Categories
FCPA Compliance Report

#Risk New York Speaker Series – Exploring the Future of GRC with Michael Rasmussen

Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration.

At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy and combating misinformation. All while meeting with the country’s top #Risk management professionals.

In this episode, Tom Fox welcomes Michael Rasmussen, a renowned expert in Governance, Risk Management, and Compliance (GRC), often referred to as the ‘father of GRC.’ Michael shares insights into his contributions to the field, including his work with the SEG GRC Capability Model. The conversation highlights Michael’s anticipated presentation on ‘The Future of GRC’ at the upcoming risk conference in New York City. Drawing inspiration from Star Trek (TOS, and how can you not love that?), Michael emphasizes the importance of managing business risks effectively. The discussion also touches on the benefits of face-to-face interactions and networking opportunities at such conferences.

Resources:

#Risk Conference Series

#RiskNYC—Tickets and Information

Michael Rasmussen on LinkedIn

Categories
Everything Compliance

Everything Compliance: Episode 155, To Tesla and Beyond Edition

Welcome to this edition of the award-winning Everything Compliance. In this episode, we have the quartet of Matt Kelly, Jonathan Marks, Jonathan Armstrong, and special guest panelist Hemma Lomax, all hosted by Tom Fox, the Compliance Evangelist.

  1. Hemma Lomax examines the customers of a compliance program and introduces us to the terms EX and CX. She shouts out to AI for podcasters.
  2. Matt Kelly delves into Google’s compliance spending announcement and asks why the company does not have a Chief Compliance Officer. He both shouts out and rants about Marjorie Taylor Greene and her reading list.
  3. Jonathan Marks gives us a primer on corporate governance. He shouts out the quiet compliance professionals who do the day-to-day spadework of compliance.
  4. Jonathan Armstrong takes a deep dive into the finances of Tesla and its profitability. He shouts out to Operation Spider’s Web.
  5. Tom Fox highlights Wells Fargo’s compliance remediation, the Fed’s asset cap placed on Wells Fargo, and its subsequent removal.

The members of Everything Compliance are:

Tom Fox, the Voice of Compliance, is the host, producer, and sometimes panelist of Everything Compliance. He can be reached at tfox@tfoxlaw.com. The award-winning Everything Compliance is part of the Compliance Podcast Network.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Code of Conduct as an Internal Control

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

How does your Code of Conduct act as an internal control?

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Daily Compliance News

Daily Compliance News: June 12, 2025, The Brutal Truth Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, and general interest, all of which are relevant to the compliance professional.

Top stories include:

  • 4 questions to ask employees. (WSJ)
  • The Brutal Truth About Layoffs in 2025. (FT )
  • The CITGO auction date has been extended (yet again). (Reuters)
  • Rubio is pressing the DOJ to investigate Harvard. (NYT)
Categories
Blog

Wells Fargo, Risk Management and Reputational Recovery – Part 1: The Penalty

On June 3, 2025, the Federal Reserve lifted its unprecedented $2 trillion asset cap on Wells Fargo, marking the symbolic end to one of the most consequential compliance enforcement actions in modern U.S. banking history. For the compliance and risk management community, this moment is not a victory lap—it is a case study of how compliance failures cascade, reputational risk becomes operationally tangible, and regulatory patience has its limits.

Over the next two blog posts, I want to explore what happened, why it mattered, and what lessons every compliance professional should carry forward. These blog posts are based on two primary articles. The First Wells Fargo Is Allowed to Grow Again After 7 Years Under Asset-Cap Penalty, by Gina Heeb in the Wall Street Journal. The second is “Wells Fargo Asset Cap Lifted by Fed, Paving Way for Growth” by Yizhu Wang in Bloomberg. The final is an op-ed piece in Bloomberg, entitled “Wells Fargo’s Asset Cap Has Been a Good Punishment,” by Paul Davies.

The Scandal That Shook the System

The Wells Fargo saga began with a simple, albeit stunning, revelation: employees had opened millions of unauthorized deposit and credit card accounts to meet aggressive internal sales goals. Between 2009 and 2016, over 3.5 million accounts were opened without the customer’s consent. Many of these accounts generated fees, tarnishing customer relationships and shaking public trust in one of the most storied names in American banking.

