Categories
Creativity and Compliance

Creativity and Compliance: Reinventing Compliance: Lauren Thal on Improv, Humor, and Approachable Messaging at Tolmar

Tom Fox and co-host Ronnie Feldman interview Lauren Thal, VP of Compliance at mid-size pharma company Tolmar, about building an in-house compliance program after external partners previously ran it.

Lauren describes her background in healthcare compliance and earlier consulting at Ernst & Young and Navigant and explains why Tolmar’s legal/compliance team used improv training at a retreat to strengthen soft skills, bonding, and collaboration in a remote, cross-location environment. They discuss how exercises like “Red Ball” and role-playing highlight communication styles, active listening, adaptability, and managing competing priorities, helping compliance partner with the business without appearing “finger-waggy” or like the “police.” Lauren also explains her training/communications strategy using short, playful compliance videos on topics such as Speak Up and Code of Conduct to disarm fear, increase attention and recall, and encourage engagement, offering practical ideas for deployment and emphasizing that humor reinforces rather than undermines compliance messages.

Key highlights:

  • Lauren’s Compliance Journey
  • Why Improv at Retreat
  • Red Ball and Styles
  • Partnering Without Fear
  • Handling the Chaos
  • Business Feedback and Impact
  • Advice to Sell the Idea

Resources:

Ronnie

Lauren Thal

On LinkedIn 

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Creativity and Compliance is a multiple-award-winning podcast and was recently honored as one of the Top 35 Podcasts on Creativity by Feedspot.

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending July 31, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include the following:

  1. Using traditional legal frameworks to regulate AI. (Reuters)
  2. HSBC opens AI center of excellence. (FinTech Global)
  3. The 60-25-15 rule is reshaping AI compliance pilots. (FinTech Global)
  4. Banks appointing Chief AI Officers. (FinTech Magazine)
  5. BaFin to monitor AI use at banks and insurers. (Reuters)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI Today in 5

AI Today in 5: July 31, 2026, The 60-25-15 Rule Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. 8 compliance changes under the EU AI Act. (Orrick)
  2. Agentic AI in banking in APAC. (CFO Tech)
  3. The 60-25-15 rule is reshaping AI compliance pilots. (FinTech Global)
  4. 5 key issues for AI in healthcare. (HealthExec)
  5. 5 top AI in fintech stories from July. (FinTech Futures)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

Facing the Unknown: Five Investigative Lessons from Star Trek’s “Spectre of the Gun”

One of the most fascinating aspects of compliance investigations is navigating the unknown—those ambiguous, often illogical circumstances where instinct and method must work together. Few television episodes dramatize this challenge as vividly as the Star Trek: The Original Series (TOS) episode, “Spectre of the Gun.”

In this third-season episode, Captain Kirk and his landing party beam down to a planet of the reclusive and telepathic Melkotians, only to be punished for trespassing. Their punishment? Being cast into a surreal, incomplete recreation of the 1881 Gunfight at the O.K. Corral, destined to play the losing side against the Earps and Doc Holliday. As the Enterprise crew quickly learns, logic, memory, and even physical law are unreliable. Their investigation into their predicament and their survival depends on teamwork, analysis, and the willingness to question what’s real.

The compliance world may not often resemble the Wild West, but the best compliance investigators know that the strange and surreal are not always fiction. Misunderstandings, missing evidence, and “unwritten rules” can make the truth as elusive as any Melkotian illusion. “Spectre of the Gun” provides a powerful lens through which to examine the investigative process.

Today, we saddle up and explore five essential investigative lessons for compliance professionals from Tombstone in the Arizona Territory, as featured in this classic episode.

Lesson 1: Never Assume Reality Is What It Seems

Illustrated by: From the moment Kirk and his team arrive, things are… off. The town is half-finished, with buildings lacking walls and only a few facades standing. There are missing objects and inexplicable absences. Despite this, the crew initially tries to follow the “script” of Tombstone’s history, assuming their actions will play out as expected.

Compliance Lesson. In a compliance investigation, assumptions are your enemy. Initial appearances can deceive, especially when dealing with incomplete data, manipulated records, or the subtle influence of organizational culture. Like the Enterprise crew, investigators often find themselves in environments that “look” right but don’t quite add up.

A skilled investigator asks:

  • What’s missing from this picture?
  • Are there gaps or inconsistencies in the documentation?
  • Do witness accounts align, or are they conspicuously similar as if rehearsed?

Always challenge the first layer of evidence. Probe for context. Cross-check data sources and resist the urge to “solve” the case too quickly.

