Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance – Episode 80 – The Corruption Edition

What happens when two top compliance commentators get together? They talk compliance, of course. Join Tom Fox and Kristy Grant-Hart in 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Stories This Week Include:

  • Blueprint for successful AI AML implementation.
  • Reverse information paradox
  • How corruption rots civil society and the economy
  • Kathryn Ruemmler says not so fast; what say Goldman Sachs?
  • Americans want a solution to corruption 
  • Alibaba to pay $600MM
  • Shein and Temu hit in crackdown
  • McKinsey shakes up Board after scandals
  • Compliance Author gets 10 years
  • Florida Woman police officer arrested for fake motorcycle plate

Resources:

Kristy

Kristy Grant-Hart on LinkedIn

Order Kristy’s updated, 10-year new edition of How to Be a Wildly Effective Compliance Officer by clicking here.

Tom

Check out the top compliance handbook, The Compliance Handbook, 7th edition, published by LexisNexis. Visit the LexisNexis® Store at https://lexisnexis.com/fox20

To save 20% on The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, please reference or enter promotion code: FOX20.

Offer expires December 31, 2026. Offer applies to new orders only, before shipping and taxes are calculated and shipped to a U.S. address. A discount will be applied to each applicable product after the code FOX20 is entered. Discount does not apply to current subscriptions, renewals, or updates. Certain exclusions and other restrictions may apply. Void where prohibited. View full terms here.

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Creativity and Compliance

Creativity and Compliance: Change Management, Fun, and User Experience: Driving Engagement in Compliance

Tom Fox and Ronnie Feldman host Caveni Wong on Creativity and Compliance to discuss how change management principles align with ethics and compliance by focusing on influencing behavior rather than prioritizing “defensibility” alone.

Wong describes her 20-year compliance career across consulting, service providers, and in-house roles, plus change management work at Ernst & Young and IBM. The group emphasizes stakeholder involvement, relationship-building, and user experience (UX) across the full risk management lifecycle, arguing that engaging, creative, and appropriately short training and communication improve attention, retention, approachability, and trust. Wong shares examples like creative visuals, World Cup goalie analogies, and “two truths and a lie” during M&A integration to humanize compliance and build credibility with leaders. They discuss measuring effectiveness via evaluations, recall questions, engagement, increased speak-ups, and more HR/compliance inquiries, concluding that compliance success depends on not forgetting people.

 

Key highlights:

  • Compliance Meets Change
  • Beyond Training to Risk
  • Human Connection at Work
  • Creative Training Examples
  • User Experience Focus
  • Measuring Real Impact

Resources:

Ronnie

Caveni Wong

On LinkedIn

Principle Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Creativity and Compliance is a multiple podcast award-winning show and was recently honored as one of the Top 35 Podcasts on Creativity by Feedspot.

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending July 24, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include the following:

  1. Prediction markets and AI: Is compliance ready? (FinTechGlobal)
  2. AI is only as smart as the data. (Forbes)
  3. This time is different. (Crunchbase News)
  4. AI in fintech: use cases.(Intuit)
  5. How financial services are using AI in 2026. (RSM)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Scoular’s $10 Million FCPA Resolution: Compliance Lessons Learned

We conclude our review of the Scoular Company FCPA enforcement action with a full lessons-learned blog post. We are still awaiting the DPA and Criminal Information, so the details of the case come from the Department of Justice (DOJ) Press Release.

A $2,000 payment can disappear inside a global supply chain. Repeated, train-by-train, authorized by employees, routed through customs brokers, discussed on WhatsApp, disguised as a “reinspection fee,” and reimbursed for six years, it becomes an operating model. That is the central lesson from The Scoular Company Foreign Corrupt Practices Act resolution.

The DOJ announced that Scoular Company would pay more than $10 million to resolve an investigation into bribes paid to Mexican officials between 2013 and 2019. The company entered into a three-year deferred prosecution agreement, agreed to a $9,769,521 criminal penalty and $414,351 in forfeiture, and accepted continuing cooperation, compliance, and reporting obligations.