As the crisis deepened, it was not just a case of bad apples. It was a system-wide failure of controls, risk oversight, and a corporate culture that incentivized misconduct. The sales quotas that fueled the behavior were directly tied to compensation and job security, creating a high-pressure environment where fraud became a means of survival.

Regulators acted swiftly. In 2016, Wells Fargo was fined $185 million. In 2018, the Federal Reserve took the rare and dramatic step of capping the bank’s total assets at approximately $2 trillion, essentially freezing its ability to grow until it could demonstrate a wholesale overhaul of its risk management and governance practices.

The Asset Cap: Punishment with Purpose

We need to be clear: this was not just a penalty. It was a structural constraint that directly impacted Wells Fargo’s ability to operate and compete in its core business. The $2 trillion asset cap imposed by the Federal Reserve in 2018 did not simply send a signal; it built a wall. It limited Wells Fargo’s ability to grow its balance sheet, take on new deposits, issue new loans, and expand into revenue-generating business lines, such as investment banking, trading, and wealth management. Unlike traditional enforcement actions, which often result in fines or deferred prosecution agreements, the asset cap attacked the bank’s future potential, not just its past misdeeds.

In short, it was a period of growth stagnation. For a publicly traded institution that relies on growth to attract investors, increase shareholder value, and maintain market position, such a freeze is devastating.

The restriction forced the bank into a defensive crouch. Instead of competing for market share or innovating with new financial products, Wells Fargo was compelled to pour resources into compliance remediation and cultural rehabilitation. According to public filings and internal estimates, the bank spent more than $2.5 billion above its 2018 baseline to maintain the risk, control, and compliance infrastructure needed to satisfy dozens of consent orders. This included the hiring of more than 10,000 employees dedicated to risk and regulatory functions—a remarkable mobilization of resources that most firms would struggle to afford.

As Davies aptly observed, “The asset cap has become a feared punishment for banks in the U.S.; they will want to avoid it at all costs.” And banks should. Because it not only restricts current operations, it sends a clear signal to markets, analysts, and regulators: this institution is not yet trusted to grow.

However, here’s the twist: in the case of Wells Fargo, it did work.

The asset cap’s forced pause compelled the bank to undertake a comprehensive review of its governance and culture. Under the leadership of CEO Charlie Scharf, who joined BNY Mellon in 2019 and previously held senior roles at Visa and JPMorgan, Wells Fargo began the arduous but necessary work of rebuilding. Scharf wasted no time restructuring the risk and compliance functions, streamlining reporting lines, and replacing much of the leadership team that had presided over the bank’s previous failures. Perhaps most importantly, he made compliance the focal point of executive decision-making, beginning every operating committee meeting with a thorough review of regulatory progress.

In effect, the asset cap did not simply punish Wells Fargo; it saved the bank from itself. It forced the kind of systemic, sustainable change that no fine or press release could have achieved. Wells Fargo emerged leaner, more disciplined, and more compliant. In many ways, it became a model for what the Federal Reserve, the Department of Justice (DOJ), and numerous other regulatory agencies now expect. Not simply accountability but a demonstrable and lasting commitment to cultural transformation.

This is remediation before reward. It is tone at the top in action. And for compliance professionals everywhere, it is proof that when structural enforcement is coupled with leadership willing to change, reform is not only possible but, as Theranos might say, “inevitable.”

Why It Worked: Enforcement as a Governance Driver

For corporate compliance professionals, Wells Fargo is more than a cautionary tale. It is proof that regulatory enforcement, when aligned with structural consequences, can drive actual change. The asset cap was not a mere symbolic gesture. It constrained Wells Fargo’s operations at its core, limiting everything from loan issuance to deposit intake to investment banking expansion.

Even more significantly, it reshaped how the bank’s board and senior executives prioritized compliance. For years, every operating committee meeting began with updates on regulatory matters. This became the bank’s daily bread.

The message is clear: when enforcement bites into business, executives listen.

Join us tomorrow as we delve into Part 2, where we examine lessons learned for the compliance professional.

Categories
Daily Compliance News

Daily Compliance News: June 11, 2025, A Bondi Too Far Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, and general interest, all of which are relevant to the compliance professional.

Top stories include:

Categories
Compliance Into the Weeds

Compliance into the Weeds: Changes in FCPA Enforcement

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you seeking insightful perspectives on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent memorandum from the Deputy Attorney General regarding the investigation and enforcement of the FCPA.

