Categories
Compliance Tip of the Day

Compliance Tip of the Day – COSO Objective 4 – Control Information and Communication

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we continue our look at the 5 COSO Objectives. Today, Number IV—Control Information and Communication.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Hill Country Authors

Hill Country Authors – The Legacy and Literature of Phil Oakley: A Life of Stories from Texas

Welcome to a new season of the award-winning Hill Country Authors Podcast, sponsored by Stoney Creek Publishing. In this podcast, Hill Country resident Tom Fox visits with authors who live in and write about the Texas Hill Country. In this episode, Tom visits author Phil Oakley, discussing his intriguing professional background and his novels, which are based on his family’s history in Texas.

Oakley shares stories from his childhood, professional encounters, and inspirations drawn from his grandparents’ lives. They delve into his book series, starting with ‘Little Hatchet’ and ‘Runners,’ exploring the ways he incorporates Texas history and personal heritage into his work. Oakley also reflects on the impacts of weather, railroads, and prohibition on his family and the state. Towards the end, he discusses his transition from biography to fiction and the potential for his books to be adapted into a streaming series. The session concludes with insights on working with Stony Creek Publishing and resources for readers to find his books.

Key highlights:

  • Phil Oakley’s Professional Background
  • Remembering Ronnie Dugger
  • Phil Oakley’s Books and Inspirations
  • Writing Craft and Historical Context
  • Prohibition and Family Stories
  • Current Projects and Future Directions

Resources:

Little Hatchet | Book 1 of The Oakley Series

Runners | Book 2 of The Oakley Series

Little Hatchet and Runners on Texas A&M University Press

Stoney Creek Publishing Website

Little Hatchet Book Trailer on YouTube

Podcast Cover Art

Nancy Huffman Fine Art

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Blog

COSO’s Corporate Governance Framework: A New Compass for the Compliance Professional

The compliance profession has long relied on the COSO frameworks for a solid foundation in internal controls and enterprise risk management. Now, in a move that promises to unify governance practices across sectors, COSO has released a Corporate Governance Framework (CGF) as a Public Exposure Draft. It’s not just a policy document—it’s a strategic blueprint. For compliance professionals, it represents an opportunity to elevate our role from risk mitigators to architects of long-term value. Today, we begin a multipart exploration of the Framework: what you need to know, why it matters, and how it changes the governance game.

The Big Picture: What Is COSO’s Corporate Governance Framework?

At its core, the CGF is a principles-based, integrated governance system that complements COSO’s earlier frameworks for internal control (ICIF) and enterprise risk management (ERM) while extending beyond them. It is designed to guide boards, executives, shareholders, employees, and other stakeholders in aligning governance structures and practices with the creation of long-term value.

The CGF is built around six interdependent components:

  • Oversight
  • Strategy
  • Culture
  • People
  • Communication
  • Resilience

Each Component contains several Principles (24 in total), supported by Points of Focus, Deeper Insights, and Leading-Edge Considerations.

In short, this is not a checkbox approach to governance. It’s a holistic, iterative model that adapts to an entity’s purpose, risk profile, stakeholder expectations, and regulatory landscape.

Why This Framework—and Why Now?

The business case for the CGF is compelling and overdue. COSO makes clear that good governance is no longer just about compliance; rather, it should be seen as a competitive differentiator.

Consider the drivers:

  • Regulatory complexity and fragmentation—Boards face a maze of requirements (state law, SEC rules, listing standards, ESG expectations).
  • Multi-stakeholder capitalism—Long-term shareholder value now demands attention to customers, employees, communities, and ecosystems.
  • Technology disruption—AI, cyber risk, and data ethics—demands new models of oversight.
  • Reputation and trust—Ethics, culture, and transparency are now strategic assets.

COSO’s framework encourages organizations to move beyond the reactive “check-the-box” mindset and embed governance into every aspect, from executive decision-making to workforce engagement.

The Six Components: What Compliance Needs to Know

Now, consider each component through a compliance lens.

1. Oversight

This section reminds us that effective governance starts with the board, not ends there. It focuses on board structure, independence, committee roles, director selection, and accountability.

Compliance takeaway: The audit committee remains central, but boards are encouraged to create or expand roles for risk, technology, ethics, and culture oversight, which is great news for CCOs who want more engagement at the top.

2. Strategy

This is where compliance shifts from gatekeeper to enabler. The CGF pushes alignment between strategy and purpose, with boards and management jointly accountable for development, execution, and course correction.

Compliance takeaway: This is your call to integrate risk and ethics into strategic planning. Be present in the room when business models are reviewed, not after decisions have been made.

