Categories
Blog

Connected Compliance: Part 1 – Communication as the Operating System of Compliance

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. Over this four-part blog post series, we will examine those connections, beginning with the discipline that makes every other element work: communication.

Compliance professionals often describe communication as one element of a program. That description is too narrow. Communication is the operating system through which employees learn expectations, seek advice, identify risk, report concerns, and judge whether management means what it says. If that system is slow, generic, inaccessible, or untrusted, even well-designed controls can fail in practice.

This matters because a compliance program does not become effective when a policy is published or training is completed. It becomes effective when an employee facing pressure knows what to do, understands where to go, and believes that asking for help will not create a career problem. Communication is therefore not simply messaging. It is a preventive control, a detection mechanism, and a source of management information.

Communication Is a Control, Not a Campaign

Many organizations still approach compliance communication as a calendar exercise. They send a Code of Conduct message, deliver annual training, publish a hotline reminder, and count distribution. Those activities may be necessary, but they do not establish whether the message reached the employee at the moment of risk.

An effective communication control has four characteristics.

  1. It is accessible, so employees can find guidance without having to navigate a maze.
  2. It is relevant, so examples reflect the decisions employees actually face.
  3. It is interactive so that employees can ask questions and test judgment.
  4. It is responsive, so the organization uses employee feedback to improve policies, training, and controls.

These distinctions are important. A campaign pushes information out. A control creates a reliable exchange of information. That exchange gives compliance an early view of confusion, pressure, process weakness, and emerging misconduct. It also gives employees a practical path to lawful and ethical decisions.

What the DOJ Is Really Asking

The Department of Justice has moved the compliance discussion away from paper design and toward operational effectiveness. The three fundamental questions in the 2024 Evaluation of Corporate Compliance Programs (ECCP) examine the program’s design, empowerment, and whether it works in practice.

For culture, the DOJ asks, “Does the company seek input from all levels of employees?” It then asks, “What steps has the company taken in response to its measurement of the compliance culture?” Those questions place two obligations on compliance. First, the company must listen across levels, functions, and locations. Second, it must demonstrate that listening changed something. Data without response is observation, not effectiveness.

The ECCP also directs prosecutors to examine policy accessibility, training effectiveness, the availability of guidance, and whether employees know when to seek advice. Taken together, these questions make communication evidence. A company should be able to show not only what it said but also who could access it, whether employees understood it, how they used it, and what management learned from it.

Build Channels Around Employee Behavior

Employees do not experience the company through a single channel. They communicate through managers, messaging platforms, internal websites, employee groups, town halls, mobile devices, and informal workplace networks. A compliance program that relies on one formal channel will miss important signals.

The practical response is a channel portfolio. Policies should be searchable and written in language employees can use. Guidance should be available through live compliance contacts and appropriate digital tools. Reporting options should include the hotline, web intake, direct contact with compliance or human resources, and management escalation. Communications should reach operational employees who may not sit at a computer, as well as global employees who may face language or cultural barriers.

Compliance also needs to listen where employees are already speaking. That may include internal collaboration channels, employee surveys, focus groups, office visits, and patterns in questions received by the compliance team. Any monitoring must be consistent with law, privacy expectations, company policy, and records-management requirements. The goal is not surveillance. The goal is to understand the employee experience before a cultural weakness becomes a control failure.

Face-to-face contact remains especially valuable. A visit to a business unit can reveal whether employees understand a policy, whether managers create pressure, and whether the local process matches the written procedure. It also changes how employees see compliance. A familiar adviser is easier to contact than a distant function that appears only during training or an investigation.

Replace Training Completion With Decision Readiness

Completion rates answer whether an employee opened a course. They do not answer whether the employee can recognize a conflict, challenge a questionable payment, escalate an export-control concern, or pause the use of an unapproved AI tool. As Hui Chen continually reminds us, it is about results, not inputs.

Training should therefore be built around decision readiness. Scenario-based sessions allow employees to work through realistic gray areas and explain why one course of action is safer than another. Shorter, targeted modules can address risk by role. Experienced employees may be able to demonstrate proficiency through testing, while supervisors may require additional training because they receive concerns and translate policy into daily conduct.