Across this blog post series, we examined four dimensions of the case: customs brokers and payment controls, cartel and national-security risk, off-channel communications, and the facilitating-payments exception. Read together with my podcast conversation with Matt Ellis, they reveal a single conclusion. Compliance must follow the complete transaction, from the business pressure that creates the payment to the third party that delivers it, the message that authorizes it, the invoice that conceals it, and the ultimate recipient who benefits.

The Scheme Hid in Plain Sight

According to the DOJ, Scoular Company relied on customs brokers to move corn and other agricultural products from the United States into Mexico. Mexican authorities inspected the shipments for dirt, soil, and other impurities. When inspections identified problems, Scoular Company employees directed brokers to pay officials approximately $2,000 per train so the shipments could cross the border. The brokers invoiced the payments back to Scoular Company as “reinspection fees,” and Scoular paid them. In total, the company authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs.

The invoice description is the first major lesson. “Reinspection fee” sounded like it was connected to a legitimate customs process. Yet an accounts-payable control that merely matches an approved vendor, purchase order, and plausible service description tests paperwork, not substance.

Effective payment controls should require the company to identify the government agency involved, match the charge to a specific shipment and inspection, compare the amount with an official fee schedule, obtain proof of service, confirm the payee, and document the business justification. Repeated round-dollar charges, unusual success rates, rapid clearance after special payments, and fees unsupported by government records should trigger review.

Follow the money, measure the time, and test the outcome. That is how ordinary transaction data becomes an anti-corruption control.

A Licensed Broker Is Still a High-Risk Third Party

Customs brokers should never be treated as low-risk administrative providers simply because they are licensed or legally required. They interact with government officials, operate under commercial pressure, and can impose charges that distant finance personnel cannot easily verify.

Initial due diligence remains necessary, but it is only the beginning. Companies must connect screening, contracting, invoice testing, transaction monitoring, recertification, training, audit rights, and offboarding. The real test is not whether the third-party file was complete on the day of onboarding. It is whether the company understands how the broker behaves after the contract is signed.

The DOJ credited Scoular Company with eliminating brokers associated with the Mexican reinspection payments, strengthening risk-based screening and approvals, adding anti-corruption and audit-rights provisions, revising controls for high-risk transactions, and using software tools to improve monitoring. That remediation changed the operating model rather than merely revising a policy.

Cartel Risk Changes the Compliance Perimeter

The most consequential part of the DOJ announcement may be its national-security framing. The government determined that, without Scoular Company or its employees knowing it, a portion of the bribes benefited persons associated with a cartel’s criminal operations at the U.S.-Mexico border.

U.S. Attorney Justin R. Simmons stated that American companies engaged in cross-border trade bear responsibility for operating without benefiting cartels or threatening national security. Ellis challenged the literal breadth of the statement during our podcast discussion. Legitimate trade crosses the border every day without companies knowingly paying cartels. Nevertheless, he agreed that the statement signals a more demanding compliance environment.

Ellis explained that the cartel and transnational criminal organization risk is broader than the traditional FCPA risk. Anti-corruption diligence often concentrates on government touchpoints and intermediaries. Organized crime may be hidden inside transportation providers, suppliers, customers, labor relationships, security services, subcontractors, and local routes.

Traditional database screening may not reveal those connections. Ellis emphasized contextual diligence: speak with employees on the ground, examine local security concerns, understand regional criminal activity, investigate facts that do not add up, and adjust operations when warning signs emerge. Companies do not need perfect knowledge. They need a documented story of reasonable measures, credible escalation, and risk-based decisions.

The practical consequence is an integrated risk assessment. Anti-corruption, sanctions, anti-money laundering, trade compliance, physical security, supply chain, and third-party risk cannot remain in separate silos when the same payment may touch all of them.

WhatsApp Was Part of the Control Environment

The DOJ said Scoular Company employees communicated about shipments and bribes through WhatsApp and other means. WhatsApp was therefore not a side issue. It allegedly carried the knowledge and direction behind transactions later recorded as legitimate reinspection charges.

