Categories
Innovation in Compliance

Innovation in Compliance: Scaling the RiskCloud and Agentic AI for Enterprise GRC with Diego Panama

Innovation comes in many areas, and compliance professionals need not only to be ready for it but also to embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with Diego Panama, the new CEO of LogicGate.

They discuss his career from Microsoft product management to scaling Live Ramp to an IPO, building go-to-market at Olo, and joining LogicGate through a planned CEO transition with co-founder Matt Kunkel. Panama describes his focus on scaling operations while preserving a customer-first, values-driven culture and sharpening the company’s positioning as the leading AI GRC platform for enterprise. The discussion highlights AI’s role in moving GRC from check-the-box defense to real-time, strategic enablement, including holistic risk visibility across silos, third-party risk blind spots, and always-on monitoring. Panama explains LogicGate’s workflow agents and the path toward orchestrated, autonomous GRC, with humans setting risk appetite; emphasizes data access, quality, and governance; and outlines product UX evolution from no-code to prompt-driven configuration. He notes boards’ increased attention to GRC due to AI risks and encourages students and practitioners to stay curious and aligned to business outcomes.

Key highlights:

  • Why LogicGate and GRC
  • AI Makes GRC Strategic
  • Holistic Risk and Third Parties
  • Workflow Agents Explained
  • Data Access and Governance
  • Big Tech Lessons on Focus
  • Staying Current in Tech

Resources:

LogicGate

Diego Panama on LinkedIn

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
Blog

Risk Management in Compliance: Five Lessons from Star Trek’s That Which Survives

In compliance, risk management is more than a checklist. It is the ongoing discipline of identifying threats, assessing their potential impact, and implementing measures to mitigate or neutralize them before they cause harm.

Few Star Trek episodes illustrate the escalating consequences of underestimated risks as effectively as That Which Survives. In it, the Enterprise crew encounters a seemingly lifeless planet guarded by Losira, an alien projection who can kill with a single touch. Her purpose is to protect the planet’s secrets, but her method is indiscriminate, deadly, and poorly aligned to the situation at hand.

For compliance professionals, this episode offers five important lessons on anticipating, assessing, and responding to risks, both known and unknown, within an organization.

Lesson 1: Identify Risks Before Engaging in New Ventures

Illustrated by: The Enterprise arrives at an uncharted planet, scans it briefly, and beams down a landing party. Within moments, a mysterious woman materializes and kills a crew member simply by touching him.

Compliance Lesson. Too often, companies rush into new markets, partnerships, or projects without conducting a thorough risk assessment. This can expose the organization to sanctions violations, corruption risks, cybersecurity vulnerabilities, or operational failures. Compliance should lead or be deeply involved in pre-engagement risk assessments. Before “beaming down” into a new business environment, map potential threats—regulatory, operational, reputational—and identify safeguards. Skipping this step can lead to preventable harm and costly remediation.

Lesson 2: Understand That Some Risks Are Intelligent and Adaptive

Illustrated by: Losira’s ability to appear anywhere, both on the planet and aboard the Enterprise, shows she is not a passive hazard. She targets specific individuals and adapts her approach to their vulnerabilities.

Compliance Lesson. Not all risks are static. Fraudsters change tactics, cyber threats evolve, and corrupt third parties find new ways to conceal misconduct. A compliance program must anticipate that some risks will actively seek to bypass controls. Build adaptive monitoring into your compliance systems. Use continuous transaction monitoring, real-time alerts, and data analytics to detect changes in patterns. A one-time risk assessment is not enough—ongoing vigilance is essential.

Lesson 3: Don’t Dismiss Low-Probability, High-Impact Threats

Illustrated by: At first, the crew assumes Losira’s appearances are isolated incidents, but they quickly realize she poses an existential threat. Even though she is only one individual, her capabilities could destroy the Enterprise if not addressed.

Compliance Lesson. Rare events, such as a single high-value bribery transaction, a lone rogue employee, or a targeted cyberattack, can have catastrophic consequences. Organizations sometimes underprepare for these scenarios because they seem unlikely. Compliance departments should incorporate low-probability, high-impact risks into the risk register. Conduct tabletop exercises to simulate rare but potentially devastating events, ensuring the organization has both prevention and response plans in place.

Lesson 4: Risk Mitigation Requires Cross-Functional Coordination

Illustrated by: The landing party on the planet and the Enterprise crew in orbit are each facing threats from Losira, but their survival depends on sharing information and coordinating responses. Without clear communication, both groups would be doomed.