3. Culture

The CGF recognizes culture as both a risk and an asset. Boards are expected to model ethical conduct and oversee cultural assessments, while management must embed values into decision-making, hiring, rewards, and performance management.

Compliance takeaway: If culture eats policy for breakfast, this is your lunch menu. From whistleblower protections to leadership coaching, this is your roadmap for making culture measurable and actionable.

4. People

Talent is governance. This Component covers workforce strategy, succession planning, performance management, and incentives. It also underscores the board’s growing responsibility to understand workforce-related risks.

Compliance takeaway: Pay attention to the alignment between values, behaviors, and rewards. Compensation structures are now squarely in the realm of ethical risk, and compliance should have a voice in this area.

5. Communication

Information flow is framed as a governance issue, not just a reporting function. This section covers data quality, internal and external communications, technology platforms, escalation protocols, and stakeholder engagement.

Compliance takeaway: Effective GRC programs rely on reliable data and timely communication to ensure effectiveness. If your systems still rely on spreadsheets and email, the CGF serves as a reminder to modernize.

6. Resilience

This section ties together risk management, compliance, internal controls, and adaptability. It encompasses principles related to compliance ownership, fraud management, third-party risk, and continuous monitoring.

Compliance takeaway: The CGF validates what we already know —that compliance is a pillar of enterprise resilience. However, it also encourages us to adopt more intelligent tools (e.g., risk analytics, AI-driven monitoring, integrated assurance platforms).

What Makes This Framework Different?

Several innovations stand out:

  • Cross-functionality: The CGF is not siloed. Each Component is tied to others through stakeholder dynamics and shared responsibilities.
  • Flexibility with discipline: It’s grounded in principles, not prescriptive rules, making it adaptable across industries and organizational types.
  • The tone throughout the organization: Culture, communication, and people strategies extend well beyond the C-suite.
  • Forward-looking: Technology governance, AI risk, and stakeholder capitalism are not afterthoughts; instead, they are built in.

What Should Compliance Professionals Do Now?

The CGF is in the public exposure draft phase, with comments due by July 11, 2025. You should take the time to respond proactively:

  1. Read it, annotate it, and engage with it. COSO wants stakeholder feedback. If you’re a CCO, CAE, or GRC leader, now’s your chance to shape the future.
  2. Map your current practices to the six components. Where are your gaps? What metrics do you need? Start small, with one principle per quarter, perhaps.
  3. Socialize the CGF internally. Use it to open conversations with HR, IT, legal, risk, and the board. This is not simply a governance framework; instead, it should be viewed as a bridge to enterprise-wide alignment.
  4. Rethink your compliance program as a governance engine, especially in areas such as culture, people, and communication, where compliance can become a valuable partner in strategic execution.

Final Thoughts

COSO’s Corporate Governance Framework is more than a governance tool. It is a leadership manual for the modern era. For those of us in compliance, it validates that our work is not merely about avoiding risk but about enabling performance, trust, and value creation.

In the spirit of the Compliance Evangelist: Preach governance, embed culture, and lead with purpose.

Now, we should all roll up our sleeves and help build the future of corporate governance, one component at a time.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes on July 11, 2025.

Categories
Hill Country Hustlers

Hill Country Hustlers – Building Success and Overcoming Challenges with Ross Dunagan of Flyin’ Diesel Performance

In this episode of the Hill Country Hustlers Podcast, host Zach Green speaks with Ross Dunagan, the owner of Flyin’ Diesel Performance, to discuss his journey from starting a small mom-and-pop shop to growing a thriving business in Kerrville, Texas. Ross shares his background, the challenges he faced starting, and the importance of overcoming fear and leveraging available resources. He delves into the significance of communication, loyalty, and making use of key ratios to ensure business growth. Ross also highlights the evolving nature of leadership and the importance of employee relationships in a successful business. The conversation touches on the rewards of entrepreneurship, the joy of giving back to the community, and the continuous pursuit of personal and professional growth.

Key highlights:

  • Challenges and Overcoming Fear in Entrepreneurship
  • The Importance of Relationships and Networking
  • Managing Growth and Leadership
  • Handling Rapid Business Growth
  • The Role of Communication in Business
  • The Entrepreneurial Spirit

Resources:

Zach Green on LinkedIn

Flyin Diesel Performance

Categories
Compliance Into the Weeds

Compliance into the Weeds: Boeing’s New Safety Initiatives and Compliance Reforms

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Are you seeking insightful perspectives on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss Boeing’s recent safety initiatives and reforms, as outlined in their annual aerospace safety report.

