Categories
Compliance Into the Weeds

Compliance into the Weeds: Governing Agentic AI: DFS Cyber Risk Assessments, EU AI Act Accountability, and the Inventory Problem

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore them fully and uncover hard-hitting compliance insights. Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the growing compliance and cybersecurity challenges posed by agentic AI.

 

They focus on New York Department of Financial Services (DFS) guidance on cybersecurity risk assessments and a European survey Kelly cites. They argue DFS’s rule, requiring annual or as-needed reassessments after significant technology and threat changes and maintaining an accurate IT asset inventory, implicitly compels organizations to identify and track AI agents, even though agents are not mentioned. Kelly cites a Veeam Software survey of 1,000+ European executives reporting limited visibility into employee-created autonomous AI workflows and AI interactions with sensitive data, complicating EU AI Act requirements for human accountability. The conversation compares potential governance models to Sarbanes-Oxley sub-certifications and enterprise software management, questions whether CISOs can certify compliance amid decentralized agent creation, and notes potential enforcement avenues and the risks of industry self-regulation.

Key highlights:

  • Why DFS Guidance Matters
  • Risk Assessments Meet Agents
  • Accountability Under EU AI Act
  • SOX Style Governance Model
  • Enforcement and Self-Regulation

Resources:

Matt in Radical Compliance (2 posts)

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcasts, and a Top 12 Risk Management Podcasts. Compliance into the Weeds has received Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
AI Today in 5

AI Today in 5: September 16, 2026, The False Choice Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. The difference between AI pilots and AI. (Federal News Network)
  2. AI for Supply chain compliance. (ESG News)
  3. AI governance is pressing in healthcare. (Healthcare IT News)
  4. Enterprise AI enters a new era in banking. (FinTech Futures)
  5. Jensen Huang says you can have AI innovation and safety. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Great Women in Compliance

Great Women in Compliance: Setbacks, Second Acts, and A Return to Purpose

Sarah Hadden sits down with Cindy Hennessy for a candid, funny, and deeply human conversation about career loss, reinvention, and what can happen when the next chapter of your life isn’t the one you planned. Cindy talks openly about being laid off late in her career—and refusing to let her employer call it “retirement”—and the long “hallway” between that ending and the unexpected opportunity that eventually brought her full circle to mission-driven work at Make-A-Wish. Along the way, Sarah and Cindy talk about resilience, the luxury and importance of waiting for work that aligns with your values, the surprising gifts that can come from rejection, and the power of writing to help us make sense of difficult experiences. There’s also an emotional-support Pomeranian, a lifelong love affair with the Oscar Mayer Wienermobile, and a reminder that sometimes joy, hope, and a willingness to laugh at yourself are pretty good tools for navigating whatever comes next.

Takeaways:

  • Losing a job can be deeply personal—especially when work has been an important part of your identity—and there’s no reason to sanitize the experience or pretend it didn’t hurt.
  • Cindy describes the uncertain period after a major life disruption as “the hallway”: one door has closed, the next hasn’t opened yet, and sometimes the only way forward is simply to live through the space in between.
  • A late-career transition can also create an opportunity to get much more intentional about what you want—including the freedom to say no to work that doesn’t align with your values.
  • Cindy’s path back to Make-A-Wish, where she had worked 25 years earlier, wasn’t something she carefully engineered. In fact, she initially wasn’t sure she wanted the job—a good reminder to stay open to possibilities that don’t look quite right at first.
  • Mission matters. After years of interesting but sometimes less personally aligned work, Cindy talks about the joy of using her experience to serve an organization whose purpose she deeply believes in.
  • Writing has been one of Cindy’s lifelong tools for processing difficult experiences. She shares her experience with the 100-Day Reckoning, a structured writing practice that helped her step outside a painful situation and find greater perspective, kindness, and understanding.
  • Reinvention doesn’t necessarily mean chasing another bigger title. Cindy is deliberately thinking about how to do meaningful work while also making more room for travel, friends, family, writing, Mahjong—and eventually a life that isn’t organized around a W-2.
  • And finally: Never give up on the Wienermobile. Cindy certainly hasn’t.
Categories
Blog

Does Your Board Have the Expertise and Independence to Oversee Compliance

A board can have impressive credentials and still lack the experience needed to challenge management on the company’s most significant compliance risks. Directors may understand finance, strategy, and operations in broad terms while struggling to recognize how misconduct could arise within a particular business model. Effective oversight requires relevant knowledge and the willingness to use it when the answers become uncomfortable.