Compliance Lesson. Compliance cannot manage risk in isolation. It must work with legal, internal audit, operations, IT, and HR to identify threats and implement controls. Silos breed blind spots, and blind spots breed crises. Establish cross-functional risk committees or working groups. Ensure that incident reporting and escalation procedures are well understood across departments. Make compliance the hub of a collaborative risk network, not a separate spoke.

Lesson 5: Address the Root Cause, Not Just the Symptoms

Illustrated by: The crew eventually discovers that Losira is an automated defense mechanism left behind by an extinct race. She’s not malicious—she’s simply executing a program without context or adaptability. Once the crew understands her origin and purpose, they can neutralize the threat.

Compliance Lesson. In risk management, addressing surface-level problems without finding the underlying cause only delays future incidents. For example, punishing an employee for violating a policy without examining why the policy was ignored leaves the organization vulnerable to repeat violations. Compliance should integrate root cause analysis into all investigations. Whether it’s a process flaw, cultural issue, or oversight gap, solving the real problem is the only way to reduce recurrence.

The Enterprise as a Risk Management Model

Captain Kirk and his crew succeed not because they are lucky, but because they adapt quickly, share intelligence, and dig deeper to understand the nature of the threat. These are precisely the attributes a corporate compliance department needs to lead risk management:

  • Proactive assessment before engagement.
  • Adaptive controls that respond to evolving risks.
  • Preparation for rare but high-impact events.
  • Collaboration across organizational functions.
  • Root cause remediation for lasting solutions.

Practical Compliance Takeaways

From That Which Survives, compliance professionals can draw these operational insights:

  1. Integrate Compliance Early—Risk management starts before contracts are signed or operations begin, not after.
  2. Invest in Technology—Data analytics, AI monitoring, and continuous auditing tools make adaptive risk management possible.
  3. Conduct Scenario Planning—Practice responding to “Losira-like” threats: targeted, intelligent, and hard to predict.
  4. Build Risk Alliances—Partner with all departments to create a unified threat picture.
  5. Close the Loop—Use each incident to strengthen your program against future threats.

Final ComplianceLog Reflections

That Which Survives is more than a suspense episode; it is a cautionary tale about the dangers of underestimating risk. Losira was not inherently evil; she was a misunderstood, unexamined part of an environment the crew did not fully assess before engagement.

The compliance officer’s mandate is to ensure the company doesn’t make the same mistake: to scan for threats before beaming in, to adapt to risks that evolve, to prepare for unlikely but devastating events, to coordinate across the enterprise, and to address the root cause when problems arise.

In other words, risk management is not just about surviving; it is about ensuring that your organization thrives in any environment, whether it’s an unexplored planet or a rapidly changing market.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

THE BERKO TRIAL – PART 2: The Missing Last Mile: How the Defense Challenged the Berko Case

Yesterday in Part One of our series on the Asante Berko FCPA trial and conviction, we examined the prosecution’s mosaic. Today in Part 2, we ask the defense question that cut across every category of proof: Where was the bribe?

The Department of Justice (DOJ) had more than 300 emails, payments to intermediaries, financial-flow charts, compliance concerns, and a secretly recorded lunch. The defense argued that the case still lacked its last mile. No alleged recipient testified. No Ghanaian witness took the stand. No eyewitness described a bribe. No bank record showed money reaching a public official. None of the participants in the email chains explained their meaning to the jury.

That position did not prevail. Only after approximately three hours of deliberation did the jury convict Asante Kwaku Berko on conspiracy to violate the FCPA, a substantive FCPA violation, and a money laundering conspiracy. But a fair account of the trial requires more than repeating the result. It requires understanding why the defense believed suspicious conduct and compliance red flags did not add up to proof beyond a reasonable doubt.

Red Flags Are Not the Elements of a Crime

The defense began with the burden of proof. A high-risk intermediary, personal email, opaque invoices, and cash discussions may justify enhanced diligence, an internal investigation, or a decision to exit a transaction. They do not, standing alone, prove corrupt intent or participation in a bribery agreement. Defense attorney Robert Boone told jurors that the government had years to find a witness or record connecting the money to an official. The courtroom presentation, he argued, was impressive, but the underlying proof was missing. The government’s financial charts traced money from Aksa accounts in Turkey to Tricorp, Berko, and others. According to the defense, those charts stopped before showing a transfer to any alleged public-official recipient.