They explore Boeing’s efforts to improve its speak-up culture, internal reporting systems, and the introduction of an expansive Safety Champions Program. The episode explores the procedural changes Boeing has implemented, including the handling of third-party reports and increased transparency for employees. Additionally, they examine the challenges and necessities of manager training in fostering an ethical corporate culture. The conversation concludes with insights on the recent Federal District Court hearing regarding Boeing’s non-prosecution agreement and the implications for transparency and accountability.

Key highlights:

  • Speak Up Culture Enhancements
  • Ambassador Program Expansion
  • Manager Training and Corporate Culture
  • Court Hearing on Boeing’s Non-Prosecution Agreement

Resources:

Matt Kelly in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds, was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – COSO Objective 3 – Control Activities

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we continue our look at the 5 COSO objections. Today, Number III—Control Activities.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Daily Compliance News

Daily Compliance News: June 25, 2025, The PCAOB Elimination Hits Roadblock Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest, all relevant to the compliance professional.

Top compliance stories:

  • DeepSeek is bad, very bad for the US. (Reuters)
  • A global AI divide isn’t coming; it’s here. (NYT)
  • PCAOB elimination hits a roadblock. (WSJ)
  • Tesla was threatened in France for deceptive marketing. (FT)
Categories
Great Women in Compliance

Great Women in Compliance: GWIC X EC Q2 2025 – Exploring Compliance Innovations

We’re back with another GWIC x EC crossover episode. Today, we have the quartet of Great Women in Compliance of Kristy Grant-Hart, Karen Moore, Lisa Fine, and Hemma Lomax.

The GWIC quartet discusses various intriguing topics related to compliance. Lisa Fine kicks off the conversation by discussing the new ‘failure to prevent fraud’ guidance in the UK, which places greater responsibility on companies to avoid engaging in fraud. The group delves into the implications of this law and its extraterritorial elements. Hemma Lomax shifts the conversation to changes in the False Claims Act in the US, highlighting its expanded use beyond fraudulent billing to areas like cybersecurity and diversity obligations. Karen Moore introduces the innovative ‘Karma’ rewards system by Revolut Bank in the UK, which incentivizes compliance behaviors through team performance multipliers. Kristy Grant-Hart wraps up with a fascinating discussion on AI, touching on AI’s potential as a whistleblower and whether AI could attain employment rights if it becomes sentient. They conclude by sharing their rants and raves, offering insights on topics ranging from the importance of local theaters to women’s leadership in compliance.

Join the Great Women in Compliance community on LinkedIn ⁠here⁠

Categories
Blog

The Boeing 737 Max Imbroglio: Part 2 – A Path Forward with a Special Master

In recent weeks, the spotlight has again intensified on The Boeing Company, following a provocative motion filed by families of victims from the tragic 737 Max crashes. They have petitioned a Texas federal judge to appoint a special prosecutor in Boeing’s criminal conspiracy case, arguing fervently against the Department of Justice’s recent Non-Prosecution Agreement (NPA) with Boeing. At stake is not merely corporate accountability but, fundamentally, the integrity of our justice system itself. If all a company is required to do under the Department of Justice (DOJ) is throw money at a series of problems, there will never be true reform.

Yesterday, I began a two-part look at the current set of issues raised in the DOJ capitulation to Boeing, its ignoring of the families of the crash victims, and its complete lack of holding Boeing accountable beyond financial penalties. Today, I want to conclude this short series by proposing a path forward that helps to ameliorate the rights of the parties as well as all the other stakeholders involved in this Boeing imbroglio.

For reasons that are not articulated, the DOJ has dropped its requirement for an Independent Corporate Monitor to oversee the overhaul of culture at Boeing, instead allowing a Boeing-hired compliance consultant to be part of the process. This is wholly insufficient as it requires zero transparency for any of the key parties to the litigation: the families of the victims of the 737 MAX crashes, the Court, and even the DOJ itself. Indeed, the DOJ did not even consult with the families of the victims, as it was reported that the DOJ gave them one day’s notice that it was going to provide Boeing with a Non-Prosecution Agreement (NPA) with no Independent Compliance Monitor.

The significance of an Independent Compliance Monitor tasked with overseeing Boeing’s adherence to compliance and safety protocols over the next three years cannot be overstated. The role of an Independent Compliance Monitor in this case should be expansive. Beyond traditional compliance responsibilities, such as policies, procedures, internal controls, and training, the Independent Compliance Monitor should also address anti-fraud measures, safety, and quality assurance/control (QA/QC) issues. This broader remit is essential, given the systemic failures at Boeing that contributed to the 737 MAX disasters. (Looming, of course, is the 787 Dreamliner crash in India.)

