Categories
AI Today in 5

AI Today in 5: August 27, 2026, The Identity Problem Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Four places AI cuts paperwork in food compliance. (HealthcareITNews)
  2. New Anthropic models struggling. (FT)
  3. Colorado’s AI proposed law raises compliance concerns. (Housing Wire)
  4. Compliance controls for AI meeting notes. (Yahoo!Finance)
  5. The identity problem. (FinTechGlobal)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Hill Country Authors

Hill Country Authors Podcast: Local Authors Only: Strategies for Community Retailing with J. E. Warr

Welcome to a new season of the award-winning Hill Country Authors Podcast, sponsored by Stoney Creek Publishing. In this podcast, Hill Country resident Tom Fox visits with authors who live in and write about the Texas Hill Country. Today, Tom welcomes Author and President of Local Authors Only, J. E. Warr.

Warr talks about helping writers overcome publishing gatekeepers and the “non-writing” work of selling books and describes his own obstacles (agents, editing costs, limited marketing) and argues publishers mainly distribute rather than market. Local Authors Only places local-author books in high-traffic, non-interruption settings—kiosks in grocery stores and locations like Lowe’s, plus coffee shops, waiting rooms, and author signings—to drive impulse discovery and community loyalty, while using QR codes that link buyers to Amazon or other seller pages without taking royalties. He encourages writers to start “bird by bird,” avoid premature self-criticism, use AI tools to correct mechanics ethically, and leverage audiobooks as a growing channel, including voice-cloning options and direct-to-consumer sales that capture audience data. He outlines membership pricing and provides contact details and web/social links.

Key highlights:

  • Why Local Authors Only Exists
  • Selling Books Without Gatekeepers
  • From Draft to Published
  • Audiobooks Are the Future
  • Membership and Author Support

Resources:

J.E. Warr on LinkedIn

Local Authors Only

Podcast Cover Art

Nancy Huffman Fine Art

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Everything Compliance

⁠Everything Compliance: The AI, Investigations, Kickbacks and Kids Edition⁠

Welcome to a revamped Everything Compliance. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, who joins returning regulars Jonathan Armstrong and Karen Moore for the next iteration of Everything Compliance. Matt is on assignment this week. This episode features a cross-Atlantic discussion on emerging compliance issues. Fan favs, Shout Outs, and Rants end this week’s episode.

  • Karen Moore analyzes the DOJ’s $46M Veloxis Pharmaceuticals resolution, focusing on Sunshine Act misreporting caused by falsified expense data and the need to test controls for circumvention using analytics.
  • Jonathan Armstrong warns that generative AI is driving more frequent, longer, more aggressive, and sometimes hallucinated whistleblowing and investigation communications, increasing complaints to regulators and burdening tribunals; he offers six tips, including awareness, checking for AI use, cautious AI adoption for workload, budgeting, restricting AI inputs for data protection, and improving AI literacy under the EU AI Act.
  • Rebecca Walker reviews new developments in the KPMG Australia whistleblower controversy, highlighting investigation rigor, handling persistent whistleblowers with humility and curiosity, and the costs of getting investigations wrong.

The members of Everything Compliance are:

The award-winning Everything Compliance is a part of the Compliance Podcast Network.

Categories
Daily Compliance News

Daily Compliance News: August 27, 2026, The Meta Settles Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • NBA gambling defendant has bail revoked for witness tampering. (ESPN)
  • Two individual FIFA defendants get DPA. (NYT)
  • Meta settles for $18 bn. (FT)
  • Walter’s troubles disrupting insurance company deals. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Boeing, Caremark, and the Evidence of Good-Faith Oversight

On August 13, 2026, the Delaware Court of Chancery dismissed claims arising from the January 2024 Alaska Airlines door-plug blowout. A door plug left Boeing’s factory without four securing bolts, the FAA grounded the aircraft, and investigations identified production and quality problems. Yet corporate trauma did not establish bad-faith board oversight. The question was what the directors knew, what systems delivered that information, and how the company responded. For a Chief Compliance Officer, that distinction is the heart of the case. Boeing showed what evidence of conscientious oversight can look like. The Boeing Derivative Litigation, Consol. C.A. No. 2024-1210-MTZ (Del. Ch. Aug. 13, 2026) (the “Opinion”).

This decision continues the evolution of the Caremark Doctrine and details what Boards of Directors need to consider to meet their obligations under the Caremark Doctrine. For compliance professionals, this case should be studied for not only its substantive analysis but also for how you will need to train.