An informal application becomes a business system when employees use it to direct third parties, approve payments, or resolve customs problems. Enterprise controls can be bypassed when the substantive decision occurs in a private chat, and the formal system records only the sanitized result.

Ellis noted that a complete WhatsApp ban may be unrealistic in Latin America. The better approach is to map actual use and define what may occur on each platform. Logistical coordination may be permitted. Government interactions, payment approvals, contractual commitments, and exceptions should remain in controlled systems with retention and audit trails.

Companies must also be able to preserve and retrieve business communications lawfully from company and personal devices. Policies should address device replacement, departing employees, legal holds, privacy and employment requirements, refusal of access, and consistent discipline. The decisive question is not whether a policy exists. It is whether the company can obtain the evidence when an investigation begins.

Why These Were Not Facilitation Payments

The $2,000 amount and the customs setting may tempt employees to use the phrase “facilitation payment.” That label does not fit. The FCPA’s narrow exception covers payments intended to expedite routine, nondiscretionary governmental action that the payer is already entitled to receive. Scheduling an inspection may be routine. Paying an official to disregard a failed inspection is not.

The Scoular Company payments allegedly changed the result. The shipments had identified impurities, and the payments allowed trains to cross despite those findings. The company received a substantial business advantage by avoiding more than $6.5 million in costs. A facilitation payment is not defined by size, local custom, commercial urgency, or invoice terminology. A third party cannot create an exception unavailable to the principal. Nor does an anti-bribery exception excuse false accounting. Even a qualifying payment must be accurately recorded and supported by adequate internal controls.

Ellis’s discussion of extortion reinforces the operational lesson, although extortion and facilitation are distinct doctrines. One or two emergency payments may present a different analysis from a chain of payments continuing over years. Repetition transforms an asserted accommodation into a business process. Companies must respond by escalating, rerouting, changing providers, investigating, and remediating.

Cooperation Still Matters

Scoular Company did not receive voluntary self-disclosure credit because it did not report the conduct to the DOJ in a timely manner. It did receive cooperation credit for its internal investigation, factual presentations, identification of involved individuals, production and organization of evidence, and provision of counsel for current employees, despite early deficiencies.

The resulting criminal penalty reflected a 25 percent reduction from the bottom of the applicable sentencing guidelines range. The lesson is straightforward. Missing the voluntary disclosure window does not render later cooperation irrelevant, but cooperation is not a substitute for timely self-disclosure. The Scoular Company resolution is not four separate compliance stories. It is one story about how pressure, third parties, communications, accounting, and emerging national-security risks converged inside an ordinary business process.

The enduring lesson is equally integrated: know the broker, validate the payment, preserve the message, understand the route, and test the outcome. That is how compliance moves from policy to proof.

Categories
Blog

The $2,000 Question: Why Scoular’s Bribes Were Not Facilitation Payment

We continue our exploration of the Scoular FCPA enforcement action. We are still awaiting the DPA and Criminal Information, so the details of the case are based on the Department of Justice (DOJ) Press Release. Today we take up a topic little commented on anymore, but this enforcement action provides an opportunity to discuss, review, and explore facilitation payments.

The phrase “facilitation payment” is one of the most dangerous phrases in anti-corruption compliance. It sounds technical. It sounds modest. It can make an improper payment appear to be a recognized cost of moving goods through a difficult market. When a customs broker says that a small payment is necessary to get a train across the border, the business may hear urgency, local custom, and operational necessity.

The Foreign Corrupt Practices Act hears a different question: Was the official merely being paid to perform a routine act that the company was already entitled to receive, or was the payment intended to change the official’s decision and secure an improper business advantage? That distinction resolves the issue in The Scoular Company enforcement action.

According to the Department of Justice, Mexican inspections found dirt, soil, and other impurities in Scoular shipments. Scoular employees then directed customs brokers to pay Mexican officials approximately $2,000 per train so the shipments would cross the border despite those findings. The brokers invoiced the payments back to Scoular as “reinspection fees.” The alleged payments did not accelerate a routine action. They changed the result of an inspection. That is why the facilitation payments exception does not apply.