Relevance is a control feature. Employees are more likely to retain training that reflects their workplace, business model, and actual risk. A procurement team needs different scenarios from a sales team. A manager needs to understand retaliation and escalation. An engineer needs clear boundaries around data, cybersecurity, and AI. Localization must also address more than translation. Examples, delivery methods, and escalation paths should make sense in the local operating environment. The measurement should move beyond completion. Useful indicators include questions asked after training, repeat areas of confusion, scenario performance, requests for advice, policy-page use, control exceptions, and whether similar misconduct declines over time.

Make Leadership Visible and Consistent

Tone at the top loses force when it sounds scripted or appears only once a year. Employees judge leadership commitment through repeated choices: which risks receive attention, whether high performers are disciplined, whether managers welcome questions, and whether business pressure routinely overrides control requirements.

Compliance communication is stronger when leaders explain expectations in their own voices and connect them to business responsibilities. The chief executive can frame integrity as part of strategy. Finance can address books and records. Human resources can speak to respect, retaliation, and accountability. Business leaders can explain why escalation protects customers and sustainable growth.

Middle management is equally important. Most employees experience culture through their direct supervisor. Managers should be trained to receive concerns, avoid promises they cannot keep, protect confidentiality, escalate promptly, and prevent retaliation. If employees hear an ethical message from senior leadership but experience dismissal from a supervisor, the local message will win. Consistency completes the control. The organization must apply standards across rank, geography, and commercial importance. Unequal treatment communicates more powerfully than any policy statement.

Use Data Without Losing the Human Signal

Technology can help compliance measure reach and engagement. Policy-page analytics can show whether employees use key resources. Digital guidance tools can identify common questions. Investigation and reporting data can reveal trends by issue, region, or function. Training results can show where judgment remains weak.

These data points should be treated as signals, not verdicts. High question volume may indicate confusion, but it may also show that employees trust compliance. An increase in reports may reflect more misconduct, a successful awareness campaign, or greater confidence in the reporting process. Low reporting may indicate a healthy environment, or it may be a warning that employees believe speaking up is futile.

The best analysis combines quantitative and qualitative evidence. Compliance should compare usage data with employee interviews, survey responses, investigation themes, audit findings, exit information, and observations from business partners. It should protect privacy, limit access, and avoid metrics that encourage the wrong behavior. A target that simply seeks fewer reports can suppress the very information the company needs.

Convert Listening Into Action

The strongest evidence of culture is not the survey itself. It is what the company does next. If employees cannot find a policy, redesign access. If repeated questions reveal ambiguity, rewrite the guidance. If a region reports little despite known risk, test for fear or channel barriers. If investigations identify manager misconduct, adjust training, incentives, supervision, and discipline.

This requires a closed-loop process. Gather information. Analyze it for themes and root causes. Assign ownership for action. Document the decision. Communicate appropriate changes. Then measure whether the change worked. That process turns communication into continuous improvement and creates a defensible record of program evolution.

It also connects this first installment to the rest of the series. Employee questions and reporting patterns are early risk indicators. Investigation quality tells employees whether the company acts on what it hears. Whistleblower-program credibility determines whether critical information enters the system at all. Each element depends on the others.

From Culture to a Shifting Risk Environment

Communication gives compliance something more valuable than reach. It provides intelligence. Questions about a new market, an AI application, a third party, a customer demand, or a supply-chain disruption may be the first evidence that the risk environment has changed.

Join us tomorrow for our next installment, where we will examine how compliance can convert those signals into dynamic risk assessment, clear ownership, and adaptive controls. A shifting risk environment cannot be managed by an annual exercise alone. It requires the listening discipline established here.

Bonus Questions for Compliance Professionals

  1. Can employees find practical guidance at the moment they face a risky decision?
  2. Which groups, locations, or shifts are least engaged with compliance resources, and why?
  3. What evidence shows that employee feedback has changed the program?
  4. Are managers prepared to receive concerns, escalate them, protect confidentiality, and prevent retaliation?
  5. Do current metrics reward learning and trust, or do they unintentionally reward silence?
  6. What recent employee question should be treated as an emerging-risk signal?
Categories
Sunday Book Review

Sunday Book Review: July 26, 2026, The Top Books on Environmental, Science and Tech Edition

In the Sunday Book Review, Tom Fox considers books that would interest compliance professionals, business executives, or anyone curious about the subject. It could be books about business, compliance, history, leadership, current events, or any other topic that might interest Tom. In this episode, we look at 4 top books on Environmental, Science and Technology for the summer of 2026.