Caremark Still Asks Two Hard Questions

Caremark liability is rooted in the duty of loyalty and bad faith, not negligence or a poor outcome. Directors may face liability if they fail to implement a reporting system or if they establish one but consciously fail to monitor it, preventing themselves from learning about problems that require attention. The required state of mind is an intentional dereliction of duty or conscious disregard of known responsibilities. A flawed effort is not the same as no good-faith effort.

That standard should not become a message that directors are protected unless they do nothing. Directors must demonstrate how they tried. Fiduciaries who implement and attend to a reasonable board-level reporting system meet the baseline duty. Even for mission-critical operations, “Caremark does not demand omniscience.” The Board’s task is therefore not perfect foresight. It is disciplined attention.

The Record That Protected the Board

The most useful part of the Opinion for compliance professionals is its description of Boeing’s governance machinery. The board met at least every two months, and airplane safety was discussed at every meeting. Management provided commercial-airplane updates on safety, quality, operational performance, and production targets. A Chief Aerospace Safety Officer delivered global safety updates twice each year.

Boeing also had an Aerospace Safety Committee with directors experienced in engineering, manufacturing, aerospace, aviation, or safety. It met at least 23 times from January 2022 through July 2024. Reporting included safety risk registers, in-service safety reports, Speak Up updates, and special-attention reports. Significant safety incidents or regulatory actions were to be reported to the board or committee within 24 hours or as soon as reasonably practicable. The Audit Committee separately monitored internal controls, legal compliance, the DOJ deferred prosecution agreement, and FAA obligations.

After the door plug incident, the Aerospace Safety Committee met within a day, met again twice during the following week, and arranged an onsite factory inspection. That record did not erase the operational failure. It demonstrated an active reporting and response system.

An analysis from the law firm of Sullivan & Cromwell, whose authors’ firm represented Boeing and the defendants, makes the same point: mission-critical reporting, clear committee mandates, escalation channels, and contemporaneous records can be decisive when a court examines good faith. “Delaware Court of Chancery Reinforces Limits on Oversight Liability; Stresses Importance of Conscientious Board Oversight,” Harvard Law School Forum on Corporate Governance (the “S&C Analysis”).

Train Directors to Distinguish Red from Yellow

Plaintiffs characterized dozens of reports on manufacturing and safety risks as ignored red flags. The Court rejected that theory because it threatened to convert the “volume and depth” of reporting from a best practice into evidence of disloyalty. As the defendants put it, “If everything is a red flag, then nothing is.”

Recurring adverse information is not harmless, but the board must classify and connect it. A Caremark red flag must put directors on notice that the company is violating law or headed toward specific corporate trauma. It must also connect to the misconduct that caused the loss. General operational risks under active remediation may instead show that reporting is functioning. The Court described yellow flags involving operational risk, management responses, or matters insufficiently tied to the door-plug incident.

Board training should therefore require directors to ask three questions whenever adverse information arrives: Is this a business risk or a legal compliance risk? What is management doing about it? What facts would require escalation, independent verification, or a change in strategy?

Business Judgment Has a Boundary

The Opinion also distinguished business risk from positive law. Production schedules and the management of ordinary operational risk generally receive business-judgment deference. Directors, however, have no discretion to cause the company to violate the law knowingly.

The plaintiffs argued that Boeing’s production goals favored profits over safety. The Court found no particularized allegation that the targets themselves violated the law or that directors pursued a lawbreaking strategy. The record also showed that Boeing adjusted targets, delayed production increases, and evaluated staffing, quality, supply chain, and factory-health risks. Those actions supported an inference of good-faith business judgment, not conscious disregard.

For directors, the training point is not that every production decision is insulated. The board should understand where business discretion ends, and legal obligation begins. Compliance should identify the applicable mandates, show how they enter board reporting, and specify which thresholds require action rather than monitoring.

Books and Records Are Part of the Control Environment

The plaintiffs obtained extensive books and records describing committee responsibilities, recurring reports, risk metrics, remediation, and post-incident response. The record used to challenge the directors also demonstrated their engagement.

This is not a reason to create defensive minutes. It is a reason to create accurate, decision-useful records. Minutes should capture material questions, requested follow-up, commitments, and unresolved issues. Dashboards should show trends and control effectiveness, not merely activity. Closed items should include validation. Elevate persistent issues rather than repeatedly relabeling them. As the S&C Analysis observes, contemporaneous records can be critical because the court examines what the board received, whether it signaled obvious illegality or specific trauma, and how directors and management responded.