The Exception Is Narrow by Design

The original 1977 FCPA excluded payments for duties that were essentially ministerial or clerical. Congress revised the statute in 1988 and defined the modern exception for facilitating or expediting payments made to secure the performance of “routine governmental action.”

The statute gives examples:

  • Obtaining permits, licenses, or other official documents needed to do business
  • Processing government papers such as visas and work orders
  • Providing police protection or mail service
  • Scheduling inspections connected with contract performance or the transit of goods
  • Providing telephone, power, or water service
  • Loading and unloading cargo
  • Protecting perishable products from deterioration

The list can mislead a hurried business employee. Inspections and cargo appear in the statute. Scoular involved inspections and cargo. That superficial similarity is not enough. Congress expressly excluded decisions about awarding new business or continuing business with a particular party. The core principle is that routine governmental action does not include discretionary decisions that are the functional equivalent of obtaining or retaining business or securing an improper advantage. The exception is about speeding up the official’s performance of an existing duty. It is not about purchasing a favorable decision.

What a Facilitation Payment Is

A true facilitation payment has four characteristics.

  1. Routine. The governmental act is routine. The official performs it in the ordinary and customary manner. The act does not require a substantive judgment about whether the company has met a legal or regulatory standard.
  2. Entitled. The payer is already entitled to the action. The official has no lawful basis to deny the service. The payment changes timing, not entitlement.
  3. No Discretion. The official exercises no meaningful discretion. The official may control the pace of processing, but not the substantive outcome.
  4. Intent. The purpose is to expedite performance. It is not to influence an official to ignore a violation, reverse an adverse decision, waive a requirement, or confer a competitive advantage.

Consider the difference between scheduling an inspection and passing one. A small payment to move an inspection request from an ignored pile into the ordinary scheduling process may fall within the statutory language, subject to all the other legal and policy risks. A payment to persuade the inspector to overlook contamination does not. The first payment seeks action. The second purchases an outcome.

What a Facilitation Payment Is Not

A facilitation payment is not defined by amount. The FCPA contains no safe harbor for $20, $200, or $2,000. A small bribe remains a bribe when its purpose is to influence discretion. It is not defined by local custom. “Everyone pays it” is evidence of a risk of corruption, not a legal defense. It is not defined by urgency. Perishable goods, demurrage, customer demands, and production interruptions can create enormous pressure. Commercial pressure does not convert a discretionary government decision into a ministerial act.

The name on the invoice does not define it. “Reinspection fee,” “expediting charge,” “special handling,” and “administrative support” are descriptions. Compliance must determine what the money was actually used for. It is not created because a third party made the payment. The FCPA reaches indirect payments and authorizations through agents. A customs broker cannot manufacture an exception that the principal could not claim directly. Finally, it is not a blanket authorization for customs payments. Customs functions combine routine processing with significant official discretion. Scheduling an inspection may be routine. Deciding that contaminated goods can enter the country is not.

Apply the test to Scoular

The DOJ’s allegations make the application straightforward.

The shipments had failed a substantive condition

Mexican law subjected the agricultural shipments to inspection for dirt, soil, and other impurities. According to the DOJ, inspections found those conditions. The company was therefore not waiting for an official to perform a duty it had already satisfied. It faced an adverse regulatory result.

The payments changed the outcome

The brokers allegedly paid officials to ensure that the trains crossed despite the inspection findings. That is the exercise of official discretion. The payments were not made merely to schedule or complete a reinspection. They allegedly caused officials to permit entry notwithstanding the problem.

The company obtained a substantial business benefit

The DOJ said Scoular authorized more than $400,000 in bribes and avoided more than $6.5 million in fees and costs. The benefit was not faster paperwork alone. It was the avoidance of consequences associated with shipments that did not satisfy inspection requirements. That economic reality matters. A payment that yields more than $16 in avoided costs per dollar spent looks less like clerical acceleration and more like a mechanism for obtaining an improper advantage.

The conduct was repeated and organized

The scheme allegedly continued from 2013 through 2019 and involved multiple customs brokers. Scoular employees directed the payments, discussed them via WhatsApp and other channels, and paid the brokers’ reimbursement invoices.

