Categories
TechLaw10

TechLaw10: AI & Its Impact on Law Firms with guest Jill Kawakami

In this episode of TechLaw10, Punter Southall Law’s Jonathan Armstrong & Eric Sinrod, Professor, and Duane Morris LLP attorney, chat with a returning special guest, Jill Kawakami. This is episode 302 in the popular TechLaw10 series. You can listen to earlier podcasts here. Jill, Jonathan & Eric discuss several issues, including:

  • how AI has changed law firms
  • what are the concerns of junior lawyers, and what do they want from a post-AI world?
  • the economics of the use of AI in the law
  • what seems to be the world’s first ban for a lawyer for hallucination
  • some of the positive uses for AI in the law
  • the issues with access to justice
  • the impact on privilege
  • how law firms can grade AI use
  • how law firms can deal with the scrutiny gap
  • what some law firms are doing to train their lawyers
  • the issues with token wastage
  • the latest figures on AI reducing headcount
  • the issues with AI anxiety
  • AI displacement
  • the impact on diversity & social advancement

Jonathan talks about the Abhishek Kumar case. There’s a copy of the Tribunal’s judgment here.

Jonathan & Eric refer to Damien Charlotin’s database on hallucinations, which is here. There’s a summary of hallucination cases in the UK, including the Ayinde case, which Jonathan mentions here. The NYSBA paper Jonathan talks about is here.

Jonathan also talks about the EU AI Act. FAQs are here. A glossary of AI terms is also available here. You can find out more about Jonathan Armstrong here. You can find out more about Eric Sinrod here.

Categories
Everything Compliance - Shout Outs and Rants

Everything Compliance: Shout Outs and Rants – Conflicts of Interest, The False Claims Act, AI and More AI

Welcome to a new season of Everything Compliance—Shout Outs and Rants. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, joining returning regulars Matt Kelly, Jonathan Armstrong, and Karen Moore for the next iteration of Everything Compliance Shout Outs and Rants.

  • Adam Turteltaub shouts out to his brother, Jon Turteltaub, for announcing that National Treasure 3 will go into production.
  • Rebecca Walker rants about the failure to handle conflicts of interest consistently.
  • Jonathan Armstrong rants about AI slop and personalized pricing.
  • Karen Moore shouts out to independent cinemas in general and the Alhambra Cinema specifically for first-run films, art house films, community film interaction with the local film club, and showing documentaries of social importance.
  • Matt Kelly rants about why professional sports teams such as the LA Clippers fail to have a compliance and ethics officer.

Everything Compliance Shout Outs and Rants is a production of the Compliance Podcast Network.

Categories
AI Today in 5

AI Today in 5: September 22, 2026, The Kill Switch Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Newsom wants an AI kill switch. (Bloomberg)
  2. Policing AI in finance. (FT)
  3. What’s advancing AI in healthcare? (Distilled Post)
  4. Trust and AI in the financial sector. (FinTech Global)
  5. AI co-agents in drug development. (NYT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Daily Compliance News

Daily Compliance News: September 22, 2026, The Door Open Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Poor data sharing undermines EU cyber defenses. (Reuters)
  • Polymarket leaves open door for fraudsters. (WSJ)
  • Paramount settles state antitrust lawsuit. (NYT)
  • Ex-PLA head kicked out of the Party for corruption. (NYT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

Da Vinci Week: Part 2 – Leonardo’s Anatomical Studies and Getting Beneath the Surface

In the first post in our Leonardo Compliance Framework, the Mona Lisa introduced Refine: the discipline of continuous improvement. An effective compliance program should learn from investigations, monitoring, risk assessments, employee feedback, control failures, and business changes. The program should evolve because the organization knows more today than it knew yesterday. That brings us to the second principle: investigate.