For the chief compliance officer, that makes board capability a practical program issue. The quality of oversight influences the questions management must answer, the resources compliance receives, and what happens when a concern conflicts with a commercial priority. Today we examine board composition in the article Measuring Board Fit — Evidence from Elliott’s Campaign at Norwegian Cruise Line, from the Harvard Law School Forum on Corporate Governance. Their analysis uses AI to compare directors’ professional backgrounds with company strategy and with one another. It offers a starting point for a broader compliance question: Does this board have the expertise and independent judgment to oversee the risks this company actually faces?

Look Beyond the Skills Matrix

DesJardine and Mertens argue that conventional skills matrices can conceal meaningful differences in experience. Two directors may receive the same designation for operations or risk management while bringing very different capabilities to the boardroom.

The compliance application is straightforward. A risk management designation should prompt further inquiry into the nature, relevance, and recency of that experience. Has the director overseen a business using intermediaries in difficult markets? Has the director managed the integration of acquired companies? Examined an investigation involving senior leadership? Challenged a compensation structure that encouraged questionable conduct? No director needs to possess every capability. The board and its committees do need an informed basis for questioning management across the company’s priority risks.

The CCO can help define that basis. Translate the risk assessment into the experience and understanding needed for oversight. Where third-party conduct creates substantial exposure, explain the commercial relationships, payment practices, and escalation decisions directors need to understand. This gives the nominating and governance committee a more useful description than a generic request for compliance expertise.

Read the Norwegian Findings Carefully

The authors apply their method to Norwegian Cruise Line Holdings before and after Elliott Investment Management’s campaign, comparing its board with those of three cruise industry peers. They report that the company’s board-to-company similarity score increased from 0.382 to 0.396 following the changes. Average director-to-board similarity declined from 0.729 to 0.701, which they interpret as more distinct professional perspectives.

Those results describe changes in the authors’ measures of professional alignment and overlap. They do not establish that the reconstituted board became more effective at compliance oversight, that individual directors exercised greater independence, or that misconduct risk declined. That distinction matters for CCOs. An assessment can identify questions about composition without answering how directors perform. A board with relevant backgrounds still needs reliable information, sufficient time, and the resolve to follow an issue through. The practical response is to combine an examination of credentials with evidence of the board’s oversight process.

Examine Independence Through the Oversight Process

The authors acknowledge that their method cannot assess integrity, interpersonal skills, or willingness to challenge a chief executive. Those limitations point directly to the independent judgment compliance oversight requires. Consider a hypothetical board discussion about a distributor generating substantial revenue while repeatedly failing to provide requested ownership information. Management recommends extending the relationship during further review. A director with relevant experience may recognize how significant the missing information is. The next question is whether the board presses management to explain the proposed safeguards, decision authority, and consequences of continued delay.

The CCO should help create the conditions for that discussion. Present the facts, uncertainties, available options, and recommendation clearly. Identify who owns the decision and what would trigger escalation. Provide access to the underlying analysis where needed.

Direct access to the responsible committee and opportunities for discussion without management present can support candid oversight. Follow-up is equally important. An unresolved concern should return with updated evidence and a clear account of management’s actions. A difficult question has value when the governance process ensures it receives an adequate answer.