  1. Control Science by Henry Snow
  2. Incorruptible by Eric Ries
  3. Adrift in the South by Xiao Hai
  4. House of Fidelity by Justin Baer

Resources:

The Best Summer Books of 2026: Environmental, Science and Technology in the Financial Times

Categories
Blog

Rewiring the Enterprise: What Spock’s Brain Teaches Us About Compliance Training

Few episodes of Star Trek: The Original Series are as infamous or as misunderstood as “Spock’s Brain.” Dismissed by many as campy science fiction, the episode nevertheless offers a wealth of practical insights for today’s compliance professionals, especially those tasked with building, maintaining, and delivering effective compliance training programs.

Let’s boldly go where few compliance trainers have gone before and extract five key compliance training lessons from the Enterprise’s wild quest to retrieve Spock’s missing brain. Along the way, we will see that even the quirkiest stories can teach us how to build smarter, more resilient compliance cultures.

Lesson 1: When the Unimaginable Strikes, Training Must Enable Action, Not Panic

Illustrated by: The crew awakens to chaos. Spock is incapacitated. The bridge officers, stunned and confused, look to Kirk for leadership.

Compliance Lesson: The true test of a compliance training program is not how well it’s received during routine times, but how effectively it empowers employees to act decisively under pressure.

Lesson 2: You Can’t Train for Every Event, But You Can Teach Problem-Solving

Illustrated by: There is no manual for “what to do when someone steals your first officer’s brain.”

Compliance Lesson: No training program can anticipate every possible scenario. What you can train, however, is a culture of problem-solving, adaptability, and continuous learning.

Lesson 3: Communication Bridges the Knowledge Gap

Illustrated by: The landing party discovers a society split in two: the technologically advanced women who control the planet’s systems, and the men, who live in primitive conditions below.

Compliance Lesson: The episode’s iconic “teaching helmet” is a comical take on knowledge transfer, but it highlights a real challenge: bridging the gap between compliance expertise and employee understanding.

Lesson 4: Just-in-Time Training—When You Need It Most

Illustrated by: Faced with the daunting task of reattaching Spock’s brain, Dr. McCoy uses the teaching helmet to acquire the necessary surgical skills.

Compliance Lesson: The best compliance programs recognize this and provide “just-in-time” resources: quick-reference guides, FAQs, and on-demand training for when employees need to act.

Lesson 5: Teamwork and Psychological Safety Are the Real Secret Sauce

Illustrated by: With Spock’s brain reconnected, he awakens mid-surgery and begins to talk McCoy through the final steps.

Compliance Lesson: Effective compliance training creates this same sense of psychological safety.

Final ComplianceLog Reflections

Spock’s Brain” might not win any awards for scientific realism or dramatic subtlety, but its outlandish premise is a powerful allegory for the daily realities of corporate compliance training. Unexpected risks will arise. Knowledge will lapse. Sometimes, you will need to act with incomplete information and under enormous pressure.

The crew of the Enterprise prevails not because they followed a script, but because they were trained, through experience, teamwork, and relentless problem-solving, to adapt and respond to the unknown. The same should be true of your compliance training program.

A training program inspired by the lessons of “Spock’s Brain” will not only teach the rules but empower employees to act ethically and effectively when it matters most. And that, ultimately, is how we boldly go forward together.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 55 – Out of Time: Due Diligence Lessons from ‘Assignment: Earth

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners all come with their backgrounds and histories.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is but what they are capable of and what they plan to do with that capability.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyber-attacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences?

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Fiona is an AI-generated voice

Categories
Blog

What Gary Seven and Assignment Earth Teach Us About Due Diligence

If there is one constant in the universe, it is that business, regulations, and politics never stand still. Each new venture, partnership, or acquisition brings a fresh set of risks, obligations, and opportunities. Yet too often, organizations approach due diligence as a box-checking exercise when, in truth, it is the essential safeguard that ensures they are not letting an unknown variable derail their mission. Nowhere is this more cleverly dramatized than in the Star Trek TOS episode “Assignment: Earth,” where the Enterprise crew finds themselves conducting the ultimate form of due diligence, investigating the mysterious Gary Seven and the true risks he poses to Earth’s future.