Leonardo was not satisfied with observing the human body from the outside. His anatomical studies examined muscles, bones, organs, movement, and the relationships among different parts of the body because he wanted to understand how the entire system worked. That provides a useful model for the modern Chief Compliance Officer because an effective corporate investigation should accomplish more than determine whether an employee violated a policy. It should help the organization understand why the conduct occurred, which controls failed, what incentives influenced behavior, whether management contributed to the problem, whether similar conditions exist elsewhere, and what should change as a result.

The compliance lesson from Leonardo is to look beneath the visible misconduct and understand the system that produced it.

An Investigation Is More Than a Search for Misconduct

Consider a familiar scenario. An investigation establishes that a sales employee used a consultant to make an improper payment to secure business. The company confirms the misconduct, terminates the employee and consultant, documents the findings, and closes the matter.

That process may answer the immediate legal and disciplinary questions, but it does not necessarily answer the larger compliance question. The company should also understand why it hired the consultant, how it approved the relationship, what due diligence it performed, whether it identified red flags, how it compensated the consultant, and how the resulting invoices and payments moved through the organization. Management should consider whether commercial incentives contributed to the conduct, whether supervisors encountered warning signs, and whether similar consultants are being used elsewhere.

If the company concludes only that one employee violated the anti-corruption policy, it may remove the individual while leaving intact the conditions that allowed the misconduct to occur. The investigation has then addressed the actor without addressing the vulnerability. That is why investigations should be viewed as a source of organizational intelligence.

Root Cause Should Drive Remediation

Root-cause analysis is where Leonardo’s anatomical method becomes particularly relevant. The objective is to move from the visible event to the systems underneath it. The Evaluation of Corporate Compliance Program (ECCP) states, “Finally, a hallmark of a compliance program that is working effectively in practice is the extent to which a company can conduct a thoughtful root.” It asks: What is the company’s root cause analysis of the misconduct at issue? Were any systemic issues identified? Who in the company was involved in making the analysis?

Root-cause analysis helps the company distinguish symptoms from causes, and that distinction should determine remediation. A response directed only at the visible misconduct may create the appearance of action without materially reducing the underlying risk.

This is also why significant investigations should test assumptions about the compliance program. If an intermediary engages in misconduct despite passing third-party due diligence, the company should examine whether the process missed information it reasonably could have identified. If an employee disguises improper payments, Compliance and Finance should understand how the relevant financial controls were circumvented. If retaliation occurs after an employee raises a concern, the organization should determine whether its anti-retaliation controls function in practice.

A well-designed compliance program can still experience misconduct. No reasonable system eliminates all risk. Effectiveness is measured by how the organization detects misconduct, responds, learns from failures, and strengthens the program when it identifies weaknesses.

Follow the Decision Trail

Investigators naturally follow evidence by reviewing documents, interviewing witnesses, analyzing transactions, and reconstructing events. Compliance investigations should also follow the decision trail because misconduct frequently passes through business processes designed to create accountability.

The investigation should identify who selected and approved a problematic third party, who authorized exceptions or unusual compensation, who approved payments, who received warnings, and who decided whether concerns warranted escalation. This becomes especially important when misconduct involves senior personnel, high performers, or commercially significant relationships.

The purpose is not to assign blame indiscriminately across every function connected to an incident. It is to understand where accountability actually resided and whether the people responsible for operating or supervising controls fulfilled those responsibilities.

A decision trail can reveal that misconduct was not simply the act of one individual. Other employees may have facilitated the conduct, ignored warning signs, approved questionable transactions, or failed to escalate information. Conversely, the evidence may demonstrate that established controls operated appropriately and that the individual deliberately circumvented them.

Organizational Justice Requires Consistency

Investigations also play a central role in corporate culture. Employees watch how organizations respond to allegations, particularly when cases involve senior executives or high-performing employees. They notice whether powerful people receive different treatment and whether employees who raise concerns suffer professional consequences. This makes consistency an important component of organizational justice, which the ECCP identifies as a part of every compliance program.