Prosecutors answered that cash completed the path and concealed the payments. The defense response was that an explanation for missing evidence is not the same as the evidence itself. The last-mile gap was not necessarily a claim that a bank receipt was required for every charged theory. It was an attack on the inferences the government asked the jury to draw about agreement, knowledge, purpose, and authorization.

A Scam, Not a Conspiracy

The defense supplied an alternative explanation for the intermediaries’ demands. Tricorp’s principals, Boone argued, saw outsiders pursuing a valuable project and used claims of political access and urgent payment needs to extract money. They were running a shakedown, not carrying out a bribery agreement.

The emails gave that theory something to work with. In one April 2015 message, a Tricorp principal demanded $500,000 immediately and insisted that unspecified necessities had to be handled. Other exchanges reflected disagreements over amounts, timing, and what had supposedly been promised. Boone characterized the demands as exaggerated and unreliable, comparing them to familiar advance-fee scams.

That distinction was critical. If an intermediary falsely claimed that officials had been or needed to be paid, an email repeating that claim might document the intermediary’s sales pitch rather than an actual bribe. Even the reported statement that Berko had paid Parliament came from a Tricorp principal. The defense asked the jury to consider whether the speaker was reporting a fact or using the language of a scam to justify another reimbursement.

The prosecution had a powerful answer: Berko was not merely copied on one stray message. His communications, payment negotiations, channel choices, and recorded statements appeared throughout the chronology. Still, the defense theory targeted an important evidentiary question. Before accepting an intermediary’s statement as proof, who made it, why, and with what first-hand knowledge?

A Legitimate Project With Commercial Logic

The underlying project was real. Ghana was confronting serious electricity shortages and wanted to add 1,000 megawatts of generating capacity quickly. Aksa later obtained financing from Barclays and a Turkish bank after Goldman withdrew, and its 370-megawatt plant entered commercial operation.

The defense used those facts to challenge motive. Ghana needed available power, Aksa could supply it, and other financial institutions ultimately supported the project. Boone put the point bluntly: Why would a qualified company need to bribe a government that was desperate for electricity?

Commercial merit is not a defense to bribery. Legitimate projects can still be advanced through corrupt means. Yet the project’s reality gave the defense a noncriminal explanation for meetings, urgency, large fees, and intense communications. The government had to prove that the conduct crossed the line from hard-driving project execution into corrupt payment activity.

Hundreds of Emails, but No Voice From the Chain

The prosecution treated the emails as the scheme speaking for itself. The defense treated them as fragments without context. FBI Special Agent Ryan Collins introduced much of the correspondence, but Boone emphasized that Collins did not participate in the exchanges and did not know what the writers meant. No participant in the chains took the stand to explain the language.

That allowed the defense to challenge words such as “payment,” “millions,” “fees,” and “cash.” Depending on purpose and recipient, those terms can describe legitimate compensation, reimbursement, or financing. Similarly, using Gmail for business after acknowledging that a Goldman account was monitored could demonstrate poor judgment, policy evasion, or concealment. The defense argued that the criminal inference depended on what the communications concerned, not the platform alone. This was also the weakness in the defense position. The messages were numerous, contemporaneous, and aligned with transaction milestones. An alternative interpretation had to explain the full pattern, not merely establish that individual phrases were ambiguous.

Testing the Recorded Lunch

The recorded lunch carried the drama of a direct conversation, but the defense attacked its context and origin. The unnamed source first approached the SEC, later assisted the FBI, and was described at trial as the genesis of the investigation. The defense argued that possible eligibility for an SEC whistleblower award created a financial incentive. According to the reporting, the source did not testify, and defense filings asserted that the source had supplied false information to investigators.

The FBI also identified subjects for the source to raise before the November 2016 meeting. One was cash. The resulting video was grainy, the restaurant was noisy, and the conversation moved among English, Twi, and Ghanaian Pidgin English. Jurors relied in part on a translated transcript.

The defense emphasized that the cash exchange arose during an apparently hypothetical discussion involving investors, Ghanaian stock, and a botanical garden. Berko initially said paying the people under discussion was not a good thing. Only after the source asked for the best way to pay did Berko answer that cash could be used.

The government’s strongest response was Berko’s own reported language, including his statement that “KD got one million” and his assurance that he could obtain a large amount of cash.[4] Source motive did not erase those words. The defense attack went to whether the source’s prompting, translation, and hypothetical setup changed their meaning.