With its spy-fi trappings, high-stakes secrets, and moral ambiguity, “Assignment: Earth” is a goldmine for compliance professionals seeking fresh insights into what robust due diligence truly requires. Today, we beam down and explore five timeless lessons from this episode, each rooted in a scene that every compliance leader should remember the next time a critical business decision looms.

Lesson 1: Verify Identity—Trust, But Always Confirm

Illustrated by: When Gary Seven appears on the Enterprise, he claims to be a human agent from the future, sent to prevent Earth’s destruction. His credentials, demeanor, and even physiology confound the crew. Spock’s scans confirm some aspects, but other elements remain mysterious. Kirk is forced to weigh trust against hard evidence, deciding that until Seven’s story is verified, he must remain under close observation.

Compliance Lesson: In every business deal, knowing exactly who you are dealing with is non-negotiable. Vendors, acquisition targets, third-party agents, and partners each have their own backgrounds and histories. “Assignment: Earth” illustrates the risks of acting on assumptions or charm; as the Enterprise crew learns, even the most convincing story requires verification. For compliance teams, this means robust onboarding processes, identity verification, and background checks not only at the outset but throughout the relationship. Trust is good; verification is better.

What should you do? Deploy enhanced due diligence for high-risk or high-impact relationships. Use independent sources, cross-check credentials, and don’t hesitate to pause the process if any red flags arise.

Lesson 2: Investigate the Full Scope—Understand Intent, Capability, and History

Illustrated by: The crew’s investigation into Gary Seven doesn’t stop with his identity. They probe his capabilities, his advanced technology, his mysterious “servo,” and the highly sophisticated computer at his headquarters. Spock and Kirk ask probing questions about Seven’s mission, intent, and track record.

Compliance Lesson: Surface-level information often fails to reveal the entire story. In business, a potential partner’s capabilities and intent matter as much as their identity. Due diligence is not just about who someone is, but also what they are capable of and what they plan to do with that capability. A company’s operational strengths, compliance record, and ethical history all inform future risk. Teams must go beyond public filings and financials. Look for operational gaps, management weaknesses, and track records of regulatory engagement. Just as Kirk and Spock dig into Gary Seven’s motives and methods, compliance officers should investigate all relevant dimensions.

What should you do? Expand your checklist: evaluate litigation history, regulatory fines, press coverage, key executive backgrounds, and past compliance breaches. Interview multiple stakeholders to triangulate intent.

Lesson 3: Control Information—Monitor and Secure Sensitive Data

Illustrated by: Much of “Assignment: Earth” revolves around the management of sensitive information. Seven’s computer contains data that could alter the fate of the planet. Both Seven and the Enterprise crew are vigilant about access, using encryption, voice authentication, and physical security to ensure information is only available to those with a legitimate need.

Compliance Lesson: Whether you are acquiring a company or onboarding a supplier, data security is central to modern due diligence. The risks of data leaks, cyberattacks, or inadvertent disclosure can be devastating, especially if sensitive deal information falls into the wrong hands. Therefore, it is crucial to monitor who has access to key data during the diligence phase. Implement robust information barriers and control access to confidential material. Make cybersecurity a core part of your diligence process.

What should you do? Require non-disclosure agreements from all parties. Use secure data rooms and audit access logs. Include cybersecurity posture and data protection history in every due diligence report.

Lesson 4: Expect the Unexpected—Adapt When New Risks Emerge

Illustrated by: Kirk and Spock’s plan to detain Gary Seven is upended when he escapes and races to sabotage a nuclear missile test that could ignite World War III. The crew must adapt instantly, using every tool and resource at their disposal to prevent disaster, even as their understanding of the mission’s stakes evolves in real time.

Compliance Lesson: Due diligence is not a static process. The best-laid plans are often disrupted by new information, sudden market fluctuations, or the revelation of previously unknown risks. Teams must be nimble, ready to reassess, escalate, and change course as new facts emerge. Establish protocols for escalating concerns and adjusting timelines when red flags appear. Build flexibility into your diligence process; sometimes, a deal should slow down or even pause while serious concerns are addressed.

What should you do? Schedule interim reviews, not just final sign-offs. Empower team members to call for additional investigation when new risks emerge, and document all changes to scope and focus.