Consistency does not require identical outcomes. Facts, intent, responsibilities, prior conduct, cooperation, supervisory duties, and other legitimate considerations can justify different consequences. What matters is that the organization uses a credible process and applies its standards without creating privileged classes of employees.

Investigation governance is therefore important. The company should establish clear decision rights concerning whether allegations require investigation, who determines scope, who approves closure, how disciplinary decisions are made, when conflicts of interest require independent handling, and when matters involving senior executives should be escalated to the Audit Committee or board. These governance arrangements should be in place before a sensitive case arises.

Accountability should also extend beyond the individual who directly engaged in misconduct. Management behavior matters. A supervisor who ignored repeated warning signs, encouraged excessive risk-taking, approved unjustified exceptions, or created incentives that contributed to misconduct may raise separate accountability issues.

If employees see junior personnel disciplined while supervisors face no consequences for meaningful oversight failures, the company may signal that accountability flows only downward. Credible organizational justice requires a more consistent approach.

Investigation Data Is Enterprise Risk Intelligence

Individual investigations explain specific events. Aggregated investigation data can reveal enterprise-wide patterns, making it an important compliance asset. A CCO must understand which allegations recur, whether particular business units or managers appear repeatedly, where investigations are delayed, what root causes occur most often, whether similar control failures appear across jurisdictions, and whether employees who raise concerns subsequently experience unusual turnover or other adverse outcomes.

Those patterns can identify emerging risks that individual case files may not reveal. The data must be interpreted carefully. A business unit with a high number of hotline reports may have significant cultural problems, or it may have a healthy speak-up environment in which employees trust the reporting system. A location with few reports may have an excellent culture, or employees may fear retaliation.

Investigation data works best when combined with other information, including hotline trends, employee surveys, HR data, audit findings, transaction monitoring, exit interviews, and business knowledge. The objective is not simply to count cases but to use investigative information to understand the organization more effectively. This is the Leonardo approach in practice: observation combined with inquiry.

AI Changes the Investigation Function

Artificial intelligence is also changing corporate investigations. AI tools may assist with document review, chronology development, translation, pattern identification, data analysis, and summarization. Used appropriately, these capabilities may allow investigation teams to analyze larger volumes of information and identify relationships more efficiently.

They also create significant governance issues because investigations frequently involve some of the company’s most sensitive information. Before using AI, the organization should understand what data it will provide to the system, whether the material includes privileged, confidential, personal, or commercially sensitive information, where the data will be processed and retained, and what contractual and technical protections apply. Once again, the ECCP puts this onus on your compliance function.

Reliability is equally important. Investigators need a process to validate AI-assisted analysis and identify inaccurate or unsupported outputs. AI use should not obscure how a significant investigative conclusion was reached or prevent the company from explaining the evidence supporting its decision.

Human accountability should remain clear. AI can assist investigators, but it should not replace professional judgment concerning scope, credibility, findings, discipline, or remediation. The broader governance principles reflected in the NIST AI Risk Management Framework and ISO/IEC 42001 can help organizations think about risk management, human oversight, documentation, and monitoring. Still, the fundamental investigation requirements remain confidentiality, accuracy, fairness, privilege, and defensibility.

Connect Investigations to Remediation and Lessons Learned

Companies sometimes separate investigations and remediation too sharply. Legitimate reasons exist to maintain appropriate independence between fact-finding and certain management decisions, but the compliance program still needs a clear mechanism to convert investigative findings into corrective action.

For significant matters, management should understand what failed, why it failed, whether the weakness could exist elsewhere, what corrective action is required, who owns that action, and how the company will determine whether remediation worked. This turns an investigation from a historical examination into a forward-looking compliance tool. Without that connection, an organization can become highly proficient at investigating the same problem repeatedly without becoming better at preventing it.

Lessons learned should also travel beyond the specific business unit or jurisdiction involved. If an investigation in one market identifies improper distributor discounts caused partly by weak approval controls, the company should consider whether comparable controls exist elsewhere. If employees use personal messaging applications to circumvent company systems, management should assess whether the practice extends beyond the employees involved in the investigation. If an AI incident reveals that employees can deploy unapproved tools without effective technical restrictions, the organization should consider the broader governance implications.