Five Questions For Your Board

  1. Mission-critical risk. Which legal, safety, compliance, cybersecurity, or operational risks could threaten the company’s viability, customers, or license to operate? The board should identify these risks based on the company’s industry, regulatory obligations, business model, and risk profile. Directors should understand which controls address each mission-critical risk and which executives are accountable for operating them. Compliance should periodically test whether the board’s risk priorities remain aligned with changing regulations, business operations, and emerging threats.
  2. Reporting architecture. Which committee owns each risk, what information reaches it, and through which escalation channel? Committee charters should assign clear oversight responsibility and prevent material risks from falling into gaps between the board and its committees. Directors should receive decision-useful information, including trends, control failures, remediation progress, and emerging exposure, rather than raw operational data. The reporting architecture should also define when management must escalate an issue from a committee to the full board.
  3. Red-flag discipline. What criteria distinguish ordinary variance, a yellow flag requiring remediation, and a red flag requiring Board action? Management and the board should establish objective escalation thresholds based on legal exposure, customer harm, financial impact, recurrence, control failure, and the possibility of significant corporate trauma. Yellow flags should receive documented remediation plans, accountable owners, deadlines, and continuing monitoring. Red flags should trigger prompt board attention, independent inquiry where appropriate, and documented decisions about containment, investigation, disclosure, and corrective action.
  4. Response evidence. Do minutes and dashboards show questions, decisions, owners, deadlines, testing, and closure, or only that a presentation occurred? Board records should demonstrate that directors engaged with material information, challenged management assumptions, and requested appropriate follow-up. Dashboards should track remediation through completion and include evidence that corrective actions were tested for effectiveness. Minutes should accurately capture the substance of your Board’s oversight without becoming defensive narratives or sanitized accounts of difficult discussions.
  5. Speak-up integrity. Can employees raise concerns without retaliation, and does the board receive meaningful information about allegations, investigations, trends, and corrective action? Directors should understand how reports are received, triaged, investigated, escalated, and resolved across the organization. Board reporting should address substantiation rates, recurring allegations, investigation delays, retaliation claims, root causes, and remediation effectiveness. Your Board should also evaluate whether employees trust the reporting system and whether management responds consistently regardless of the seniority or business importance of the individuals involved.

Boeing continues to provide a wealth of lessons learned for compliance professionals. The Delaware Court Opinion reminds us that the Caremark Doctrine offers neither immunity nor a checklist safe harbor. It reminds boards that the Caremark Doctrine is tested through evidence of good-faith effort. Compliance must build that effort into governance before the next crisis and ensure the record shows that directors received, understood, challenged, and followed through on critical information.

Categories
Beyond the Label

Beyond the Label Podcast: Flood Recovery Resources & Emotional Support: Texans Recovering Together with Haley Salazar

Hosts Kelsi Wilmot and Tyler Townsend welcome Haley Salazar, Program Manager of the Texans Recovering Together Crisis Counseling Program (CCP) under Hill Country MHDD, to share post-flood support and resources for the community.

Haley explains how she moved from the Kerr Clinic to disaster response after the July floods and describes CCP as a non-clinical outreach team that provides emotional support and “holds space” for people in homes, schools, businesses, and community locations while also connecting them to partner agencies for practical help. They highlight key resource hubs, including the Kerr Together Disaster Relief Center (98 Coronado Dr., Kerrville, Mon–Fri 9–5) and Light on the Hill, discuss the importance of completing the i-STAT to help communities meet thresholds for assistance, and validate community frustration while emphasizing support for both directly and indirectly impacted residents. They also preview Suicide Awareness Month fundraising and tattoo-shop partnerships. Contact: 819 Water St., Mon–Fri 8–5; 830-928-9022; Emotional Support Center 830-955-1745.

Key highlights:

  • Welcome and Flood Update
  • Suicide Awareness Plans
  • Meet Haley and CCP Origins
  • What CCP Does
  • Flood Resource Hubs
  • i-STAT: Why It Matters
  • Coping With Anger
  • Community Events
  • Why Haley Does This Work

Resources: 

Hill Country MHDD

Categories
Compliance Into the Weeds

Compliance into the Weeds: AI for Compliance: Lessons from Teaching Cohorts

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss Kelly’s collaboration with Ethena to run short, paid online AI classes for compliance professionals.

Since May, there has been an excellent AI training for compliance professionals, covering vibe coding, content/video generation, and data analytics with hands-on exercises using dummy or public data. Kelly says his biggest takeaway has been how much AI education is still needed and that many compliance teams are only scratching the surface, despite fears that “everyone else” is further along. They review common tools but emphasize that success depends more on the inputs and outputs, data readiness, clear use cases, and acting on results than on which model is chosen. They also address governance, security, privacy, maintenance, technical debt, costs and token budgets, and the need to involve compliance, which often leads to AI governance. The episode ends with reflections on Dolly Parton’s leadership and a story about her retaining rights to the hit song “I Will Always Love You.”

