffs to focus on practical strategies to navigate these uncertain times and mitigate the risk of future enforcement actions. Specifically, they discuss what longer-term geopolitical trends help businesses to plot a strategy despite being whipsawed by tariff news each day (01:57), a recent and helpful Foreign Affairs article, by Emily Kilcrease and Geoffrey Gertz of the Center for a New American Security (03:21), the recent book “Chokepoints: American Power in the Age of Economic Warfare” by Edward Fishman and his description of the “impossible triad” between economic interdependence, economic security, and geopolitical competition (04:21), relevant historical background on the rise of China after the Second World War and its current oversupply problem (04:54), how severe pressures on businesses in both the U.S. and China will create white collar compliance risks today and enforcement risks tomorrow (07:42), customs evasion enforcement risk under the U.S. False Claim Act (FCA) and the FCA’s definition of “knowledge” (08:06), the importance of dynamic assessments of customs evasion risks (11:25), potential fines and penalties from U.S. Customs & Border Protection (CBP) and U.S. Department of Justice (DOJ) enforcement (12:54), a deeper dive into the FCA’s “knowledge” standard and its similarities to the “high probability” standard under the U.S. Export Administration Regulations (EAR) (16:14), and practical strategies for companies trying to manage these risks (17:50). Then they conclude with another installment, back by increasing popular demand, of Brent Carlson’s “Managing-Up” segment (20:39).

Resources:

Geoffrey Gertz & Emily Kilcrease, “A World Safe for Prosperity How America Can Foster Economic Security,” Foreign Affairs Magazine

Edward Fishman, “Chokepoints: American Power in the Age of Economic Warfare”

Brent LinkedIn

Mike LinkedIn

Mike & Brent’s “Fresh Looks” Series

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Leveraging AI for Real-Time Third-Party Risk Management

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, Tom Fox considers the advantages of using AI for third-party risk management.

For more on embedded compliance, check out my new book, Upping Your Game: How Compliance and Risk Management Move to 2030 and Beyond, available from Amazon.com

 

Categories
Innovation in Compliance

Innovation in Compliance: Design-Centric Compliance Training with Karen Oddo

Innovation comes in many areas, and compliance professionals must be ready for and embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. This series is introduced by Tom Fox and hosted by Roxanne Petraeus. Ethena sponsors this special five-part series on Innovation in Compliance.

In this episode, Roxanne Petraeus welcomes Karen Oddo, Senior Managing Counsel and Legal Compliance at Unity Technologies. Karen shares insights on Unity’s software platform, which is predominantly known for video game development, and its expansive global footprint. The discussion dives into best practices for compliance training, emphasizing the importance of user experience and personalized content to engage employees effectively. Karen highlights the significance of targeted risk-based training and the benefits of leveraging advanced analytics to improve compliance programs. With anecdotes from her experience and her value in working with Ethena’s customizable and responsive platform, Karen offers practical advice for compliance leaders looking to enhance their training efforts.

Key highlights:

  • Compliance Training Best Practices
  • The Importance of User Experience in Compliance Training
  • Customizing Compliance Training with Ethena
  • Leveraging Analytics for Targeted Training
  • The Value of Strong Vendor Support

Resources:

Karen Oddo on LinkedIn

Unity Technologies on LinkedIn

Unity Technologies 

Ethena 

Roxanne Petraeus on LinkedIn

Ethena on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Hill Country Authors

Hill Country Authors – True Crime with Robert Riggs

Welcome to a new season of the award-winning Hill Country Authors Podcast, sponsored by Stoney Creek Publishing. In this podcast, Hill Country resident Tom Fox visits with authors who live in and write up the Texas Hill Country.  In this episode, Tom visits with Robert Riggs, a Texas native, A&M grad, journalist, author, and now true crime podcaster.

In this episode, Tom and Robert review his journey from a small town in Texas to his varied career, highlighting his ventures into politics, journalism, and podcasting. Riggs shares fascinating anecdotes from his professional life, including experiences with the FBI, his first-hand reporting during major conflicts, and his latest work on cold cases and true crime podcasts. Riggs also dives deep into how he leverages AI tools like ChatGPT to enhance his creative process, create compelling podcast content, and even solve complex analytical problems. Their conversation provides unique insights into the convergence of technology, storytelling, and real-world crime investigations.