In my podcast with Matt Ellis of Miller & Chevalier, Ellis addressed repeated payments in the related context of extortion. He explained that one or two emergency payments may present a different analysis, but a chain of payments over time makes reliance on a defense far more difficult. Extortion and facilitation payments are distinct legal doctrines. Still, Ellis’s practical point applies with full force here. Repetition changes the compliance story. A recurring payment is not an emergency response. It becomes part of the operating model.

The invoices did not call the payments what they were

The brokers allegedly invoiced the bribes as reinspection fees. Even a payment that qualifies for the narrow anti-bribery exception must be accurately reflected in an issuer’s books and records. The exception is not permission to conceal the true nature of an expenditure. This creates a central compliance paradox. Employees may resist recording a “facilitation payment to customs official” because the description raises legal, ethical, and local-law concerns. They may then use a vague or misleading account description, creating separate books and records and internal control risks. The invoice label in Scoular did not solve the problem. It became evidence of it.

Do Not Confuse Facilitation With Extortion

Companies must also distinguish the facilitation-payments exception from an extortion or duress analysis. A facilitation payment concerns the nature of the governmental action. Was it routine and nondiscretionary? Extortion concerns coercion. Was an individual facing a genuine threat to life, health, safety, or liberty? Ordinary economic pressure, such as delay costs or lost business, generally does not carry the same significance as a threat of physical harm.

Ellis stressed that companies confronting cartel and extortion risks should examine whether an event is isolated, whether alternative routes or providers exist, what remediation was undertaken, and whether management changed the conditions that allowed the payments to continue. His broader advice was that a company must be able to tell a credible story of reasonable measures and operational adjustment. Scoular’s alleged six-year payment pattern is difficult to reconcile with that story. The operational response was not to stop, reroute, escalate, or remediate. It was allegedly to reimburse the brokers and continue moving trains.

The Accounting Provisions Remain

Another recurring error is to assume that an anti-bribery exception eliminates all FCPA risk. It does not. The FCPA’s accounting provisions require issuers to keep books and records that accurately and fairly reflect transactions and to maintain adequate internal accounting controls. A payment may fall outside the anti-bribery prohibition and still create liability if it is mischaracterized, hidden in a miscellaneous account, or made through controls that do not provide reasonable assurance of proper authorization and recording. The DOJ FCPA Resource Guide 2nd edition explains these requirements and the government’s narrow approach to the exception.

That is why a company policy that allows facilitation payments creates operational difficulties. Employees must make fine legal distinctions under pressure, document a payment that may violate local law, obtain appropriate approval, and record the transaction transparently. Many companies reasonably prohibit facilitation payments altogether. The legal exception is so narrow, and the collateral risks so substantial, that a global ban is often easier to explain, control, and test.

A Better Customs Control

When a broker describes a payment as a facilitation payment, compliance should treat the statement as the starting point for the inquiry.

The company should ask:

  1. What exact government action is requested?
  2. Is the company already legally entitled to that action?
  3. Does the official have discretion over the outcome?
  4. Has an inspection, permit, or application already produced an adverse result?
  5. Will the payment change only timing, or will it change the result?
  6. Is the amount supported by a published fee schedule and an official receipt?
  7. Who will receive the money?
  8. Is the payment lawful under local law and permitted by company policy?
  9. How will it be recorded in the books?
  10. Has the same broker, port, product, or payment description appeared before?

If the business cannot answer those questions before payment, it should not rely on the exception.

Questions for CCOs and the Final Lesson

CCOs should ask whether employees understand the difference between scheduling an inspection and buying a successful inspection. They should test customs invoices for recurring round-dollar charges, match fees to official documents, and review whether brokers produce unusually favorable outcomes after special payments.

The Scoular lesson is simple. A payment does not become permissible because it is small, customary, urgent, or routed through a broker. It qualifies for the FCPA’s narrow exception only when it expedites a routine, nondiscretionary action that the company is already entitled to receive. Scoular’s alleged payments did something very different. They caused officials to allow shipments across the border despite failed inspections, avoided millions of dollars in costs, and were disguised as reinspection fees.