Key highlights:

  • AI Class Overview
  • AI Skills Gap Reality Check
  • Good Enough to Start
  • AI Angst and Cost Questions
  • Why Compliance Should Lead AI Governance
  • Dolly Parton Tribute

Resources

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence. 

Categories
AI Today in 5

AI Today in 5: August 26, 2026, The 4 Places Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Four places AI cuts paperwork in food compliance. (FoodIndustryExec)
  2. AI changing communications compliance. (UC Today)
  3. AI-powered compliance monitoring. (Plan Adviser)
  4. Americas want transparency around the use of AI in healthcare. (Pew Research Center)
  5. Nvidia becoming AI’s bank. (WSJ)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: August 26, 2026, The Toothless Sanctions Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Trump issues toothless sanctions against Iran.  (WSJ)
  • SEC investigating Situation Awareness near implosion. (NYT)
  • US trial for Lockerbie bombing suspect delayed. (Reuters)
  • China looks to extend its ABC reach. (Bloomberg)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

From Gatekeeper to Navigator: Dr. Hemma Lomax on the Decision Intelligence Gap

Compliance failures are usually narrated backward. Once the outcome is known, every warning appears obvious, every missed escalation looks negligent, and every decision seems to point toward the result. The board asks who knew what and when. The investigation searches for the broken control. Management wants the person or moment that explains the failure.

Dr. Hemma Lomax has done it again, leading the discussion in the compliance community. Her most recent book, The Decision Intelligence Gap, asks compliance professionals to look earlier. What happened before the decision became visible? Which assumptions hardened into facts? When did reversal become more expensive? Who noticed something that never gained enough purchase to change the direction? The book’s central insight is that the distance between intention and execution is not space. It is an operating environment shaped by incentives, defaults, authority, silence, pressure, and the accumulated residue of earlier decisions.

That makes this an important book for CCOs, boards, in-house counsel, audit, risk, and business leaders. It is not a conventional compliance manual. It does not provide a new risk taxonomy or a checklist for program design. It offers something more foundational: a way to examine how organizational choices form while there is still time to influence them.

A Book About the Decisions Before the Decision

Lomax defines the Decision Intelligence Gap in two related ways. It is the distance between the responsibility people carry for decisions and the visibility they have into how those decisions form. It is also the space between intention and execution, where choice remains alive. The book develops that idea across five parts: how choice narrows, how decision architecture changes what remains possible, how leaders can redesign the environment, how organizations should respond when things go wrong, and how learning can scale.

The governing image is the trolley problem viewed upstream. Compliance professionals know the familiar last-minute choice between two unacceptable outcomes. Lomax is more interested in what happened before anyone reached the lever. Who laid the track? When did the brakes become unavailable? Which earlier choices reduced the available paths? This move from moral drama to decision architecture is the book’s most valuable contribution.

Several concepts give that architecture practical shape. The silent hijack occurs when a concern is heard but never alters the decision. The threshold paradox describes the point at which an option remains technically open but becomes materially more costly to exercise. Designed desperation arises when the system makes the wrong choice easier, safer, or more serviceable than the right one. Defaults then carry yesterday’s decisions forward until repetition begins to look like legitimacy. None of these concepts removes individual agency. They show why accountability must examine both the actor and the conditions the organization created.

Why Compliance Leaders Should Read It

The book challenges the compliance function’s instinct to become the gatekeeper for every uncertain choice. Lomax does not argue against approvals, bright lines, or specialist authority. Some risks require them. Her sharper point is that a program can become excellent at routing questions to experts while failing to build decision capacity in the business. The CCO answers the immediate question, but the next employee facing similar terrain remains dependent on the same escalation.

Lomax proposes a navigation layer instead. Expertise should travel without automatically taking ownership of the decision. Employees need to understand the objective, the boundary being protected, the conditions that change the answer, the discretion that remains local, and the threshold for seeking another perspective. This is a powerful description of compliance as a business discipline. It moves the function from permission provider to designer of better choices while preserving hard stops where the risk requires them.

Her discussion of speak-up culture is equally strong. The important question is not only whether employees are permitted to report. It is what speaking has come to require and what happens when the room responds. A concern may be incomplete, inconvenient, or wrong. If the first response demands a finished case, the organization may force one employee to do the collective work of noticing, investigating, proving, and solving before the signal deserves attention. Lomax’s idea of being safe to learn goes beyond psychological safety. It asks whether people can contribute uncertainty, revise a position, or discover they were wrong without losing the standing to participate next time.