This does not require distributing confidential investigative details throughout the company. It means converting case-specific findings into enterprise risk intelligence. Depending on the issue, the lesson may lead to changes in controls, risk assessments, monitoring, training, policies, management communications, or incentive structures. That is how Investigate feeds Refine.

What the Board Should Understand About Investigations

Boards and Audit Committees should resist evaluating the investigation function primarily through case counts. Knowing how many matters were opened and closed provides useful operational information, but it offers limited insight into program effectiveness.

Directors should understand what the company is learning from investigations. Significant themes, recurring root causes, internal control weaknesses, unusual patterns across business units, retaliation concerns, and the status and effectiveness of remediation all provide more meaningful information about compliance risk.

The board should also understand whether investigative resources match the company’s risk profile. Significant cases should not remain unresolved because the organization lacks appropriate staffing, cross-border expertise, data capabilities, employment-law support, or access to information. Matters involving senior personnel should be handled through processes designed to preserve independence and avoid conflicts.

The board does not need to manage individual investigations. Its role is to understand whether the investigation system provides reliable information about significant compliance risks and whether management responds appropriately to what that system reveals.

Getting Beneath the Surface

Leonardo’s anatomical studies give compliance professionals a useful model for investigations because the visible event may be only the first indication of a larger systemic issue. An improper payment may reveal a third-party weakness that exposes deficiencies in due diligence, technology, ownership, incentives, or management oversight.

The investigator’s task is to understand those connections without allowing every matter to become an unlimited enterprise-wide inquiry. Scope should remain proportionate to the seriousness, complexity, and potential reach of the issue. The objective is disciplined curiosity: understanding whether the evidence points to an isolated act or a broader weakness in the compliance system.

For the CCO, the practical lesson is that investigations should do more than establish whether a rule was violated. Significant matters should help the organization understand the controls, incentives, management decisions, and business conditions that contributed to the conduct. Root-cause analysis should drive remediation, investigation findings should test assumptions about program effectiveness, aggregated case data should inform enterprise risk assessment, and lessons learned should improve controls beyond the immediate matter.

That is Investigate, the second principle of the Leonardo Compliance Framework. Finding misconduct matters, but the greater compliance value comes from understanding the system that produced it and using that knowledge to reduce the likelihood of recurrence.

From Investigation to Innovation

Investigation helps the compliance professional understand how existing systems work and why they sometimes fail. Leonardo, however, was equally interested in systems that did not yet exist, which takes us to the third principle in the Leonardo Compliance Framework: Innovate.

In Blog Post Three, Leonardo’s Flying Machines and AI Governance, we will use Leonardo’s studies of flight to examine responsible innovation in 2026. Artificial intelligence and increasingly agentic technologies are moving from generating information to taking action within business processes, raising new questions about risk classification, human accountability, third-party AI, data governance, testing, monitoring, NIST AI RMF, and ISO/IEC 42001.

Leonardo’s willingness to imagine flight provides the innovation lesson. For the modern CCO, the corresponding governance task is ensuring the enterprise understands the risks, controls, and accountability needed before giving new technology meaningful authority inside the business.

Categories
Daily Compliance News

Daily Compliance News: September 21, 2026, The Aguilar Sentenced Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Former Vitol trader Javier Aguilar sentenced to 4 years. (Bloomberg)
  • Russia seizes control of Nestle operations. (WSJ)
  • The Class ceiling in America. (NYT)
  • SEC rollback puts audit fees at risk. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
AI Today in 5

AI Today in 5: September 21, 2026, The AI Czar Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. The business case for responsible AI. (WBCSD)
  2. Medical AI and its proof problem. (FT)
  3. AI recordkeeping hurdles for financial services firms. (ACA)
  4. Can financial services overcome barriers to AI adoption?  (FinTechGlobal)
  5. Trump wants to create an AI Czar. (WSJ)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
FCPA Compliance Report