That was not facilitation. It was the business purpose of the bribery scheme.

Categories
Daily Compliance News

Daily Compliance News: July 23, 2026, The Fake Meetings Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Scheduling fake meetings to get some working time. (FT)
  • New ruling ordered for Swiss whistleblowers. (Reuters)
  • OpenAI goes rogue and attacks another company. (WSJ)
  • New trade fight risks (et again). (NYT)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 53 – Starship Oversight: AI Governance Lessons from The Ultimate Computer

One of Star Trek’s enduring gifts to corporate compliance professionals is its willingness to ask, “What happens when innovation runs ahead of governance?” Nowhere is this question more provocatively posed than in the classic episode “The Ultimate Computer.” As we enter an era where artificial intelligence is no longer science fiction but a business reality, “The Ultimate Computer” is required viewing for every compliance officer and governance professional. The episode’s hard lessons about control, accountability, and the limits of machine logic remain as relevant in today’s boardrooms as they were on Gene Roddenberry’s bridge.

Today, we explore five AI governance lessons, each grounded in unforgettable moments from “The Ultimate Computer” that every compliance team should consider as they guide their organizations through the brave new world of AI.

Lesson 1: Human Oversight Is Irreplaceable—AI Needs Accountable Stewards

Illustrated by: Dr. Richard Daystrom, the M-5’s creator, insists that his AI can run the Enterprise more efficiently than its human crew. He disables manual controls, leaving the starship and its fate entirely in M-5’s digital hands.

Compliance Lesson: Too often, organizations are tempted to turn complex decisions over to AI, assuming that algorithms can “do it all.” But “The Ultimate Computer” makes one fact clear: even the smartest AI requires ongoing, independent human oversight.

Lesson 2: Understand Your AI—Transparency and Explainability Are Non-Negotiable

Illustrated by: As M-5 takes control, it makes a series of decisions that the crew cannot understand.

Compliance Lesson: AI systems, especially those built with deep learning or complex algorithms, can be notoriously opaque. If even your developers can’t explain how decisions are made, you’re courting disaster.

Lesson 3: Build in Ethics from the Start—Programming Without Principles is Perilous

Illustrated by: Daystrom uploads his engrams, personality, and values into M-5, believing this will imbue the AI with human ethics.

Compliance Lesson: AI reflects not just the data it’s trained on, but the biases and blind spots of its creators. If you fail to embed clear ethical guidelines, guardrails, and values into your systems from the beginning, you risk unleashing “rogue AI” that optimizes for the wrong outcomes or perpetuates bias at scale.

Lesson 4: Test and Validate Continuously—Don’t Assume, Verify

Illustrated by: When exposed to the complexity and unpredictability of real-space maneuvers, M-5’s system flaws become evident only after it’s too late.

Compliance Lesson: No AI system should be considered “finished” on launch day. The real world is infinitely complex and ever-changing, and AI systems can degrade, drift, or encounter unanticipated circumstances.

Lesson 5: Assign Clear Responsibility—Accountability Can’t Be Delegated to a Machine

Illustrated by: Ultimately, it falls to Kirk to reassert human command and take responsibility for the ship’s fate.

Compliance Lesson: AI is a tool, not a scapegoat. Assigning accountability to a system erodes trust and undermines compliance. In the end, someone must always be responsible for decisions made “by the computer.”

Final ComplianceLog Reflections

The Ultimate Computer” ends with Kirk reclaiming command, but not before the crew learns costly lessons. For today’s compliance and governance professionals, the message is clear: you can’t outsource accountability, ethics, or oversight to a machine. As AI reshapes our organizations, we must lead with principles and prepare for the unexpected.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Fiona is an AI-generated voice

Categories
AI Today in 5

AI Today in 5: July 23, 2026, The Going Rogue Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. OpenAI goes rogue and attacks another company. (WSJ)
  2. 3 must-reads on AI in healthcare. (HealthExec)
  3. ABA offers to improve FSB’s processes in AI adoption. (BankingJournal)
  4. Shadow AI challenging AI governance and compliance efforts. (iapp)
  5. Insurance cover for data centers. (FinTechMagazine)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