Corporate Withdrawal Was Not a Criminal Verdict

Goldman’s review produced genuine concerns. Amandine Martin testified that Aksa’s explanations for payments to Tricorp did not match earlier information and that months of questions did not produce satisfactory answers. Goldman withdrew and earned nothing from the contemplated financing. For the defense, that corporate decision showed a risk-control judgment, not proof of Berko’s guilt. Businesses act before uncertainty is resolved because they do not apply the criminal standard of proof. Other lenders later financed the project, reinforcing the defense position that the transaction had commercial substance.

The distinction matters. A company may properly stop a transaction when diligence cannot resolve serious red flags. A jury must decide whether the government proved the charged crime beyond a reasonable doubt. Those are different decisions made for different purposes.

The Missing Link and the Complete Pattern

The jury rejected the defense position and returned guilty verdicts on all three counts. The general verdict does not disclose why. It does not tell us whether jurors found the emails decisive, credited the cash explanation, accepted the recorded statements at face value, or concluded that all of the evidence corroborated itself.

The defense nevertheless framed the trial’s central proof contest. The government had to turn red flags into criminal evidence. The defense had to offer an innocent explanation capable of accounting for the complete record: the emails, milestone timing, intermediary payments, off-channel communications, compliance interactions, financial flows, and recorded lunch. Identifying a missing link can create reasonable doubt. But the alternative theory must also explain why every other link appears to point in the same direction. In Berko, the jury concluded that the government carried its burden.

Join us tomorrow for Part 3, where we will consider what those three guilty verdicts legally established, what a general verdict leaves unresolved, and why compliance professionals should resist turning a verdict into factual findings the jury never made.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

Categories
Blog

Third-Party Due Diligence: 5 Lessons from Star Trek’s The Mark of Gideon

In the modern compliance landscape, third-party due diligence is not optional but essential. Regulators from the DOJ to the SFO have made it clear: if your business partner is involved in misconduct, you are on the hook if you did not take reasonable steps to know who you were dealing with.

Few pop culture moments capture the risks of blind engagement as vividly as Star Trek: The Original Series’ “The Mark of Gideon.” In this episode, Captain Kirk beams down to what he believes is the planet Gideon for diplomatic talks—only to find himself aboard what appears to be an empty Enterprise. What follows is a masterclass in the dangers of walking into a deal without verifying the facts. For compliance professionals, Gideon’s deception is the perfect allegory for the hazards of onboarding a third party without a thorough vetting process. Let’s break down five key lessons.

Lesson 1: Verify the True Identity of Your Counterparty

Illustrated by: When Kirk believes he is beamed down to Gideon, he is actually inside a replica of the Enterprise. The Gideonites have created this fake environment to isolate him for their purposes.

Compliance Lesson. If you do not confirm the true identity of a third party, you may find yourself dealing with a façade. Shell companies, undisclosed beneficial owners, and entities with misleading corporate registrations are the corporate world’s “empty Enterprise.”Always confirm a third party’s corporate existence and ownership through independent sources. This means checking official registries, using reliable due diligence databases, and, when needed, engaging investigative firms to trace beneficial ownership. Without these checks, you risk contracting with a front for illicit activity.

Lesson 2: Understand the Real Motives Behind the Partnership

Illustrated by: The Gideonites’ true purpose is not peaceful diplomacy; instead, they want to infect their overpopulated planet with a deadly virus carried by Kirk. They present their plan as a noble solution to their problem, but it’s built on deception and exploitation.

Compliance Lesson. Third parties sometimes have agendas that differ sharply from what they present. They may seek access to your brand to legitimize questionable practices, gain entry to restricted markets, or launder illicit funds. Beyond standard questionnaires, compliance teams should assess the commercial rationale for the relationship. Why do they want to work with you? Who else do they do business with? Are their financials consistent with the scale of the deal? If their motives don’t align with your values and compliance commitments, that is a red flag.

Lesson 3: Never Rely Solely on What the Other Party Tells You

Illustrated by: Kirk repeatedly asks the Gideonites to explain what is happening, but their answers are vague, evasive, and occasionally contradictory. They hope his lack of information will keep him compliant long enough to serve their plan.

Compliance Lesson. Self-reported information from a potential third party should be viewed as one data point, not the whole picture. Misrepresentations are common, whether deliberate or due to internal ignorance. Cross-verify all claims with independent checks, customer references, industry reputation research, litigation and sanctions screening, and on-site visits when possible. If the only source for a claim is the counterparty itself, your risk exposure rises dramatically.