FCPA Compliance Report: Natural Disaster Expo Houston: Preparedness, Resilience, and Business-to-Government Networking

In this episode, Tom Fox welcomes Jack Moss, CEO & Board Member at Fortem International, to discuss the Natural Disaster Expo series and the upcoming Houston event (October 14–15). Moss explains the expo evolved from a UK Flood Expo launched about 10 years ago and expanded in the U.S. after interest from major agencies and stakeholders, including FEMA, Homeland Security, NASA, and NOAA, first in Miami and later California, then Houston as disasters increased in Texas. The conference brings together government entities, municipalities, first responders, private industry, risk and compliance professionals, reconstruction and construction providers, and funding-related participants to source products and services and learn how to predict, prevent, and manage disasters. Listeners can get a free pass to the event by using the link and code below.

Key highlights:

  • From UK to US
  • Why Disaster Expo
  • Expanding Across States
  • Preparing for Disasters

Resources:

Natural Disaster Expo

Click for Free Pass

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

Da Vinci Week: Part 1 – The Mona Lisa and Continuous Improvement

I recently wrote a five-part blog series on compliance through Michelangelo’s lens. In our Michelangelo Compliance Framework, we used five extraordinary projects to explore five disciplines of the modern compliance function: Challenge, Execute, Defend, Build, and Govern. Michelangelo gave us a model of the compliance professional as a builder. His work showed the importance of structure, execution, resilience, accountability, and the ability to turn an ambitious vision into something enduring.

This week, I want to do the same through the lens of Leonardo da Vinci, who gives us a different model. Leonardo was an observer, investigator, experimenter, engineer, anatomist, artist, and relentless student of how things worked. Where Michelangelo offers lessons about building, Leonardo offers lessons about learning. That distinction underpins our five-part Leonardo Compliance Framework: Refine, Investigate, Innovate, Monitor, and Document. In this blog post 1, we begin with Refine and Leonardo’s most famous painting, the Mona Lisa.

The compliance lesson is continuous improvement. An effective compliance program is never truly finished because the business it supports is never truly static. Markets change. Employees change. Third parties change. Regulations change. Technology changes. Criminal methodologies change. Artificial intelligence is accelerating many of those changes simultaneously. For the Chief Compliance Officer (CCO) or compliance professional in 2026, the question is therefore not simply whether the company has a compliance program. The better question is whether the program is materially better today because of what the organization learned yesterday.

The Compliance Program Is Never Finished

One fascinating aspect of the Mona Lisa is Leonardo’s extended relationship with the work. He kept refining it as he developed his understanding of light, anatomy, optics, and human perception. That provides a useful metaphor for compliance because companies often approach compliance initiatives through the language of completion. Policies are issued, training is delivered, third-party systems are implemented, investigations are closed, remediation projects are completed, and risk assessments are presented to the board.

A policy issued three years ago may no longer address how the business operates. A successful third-party implementation may not account for changes in the company’s distribution model. A 100 percent training completion rate does not demonstrate that employees can apply the training when confronting an ethical problem. Closing a remediation item does not establish that the revised control reduced the underlying risk.

Leonardo offers a different approach. Completion should create an opportunity for observation and learning. Management should understand what worked, what did not work as expected, what changed in the business, and whether those lessons justify refinement of the program. That is continuous improvement.

Turn Compliance Failures Into Organizational Knowledge

The DOJ has made clear in the most recent iteration of the Evaluation of Corporate Compliance Programs (ECCP) that continuous improvement sits at the heart of modern expectations for compliance program effectiveness. A risk-based program should evolve as the company’s risks evolve, using risk assessments, investigations, audits, monitoring, employee feedback, transaction data, and lessons learned to inform changes. A company that identifies the same weakness year after year without changing its response has not created an effective learning system.