The DOJ previously found disturbing lapses in Boeing’s safety and quality records.  It is unclear whether the DOJ has revised these findings in light of its proposed NPA. Boeing employees reported feeling pressured to prioritize productivity and financial performance over safety and quality, a cultural flaw that contributed to the compliance breaches. This pressure led to out-of-sequence work, poor record-keeping, and inadequate safety audits, all of which are indicative of a deeper systemic problem.

Addressing these issues requires a comprehensive culture-focused approach. An Independent Compliance Monitor must not only enforce existing standards but also foster a culture of integrity and transparency within Boeing. This involves ensuring that employees can report concerns without fear of retaliation and that safety protocols are rigorously followed and documented.

The families of the crash victims are not mere bystanders in this process. They have voiced strong objections to this NPA, particularly its leniency and the lack of accountability for senior executives, as well as for any future actions by Boeing. They argue that the NPA exonerates those responsible for the safety lapses. This concern resonates with many compliance professionals who advocate for robust accountability at all levels of an organization.

In light of the unique facts and procedural history of this matter, judicial oversight will be crucial in ensuring that an Independent Compliance Monitor leads to genuine remediation. Transparency is a cornerstone of effective compliance and accountability, and its absence could undermine the entire process.

This is where the District Court should step in and appoint a Special Master to act as an Independent Compliance Monitor. Under the Federal Rules of Procedure, a District Court can appoint a Special Master to monitor compliance with court orders or settlement agreements. This can be especially useful in cases where the parties have a history of noncompliance or need ongoing oversight. The appointment of a Special Master is a powerful option for this specific fact pattern.

For Boeing to restore its reputation and regain public trust, it must go beyond the minimum requirements of the NPA. This involves a commitment to comprehensive remediation, encompassing cultural change, structural reforms, and rigorous enforcement of safety and compliance standards. All done with transparency.

A Special Master’s remit would be a step in the right direction, but it must be accompanied by genuine transparency and accountability. This includes involving the victims’ families in meaningful ways, such as through regular updates and consultations, and ensuring that their concerns are addressed substantively. In other words, transparency.

The Boeing case serves as a stark reminder of the critical importance of compliance, transparency, and accountability in the corporate world. It highlights the devastating consequences of systemic failures and the urgent need for robust oversight mechanisms. As compliance professionals, we must advocate for comprehensive and transparent processes that ensure not only compliance with legal standards but also the fostering of a culture of integrity and responsibility.

Ultimately, true remediation and accountability are in the best interests of all stakeholders, from the victims’ families seeking justice to the company itself, which strives to rebuild its reputation and restore public trust.  The DOJ has completely abrogated its role in this moving forward. However, the District Court can facilitate this process by appointing a Special Master who can act as an Independent Compliance Monitor.

The path forward is clear: there must be a firm commitment to rigorous compliance, transparent practices, and a culture that prioritizes safety and integrity above all else. However, this must be accompanied by independent oversight. If the DOJ does not wish to assume this role, the District Court should consider appointing a Special Master. Only then can it hope to move beyond the shadows of the 737 MAX scandal and emerge as a leader in the aviation industry once again.

Categories
Blog

The Boeing 737 Max Imbroglio: Part 1 – The DOJ Ditches Transparency

In recent weeks, the spotlight has again intensified on The Boeing Company, following a provocative motion filed by families of victims from the tragic 737 Max crashes. They have petitioned a Texas federal judge to appoint a special prosecutor in Boeing’s criminal conspiracy case, arguing fervently against the Department of Justice’s recent Non-Prosecution Agreement (NPA) with Boeing. At stake is not merely corporate accountability but, fundamentally, the integrity of our justice system itself. Today, I begin a two-part look at the current set of issues raised in the DOJ capitulation to Boeing, its ignoring of the families of the crash victims, and its complete lack of holding Boeing accountable beyond financial penalties.

The victims’ families and the general flying public represent crucial stakeholders who deserve answers, accountability, and assurances of safety. Disturbingly, the DOJ’s actions appear dismissive of these stakeholders. This lack of consideration significantly undermines public confidence in Boeing and the effectiveness of regulatory enforcement.

The victims’ families seek accountability, including criminal charges for executives, strict compliance oversight, and transparency to prevent future disasters.  Instead, they have received a diminished settlement and an opaque independent consultant, leaving them rightly skeptical and outraged, all of which occurred without any meaningful consultation with the DOJ. At its core, the families argue, the DOJ’s latest move sets a hazardous precedent, allowing corporations essentially to circumvent accountability through financial settlements and carefully crafted agreements.