Lesson 4: Assess the Operating Environment Before Engagement

Illustrated by: The Gideonites hide the actual conditions on their planet. Kirk learns later that Gideon is overcrowded to the point of people standing shoulder-to-shoulder, unable to move freely. Had this been disclosed, he would have understood the real risks before arriving.

Compliance Lesson. A third party’s operating environment, political stability, corruption levels, and regulatory enforcement directly affect your compliance risk. Entering into a business relationship without assessing this environment is akin to beaming down blind. Incorporate country risk analysis into your process. Use resources like Transparency International’s Corruption Perceptions Index, U.S. State Department human rights reports, and local legal counsel. An otherwise legitimate partner in a high-risk jurisdiction requires enhanced due diligence and monitoring.

Lesson 5: Build Exit Strategies Into the Relationship

Illustrated by: Once Kirk understands the Gideonites’ true intentions, he must escape the replica Enterprise to stop their plan. Without a clear route back to his crew, he risks being trapped indefinitely.

Compliance Lesson. Some third-party relationships turn sour despite your best due diligence efforts. Whether due to leadership changes, shifts in political conditions, or the surfacing of previously hidden misconduct, you need a plan to disengage without disrupting your operations. Include termination clauses tied to compliance breaches in your contracts. Maintain operational flexibility so you can pivot to alternate suppliers or partners if needed. Regularly re-screen third parties to ensure ongoing compliance, not just a one-time check at onboarding.

Final ComplianceLog Reflections

In The Mark of Gideon, the Enterprise crew’s lack of verified intelligence before Kirk’s “beam down” mirrors what happens when companies rush into a third-party relationship to seize a perceived opportunity. The Gideonites knew how to manipulate the Federation’s diplomatic eagerness. Likewise, unscrupulous partners today exploit companies’ urgency to enter new markets or secure rare supply chains.

The lesson? Due diligence is not a delay; it is a safeguard. The few extra weeks spent vetting a partner can prevent years of litigation, regulatory penalties, and reputational damage.

The Mark of Gideon” is not just a quirky Star Trek morality tale. It is a warning for every compliance professional. Without thorough third-party due diligence, you risk waking up in a corporate “replica Enterprise,” surrounded by partners whose true motives only become clear when it’s too late.

Your job as a compliance officer is to ensure the company doesn’t act blindly. By verifying identities, probing motives, cross-checking information, assessing environments, and building exit strategies, you safeguard your organization’s reputation and operational integrity. In short: trust, but verify, especially when the other side is as smooth-talking as the people of Gideon.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
FCPA Compliance Report

FCPA Compliance Report: The Berko Verdict with Mike Volkov

In this episode, Tom Fox welcomes back his good friend and colleague Mike Volkov and takes a deep dive into the Asante Berko FCPA guilty verdict.

They question why Berko went to trial given the strength of the case, discuss the power of recorded statements like requests to use private email, and highlight Goldman Sachs compliance personnel as corroborating witnesses after the firm stopped the transaction and disclosed it. They conclude with compliance lessons that include rigorous deal due diligence, escalation of red flags, sampling internal communications, and monitoring attempts to move discussions off-channel.

Key highlights:

  • Quick Jury Verdict
  • Recordings And Emails
  • Goldman Compliance Witness
  • Sentencing Trial Penalty
  • SEC Settlement Strategy
  • Compliance Lessons Red Flags

Resources:

Berko Trial Blog Post series on FCPA Compliance and Ethics Report

Mike Volkov on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 71 – Beaming Down Blind: Compliance Lessons on Third-Party Due Diligence from “The Mark of Gideon”

Few pop culture moments capture the risks of blind engagement as vividly as Star Trek: The Original Series’ “The Mark of Gideon.” In this episode, Captain Kirk beams down to what he believes is the planet Gideon for diplomatic talks—only to find himself aboard what appears to be an empty Enterprise. What follows is a masterclass in the dangers of walking into a deal without verifying the facts. For compliance professionals, Gideon’s deception is the perfect allegory for the hazards of onboarding a third party without a thorough vetting process. Let’s break down five key lessons.

Lesson 1: Verify the True Identity of Your Counterparty

Illustrated by: When Kirk believes he is beamed down to Gideon, he is actually inside a replica of the Enterprise. The Gideonites have created this fake environment to isolate him for their purposes.

Compliance Lesson. If you do not confirm the true identity of a third party, you may find yourself dealing with a façade. Shell companies, undisclosed beneficial owners, and entities with misleading corporate registrations are the corporate world’s “empty Enterprise.”