Make Expertise Usable Through Better Information

Even an experienced director can struggle with reports that emphasize activity while obscuring unresolved risk. Assess board capability and reporting quality together. A presentation may show that due diligence reviews are complete without explaining the exceptions approved. Investigation statistics may omit repeated issues within one business unit. Remediation updates may describe actions as finished without showing whether the revised controls work.

A CCO should organize reporting around decisions and consequences. Explain the issue, the evidence, management’s response, and what remains unresolved. When a commercial objective conflicts with a compliance recommendation, make that tension clear. Directors can then apply their experience to a concrete problem. Does the proposed response address the cause? Is the responsible executive accountable for delivery? What evidence will show that the correction is working? These questions help convert professional knowledge into oversight of program effectiveness.

Preserve Perspectives That Challenge Assumptions

The authors examine both alignment with company strategy and similarity among directors. That combination highlights a tension: a board needs relevant experience while retaining perspectives that question the organization’s assumptions. For compliance, industry familiarity can help a director spot questionable practices. It can also leave accepted business conventions insufficiently examined. Experience from another sector may expose weaknesses in customer treatment, escalation, or control ownership that insiders have normalized.

A CCO should therefore avoid equating a closely matched background with superior judgment. Ask what the board needs to understand and where a different perspective could improve its questions. Director education can help close specific knowledge gaps. Sessions built around the company’s actual processes, anonymized matters, and emerging business changes can give directors a better foundation for challenge. Persistent gaps may also warrant discussion of committee expertise or board recruitment, with those decisions remaining with the appropriate governance bodies.

Use AI Assessment as a Diagnostic Input

DesJardine and Mertens use contextualized word embeddings, a technique that turns text into numerical representations, to compare professional and company profiles. The approach can surface similarities that broad categories miss. For a board considering such analysis, the CCO and governance team should ask what information supports each profile and what the resulting score actually measures. Public biographies and media coverage provide an incomplete record of a director’s contributions. The volume and character of available material may differ substantially between candidates.

Company disclosures also describe the organization through a particular lens. Similarity to that description does not necessarily establish the expertise needed to address an overlooked risk or challenge an unsuccessful strategy. Use the output to inform interviews, reference discussions, and committee deliberations. Ask how sensitive the result is to source selection and whether the underlying evidence supports the interpretation. Record significant limitations. A numerical score should help the board investigate a capability question; appointment and evaluation decisions require accountable human judgment.

Action Steps for the CCO

Bring a practical assessment of oversight capability to the next discussion with the committee chair:

  1. Map priority risks to oversight knowledge. Identify what directors need to understand about the company’s business practices, controls, and escalation decisions.
  2. Provide evidence of capability gaps. Work with the corporate secretary and general counsel to inform education and composition discussions, using specific examples rather than broad labels.
  3. Strengthen the conditions for independent challenge. Establish clear access, candid reporting, and follow-up arrangements for unresolved concerns, including matters involving senior management.
  4. Test the usefulness of board reporting. Ensure directors can see material exceptions, recurring issues, remediation evidence, and decisions requiring their attention.
  5. Apply scrutiny to AI assessments. Examine source quality, missing information, and the limits of similarity measures before incorporating results into governance decisions.

Effective compliance oversight depends on directors who understand the company’s risks and are prepared to question how management addresses them. The CCO can strengthen that oversight by making capability needs explicit and ensuring the board receives the evidence needed to exercise its judgment.

Categories
Daily Compliance News

Daily Compliance News: September 15, 2026, The Bureaucratic Zeal Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Collapse of the ‘Montessori Ponzi.’ (NYT)
  • Winning big on Polymarket against KPMG clients. (WSJ)
  • Ex-Ukraine PG accuses ABC chief of falsifying documents. (Meduza)
  • Prince Michael of Liechtenstein says AML disclosure rules have gone too far. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
AI Today in 5

AI Today in 5: September 15, 2026, The Medical AI Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. What’s holding back AI in financial services? (FinTech Global)
  2. EU demands AI companies meet safety requirements. (The Jerusalem Post)
  3. Data quality is holding back AI in banks. (Asian Banking & Finance)
  4. Cybersecurity enhanced with AI. (FinTech Magazine)
  5. Trump Administration moving to deploy AI in medicine. (NYT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Innovation in Compliance

Innovation in Compliance: Mara Senn on Vibe Coding a Credible Investigations Platform

Innovation comes in many areas, and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom welcomes Mara Senn, Founder and CEO of Ethakos.