Key highlights:

  • Robert Riggs’ Early Life and Education
  • Career Beginnings and Political Involvement
  • Transition to Journalism and Broadcasting
  • Podcasting Journey and Crime Stories
  • Future Projects and Cold Cases

 Resources:

Texas Crime Stories on Amazon.com

Freed To Kill (YouTube)

True Crime Reporter Podcast

Connect with Robert Riggs

True Crime Reporter on Facebook

Robert Riggs on LinkedIn

True Crime Reporter on Instagram

Nancy Huffman Fine Art

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Daily Compliance News

Daily Compliance News: April 24, 2025, The Made in Malaysia Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy morning coffee, and listen to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • The EU fines Meta and Apple for anti-trust violations. (FT)
  • Law firms gear up to fight shareholder activism. (WSJ)
  • How to evade tariffs (or not). (Bloomberg)
  • Who will get CITGO? (Reuters)
Categories
Blog

Predictive. Proactive. Protected: Leveraging AI for Real-Time Third-Party Risk Management

Even in 2025, third-party risk management remains one of the thorniest challenges for compliance professionals. Whether you oversee distributors in the Middle East, suppliers in Southeast Asia, or data processors in Eastern Europe, the risks, including bribery, sanctions violations, labor abuses, and fraud, remain ever-present. Traditionally, compliance teams fought these battles using static tools: onboarding questionnaires, annual reviews, and spreadsheet trackers. But those blunt instruments are no longer enough in today’s real-time risk environment.

Enter AI, specifically Generative AI (GenAI), predictive analytics, and blockchain, which is revolutionizing third-party oversight and giving compliance professionals the power to act proactively, not reactively. As Jag Lamba, CEO of Certa, astutely notes, GenAI brings three significant value buckets: reduced risk, commercial ROI, and reduced legal costs. Today, I will unpack what that means for compliance and how we can move from the “check-the-box” era to one of integrated, continuous monitoring and risk mitigation.

Compliance in Real Time: The Shift to Predictive Tools

Historically, the compliance approach to third-party risk was episodic. We conducted due diligence at onboarding, maybe revisited it every few years, and crossed our fingers in between. However, the gaps between assessments were dangerous blind spots, exposing companies to risks that regulators like the DOJ and SFO are increasingly unwilling to tolerate.

That’s where predictive analytics steps in. To forecast potential violations, these systems analyze structured and unstructured data, from financial records to adverse media to geopolitical trends. AI flags early risk indicators, such as an unusual payment pattern or a politically exposed person. That allows compliance to intervene before a deal closes, a bribe is paid, and reputational damage is done.

Machine learning (ML) models also allow dynamic anomaly detection. This is especially useful in sifting through transactional data and flagging high-risk behavior patterns like duplicate invoices, mismatched documentation, or sudden changes in third-party ownership.

Blockchain brings an additional layer of trust. Immutable audit trails secure contracts, payments, and due diligence documentation, ensuring the record is tamper-proof and regulator-ready. Smart contracts can enforce compliance obligations automatically, stopping payments, triggering alerts, or suspending activity when a vendor falls out of bounds.

Three Buckets of Value: What GenAI Delivers

Jag Lamba, CEO of Certa, outlined three distinct areas where GenAI delivers:

  1. Risk Reduction Compliance risk, data privacy risk, ESG risk, reputational risk—the list goes on. AI helps companies avoid working with third parties that introduce these risks into the business ecosystem. This is more than good practice; it is a lifeline for organizations operating under Deferred Prosecution Agreements (DPAs) or with heightened scrutiny from regulators.
  2. Commercial Value Faster onboarding of sales agents, vendors, or channel partners means faster revenue. Reducing a six-week onboarding timeline to two days can translate into hundreds of millions in new revenue, especially in fast-moving sectors.
  3. Legal Savings Avoiding regulatory missteps means avoiding costly enforcement actions. In today’s aggressive enforcement climate, those savings are not simply theoretical; they are very real and very substantial.

Compliance should not be a handbrake on business; it should be a business enabler. By embedding GenAI into core operations, organizations create less friction and fewer dual processes, improving business agility without sacrificing oversight.

Five Takeaways for Compliance Professionals

  • Predictive Compliance Is the New Norm

The days of “wait and see” are over. AI lets us anticipate risk, not just react to it. Predictive tools shift compliance from being an internal auditor to a strategic partner in risk mitigation. Companies like Certa use automated third-party master data enrichment to reduce false positives and streamline screening, creating cleaner data for faster, smarter decisions.