Lesson 2: Understand the Real Motives Behind the Partnership

Illustrated by: The Gideonites present their plan as a noble solution to their problem, but it’s built on deception and exploitation.

Compliance Lesson. Third parties sometimes have agendas that differ sharply from what they present. They may seek access to your brand to legitimize questionable practices, gain entry to restricted markets, or launder illicit funds.

Lesson 3: Never Rely Solely on What the Other Party Tells You

Illustrated by: Kirk repeatedly asks the Gideonites to explain what is happening, but their answers are vague, evasive, and occasionally contradictory. They hope his lack of information will keep him compliant long enough to serve their plan.

Compliance Lesson. Self-reported information from a potential third party should be viewed as one data point, not the whole picture. Misrepresentations are common, whether deliberate or due to internal ignorance.

Lesson 4: Assess the Operating Environment Before Engagement

Illustrated by: The Gideonites hide the actual conditions on their planet. Kirk learns later that Gideon is overcrowded to the point of people standing shoulder-to-shoulder, unable to move freely.

Compliance Lesson. Entering into a business relationship without assessing this environment is akin to beaming down blind.

Lesson 5: Build Exit Strategies Into the Relationship

Illustrated by: Once Kirk understands the Gideonites’ true intentions, he must escape the replica Enterprise to stop their plan.

Compliance Lesson. Some third-party relationships turn sour, and you need a plan to disengage without disrupting your operations. Include termination clauses tied to compliance breaches in your contracts.

Final ComplianceLog Reflections

In The Mark of Gideon, the Enterprise crew’s lack of verified intelligence before Kirk’s “beam down” mirrors what happens when companies rush into a third-party relationship to seize a perceived opportunity. The Gideonites knew how to manipulate the Federation’s diplomatic eagerness. Likewise, unscrupulous partners today exploit companies’ urgency to enter new markets or secure rare supply chains.

The lesson? Due diligence is not a delay; it is a safeguard. The few extra weeks spent vetting a partner can prevent years of litigation, regulatory penalties, and reputational damage.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

Categories
AI Today in 5

AI Today in 5: August 10, 2026, The Don’t Get Your Compliance from ChatGPT Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. What happens when AI goes rogue? (Reuters)
  2. AI can help train healthcare workers. (World Economic Forum)
  3. AI is putting banks at the mercy of tech firms. (The Guardian)
  4. AI and PR building reputations. (Mexico Business News)
  5. Don’t get your compliance information from ChatGPT. (ACA International)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: August 10, 2026, The Asante Trial Verdict Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Asante Berko found guilty at trial. (Law360)
  • Paying soldiers directly as an ABC strategy. (Arab News)
  • What happens when AI goes rogue? (Reuters)
  • Malaysia delays charges against ex-PM. (Bloomberg)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

THE BERKO TRIAL – PART 1: The Digital Trail: How Prosecutors Built the Berko Bribery Case

A bribery case does not always arrive with a signed receipt. In the trial of former Goldman Sachs banker Asante Berko, prosecutors presented something different: a mosaic of evidence. They placed before the jury a high-value public project, politically connected intermediaries, payments tied to transaction milestones, personal email accounts, disputed consulting invoices, cash withdrawals, a recorded lunch conversation, and an individual who allegedly stood to receive millions.

Over the next five days, I will be taking a deep dive into this trial to see how the prosecution was able to convince a jury of the defendant’s guilt so quickly. The verdict was rendered in just over 3 hours, which tells you the jury did not doubt as to the defendant’s guilt. This blog post series is based upon the excellent reporting of Law360 reporter Stewart Bishop and additional source documents and resources from the Department of Justice (DOJ) and Securities and Exchange Commission (SEC).

The government’s burden was to prove the charged crimes beyond a reasonable doubt. Its strategy was to show that the evidence did not consist of isolated red flags. Each category corroborated the others. Taken together, prosecutors argued, the pattern demonstrated opportunity, corrupt intent, concealment, and personal gain.

A National Crisis and a High-Stakes Deal

The story began with a legitimate and urgent business need. Ghana had suffered widespread power shortages, and its government was seeking projects capable of adding generation quickly. Aksa Enerji Uretim A.S., a Turkish energy company and Goldman client, pursued an agreement to build and operate a power plant. The commercial stakes were substantial. Goldman contemplated arranging approximately $190 million in financing for Aksa and a $75 million letter of credit for Ghana. Goldman also held an approximately 16 percent interest in Aksa. The indictment alleged projected fees of approximately $10.3 million for the loan and more than $1 million for the letter of credit.