What is innovation in compliance? Mara Senn certainly shows it in this podcast. Her path to founding Ethakos spans Big Law, early FCPA and anti-corruption work, investigations at the World Bank, and senior in-house compliance roles at major Fortune 500 companies. That experience gave her a clear view of the everyday frustrations compliance teams face, especially clunky tools, dirty data, and rigid workflows that slow down real investigations. She built Ethakos as an AI-native, highly configurable platform to solve those pain points, using “vibe coding” with Claude to move quickly while keeping human judgment at the center of every decision. In her view, the platform reflects a simple but powerful idea: AI should make compliance work faster and cleaner, not replace the expertise and risk-based thinking that good compliance professionals bring.

Key highlights:

  • Vibe coding Ethakos through dozens of decisions
  • Start with actionable hits, not meaningless alerts
  • AI-generated first drafts for chronologies and interviews
  • Audit logs and document-linked investigative credibility
  • Tech-forward compliance teams identifying 13 risks instead

Resources:

Ethakos

Mara Senn on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

Setting the Right Ambition for Your Compliance Strategic Plan

A compliance strategic plan should explain how the function will build the capabilities the business needs to manage its risks. That requires choices about priorities, resources, authority, and execution. A plan can fall short by asking the organization for too little. It can also promise more than the company is prepared to support.

Consider a CCO preparing a three-year plan while the company expands through acquisitions and new distribution channels. The proposed compliance plan calls for refreshed policies, additional training, and a new monitoring platform. Each initiative may be useful. But does the plan address the integration gaps and third-party decisions that expansion will create? And has anyone committed the people, data, and funding needed to deliver it?

Rebecca Knight explores the calibration of strategic ambition in “Is Your Strategic Plan Too Ambitious? Or Not Ambitious Enough? In the Harvard Business Review. Her article draws on insights from Columbia Business School’s Sheena Iyengar and MIT Sloan School of Management’s Donald Sull. Their discussion provides a useful foundation for examining the compliance function’s strategy. The compliance applications below build on that discussion.

Define the Problem Before Setting the Target

Knight begins with Iyengar’s advice to identify the problem a strategy must solve before debating the ambition of its targets. For CCOs, this discipline matters because familiar deliverables can substitute for a clear diagnosis. Take a goal to increase training hours. What problem requires that increase? Employees may misunderstand an approval requirement. They may understand it perfectly but lack a workable way to obtain approval before a commercial deadline. Those conditions require different responses.

The strategic plan should connect each major initiative to an identified weakness or emerging business need. If acquisitions repeatedly leave the company with incomplete third-party records, define the intended capability: an integration process that establishes ownership, identifies missing information, and escalates unresolved risks within a specified period. This gives management a concrete outcome to fund and the board a meaningful basis for oversight.

Develop Alternatives Before Committing Resources

Knight reports Iyengar’s recommendation to consider several distinct approaches so leaders can see their trade-offs. A CCO can apply this by requiring alternatives for the plan’s largest investments. Suppose the objective is better third-party monitoring. One option might strengthen existing reviews and accountability. Another might integrate procurement and payment data. A broader approach might redesign the third-party lifecycle, including who can engage an intermediary and what evidence permits renewal.

Compare the options against the actual problem, implementation demands, and expected improvement. A technology purchase may be appropriate, but its value depends on the process and information supporting it. This exercise also exposes insufficient ambition. If every option preserves the same fragmented ownership that created the problem, the CCO has reason to question whether the proposed change goes far enough. A major redesign also needs stronger justification than an attractive vision of a fully integrated program.

Make Resource Commitments Explicit

Sull’s resource argument, as Knight presents it, is that substantial strategic change can require moving money and talent away from existing commitments. That has direct implications for compliance planning. CCOs often describe new responsibilities without specifying which existing activities will change. A team already handling investigations, advice, training, and monitoring cannot absorb unlimited transformation work simply because the strategic plan assigns it a deadline.

For each major initiative, identify the required budget, expertise, business participation, and implementation time. Explain what can be simplified or discontinued and what must remain protected. Required controls and essential response capacity need explicit provision during the transition.

Dependencies deserve the same attention as the compliance budget. If success requires information technology support, procurement process changes, or finance data, obtain named owners and documented commitments. Where a critical commitment is missing, describe the resulting limitation in the proposal presented to leadership. Your board should be able to see the relationship between the approved ambition and the resources management has committed.

Build Capability Around the Business Strategy

Knight’s discussion of staffing emphasizes the expertise needed to execute a bold plan. Applied to compliance, the question extends beyond headcount to the capabilities the company’s direction requires. Acquisition-led growth may require stronger integration management. Expansion through distributors may require regional knowledge and commercial experience. A monitoring initiative may require data analysis, systems access, and people who understand how transactions occur.

Map the company’s major strategic moves to their compliance implications, then identify the skills and authority needed to respond. This helps the CCO explain why the function needs particular capabilities and when those capabilities must be available. Business alignment also requires independence of judgment. The plan should enable informed decisions about growth while preserving the CCO’s ability to challenge unsupported assumptions, escalate concerns, and identify conditions that should be met before proceeding. Management owns the commercial strategy; compliance must be equipped to assess and address its implications.

Use Pilots With Clear Decision Rules

Knight describes experimentation as a way to pursue ambitious goals while learning through smaller steps. A compliance plan can use that approach to improve processes and build new capabilities. For example, a proposed monitoring method could begin in one business unit. Before launch, define the information required, the existing controls that remain in place, the people responsible for reviewing results, and the conditions for expansion or revision.

The pilot should answer a specific question. Does the method identify relevant exceptions? Can the business resolve them? Are the results dependable enough to support decisions? A successful software demonstration alone does not answer those questions. Set a review date and a decision owner. Without those commitments, a pilot can continue indefinitely, consuming resources while providing little clarity about whether the broader strategic objective is achievable.

Measure Progress Toward a Working Capability

Knight connects a longer strategic horizon with measurable interim progress. This is particularly useful for compliance improvements that require changes across functions and systems. A multi-year goal to improve acquisition integration could include quarterly milestones for establishing ownership, validating acquired third-party records, addressing priority exceptions, and testing whether the revised process works on a subsequent acquisition.

Select measures that reveal both implementation and performance. Completing a procedure establishes that something was produced. Evidence that business teams use it, resolve exceptions, and escalate overdue actions helps show whether the capability is functioning.

Establish a baseline before claiming improvement. Faster review times need context about review quality. Fewer exceptions need context about detection coverage. Report limitations alongside results so management and directors can distinguish progress from incomplete information. The strategic plan should also specify when it will revisit assumptions. A major acquisition, a new business model, or a material change in available resources may require revised priorities and sequencing.

Give the Board Decisions It Can Assess

Board oversight becomes more useful when the CCO presents the choices behind the plan. Directors need to understand the priority problems, the proposed response, the resource commitments, and the consequences of delay.

A practical strategy discussion should explain what the function expects to accomplish, what depends on other executives, and what remains outside the funded scope. Where alternatives exist, show their implications for timing and capability. This gives the board a basis to challenge both overpromises and underinvestment. It also establishes what management should report back as the plan proceeds.