Takeaway:

If your compliance investigation feels too neat, step back and re-examine. The truth often lies in the gaps, not the obvious.

Lesson 2: Stay Calm in the Face of Escalating Pressure

Illustrated by: As the clock ticks toward 5:00, the hour of the gunfight, the tension mounts. The Earps are aggressive, and the townsfolk are hostile or unhelpful. The crew experiences mounting psychological stress, but Kirk repeatedly counsels his team to stay calm and focused, even as the “inevitable” doom approaches.

Compliance Lesson. Investigations often bring high-pressure moments: interviewees who become confrontational, business leaders who want quick resolutions, or whistleblowers who fear retaliation. In these moments, emotions can cloud judgment and cause missteps.

Spectre of the Gun” shows that, when panic rises, clear-headed leadership and methodical process are essential. Kirk’s calm enables the team to think creatively and challenge assumptions, ultimately saving their lives.

In compliance investigations:

  • Set clear ground rules for interviews.
  • Create a calm environment, even when accusations are severe.
  • Support your team and witnesses, especially when the stakes are high.

What should you do now? Under pressure, composure and methodical thinking separate successful investigators from those who react.

Lesson 3: Leverage Diverse Perspectives and Skills

Illustrated by: Each member of the landing party brings a unique skill to the puzzle. Spock applies logic to interpret the unreality of their situation. McCoy’s medical knowledge helps craft “anti-venom” to counter the gas used by Doc Holliday. Scotty and Chekov offer technical and tactical ideas, while Kirk analyzes motivations and strategy.

Compliance Lesson. No single investigator has all the answers. The best compliance investigations are team efforts, drawing on legal, HR, IT, and business expertise. This diversity helps spot blind spots and ensures that all avenues are explored.

In the episode, Spock recognizes that their environment is illusory, and the group’s willingness to trust his logic unlocks their escape. In your investigations:

  • Gather a multidisciplinary team.
  • Encourage open debate and the airing of alternate theories.
  • Leverage outside expertise when needed, such as forensic accountants or language specialists.

What should you do now? Diversity is not just about backgrounds; it is about thinking styles and problem-solving approaches. Use every tool at your disposal.

Lesson 4: Test Hypotheses—Don’t Just Accept Stories

Illustrated by: When McCoy attempts to make “real” tranquilizer gas to stop the Earps, it fails, as the gas has no effect, because nothing in their environment is truly real. Spock theorizes that their minds are the only reality that matters. The crew realizes they must test each new hypothesis about their environment, ultimately concluding that belief itself will determine the outcome of the gunfight.

Compliance Lesson. Compliance investigators must go beyond the “story” provided by policy manuals or initial interviews. Every theory, whether about a missing document, a suspicious transaction, or a timeline inconsistency, should be tested.

This may mean:

  • Reconstructing timelines.
  • Running technical or forensic tests.
  • Seeking out independent corroboration for claims.

In the episode, only by testing (and failing) do Kirk and his team realize what’s going on. Similarly, failed hypotheses in your investigation are not a waste; they point you closer to the truth.

What should you do now? Test your investigative theories actively. Do not accept stories at face value; experiment, reconstruct, and challenge.

Lesson 5: Mindset Shapes Outcomes—Don’t Underestimate the Power of Belief

Illustrated by: As the showdown approaches, Spock deduces that their survival depends on their conviction that the Earps’ bullets cannot harm them. He leads the crew in a Vulcan mind meld, focusing their thoughts on total certainty in their safety. When the bullets fly, they are unharmed—because they believe they cannot be hurt.

Compliance Lesson. While compliance investigators don’t need Vulcan mind melds, the principle is clear: the mindset you bring to your investigation—open-mindedness, integrity, and thoroughness—shapes the outcome. Cynicism, bias, or defeatism can close your eyes to the real issues.

Additionally, the mindset of the organization matters. If employees believe investigations are futile or predetermined, they won’t participate honestly. If they believe in the integrity of the process, you’ll get better results.

Set the tone by:

  • Demonstrating impartiality.
  • Communicating the importance of the investigative process.
  • Encouraging a “speak-up” culture where all feel heard.

What should you do now? The beliefs and values you bring to an investigation shape its success. Foster a culture of open-mindedness, curiosity, and fairness.

Final ComplianceLog Reflections

Spectre of the Gun” is more than a surreal Star Trek adventure; rather, it is a case study in the art and science of investigation. As compliance professionals, we may not face ghostly gunfights at sundown, but we do face situations where logic, courage, and creative teamwork are our only tools against the unknown.