  • AI Supercharges Due Diligence

Natural language processing (NLP) and machine learning enable deep due diligence at scale. To flag red flags, AI can scan global watchlists, sanctions databases, court records, and newsfeeds. It can uncover hidden connections, shell entities, familial relationships, and obscure affiliates that human reviewers often miss.

Even better, AI does not sleep. It continually updates third-party risk profiles in real time, offering dynamic monitoring that aligns with today’s fast-changing regulatory landscape.

  • Real-Time Supply Chain Monitoring Is a Must

Supply chains are now under a microscope. From human rights to trade sanctions, regulators demand evidence that companies are proactively managing supply chain risks. AI tools monitor supplier behaviors and flag real-time ESG risks, such as forced labor or environmental non-compliance.

Blockchain ensures that supply chain data remains unaltered and provides traceability across multiple tiers of suppliers. With AI-integrated blockchain systems, compliance professionals can quickly identify issues, trace them to their source, and take corrective action.

  • AI + Blockchain = Fraud and Corruption Prevention

Fraud detection meant following static rules, like transaction thresholds or vendor location mismatches. AI adds nuance. It can detect bribery patterns or fraudulent shell entities by learning from thousands of real-world cases. Meanwhile, blockchain creates an unchangeable record of each transaction, making it harder for corrupt actors to falsify invoices or backdate payments. This two-pronged approach, predictive analytics plus immutable records, offers a potent defense against FCPA and UKBA violations.

  • Third-Party Risk Must Be Continuous, Not Episodic

Third-party due diligence cannot be a one-and-done exercise. Predictive analytics enables a live risk-scoring environment where third parties are constantly evaluated. AI can even detect patterns that suggest “compliance-sensitive” activity, like vendors interacting with government officials or operating in high-risk jurisdictions, flagging them for further review.

One multinational recently implemented a no-code solution that monitors purchase requisitions for signs of regulatory engagement, triggering automated validation questions. This kind of innovation is only possible when compliance works in tandem with IT, legal, and procurement.

Compliance at a Crossroads: Innovate or Fall Behind

After the Trump Administration’s Executive Order suspending FCPA investigation and enforcement, compliance professionals face a fundamental choice: evolve or be eclipsed. But in 2025, manual reviews and siloed spreadsheets. Business leaders expect real-time monitoring, cross-functional integration, and data-backed decision-making to create greater business value. That means compliance must step into a new leadership role that embraces technology, champions cross-department collaboration, and drives value across the enterprise.

It is time for compliance teams to stop seeing AI as a future concept and start seeing it as a present-day imperative. The organizations that embrace this shift will thrive in the next wave of regulatory scrutiny and be best equipped to meet the moment.

As the saying goes, “The best way to predict the future is to invent it.” For compliance professionals, that future is AI-driven, real-time, and risk-resilient.

This article was based on my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com.

Categories
FCPA Compliance Report

Amanda Carty on a Due Diligence and Risk Management

In this episode of the Diligent Compliance Week 2025 Speaker Preview Podcasts series, Amanda Carty discusses her presentation at Compliance Week 2025, “Going Beyond Due Diligence in Risk Management.”

Some of the issues she will discuss:

  • Demonstrate measurable and quantifiable ROI
  • Build psychological safety that drives ethical decision-making and engagement.
  • Navigate matrix environments to expand the influence.
  • Use data to tell compelling compliance success stories
  • Partner with the C-suite to help them navigate disruptive changes, including deregulation and major economic geopolitical shifts.

I hope you can join us at Compliance Week’s 20th Anniversary National Conference. This year’s event will be held April 28-30 at The Mayflower Hotel, Autograph Collection, Washington, D.C. The lineup is first-rate, with some top ethics and compliance practitioners around.

Drop by the Diligent booth for some Compliance Podcast Network coffee to gain insights and make connections at the industry’s premier cross-industry national compliance event, offering knowledge-packed, accredited sessions and take-home advice from the most influential leaders in the compliance community. Back for its 20th year, compliance, ethics, legal, and audit professionals will gather safely face-to-face to benchmark best practices and gain the latest tactics and strategies to enhance their compliance programs.