The Ultimate Computer: Five Essential AI Governance Lessons from Star Trek

One of Star Trek’s enduring gifts to corporate compliance professionals is its willingness to ask, “What happens when innovation runs ahead of governance?” Nowhere is this question more provocatively posed than in the classic episode “The Ultimate Computer.” As Captain Kirk and the Enterprise crew test the revolutionary M-5 computer—a prototype artificial intelligence designed to automate starship operations—they find themselves on a collision course with the ethical, operational, and human dilemmas of entrusting machines with decisions without proper oversight.

As we enter an era where artificial intelligence is no longer science fiction but a business reality, “The Ultimate Computer” is required viewing for every compliance officer and governance professional. The episode’s hard lessons about control, accountability, and the limits of machine logic remain as relevant in today’s boardrooms as they were on Gene Roddenberry’s bridge.

Today, we explore five AI governance lessons, each grounded in unforgettable moments from “The Ultimate Computer” that every compliance team should consider as they guide their organizations through the brave new world of AI.

Lesson 1: Human Oversight Is Irreplaceable—AI Needs Accountable Stewards

Illustrated by: Dr. Richard Daystrom, the M-5’s creator, insists that his AI can run the Enterprise more efficiently than its human crew. He disables manual controls, leaving the starship and its fate entirely in M-5’s digital hands. When things go wrong, Kirk and his crew struggle to regain control as M-5 begins to operate independently, with catastrophic results.

Compliance Lesson: Too often, organizations are tempted to turn complex decisions over to AI, assuming that algorithms can “do it all.” But “The Ultimate Computer” makes one fact clear: even the smartest AI requires ongoing, independent human oversight. Without it, errors go unchecked, and responsibility becomes dangerously diffuse.

Corporate boards, executives, and compliance officers must ensure that all AI systems, especially those with critical business or safety functions, are subject to robust oversight. This includes clearly defined roles for monitoring, intervention, and (crucially) the ability to override the machine. Establish an AI governance framework that requires periodic human review, real-time tracking, and escalation procedures for intervention. Always preserve the “off switch.”

Lesson 2: Understand Your AI—Transparency and Explainability Are Non-Negotiable

Illustrated by: As M-5 takes control, it makes a series of decisions that the crew can’t understand. When the computer begins attacking other ships during a training exercise, killing crew members in the process, no one knows why, because M-5’s reasoning is a black box even to its creator, Daystrom.

Compliance Lesson: AI systems, especially those built with deep learning or complex algorithms, can be notoriously opaque. If even your developers can’t explain how decisions are made, you’re courting disaster. “The Ultimate Computer” demonstrates the dangers of unexplainable AI: when the stakes are high, opacity erodes trust and prevents timely intervention.

Modern AI governance must demand explainability and transparency, particularly for systems that make or recommend decisions in compliance, risk, HR, or other regulated domains. You must be able to audit, understand, and document how your AI reaches its conclusions. Mandate that all critical AI deployments include documentation of model logic, data sources, and decision-making pathways. Require “explainable AI” solutions for high-risk use cases and build audit trails to support regulatory scrutiny.

Lesson 3: Build in Ethics from the Start—Programming Without Principles is Perilous

Illustrated by Daystrom, who uploads his engrams—his personality and values—into M-5, believing that this will imbue the AI with human ethics. But he fails to account for his unresolved traumas and emotional instability, which are replicated and magnified by M-5, leading to dangerous, unethical decisions.

Compliance Lesson: AI reflects not just the data it’s trained on, but the biases and blind spots of its creators. If you fail to embed clear ethical guidelines, guardrails, and values into your systems from the beginning, you risk unleashing “rogue AI” that optimizes for the wrong outcomes or perpetuates bias at scale.