Lesson 5: Assess Impact and Alignment—Consider the Broader Consequences

Illustrated by: As the story unfolds, the crew realizes that Gary Seven’s actions, though seemingly dangerous, are intended to prevent an even greater catastrophe. Kirk must weigh the consequences of intervening or not, understanding that the impact goes beyond the immediate crisis and could shape the entire future of humanity.

Compliance Lesson: Effective due diligence requires looking beyond the transaction itself. Will this deal, partnership, or acquisition align with your company’s mission, values, and long-term strategy? What are the potential downstream consequences? Does the opportunity support or threaten your compliance culture? Kirk’s willingness to consider the broader impact rather than just “following the rules” mirrors the best compliance thinking. Evaluate not just the legal and financial implications, but the reputational, cultural, and strategic impacts as well.

What should you do? Be sure to include cultural fit, values alignment, and long-term strategy in your final diligence reports. Consult with leadership about potential impacts, positive and negative, before greenlighting a deal.

Final ComplianceLog Reflections

Assignment: Earth” might masquerade as a playful, spy-themed episode, but at its heart it is a meditation on trust, investigation, and the unpredictability of risk. For compliance professionals, its lessons ring true across the decades. Due diligence is not a one-time task, nor is it a matter of simply collecting signatures and ticking boxes. It is an ongoing, multi-dimensional practice rooted in skepticism, curiosity, and a willingness to adapt.

In today’s business environment, the threats and opportunities you face are more complex than ever. The partners, acquisitions, and investments you pursue all come with hidden variables. Like Kirk and his crew, your mission is to look deeper, ask more challenging questions, protect sensitive information, and never lose sight of the broader impact your decisions have on the world.

The next time your organization faces a pivotal deal or partnership, remember the spirit of “Assignment: Earth” and conduct your due diligence with the rigor, flexibility, and ethical perspective that the future demands.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 54 – Beneath the Surface: Uncovering M&A Risk with Guidance from ‘Bread and Circuses’

If there is one area in business where risk, opportunity, and culture collide, it is in mergers and acquisitions. The promise of new markets, talent, and technology is always balanced against the possibility of hidden liabilities, clashing values, and operational chaos. In the world of corporate compliance, no moment is more perilous or more revealing than when companies come together.

Star Trek: The Original Series’ episode “Bread and Circuses” offers an unlikely but fitting parable for M&A compliance professionals. Here are five key compliance-related M&A due diligence lessons from “Bread and Circuses.”

Lesson 1: Go Beyond Surface Appearances—Assess the True Culture

Illustrated by: On the planet 892-IV, Kirk and his landing party discover an authoritarian state built on forced entertainment and oppression.

Compliance M&A Lesson: It is easy to be seduced by a target company’s top-line numbers, glossy facilities, and impressive management presentations. However, proper due diligence requires a thorough examination beneath the surface.

Lesson 2: Identify Hidden Liabilities—Don’t Ignore the Risks Beneath the Entertainment

Illustrated by: The population of 892-IV, which is kept docile through violent gladiatorial games that serve as literal bread and circuses.

Compliance M&A Lesson: Effective due diligence involves identifying these concealed dangers. Compliance professionals must review litigation histories, regulatory filings, and environmental and safety records, as well as ongoing investigations and audits, to ensure compliance.

Lesson 3: Map Third-Party and Supply Chain Risks—Everyone in the Arena Matters

Illustrated by: Kirk discovers that the planet’s leader, Merikus, is a missing Starfleet captain who has chosen to assimilate rather than resist.

Compliance M&A Lesson: No company operates in isolation. A target company’s third-party relationships, joint ventures, and supply chains can be sources of immense risk; think FCPA, anti-bribery, human rights violations, or simply the risk of operational disruption.

Lesson 4: Understand Local Laws, Customs, and Power Structures—Context Is Everything

Illustrated by: Spock and McCoy are baffled by the local laws and power dynamics.

Compliance M&A Lesson: Every M&A deal is shaped by its legal, regulatory, and cultural context. Don’t assume what works in your home country will transfer easily.

Lesson 5: Don’t Underestimate the Human Element—Values and Ethics Matter

Illustrated by: Throughout the episode, it is the values and resolve of the Enterprise crew and the oppressed “Children of the Sun” that make resistance to tyranny possible. The episode ends not with a technical solution, but with an ethical stand.

Compliance M&A Lesson: Values alignment is not just a “soft” factor; it’s a predictor of post-merger success and resilience in a crisis.