Action Steps for the CCO

Use the next planning review to test whether ambition and execution are aligned:

  1. Define the priority problems. State the business risk or capability gap behind each major initiative and the evidence supporting its priority.
  2. Compare credible alternatives. Examine different ways to achieve the intended outcome, including their costs, dependencies, and implementation demands.
  3. Secure resource commitments. Identify accountable business partners, required expertise, funding, and the activities that must change to make room for execution.
  4. Set milestones and decision points. Establish baselines, measures, pilot criteria, and dates for reassessing assumptions.
  5. Present the choices to the board. Explain the funded scope, unresolved dependencies, and consequences of deferring priority capabilities.

A sound compliance strategy makes a demanding but supportable commitment to improving how the company manages risk. The CCO’s responsibility is to make that commitment specific enough to execute, measure, and oversee.

Categories
Red Flags Rising

Red Flags Rising: M&A and Export Controls – From Art of War to Art of the Deal

Mike and Brent revisit a discussion recorded in May 2026, before the prior US-China trade summit, which is timely again with the next round of meetings coming up on September 24, 2026. They also highlight their May 2026 national security enforcement and compliance event in Washington, DC, where Assistant Secretary for Enforcement David Peters spoke. Then they discuss how companies can best manage US export control risks in the context of M&A pre- and post-acquisition due diligence.

Specifically, Mike and Brent set the stage for the M&A discussion (01:49); preview what Sun Tzu’s Art of War means for the upcoming negotiations (03:50); provide a recap of their May 5, 2026, national security compliance and enforcement event in Washington, DC, and the key takeaways from the event in terms of M&A and export controls (05:36); discuss Brent’s recent NYU Program on Corporate Compliance & Enforcement (PCCE) article and how Brent’s Fraud Four-Circle Framework (SM) can help with pre-acquisition due diligence based on some anecdotal evidence from his own experience (10:32); some anecdotes from Mike’s experience (14:43); how export controls now pose “central compliance risks” in terms of boards of directors’ duty of oversight under Delaware law (20:35); and how these ideas can help sellers, not just buyers (23:36);

Mike and Brent then conclude with the latest installment of Brent’s “Managing Up” segment (24:41).

Contact Brent: brent@redflagsrising.com

More about Brent: www.redflagsrising.com/founder

Connect with Brent on LinkedIn

Brent’s article referenced in the episode: Brent Carlson, “A Light Shines Through the Darkness in Disputes, Investigations, and Trade Compliance: A Fresh Look at the Classic Fraud Triangle with the Fraud Four-Circle Framework℠,” NYU PCCE (Jan. 8, 2026)

Contact Mike: michael.huneke@morganlewis.com

More about

Mike: https://www.morganlewis.com/bios/michaelhuneke

Connect with Mike on LinkedIn

Categories
FCPA Compliance Report

FCPA Compliance Report: Michelle Tavares on Why Compliance Teams Need EB-5 on Their Radar

In this episode, Tom Fox welcomes Michelle Tavares, a former federal government forensic accountant and former USCIS EB-5 compliance officer who helped rewrite the EB-5 statute into the Reform and Integrity Act (RIA).

Tavares explains EB-5 as an investor visa program where foreign nationals invest $1,000,000 (or $800,000 in a TEA) in U.S. projects that must create jobs, and she describes how EB-5 transactions sit at the intersection of immigration, securities, banking/AML, and corporate governance, making consistent documentation and a unified “story” critical for adjudication. She outlines the roles of regional centers, NCEs, and JCEs; the challenges of proving a lawful source of funds; and the importance of third-party oversight, KYC/AML controls, and tone-from-the-top governance. She discusses how RIA added compliance expectations, penalties, and increased scrutiny of regional centers and overseas promoters, and shares why she founded Standard & Proof Investigations to close knowledge gaps in EB-5 compliance.

Key Highlights:

  • EB-5 Basics and Why It Matters
  • RIA Overhaul and New Compliance
  • Inside the Adjudicator Mindset
  • Boardroom Governance for EB-5
  • Third-Party Oversight Essentials

Resources:

Standard & Proof Investigations

Counsel Ready

Michelle Tavares on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.