The memo follows President Trump’s executive order pausing FCPA enforcement for six months. The hosts evaluate the potential impacts on compliance programs, with a possible shift to targeting foreign companies that harm US business interests and national security. They also explore the role of the Foreign Extortion Prevention Act and speculate on how the SEC might integrate these changes into its enforcement practices.

Key highlights:

  • Initial Reactions to the FCPA Memo
  • Implications for Anti-Corruption Compliance
  • Focus on Foreign Companies and National Security
  • Skepticism and Potential Bias in Enforcement
  • Strategic National Interests and Enforcement
  • Considerations for Compliance Officers

Resources:

Memo on Guidelines for Investigation and Enforcement of the FCPA

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds, was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Board Oversight on Internal Controls

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

How can your board fulfill its role in oversight of your internal controls

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Blog

5 Key Strategies For Compliance to Avoid Violating the Caremark Doctrine

The Caremark Doctrine remains one of the foundational pillars of corporate compliance, a pivotal standard that every compliance professional must understand and apply. Originating from the landmark Delaware Chancery Court decision in In re Caremark International Inc. Derivative Litigation (1996), this doctrine revolutionized the way corporate boards are viewed in terms of their oversight duties. As compliance professionals, it’s essential to grasp not only the legal intricacies but also the profound practical implications this doctrine carries for board responsibilities and organizational oversight.

At its core, the Caremark Doctrine addresses the fiduciary duty of corporate directors to actively oversee a company’s compliance and risk management practices. Before this case, oversight obligations were seen primarily as passive, reactionary, or even discretionary. Caremark fundamentally shifted this perception, articulating an affirmative duty on directors to establish, maintain, and adequately monitor compliance systems to detect and prevent corporate misconduct.

The significance of the Caremark decision lies in its delineation of two clear pathways where director liability can be triggered: first, when the board utterly fails to implement any reporting or information systems, and second, when, having implemented such systems, the board consciously disregards red flags signaling compliance failures or operational risks. Citing negligence or ignorance as a defense for oversight responsibilities is no longer sufficient. Directors became accountable not only for what they knew but also for what they should have known, emphasizing the importance of proactivity, diligence, and vigilance.

Today, the implications of Caremark resonate strongly within the realm of corporate compliance programs, setting the standards for board engagement expectations. Effective compliance no longer solely involves setting clear policies and robust procedures; instead, it demands ongoing active engagement from the board to ensure these measures are functioning effectively. Boards are expected to scrutinize, test regularly, and challenge management on compliance risks and controls, embedding compliance considerations firmly into the corporate governance structure.

In recent years, corporate compliance officers have faced heightened scrutiny as Delaware courts have increasingly emphasized board accountability through the evolution of the Caremark Doctrine. The evolving jurisprudence surrounding this doctrine, particularly highlighted by cases such as Marchand v. Barnhill and Boeing, underscores the necessity for vigilance, attentiveness, and proactive risk management. Itai Fiegenbaum undertook a thorough examination of the Caremark Doctrine in his 2025 article, “Caremark’s Fractured State.” I use his article as a starting point to outline five essential strategies compliance officers can adopt to ensure their organizations remain firmly compliant with Caremark obligations and avoid potential liability.

1. Establish Robust Monitoring Systems

At the heart of the Caremark Doctrine is the expectation that directors not only establish but also actively oversee effective corporate monitoring systems. Compliance officers must ensure that robust, comprehensive monitoring frameworks are in place, which include clear policies, detailed procedures, and continuous oversight mechanisms. These systems must be designed to identify and escalate potential compliance issues promptly.

Implementing state-of-the-art technology, such as advanced analytics and AI-driven monitoring tools, can significantly enhance the effectiveness of these systems. Such tools enable the real-time analysis of large volumes of data, allowing for the quick identification of anomalies or red flags that indicate potential misconduct. Additionally, compliance officers should regularly review and update these systems to ensure their ongoing effectiveness in response to evolving regulatory requirements and emerging risks.

2. Prioritize Oversight of Mission-Critical Activities

Recent Delaware jurisprudence, particularly the Marchand case, has underscored the need for boards to exercise increased vigilance over “mission-critical” aspects of their operations. Compliance officers must assist directors in identifying these critical functions, which are integral to the organization’s core business operations and profitability, and ensure that enhanced monitoring and reporting practices are implemented.