Final ComplianceLog Reflections

Bread and Circuses” is more than just a classic science fiction adventure. It is a powerful parable for today’s compliance professional navigating the high-stakes world of mergers and acquisitions. For compliance officers, the episode’s narrative reinforces that adequate due diligence must go far beyond the numbers and surface-level impressions. It requires a holistic investigation into the culture, values, and relationships that truly define an organization. The success or failure of a merger often hinges on the ability to identify hidden liabilities, assess third-party and supply chain risks, and deeply understand the legal and regulatory landscape unique to each deal.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Daily Compliance News

Daily Compliance News: July 24, 2026, The All WSJ Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • New IRS boss spied on co-workers at JPMorgan. (WSJ)
  • Google says AI is helping workers, not replacing them. (WSJ)
  • EU fines Google $1bn. (WSJ)
  • Lloyd’s says former CEO was too cozy with a subordinate. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI Today in 5

AI Today in 5: July 24, 2026, The It’s All About the Data Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Google says AI is helping workers. (WSJ)
  2. AI confidence outpaces adoption. (HealthCareFinance)
  3. AI is only as smart as the data. (Forbes)
  4. AI capture is the foundation of compliance. (UCToday)
  5. AI compliance failures could cost dearly. (FinTechGlobal)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

Beyond the Arena: M&A Due Diligence Lessons from Star Trek’s ‘Bread and Circuses’

If there is one area in business where risk, opportunity, and culture collide, it is in mergers and acquisitions. The promise of new markets, talent, and technology is always balanced against the possibility of hidden liabilities, clashing values, and operational chaos. In the world of corporate compliance, no moment is more perilous or more revealing than when companies come together.

Star Trek: The Original Series’ episode “Bread and Circuses” offers an unlikely but fitting parable for M&A compliance professionals. The Enterprise crew stumbles upon a planet with a civilization that mirrors Ancient Rome: gladiatorial games, a rigid class system, and a society that on the surface appears functional but underneath hides deep ethical and existential fault lines. As Captain Kirk, Mr. Spock, and Dr. McCoy navigate the complexities of this alien world, compliance professionals can draw out critical lessons for conducting effective due diligence in the high-stakes world of mergers and acquisitions.

Here are five key compliance-related M&A due diligence lessons from “Bread and Circuses.”

Lesson 1: Go Beyond Surface Appearances—Assess the True Culture

Illustrated by: On the planet 892-IV, Kirk and his landing party are initially impressed by the planet’s technological advancement. It boasts twentieth-century comforts, such as television, cars, and an advanced infrastructure. Yet, beneath the veneer, they discover an authoritarian state built on forced entertainment and oppression.

Compliance M&A Lesson: It is easy to be seduced by a target company’s top-line numbers, glossy facilities, and impressive management presentations. However, true due diligence requires a thorough examination beneath the surface. What’s the real culture? Is there a hidden culture of fear, ethical lapses, or compliance gaps? Cultural misalignment is one of the top reasons M&A deals fail. The Enterprise’s discovery of “Rome with cars” is a reminder to go beyond the show. Investigate how employees act when management isn’t around, what values truly drive decisions, and whether there’s a “bread and circuses” dynamic masking underlying dysfunction.

What should you do? Interview employees at every level, not just leadership. Review whistleblower hotlines, past HR investigations, and third-party reviews to reveal what may be hidden.

Lesson 2: Identify Hidden Liabilities—Don’t Ignore the Risks Beneath the Entertainment

Illustrated by: The population of 892-IV, which is kept docile through violent gladiatorial games that serve as literal bread and circuses. The ruling class avoids unrest by distracting the masses, but the peace is an illusion. When Kirk, Spock, and McCoy are thrust into the games, the underlying brutality and danger become clear.

Compliance M&A Lesson: In any transaction, there may be hidden liabilities—such as ongoing investigations, regulatory risks, potential litigation, or toxic business practices that have been overlooked or concealed. The “games” may keep things running, but only until something disrupts the balance. Effective due diligence involves identifying and addressing these hidden dangers. Compliance professionals must review litigation histories, regulatory filings, and environmental and safety records, as well as ongoing investigations and audits.

What should you do? First, do not be distracted by “good news only” presentations.

Request full disclosure of pending investigations, lawsuits, and regulatory actions. Utilize forensic audits and data analytics to examine financials and operational practices thoroughly.