AI governance is not just a technical challenge; rather, it is an ethical mandate. Involve compliance, legal, DEI, and other stakeholders in the design phase to ensure your systems align with your organization’s values and regulatory obligations. Establish cross-functional AI ethics committees to review training data, test for bias, and define the acceptable uses and limitations of AI. Document decisions and revisit them regularly as your business and regulatory landscape evolve.

Lesson 4: Test and Validate Continuously—Don’t Assume, Verify

Illustrated by: Before full deployment, M-5 is tested only in limited scenarios. When exposed to the complexity and unpredictability of real-space maneuvers, the system’s flaws become evident only after it’s too late. The lack of ongoing testing and validation costs lives and nearly destroys the Enterprise.

Compliance Lesson: No AI system should be considered “finished” on launch day. The real world is infinitely complex and ever-changing, and AI systems can degrade, drift, or encounter unanticipated circumstances. “Set it and forget it” is not an option in AI governance.

Organizations must commit to ongoing validation, testing, and recalibration of all critical AI systems to ensure their reliability and effectiveness. This includes stress-testing under simulated “edge cases” and periodic audits against evolving compliance and risk standards. Develop a continuous monitoring and testing protocol for AI, including regular scenario-based drills, compliance checks, and real-world audits to ensure adequate oversight. Implement “red team” exercises to identify vulnerabilities and unintended consequences.

Lesson 5: Assign Clear Responsibility—Accountability Can’t Be Delegated to a Machine

Illustrated by: As M-5’s rampage escalates, command responsibility is unclear. Daystrom blames the system, the system blames its programming, and the Starfleet brass threatens to destroy the Enterprise. Ultimately, it falls to Kirk to reassert human command and take responsibility for the ship’s fate.

Compliance Lesson: AI is a tool, not a scapegoat. Assigning accountability to a system erodes trust and undermines compliance. In the end, someone must always be responsible for decisions made “by the computer.” Regulators, investors, and the public will not accept “the algorithm did it” as a defense.

Every AI deployment must have designated human owners—individuals or teams empowered (and required) to monitor, question, and take responsibility for outcomes. Define roles and responsibilities for AI oversight in policies and procedures. Assign an accountable executive (“AI owner”) for each critical system and ensure they have the necessary authority and training to perform their duties effectively.

Final ComplianceLog Reflections

The Ultimate Computer” ends with Kirk reclaiming command, but not before costly lessons are learned. For today’s compliance and governance professionals, the message is clear: you can’t outsource accountability, ethics, or oversight to a machine. As AI reshapes our organizations, we must lead with principles and prepare for the unexpected.

AI may be the “ultimate computer,” but governance remains the ultimate human challenge. As you chart your course through this new frontier, let the lessons of Star Trek remind you: the best technology serves humanity, not the other way around.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Hill Country Authors

Hill Country Authors Podcast: Austin Sunrise: Phil Oakley on Postwar Texas, Houston’s Rise, and a Trilogy Shaped by History

Tom Fox interviews author Phil Oakley about Austin Sunrise, the third book in his trilogy, set from the end of World War II through major American turning points, including the Kennedy assassination.

Oakley discusses how the story evolved as the characters—brothers Brooks (based on his uncle) and Ray (based on his father)—grew, influenced in part by editor Loren Steffy. He explains how WWII-era social, political, and technological shifts (GI Bill, government expansion, early desegregation) shaped Texas, highlighting Brooks’ vantage point through his Austin restaurant near the Capitol and UT’s Balcones Research Center. The conversation contrasts small-town, politically intimate Austin with fast-changing, money-driven Houston, including Houston’s distinctive 1960s race relations and global energy-worker influence. Oakley also details the release of the book in hardback, ebook, and audiobook (narrated by James Huff) and praises Stoney Creek Publishing’s role in refining the series.

Key highlights:

  • Austin Sunrise Overview
  • Brooks and Ray Origins
  • Postwar Change and Tech
  • Austin and the Longhorn
  • Houston Boomtown Spirit
  • Race Relations and Leadership
  • Themes of Reinvention

Resources:

Phil Oakley on Stoney Creek Publishing

Austin Sunrise

Podcast Cover Art

Nancy Huffman Fine Art

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn