Categories
Compliance Tip of the Day

Compliance Tip of the Day – M&A-Pre-Acquisition: Reviewing Financial and Operational Data

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice for navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

We continue our look at the role of compliance in the pre-acquisition phase of a merger and acquisition. Today, we consider how to look for red flags in financial and operational data.

For more on this topic, check out The Compliance Handbook: A Guide to Operationalizing your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
AI Today in 5

AI Today in 5: December 4, 2025, The Microsoft Blips Edition

Welcome to AI Today in 5, the newest edition of the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Does AI portend the end of the law/consulting firm pyramid? (FT)
  2. Strengthening AI strategies with proactive compliance. (WSJ)
  3. Microsoft stock dips on the news. (CNBC)
  4. Salesforce touts AI adoption. (Bloomberg)
  5. Strong AI governance can foster innovation. (Bloomberg)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

Categories
Everything Compliance

Everything Compliance: Episode 162, The Numbers, Numbers, Numbers Edition

Welcome to this Edition of award-winning Everything Compliance. In this episode, we have the quartet of Matt Kelly, Jonathan Marks, and special guests Lisa Fine and Dr. Hemma Lomax with Tom Fox, the Compliance Evangelist, as host.

1. Matt Kelly looks at the recent Millicom Cellular FCPA enforcement action.  He shouts out to the ChatGPT em-dash and rants about the federal government’s attempts to ban all state regulation of AI.  

2. Jonathan Marks reviews the failures of internal controls in the NBA and MLB around the ongoing betting scandals. He shouts out MacKenzie Scott for her $70 million donation to Historically Black Colleges and Universities (HBCUs) in 2025, continuing her support after a $560 million donation to 27 HBCUs in 2020. 

3. Special Guest Panelist Dr. Hemma Lomax considers where Agentic AI in compliance is heading. She rants about ChatGPT em dashes and shouts out recent legal tech conferences.  

4. Special Guest Panelist Lisa Fine looks at three key issues on her mind about compliance for 2026. She shouts out to the Compliance Week survey, Inside the Mind of the CCO, and encourages all listeners to participate.  

5. Tom Fox shouts out to Gen Z and their play with the numbers 6 and 7 and traces the use of numerology in texts back to the Book of Genesis and the ancient text of Gilgamesh.  

The members of Everything Compliance are:

The host, producer, and sometimes panelist of Everything Compliance is Tom Fox, the Voice of Compliance. He can be reached at tfox@tfoxlaw.com.  The award-winning Everything Compliance is a part of the Compliance Podcast Network.

Categories
Daily Compliance News

Daily Compliance News: December 4, 2025, The End of the Pyramid Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Does AI portend the end of the law/consulting firm pyramid? (FT)
  • SF sues over ultra-processed food. (WSJ)
  • Will a Civility Oath make lawyers more civil? (Reuters)
  • What is the environmental cost of corruption? (BBC)

The Daily Compliance News has been honored as No. 2 in the Best Regulatory Compliance Podcasts category.

Categories
Blog

Millicom Cellular, Part 2: Lessons Learned on Cartels, Cash, and Control Failures

The Millicom Cellular FCPA enforcement action is not just another FCPA case. It is a case that signals a new frontier for compliance risk. It blends classic corrupt-payment schemes with organized crime, narcotrafficking proceeds, obstructed governance, and aggressive legislative capture. It is a wake-up call for compliance officers that the threat landscape is expanding in ways that require deeper operational controls, broader due diligence frameworks, and more sophisticated cross-functional collaboration.

In Part 1, we considered the underlying facts and FCPA violations of this matter. In Part 2, we examine what compliance professionals must take away from the case.

Lesson 1: Joint-Venture Governance Failures Are Not a Defense

Millicom Cellular held a 55 percent ownership stake in TIGO Guatemala, but the local partner exercised operational control and blocked Millicom Cellular from information and cooperation. The DOJ notes that Millicom Cellular voluntarily disclosed early concerns in 2015 but was unable to compel cooperation from local executives or obtain complete data. The result is a clear message:

Ownership without operational control equals enormous FCPA exposure.

Compliance professionals must:

  • Implement JV governance protocols that require access rights, audit rights, and cooperation language in shareholder agreements. Try to place your company’s representative as the CFO of the joint venture.
  • Establish escalation pathways if a partner obstructs investigations.
  • Treat “majority ownership without control” as a high-risk structure in compliance risk assessments.

Yet notwithstanding the foregoing, DOJ has made clear it will not accept a lack of control as an excuse for failing to detect corruption, especially when red flags are visible.

Lesson 2: Cash-Based Bribery Ecosystems Require a Different Kind of Monitoring

The bribery scheme ran almost entirely on cash: cash in duffel bags delivered by helicopter, cash laundered through drug traffickers, cash moved through shell companies, and cash withdrawn from banks in plastic bags. Traditional financial controls are almost useless in the face of an off-books cash economy. Compliance must be enhanced:

  • Controls around cash withdrawals
  • Monitoring of cash-intensive vendors
  • Patterns of invoicing irregularities
  • Real-time analytics on deviations in expense and procurement behavior

This is not a theoretical exercise. It is an operational reality for companies in high-risk jurisdictions.

Lesson 3: Cartel Exposure Is Emerging as a Corporate Compliance Obligation

This case represents one of the most explicit linkages between FCPA violations and narco-trafficking cash flows. The scheme not only involved bribes; it also involved bribes financed by organized crime. Compliance officers must now assume that criminal networks may view legitimate multinationals as conduits for illicit financial flows. This demands:

  • Enhanced beneficial-ownership checks
  • Screening for cartel-linked financial intermediaries
  • Deeper diligence on bankers, lawyers, and consultants
  • Country-level threat mapping that includes cartel and organized crime indicators

The DOJ has increasingly emphasized convergence risk between corruption, money laundering, and organized crime. The Millicom Cellular enforcement action is a prime example.

Lesson 4: “Influencing Legislation” Is a Red Flag, Not a Business Strategy

TIGO Guatemala sought legislative outcomes that would alter the national telecom law. That in itself is not illegal. What is unlawful is tying legislative outcomes to cash bribes, helicopter deliveries, and cartel-funded transactions. Compliance teams must scrutinize:

  • Payments to lobbyists, political consultants, and intermediaries
  • Relationships with legislators and political parties
  • Sponsorships, charitable donations, and community programs with political beneficiaries

Any effort to “shape legislation” must come with strict controls.

Lesson 5: Data Gaps Are Compliance Gaps

Millicom’s inability to obtain information access within its own joint venture delayed detection and undermined the credibility of its initial self-disclosure. Compliance professionals must demand:

  • Rights to data
  • Rights to conduct investigations
  • Rights to interview employees
  • The right to require cooperation from partners

A partner who denies access creates liability.

Lesson 6: Remediation Must Be Conducted Like a Corporate Transformation

Millicom’s remediation was extensive. It included:

  • Replacing senior personnel
  • Centralizing compliance oversight
  • Enhancing third-party onboarding and continuous monitoring
  • Adding data analytics
  • Conducting control testing across more than 250 transactions
  • Creating an ephemeral-messaging retention policy
  • Increasing compliance headcount by 800 percent (pages 5–6)

The DOJ’s description reads less like remediation and more like organizational reinvention. That is the expectation now. Compliance must treat remediation as a fully integrated operational overhaul.

Lesson 7: The DOJ Will Reopen Cases When New Evidence Emerges

The DOJ initially closed the investigation in 2018. It reopened the case in 2020 after uncovering new evidence from outside sources, including cartel-linked transactions. The message is clear:

  • Self-disclosure is not a shield when the company lacks visibility into misconduct.
  • Failure to detect ongoing wrongdoing can undermine trust and credit for cooperation.
  • Compliance must ensure continuous monitoring even after perceived risk has been reduced.

Conclusion: The New Compliance Mandate

The Millicom Cellular enforcement action demonstrates that compliance risk is no longer confined to corrupt payments. It now involves organized crime, cash-based bribery systems, cross-border laundering, political capture, and governance obstructions. Compliance professionals must operate with a broader risk lens, encompassing cartel risk, cash-economy vulnerabilities, high-risk political interactions, and joint-venture control structures. This is a key enforcement effort of the Trump Administration.

The future of compliance is not about preventing bribery alone. It is about defending the corporation from becoming an unwitting partner in a criminal enterprise.