Leonardo’s approach to understanding the natural world was to look beneath the visible surface. Compliance professionals should apply the same discipline. Misconduct often signals a deeper weakness in the system, and root-cause analysis helps identify it and use the lesson to improve the program.

Risk Assessment Should Produce Management Action

The compliance risk assessment provides another important opportunity for refinement. Companies frequently devote substantial resources to identifying and ranking risks, producing a heat map, presenting the findings to management and the board, and repeating the process the following year.

Here the ECCP asks, “Is the risk assessment current and subject to periodic review?” Is the periodic review limited to a “snapshot” in time or based upon continuous access to operational data and information across functions? Has the periodic review led to updates in policies, procedures, and controls? Do these updates account for risks discovered through misconduct or other compliance program issues?

The principle applies to artificial intelligence. If AI adoption changes the company’s risk profile, the risk assessment should lead to governance action through measures such as an AI inventory, risk classification, approval processes, human oversight, monitoring, or technical controls.

A mature compliance program should be able to draw a line from an identified risk to a management decision. If the risk profile changes while resources, controls, monitoring, and governance remain unchanged, the risk assessment has generated information without generating action.

Use Data to Refine the Program

Leonardo was a relentless observer who recorded what he saw and used those observations to develop new ideas. Modern compliance functions possess an advantage he could scarcely have imagined: enormous quantities of organizational data.

Hotline information can reveal cultural patterns. Investigation data can identify recurring allegations and root causes. HR data may indicate retaliation. Transaction information can identify unusual payments. Third-party data can reveal concentrations of risk, while audit findings can identify recurring control weaknesses.

But these insights are not enough. Are these insights put into practice? The ECCP inquires: Does the company have a process for tracking and incorporating into its periodic risk assessment lessons learned either from the company’s own prior issues or from those of other companies operating in the same industry and/or geographical region?

Compliance analytics should not become a competition to create the most sophisticated dashboard. The objective is better decision-making. A business unit with very few hotline reports, for example, could have an excellent culture or an environment in which employees are reluctant to speak. The number alone does not tell the whole story.

Compliance should therefore combine quantitative information with qualitative evidence, including employee surveys, focus groups, exit interviews, investigations, management discussions, and audit findings. The objective is to understand what the data mean in the business context.

AI Accelerates the Need for Refinement

Artificial intelligence makes continuous improvement increasingly important because AI systems and their uses can change faster than traditional corporate governance cycles.

The ECCP asks companies to consider how emerging technologies such as AI affect their ability to comply with criminal laws, how related risks are incorporated into enterprise risk management, and how organizations mitigate unintended consequences and potential misuse. The ECCP asks some pointed questions: How does the company assess the potential impact of new technologies, such as artificial intelligence (AI), on its ability to comply with criminal laws? Is management of risks related to the use of AI and other new technologies integrated into broader enterprise risk management (ERM) strategies? What is the company’s governance approach to using new technologies such as AI in its commercial business and compliance program? The implication for the CCO is significant: AI risk cannot be treated as a once-a-year compliance exercise.

NIST’s AI Risk Management Framework and ISO/IEC 42001 provide useful approaches to this challenge because both emphasize governance and ongoing risk management. For the CCO, the broader lesson is that AI governance should operate as a management system rather than a policy-writing project. The organization needs to learn from incidents, testing, employee behavior, technological changes, and evolving business use, then adjust governance accordingly. The principle is the same as the Mona Lisa: refinement should follow learning.

Move the Board Conversation From Activity to Learning

Boards and Audit Committees can reinforce this discipline by shifting the compliance conversation. Compliance presentations frequently focus on activity metrics: employees trained, investigations closed, third parties reviewed, policies updated, and remediation items completed. These measures provide useful information about program operations, but they do not necessarily demonstrate effectiveness.

Directors should also understand what the organization learned during the reporting period, what investigations revealed about controls, what monitoring identified that management did not previously know, how the risk profile changed, and what the compliance function changed as a result.