Berko was central to the business effort. A dual citizen of the United States and Ghana, he worked in the structured-finance group of Goldman’s United Kingdom subsidiary and had relationships with senior Ghanaian officials. Prosecutors argued that he connected three critical groups: the commercial client seeking the project, the local intermediaries who claimed access, and the public officials whose approvals were required. That role gave the government its organizing theory. Berko was not presented as a participant at the edge of the transaction. He was presented as the linchpin.

The Email Trail

The most important prosecution evidence was documentary. More than 300 emails were admitted during the nine-day trial. Prosecutors used their language, timing, recipients, and communication channels to construct a chronology of the alleged scheme. One September 2015 email shown to the jury stated that Parliament had been paid by Berko and discussed approximately $46,000 that he allegedly paid. Other messages addressed payments associated with the Ministry of Power, regulators, power-team personnel, travel, and parliamentary approval. In a July 2015 exchange over the size and timing of payments, Berko wrote that he was managing a relationship expected to pay everyone millions.

The government argued that these exchanges became more incriminating when compared with Berko’s ordinary deal communications. Routine transaction work went through Goldman’s systems. Sensitive payment discussions appeared in personal accounts. In February 2016, prosecutors showed the jury two emails sent 14 minutes apart. One used Berko’s Goldman account for ordinary deal business. The other used Gmail and instructed recipients to communicate there because his Goldman account was monitored. Personal email alone does not prove bribery. The government’s point was more precise. When an employee knows that the official system is monitored, moves sensitive discussions to a private channel, and then uses that channel for payment conversations linked to public approvals, the channel choice may support an inference of concealment.

Money That Followed Milestones

The prosecution next aligned communications with transaction events and financial flows. The indictment alleged that intermediaries used false consulting invoices to obtain reimbursement for bribes and routed funds from Turkey to Ghana through correspondent accounts in New York.

The chronology was central to the prosecution’s case. In April 2015, as the parties pushed toward execution of the emergency power agreement, an intermediary issued a $500,000 invoice. Emails allegedly discussed using part of that money to pay a Ghanaian official, and a $500,000 wire followed. Later that month, five Ghanaian officials traveled to Turkey to inspect equipment. The indictment alleged that their expenses were covered and each received $5,000.

When a senior Ghanaian official signed the agreement in May 2015, another invoice for $1.5 million was issued the same day. A $1.5 million transfer followed later that month. After Parliament ratified the agreement in July, emails discussed a $250,000 reimbursement request that included payments connected to Parliament, the Ministry of Power, regulators, engineers, travel, and Berko personally.

At trial, a government summary witness walked jurors through charts tracing funds from Aksa accounts in Turkey to accounts associated with intermediaries, Berko, and others. The records did not show the final transfer to every alleged official. Prosecutors answered that gap by pointing to evidence that cash was used to complete and conceal the payments. The amounts require discipline. The indictment alleged more than $700,000 in bribes. DOJ stated after the verdict that the government proved more than $1 million in bribes at trial.[1][5] Those figures come from different stages of the case and should remain separately attributed.

The Recorded Lunch

The recording supplied another form of corroboration. In November 2016, an FBI-assisted source met Berko at a London restaurant. The conversation moved among English, Twi, and Ghanaian Pidgin English, and the jury received a translated transcript. In one exchange, the source asked about a former energy minister. Berko replied that “KD got one million.” In another discussion, framed around a hypothetical investment, Berko initially said it was not good to pay the individuals under discussion. When asked for the best way to pay them, however, he answered, “Cash,” and said he could obtain $1 million from a bank.

The prosecution used these statements to reinforce its reading of the emails and money flows. The recording did not stand alone. It supplied the government’s alleged final piece of context: the same person who used private email for sensitive payments and appeared throughout the deal chronology also discussed a million-dollar payment to an energy minister and the practical use of cash. The source’s incentives, the FBI’s preparation of the conversation, translation issues, and the hypothetical framing were substantial defense subjects. They will be examined in Part 2. For the government’s case, the point was corroboration.