So, as you saddle up for your next compliance investigation, remember the lessons of the Enterprise crew in Tombstone. The truth is out there, sometimes behind the facade, hiding in plain sight.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – July 31, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending July 31, 2026, include:

  1. 5 key issues for AI in healthcare. (⁠Health Exec)⁠
  2. FDA rulebook for AI in drug trials. (The Clinical Trial Vanguard)⁠
  3. Healthcare needs to lean on security and integrity. (⁠HealthcareITNews)⁠
  4. AI to help in chronic disease research. (⁠HealthcareITNews)⁠
  5. AI in healthcare still has a trust problem. (Healthcare Innovation)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Connected Compliance: Part 5 – From Signals to Trust: Why Compliance Must Operate as One System

We conclude our series on various components of connected compliance by pulling them all together in an integrated whole. An effective compliance program is often described through its components: policies, training, risk assessment, reporting channels, investigations, discipline, and monitoring. That description is accurate, but incomplete. It tells us what the program contains. It does not tell us how the program works.

The deeper lesson from this series is that compliance effectiveness lives in the connections. Communication, risk sensing, investigations, and whistleblower programs are not separate workstreams that happen to sit under the same organizational chart. They are parts of one information-and-accountability system. Each part produces information that another part must receive, interpret, and convert into action.

That is the integrated argument. Compliance is truly connected because risk moves through an organization as a signal before it becomes an event. An employee question, customer request, control exception, supplier problem, unusual payment, new technology use, or hotline report may be the first indication that the company’s risk profile has changed. The program succeeds when it can move that information through a disciplined cycle: listen, assess, assign, investigate, remediate, communicate, and learn.

The program fails when the signal dies at a handoff.

The Seams Are Where Compliance Breaks

Most companies do not lack compliance activity. They lack reliable movement between activities. Training may be completed, but recurring questions never reach the risk assessment. A hotline may capture an allegation, but intake and investigation teams may use different priorities. An investigation may identify a control weakness, but the remediation owner may not be named. A new policy may be issued, but compliance may never test whether employees understand the change. Each function can report progress while the overall system remains ineffective.

This is why silos create more than inefficiency. They create control risk. A program can look mature by function and still fail as a system because no one owns the transfer of information, the decision deadline, or the feedback loop. Compliance professionals should therefore examine the seams: Who receives the signal? Who decides what it means? Who owns the response? What evidence confirms completion? Who tests whether the response worked? How does the lesson return to employees, managers, controls, and the risk assessment? Those are not administrative questions. They are the architecture of effectiveness.

Compliance Is an Information System

Communication is the first connection because it moves information in both directions. It tells employees what the organization expects, but it also tells compliance what employees are experiencing. Questions, requests for advice, training discussions, manager escalations, surveys, and workplace observations are all risk data. Communication becomes a control when it does more than broadcast. It creates a dependable exchange.

That information must then enter a dynamic risk process. Risk assessment is not merely a periodic exercise that ranks known categories. It is the organization’s method for deciding which signals require monitoring, immediate containment, deeper review, new controls, or additional resources. The quality of that decision depends on access to operational information across functions.

The Department of Justice (DOJ) makes this connection explicit in its 2024 Evaluation of Corporate Compliance Programs (ECCP). The ECCP asks whether periodic risk review is limited to a point-in-time snapshot or is based on “continuous access to operational data and information across functions.” It also asks whether the results lead to updates in policies, procedures, and controls. The enforcement lesson is straightforward: information must move, and it must change the program.

Compliance Is Also an Accountability System

Information alone does not create effectiveness. The organization must make decisions and assign responsibility. When a risk signal becomes an allegation, the investigation process establishes reliable facts. A credible investigation determines scope, protects evidence, preserves independence, treats witnesses fairly, reaches a supported conclusion, and identifies root causes. Its value is not limited to deciding whether one person violated a policy. It should reveal what the organization must change.

This is the point where accountability often weakens. A case may close when a report is issued, even though the control failure remains. Discipline may address the individual without addressing incentives, supervision, access rights, third-party oversight, or prior warnings. Recommendations may be accepted without an owner, deadline, testing plan, or escalation route.

A connected program treats investigation closure as the beginning of remediation. Findings should feed risk assessment, control design, training, management reporting, and resource allocation. Remediation should then be tested, and the result should be documented. If the company cannot show how a material finding changed the program, it has created a record of the past, not a control for the future.