Categories
The Hill Country Podcast

The Hill Country Podcast – Lorena Guillen on the July 4th Flood: Part 1 – The Flood

Welcome to the award-winning The Hill Country Podcast. The Texas Hill Country is one of the most beautiful places on earth. In this podcast, Hill Country resident Tom Fox visits with the people and organizations that make this one of the most unique areas of Texas. Today, I begin a two-part series with Lorena Guillen, owner of Howdy’s Restaurant and Blue Oak RV Park. The July 4th flood completely inundated her RV Park. In Part 1, Guillen discusses the events of the morning of July 4. In Part 2, she will discuss the events of that tragedy through today.

She begins with the beauty of July 3rd and goes to bed early on July 4. Guillen relates being awakened by flashing lights of a swift water rescue team, putting into the river. She recounts the devastating flood event where a second wave of water caused severe damage and displacement. She describes the rapid onset of the flood, the destruction of RVs, and the harrowing survival of her husband, who was swept 30-45 feet down a river but managed to climb to safety. She relates the surreal sensation of feeling electricity in the water and the loss of animals they were trying to rescue. The fire department eventually evacuated everyone from a nearby restaurant as the water levels continued to rise.

Other Hill Country Focused Podcasts

Hill Country Authors Podcast

Hill Country Artists Podcast

Texas Hill Country Podcast Network

Cover Art

Nancy Huffman

Categories
Great Women in Compliance

Great Women in Compliance – GWIC Joins Everything Compliance

Today, we have a special joint episode of GWIC and Everything Compliance. Lisa Fine and Hemma Lomax recently joined Matt Kelly and Jonathan Marks for an episode of Everything Compliance (Episode 162—the Numbers Numbers Numbers edition), which will post on Thursday, December 4. We are cross-posting the episode here on Great Women in Compliance.

Lisa Fine, Hemma Lomax, Matt Kelly, and Jonathan Marks each bring a unique perspective to the discussion of corporate corruption and the intersection with drug cartels, as exemplified by the Millicom Cellular case. Lisa highlights the need to understand the risks associated with smaller markets and the complexities of joint ventures, advocating for enhanced compliance education and vigilance to mitigate cartel-related corruption. Hemma underscores the importance of integrating proactive compliance measures and automation, promoting “everyday integrity as a service” to preempt issues like bribery and data leakage. Meanwhile, Matt and Jonathan focus on the structural vulnerabilities in governance and the critical need for transparency and robust monitoring systems to prevent the entanglement of corporate operations with cartel activities, cautioning against underestimating the risks in seemingly low-revenue markets.

 Highlights include:

  • Millicom Cellular: Corporate Corruption and Cartel Connections
  • Enhancing Compliance through Systematic Involvement Strategies”
  • AI-Driven Real-Time Risk Detection in Compliance
  • Enhancing Governance to Prevent Sports Betting Scandals
  • Regulatory Changes in the Global Compliance Environment
  • AI-Enhanced Policy Clarity and Management Techniques
  • Raves and Rants
Categories
Compliance Tip of the Day

Compliance Tip of the Day – M&A-Pre-Acquisition: Evaluating Compliance Program and Culture

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice for navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

We continue our look at the role of compliance in the pre-acquisition phase of a merger and acquisition. Today, we consider why and how to evaluate a target’s program and culture.

For more on this topic, check out The Compliance Handbook: A Guide to Operationalizing your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
AI Today in 5

AI Today in 5: December 3, 2025, The Code Red Edition

Welcome to AI Today in 5, the newest edition of the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. OpenAI declares Code Red. (WSJ)
  2. How compliance can drive AI innovation. (AboveTheLaw)
  3. How Amazon is embracing the AI chaos. (Bloomberg)
  4. AI and the economic singularity. (FT)
  5. Major banks are incorporating AI into their operations. (FinTechMagazine)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Understanding SFO Guidance and Compliance Program Assessments

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recently released Serious Fraud Office (SFO) guidance on compliance programs.

Tom and Matt highlight the SFO’s lack of specific directives and contrast them with more detailed guidance from the United States. The conversation focuses on the ambiguity organizations face in understanding what the SFO looks for in assessing compliance programs and underscores the need for a more holistic, tailored approach to individual circumstances.

Key highlights:

  • Introduction to SFO Guidance
  • Comparing SFO Guidance with US Standards
  • Uncertainty in SFO’s Expectations
  • Holistic Assessment by SFO

Resources:

Matt in Radical Compliance

Tom in the FCPA Compliance and Ethics Blog

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, a Communicator Award, and a W3 Award, all for podcast excellence.