The current controversy revolves around the DOJ’s decision to dismiss a conspiracy charge under the conditions outlined in the $1.1 billion NPA. This agreement, critics assert, permits Boeing to effectively “buy its way out of a criminal conviction,” marking a disturbing shift in how corporate criminal cases might be handled going forward.

The families’ legal representatives have raised compelling arguments about why the NPA represents a perilous deviation from standard judicial procedures. Specifically, their motion asserts that the NPA dangerously erodes the separation of powers by attempting to bypass the judicial review requirement mandated by the Federal Rule of Criminal Procedure 48(a). Such maneuvering, the families contend, could become a worrying precedent that effectively creates a new branch of governmental power, immune to the checks and balances essential to American governance.

Moreover, this case highlights critical issues surrounding the Crime Victims’ Rights Act (CVRA), legislation designed to ensure victims and their families are treated fairly throughout judicial proceedings. The families argue passionately that the NPA, in its current form, diminishes their statutory rights and sidesteps meaningful accountability, thus undermining the broader principles of justice.

Equally concerning is Boeing’s historical engagement with DOJ agreements. Initially, under a Deferred Prosecution Agreement (DPA) brokered in 2021, Boeing pledged reforms and accepted specific responsibilities. However, a disturbing mid-air incident involving a Boeing 737 Max 9 jet in January 2024 revealed serious safety oversights and compliance deficiencies, prompting the DOJ to reexamine Boeing’s commitments. Boeing’s readiness to plead guilty evaporated swiftly when the political landscape appeared favorable, a clear indication, families argue, that the aerospace giant’s commitments were strategic rather than genuine.

This raises fundamental questions about corporate culture, accountability, and oversight. Compliance professionals everywhere must consider: What mechanisms truly ensure meaningful corporate reform? Can performative contrition substitute for authentic, monitored change?

Under the revised NPA, Boeing has agreed to pay significant fines and allocate funds to victim compensation and program enhancements for compliance. Yet notably absent from this agreement is any oversight mechanism akin to the independent compliance monitor stipulated in previous arrangements. Instead, Boeing must merely retain an independent compliance consultant, a far softer requirement and one that has rightly alarmed observers concerned with genuine reform.

From a compliance standpoint, the removal of the independent monitor provision is a clear red flag. Monitors are essential to verifying that changes implemented within a corporation are genuine, sustained, and effective. By settling for a consultant rather than an empowered, independent monitor, the DOJ is creating an environment that is ripe for surface-level reforms that fail to address deeply rooted, systemic issues.

This scenario underscores a crucial lesson for corporate compliance professionals: genuine compliance reforms cannot rely solely on internal assurances or perfunctory oversight. Rigorous external verification mechanisms are essential to ensuring that compliance efforts are meaningful, impactful, and sustained over the long term. The bottom line is that transparency is the key, and this DOJ has completely deleted any Boeing requirement for transparency in its remediation process.

Furthermore, this case illustrates the importance of judicial independence and the robust application of oversight principles. Without vigilant oversight, corporations could increasingly perceive settlements as mere financial calculations rather than genuine opportunities to recalibrate organizational ethics and compliance cultures. Compliance professionals must advocate for and implement frameworks that prioritize meaningful oversight and genuine reform.

As compliance leaders, we must recognize the far-reaching implications of the Boeing case. This case serves as a stark reminder that true corporate reform cannot be bought—it must be earned through demonstrable, monitored change. Regulators and justice departments globally must hold corporations accountable not just financially but also operationally and culturally.

The demand by the victims’ families for a special prosecutor highlights a crucial juncture. Will we endorse a system where accountability is negotiable and oversight diluted? Or will we reaffirm the essential tenets of justice, ensuring robust judicial review, stringent oversight of compliance, and genuine corporate reform?

Boeing’s future actions, closely scrutinized, will reflect its genuine commitment to change. Compliance professionals, corporate leaders, and regulators alike must take heed—reform without rigorous oversight is merely an empty promise. The integrity of corporate compliance demands far more.

Ultimately, the Boeing case offers a powerful lesson: the pursuit of meaningful corporate compliance and ethical integrity requires more than financial penalties; it demands transparency, accountability, and true oversight. For corporations, anything less risks not only reputational harm but also the profound erosion of public trust, which is essential to long-term sustainability.

Tomorrow, we will explore a court-imposed solution to this imbroglio.