Regular board-level discussions and reporting on these mission-critical functions must be documented meticulously. Compliance officers should establish routine updates that enable the board to understand the risks, controls, and compliance status related to these critical activities. Such a strategic focus not only aligns with the expectations set by Delaware courts but also significantly mitigates the risk of oversight failures.

3. Ensure Active Board Engagement and Training

Delaware courts have repeatedly emphasized that passive oversight is insufficient; board members must actively engage in compliance monitoring and demonstrate awareness of their fiduciary duties under the Caremark Doctrine. Compliance officers play a crucial role in facilitating active engagement by organizing regular and specialized training sessions for directors, ensuring they fully understand their oversight responsibilities and the specific compliance risks facing the company.

Moreover, compliance officers should encourage directors to challenge management constructively, seek additional information when needed, and demonstrate thoughtful engagement during board meetings. Documenting directors’ active involvement through detailed meeting minutes and clear records of training and discussions can substantially bolster evidence of effective oversight, which is crucial in the event of litigation.

4. Foster a Strong Compliance Culture

An organization’s compliance culture has a significant impact on its ability to effectively uphold Caremark obligations. A strong compliance culture ensures that employees at all levels recognize the importance of compliance, feel empowered to raise concerns without fear of retaliation, and understand that ethical conduct is integral to organizational success.

Compliance officers should proactively foster such a culture through comprehensive ethics training, regular communications reinforcing compliance messages, and visible support from top leadership. Mechanisms such as confidential reporting channels, whistleblower protections, and prompt investigation of reported issues further strengthen this culture, ensuring that potential misconduct is identified and addressed before it escalates into larger problems.

5. Conduct Regular and Thorough Risk Assessments

Proactive risk assessments are essential under the Caremark framework, providing boards with the necessary information to effectively oversee compliance. Compliance officers must ensure that these risk assessments are comprehensive, covering both traditional risks, such as fraud and corruption, as well as emerging threats related to cybersecurity, data privacy, and geopolitical changes.

Regular risk assessments not only inform the board’s oversight activities but also allow compliance officers to adjust monitoring and controls in response to identified vulnerabilities. Documented risk assessment processes, along with clear remediation actions, demonstrate due diligence and provide robust defenses against claims of insufficient oversight.

Conclusion

The Caremark Doctrine continues to evolve, setting increasingly stringent standards for corporate oversight. Compliance officers play a pivotal role in guiding boards to meet these expectations through robust monitoring systems, prioritized oversight, active engagement, a strong culture of compliance, and proactive risk management. By implementing these five strategies, compliance officers can significantly reduce their companies’ risk of violating the Caremark Doctrine, safeguard their organizations, and protect directors from potential liability. Now more than ever, proactive compliance is not only prudent but also imperative.

Categories
FCPA Compliance Report

#Risk New York Speaker Series – The Future of AI Governance in GRC with Matt Kelly

Join Tom Fox and hundreds of other GRC professionals in the city that never sleeps, New York City, on July 9 & 10 for one of the top conferences around, #Risk New York. The current US landscape, shaped by evolving policies, rapid advancements in AI, and shifting global dynamics, demands adaptive strategies and cross-functional collaboration.

At #RISK New York, you will master the New Regulatory Reality by getting ahead of US regulatory shifts and their impact. Conquer AI and Tech Risk by Safeguarding Your Organization in an AI-Driven World and Understanding the Implications of Major Tech Investments. Navigate Financial and Crypto Volatility by Protecting Your Assets and Exploring Solutions in a Dynamic Market. Strengthen Your GRC Framework by Leveraging Governance, Risk, and Compliance for Strategic Advantage. Protect Digital Trust by addressing challenges in cybersecurity and data privacy, and combating misinformation. All while meeting with the country’s top #Risk management professionals.

In this episode, Tom Fox talks with Matt Kelly about his presentation on the importance of understanding how AI can be productively adopted within enterprises, as well as the ethical challenges it presents, including discrimination and data validity. Matt also discusses the importance of AI governance and offers a preview of his upcoming presentation on this topic. Matt expresses his eagerness to engage with other GRC professionals at the forthcoming conference to exchange ideas and discuss emerging risks in third-party and vendor risk management.

Resources:

#Risk Conference Series

#RiskNYC—Tickets and Information

Matt Kelly on LinkedIn