Lesson 3: Map Third-Party and Supply Chain Risks—Everyone in the Arena Matters

Illustrated by: Kirk discovers that the planet’s leader, Merikus, is a missing Starfleet captain who has chosen to assimilate rather than resist. He justifies his choices as necessary for survival, but his complicity also enables oppression and exposes him to risk.

Compliance M&A Lesson: No company operates in isolation. A target company’s third-party relationships, joint ventures, and supply chains can be sources of immense risk, including FCPA, anti-bribery, human rights violations, and operational disruptions. Merikus’s collaboration illustrates how easily “good people” can enable unfavorable outcomes when incentives are misaligned. Map out all third-party relationships and conduct risk-based due diligence on significant partners.

What should you do? Consider the reputational and regulatory risks that the combined entity could pose. Are there red flags in high-risk geographies or industries? Implement a robust third-party due diligence program pre- and post-acquisition. Prioritize high-risk vendors and intermediaries for enhanced review.

Lesson 4: Understand Local Laws, Customs, and Power Structures—Context Is Everything

Illustrated by: Spock and McCoy are baffled by the local laws and power dynamics. What seems irrational by Federation standards makes sense only in the context of this world’s history and social structure. Understanding these nuances proves vital for their survival and escape.

Compliance M&A Lesson: Every M&A deal is shaped by its legal, regulatory, and cultural context. Don’t assume what works in your home country will transfer easily. Local labor laws, anti-corruption regimes, data privacy rules, and unwritten power structures can significantly impact an integration. A failure to appreciate these nuances can result in compliance violations, regulatory penalties, or reputational damage after the deal closes. Contextual awareness—legal and cultural—is non-negotiable.

What should you do? Partner with local counsel and compliance experts to conduct a jurisdiction-by-jurisdiction review. Document and plan for local regulatory requirements in the integration roadmap.

Lesson 5: Don’t Underestimate the Human Element—Values and Ethics Matter

Illustrated by: Throughout the episode, it is the values and resolve of the Enterprise crew—and the oppressed “Children of the Sun”—that make resistance to tyranny possible. The episode ends not with a technical solution, but with an ethical stand.

Compliance M&A Lesson: No due diligence checklist can substitute for evaluating the ethical climate and values of a target organization. Are there tone-at-the-top issues? Does the company reward ethical behavior or cut corners? Is there a history of retaliation against whistleblowers? Ultimately, mergers are about people, bringing together teams, customers, and cultures. Values alignment isn’t just a “soft” factor; it’s a predictor of post-merger success and resilience in a crisis.

What should you do? Include values and ethical culture assessments in your due diligence. Leverage employee surveys, exit interviews, and culture audits to gauge whether ethics are truly embedded.

Final ComplianceLog Reflections

Bread and Circuses” is more than just a classic science fiction adventure. It is a powerful parable for today’s compliance professional navigating the high-stakes world of mergers and acquisitions. As the Enterprise crew discovers, the trappings of prosperity and modernity can easily mask underlying risks, cultural misalignments, and ethical fault lines that, if left unexamined, can undermine even the most promising deal.

For compliance officers, the episode’s narrative reinforces that effective due diligence must go far beyond the numbers and surface-level impressions. It requires a holistic investigation into the culture, values, and relationships that truly define an organization. The success or failure of a merger often hinges on the ability to identify hidden liabilities, assess third-party and supply chain risks, and deeply understand the legal and regulatory landscape unique to each deal. Just as

Kirk and his team had to adapt to a world with its own rules and power structures. Compliance professionals must approach every transaction with humility, curiosity, and an unwavering commitment to ethical standards. In the arena of M&A, organizations that thrive are those that embrace rigorous, context-driven due diligence, protecting not only their assets but also their reputation and long-term success. The “arena” of M&A is as perilous as any gladiatorial contest. With rigorous, holistic due diligence, compliance officers can ensure their organizations don’t become unwitting spectators to someone else’s bread-and-circuses.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – July 24, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending July 24, 2026, include:

  1. AI confidence outpaces adoption. (HealthCareFinance)
  2. 3 must-reads on AI in healthcare. (HealthExec)
  3. AI and last-mile delivery. (PharmTech)
  4. AI and operational accountability. (RSM)
  5. Healthcare needs to simplify its AI stack. (HealthcareITNews)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.