The board should also understand whether those changes worked. This moves oversight from compliance activity to compliance effectiveness. It allows the CCO to present Compliance not simply as a collection of programs and controls but as a management system that identifies risk, learns from experience, and improves organizational decision-making.

The Mona Lisa Principle: Disciplined Refinement

Leonardo’s Mona Lisa gives the modern compliance professional a straightforward lesson about continuous improvement. An effective compliance program should develop through observation, evidence, learning, and a willingness to reconsider earlier decisions when circumstances justify change. The objective is not perpetual revision. It is disciplined refinement.

That distinction matters because continuous improvement can become counterproductive if it produces continuous disruption. Employees need stability, controls need sufficient time to operate, and management needs enough information to distinguish a meaningful trend from temporary noise. A compliance function that repeatedly changes policies, procedures, training, and controls without a clear risk-based rationale can create confusion rather than effectiveness.

Program refinement should therefore follow evidence. An investigation may reveal a systemic control weakness. Employee feedback may demonstrate that a policy is difficult to understand or apply. Monitoring may show that a control generates excessive false positives or is routinely circumvented. A regulatory development may require a different process, while an acquisition, new market, or technological change may materially alter the company’s risk profile. Artificial intelligence may introduce capabilities and risks that did not exist when the original governance structure was designed.

The CCO should have a disciplined process for converting those developments into program changes. Management should understand what triggered the proposed change, what risk it addresses, who owns implementation, and how the organization will determine whether the change produced the intended result. In this sense, continuous improvement should itself be governed.

A mature CCO should also be able to explain why today’s compliance program differs from the one the company operated two or three years ago. The answer should not simply be that policies were updated or new technology was purchased. The program should have changed because the organization learned something about its risks, controls, employees, third parties, culture, or business model and acted on that knowledge.

That is the central lesson of Refine, the first principle of the Leonardo Compliance Framework. Completion should not be confused with effectiveness. Root-cause analysis should produce program improvement, risk assessments should lead to management action, and data should help the organization understand what is happening rather than simply populate dashboards. When the evidence demonstrates that change is necessary, the organization should refine the program and then determine whether the refinement worked.

Leonardo models the compliance professional as a student of the organization. The CCO observes how the business operates, learns from failures and successes, and uses that knowledge to improve the compliance system. The measure of continuous improvement, therefore, is not how often the program changes. It is whether the program becomes more effective because the organization has learned.

From Refinement to Investigation

Continuous improvement depends upon understanding why problems occur. A company cannot meaningfully refine its compliance program if it treats each incident as an isolated act of employee misconduct. It must examine the systems, incentives, controls, management decisions, and behaviors that produced the outcome. That takes us to the second Leonardo principle: Investigate.

In Blog Post Two, we will consider Leonardo’s Anatomical Studies and will use Leonardo’s study of the human body as a framework for corporate investigations. Just as Leonardo looked beneath the surface to understand how interconnected systems functioned, modern compliance investigations should move beyond identifying misconduct to understanding its causes. We will examine how root-cause analysis connects investigations to remediation, why organizational justice matters, how investigation data can reveal systemic weaknesses, and what boards should understand when management reports that an investigation has been closed.

Categories
Sunday Book Review

Sunday Book Review: September 20, 2026, The New Books On Corporate Culture Edition

In the Sunday Book Review, Tom Fox considers books that would interest compliance professionals, business executives, or anyone curious about the subject. It could be books about business, compliance, history, leadership, current events, or any other topic that might interest Tom. In this episode, we look at 4 new books on corporate culture that have been released or will be released in the fall of 2026.

  1. Friction by Maggie Sass and Ross Blankenship
  2. The Corporate Artist by Morgan Sage Norman
  3. Work Shouldn’t Hurt by Dr. Lori Campbell
  4. Simple Rules, Extraordinary Results by Addison Killeen

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.