This insight should reshape investigations. A bad outcome does not prove poor reasoning, and a good outcome does not validate the process that produced it. Lomax’s account of outcome bias provides a disciplined basis for distinguishing accepted risk, ordinary mistake, flawed reasoning, reckless conduct, concealment, and misconduct. The compliance lesson is straightforward: reconstruct the information state at the time of the decision before hindsight rewrites what was knowable. Accountability then becomes more precise, more credible, and more useful to the next decision.

Lomax’s architecture also sharpens the familiar effectiveness question. A policy may be well designed on paper yet fail because the decision environment rewards delay, makes escalation costly, or teaches employees that exceptions are easier to approve than to revisit. Monitoring should therefore test not only control completion but also control use: who bypasses, who escalates, which questions recur, where decisions stall, and whether learning from one matter changes the next. This is where the book connects most directly to modern compliance evaluation.

The Most Useful Tool: HQDM

The book’s most immediately deployable framework is High-Quality Decision Making, or HQDM. It records five elements in proportion to the significance of the choice: the objective and what the organization is actually optimizing for; the thresholds that materially change the answer; the options genuinely available at the time; the rationale connecting facts, assumptions, uncertainty, and choice; and the learning plan, including what to monitor and what would trigger reconsideration.

For compliance professionals, HQDM offers a practical bridge between governance and evidence. It can improve a third-party exception, an AI use-case approval, an investigation disclosure decision, a market-entry choice, or a board risk-acceptance decision. It also creates a contemporaneous reasoning trace that can later help separate a defensible decision from one that merely benefited from luck. Lomax wisely cautions against turning inspectability into surveillance. The record should preserve decision-useful reasoning, not every tentative thought.

The framework also fits the board’s oversight role. A board cannot manage every operating decision. Still, it can ask whether management has identified the objective, made critical assumptions visible, established escalation thresholds, considered viable alternatives, and defined the conditions for returning to the decision. That is a better oversight record than a slide showing that the policy was approved and the training was completed.

Where the Book Requires Compliance Translation

The Decision Intelligence Gap is intentionally a thinking book, not an implementation guide. Its metaphors are memorable, its research base is broad, and its questions are often excellent. Yet compliance teams will still need to convert those ideas into governance mechanisms, owners, data, testing, and metrics. The book explains why a navigation layer matters, but it does not provide a detailed operating model for building one across a global enterprise.

The same issue appears with decision traces. The concept is sound, but the compliance application requires careful design. Records can create discovery, privilege, privacy, retention, and employee-relations consequences. A proportionate trace needs risk tiers, approved fields, access controls, retention rules, legal-hold integration, and guidance on what not to record. Otherwise, a tool intended to make reasoning visible may produce defensive writing or concealment.

AI adds another layer. Lomax correctly warns that putting a human in the loop is meaningless if the human merely approves the system’s preferred answer. A true navigation layer should expose sources, assumptions, uncertainty, alternatives, and override routes. Compliance leaders will need to add the control architecture: data governance, access management, validation, bias testing, monitoring, audit logs, incident response, and clear human accountability. NIST AI RMF and ISO/IEC 42001 can help operationalize that part of the vision.

The Verdict

This is a thoughtful, humane, and unusually relevant book for the compliance profession. Its strength lies in refusing the easy choice between individual blame and system excuse. People retain agency, but they exercise it inside conditions that can make signals harder to share, boundaries harder to hold, and reversals harder to justify. Effective compliance must examine both.

CCOs should read The Decision Intelligence Gap not as a substitute for the DOJ’s Evaluation of Corporate Compliance Programs, COSO, investigations protocols, or AI governance frameworks, but as a connective operating philosophy. It explains why policies can be clear while decisions remain poor and why speak-up programs can be available. At the same time, silence persists, and why lessons learned can be documented while organizational capability barely grows. It is especially valuable for compliance leaders ready to move from owning answers to building an organization that decides, learns, and adapts with integrity.

Questions for CCOs and Boards

Decision visibility. Which high-risk choices are becoming expensive to reverse before they reach formal approval?

Speak-up response. What does the organization do with an unfinished concern, and what does that response teach the next employee?

Accountability. Can investigations distinguish a bad outcome from poor reasoning and a mistake from misconduct without losing either fairness or rigor?

Learning loop. Where do investigation findings, exceptions, overrides, and near misses change the conditions of the next decision?

Navigation. Is compliance increasing the business’s capacity to recognize thresholds and exercise sound judgment, or merely increasing the number of questions routed to Compliance?