When Compliance Became Evidence

Goldman’s compliance response became part of the prosecution’s proof and, in my mind, one of the key components of the government’s overall presentation to the jury, as it was essentially evidence from an outside party to the transaction. Amandine Martin, who worked with Berko on the transaction, testified that Goldman spent months seeking explanations for payments to the Ghanaian intermediary. According to her testimony, the answers did not match information previously provided, and Aksa’s chief executive eventually responded that the company did not have time for the questions. Goldman withdrew from the transaction and did not provide the planned financing. Goldman was not charged in the criminal case. Prosecutors nevertheless used the compliance record to argue that Berko understood the risks and the institution’s rules, knew that his communications were monitored, and failed to correct allegedly false or incomplete explanations about the intermediary.

This is the first compliance lesson of the series: a control is also a record. Questions, responses, escalation, monitoring, and the decision to exit can later become evidence of what an employee knew, what the company challenged, and how the organization responded.

The Government’s Mosaic Holds

After approximately three hours of deliberation, the jury convicted Berko on all three counts: conspiracy to violate the FCPA, a substantive FCPA violation, and money laundering conspiracy. He was remanded pending sentencing. The general verdict does not tell us which email, payment path, witness, or recorded statement the jury found most persuasive. It also does not convert every factual assertion in the government’s narrative into a special finding. It does establish that the jury found the charged elements proven beyond a reasonable doubt.

That is the power of a circumstantial case. The government did not ask the jury to rely on one dramatic piece of evidence. It asked jurors to see a single pattern across communications, payments, timing, conduct, compliance warnings, and alleged concealment. The jury accepted that case.

Join us tomorrow in Part 2 where we will examine the defense’s answer: if the government said bribes went “up and down the chain,” where was the last mile showing money reaching a public official?

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 70 – Lessons from Let That Be Your Last Battlefield: Building Justice and Fairness into Corporate Culture

Few episodes capture the destructive power of bias, systemic injustice, and the refusal to see common humanity as vividly as Star Trek: The Original Series’ “Let That Be Your Last Battlefield.” From a compliance perspective, the episode provides an unflinching mirror: organizations that fail to ensure fairness in their systems—whether in investigations, promotions, whistleblower treatment, or discipline—risk breeding internal hostilities just as destructive as Cheron’s. Today, we unpack five key compliance lessons for embedding institutional justice and fairness into the corporate DNA.

Lesson 1: Bias—Even When Invisible to Some—Can Destroy Organizational Cohesion

Illustrated by: When Bele first encounters Lokai aboard the Enterprise, he describes him as “obviously inferior.”

Compliance Lesson. Bias often hides in plain sight for those not affected by it. In corporate settings, decision-makers may not recognize that promotion patterns, discipline rates, or resource allocations favor certain groups until a whistleblower, audit, or public scandal exposes it.

Lesson 2: Enforcement Must Be Fair, Consistent, and Transparent

Illustrated by: Bele claims the right to arrest Lokai for crimes committed on Cheron. Lokai, in turn, accuses Bele of genocide. Neither offers verifiable evidence; instead, both rely on their moral certainty.

Compliance Lesson. Internal enforcement that rests on vague accusations or uneven application destroys trust in compliance systems.

Lesson 3: Leaders Must Refuse to Be Drawn into Partisan Vendettas

Illustrated by: Kirk insists on the Enterprise’s code of conduct and rules of evidence.

Compliance Lessons. Senior leaders are often pressured, subtly or overtly, to “pick a side” in internal disputes.

Lesson 4: Systemic Injustice Can Persist Until It Consumes the Organization

Illustrated by: When Bele and Lokai finally return to Cheron, they find their planet in ruins, destroyed by centuries of hatred. Yet, even faced with the extinction of their people, they continue their pursuit, consumed by the need to destroy the other.

Compliance Lesson. Corporate cultures that allow systemic injustice, favoritism in promotions, discriminatory pay structures, and retaliation against whistleblowers risk not only reputational harm but also the destruction of the organization’s ability to function cohesively. Over time, injustice becomes normalized, making reform nearly impossible without significant disruption.

Lesson 5: Without a Shared Framework for Fairness, Conflict Has No Resolution

Illustrated by: Spock, ever the voice of logic, tries to point out that the two aliens are more alike than different. To them, justice is entirely defined by the defeat of the other.

Compliance Lesson. In corporations, the absence of a clear, visible framework for fairness, along with policies, expectations, and trusted reporting channels, leads to conflicts that devolve into zero-sum games.

Final ComplianceLog Reflections

Let That Be Your Last Battlefield ends on a tragic note: the two survivors beam down to a dead world, still locked in mutual hatred. It’s a cautionary tale for corporate life. Without institutional justice and fairness, even the most advanced organizations can collapse into destructive internal conflict.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Timothy is an AI-generated voice