Trust Is Both an Input and an Outcome

The whistleblower program completes the system because it determines whether critical information enters at all. A hotline provides access, but employees decide whether the reporting system is credible. Their decision is shaped by manager behavior, confidentiality practices, investigation quality, anti-retaliation protection, communication during the process, and what they observe after a concern is raised.

Trust is therefore not a soft cultural benefit sitting outside internal control. It is an operating condition for detection. Employees who believe that reporting is unsafe or futile will withhold information. The company then loses the opportunity to address misconduct early, protect people, preserve evidence, and reduce loss. Trust is also an outcome of the company’s response. A respectful intake, timely triage, fair investigation, consistent accountability, active anti-retaliation monitoring, and appropriate closure communication strengthen the next employee’s willingness to speak. A mishandled matter does the opposite. Every case affects the future supply of risk information.

The ECCP captures this end-to-end logic. It calls for an “efficient and trusted mechanism” for anonymous or confidential reporting, asks whether reporting and investigation information is analyzed for patterns and compliance weaknesses, and asks whether the company tests hotline effectiveness by tracking a report from start to finish. That is a systems test. It examines the full journey, not the existence of a vendor platform.

Think in Loops, Not Lines

Compliance professionals should stop viewing the program as a sequence that ends when a task is completed. Training does not end with completion. Risk assessment does not end with a heat map. An investigation does not end with a finding. A report does not end when the case is closed.

Each activity must create an output for the next decision and a feedback path to the earlier controls. Communication produces risk intelligence. Risk assessment prioritizes that intelligence. Reporting channels supply allegations and weak signals. Investigations convert allegations into facts and root causes. Remediation changes controls and accountability. Communication then explains the change, and monitoring tests whether it worked. The experience shapes culture and determines whether employees will use the system again.

This loop also changes the role of the compliance professional. The CCO does not need to own every business risk or perform every task. The CCO must help design and steward the system that connects them. That means establishing decision rights, information-sharing protocols, escalation thresholds, common taxonomies, remediation ownership, testing standards, and reporting that shows whether the loop is moving.

The practical objective is not centralization. It is coordinated accountability. Legal, human resources, internal audit, finance, security, procurement, technology, and business leaders may own different decisions. Compliance should ensure that the handoffs are explicit and that no material issue disappears between functions.

Measure the Health of the Cycle

Traditional metrics often count isolated activity: training completions, policy attestations, number of reports, cases closed, or risk assessments performed. Those measures remain useful, but they do not show whether the system is connected. A stronger dashboard measures movement and learning. How long does it take to move a material signal to a decision? What percentage of remediation actions has a named owner, deadline, evidence requirement, and testing plan? How often do investigation findings change the risk assessment? Which recurring employee questions lead to policy or training changes? Are reporter updates timely? Are retaliation concerns monitored after closure? Do repeat issues decline after remediation?

These measures test whether compliance converts information into action and action into improved performance. They also expose stalled handoffs. A long delay between investigation closure and remediation, for example, is not simply a case-management issue. It is a weakness in the connected program.

From Culture to Credibility

The best compliance programs do not eliminate uncertainty, misconduct, or failure. They create a reliable way to identify change, surface concerns, establish facts, make accountable decisions, and learn. That reliability is what turns stated values into operating culture.

Compliance is truly connected because culture affects reporting, reporting affects risk visibility, risk assessment affects resource allocation, investigations affect accountability, remediation affects controls, and communication affects whether employees trust the system enough to use it again. No element can be fully effective on its own.

The final question for compliance professionals is therefore not whether every component exists. It is whether the components exchange information, preserve accountability, and improve one another. When they do, compliance becomes more than a collection of requirements. It becomes a business system that turns signals into decisions, decisions into controls, and controls into credibility.

Bonus Questions for Compliance Professionals

  1. Where are material compliance signals most likely to stall or disappear in the current program?
  2. Who owns the transfer from employee concern to risk decision, and from investigation finding to tested remediation?
  3. Can the organization trace a recent issue from first signal through final control improvement?
  4. Which functions use different taxonomies, priorities, or case thresholds in ways that weaken handoffs?
  5. What evidence shows that reporting and investigation data changed risk assessment, resources, policies, or controls?
  6. Do current metrics reveal system delays and repeat weaknesses, or only completed activity?
  7. How does the organization communicate lessons without compromising confidentiality?
  8. What recent employee experience strengthened or weakened trust in the compliance system?
Categories
AI Today in 5

AI Today in 5: July 30, 2026, The Compliance Decision Fatigue Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Compliance decision fatigue in the age of AI. (JD Supra)
  2. BaFin to monitor AI use at banks and insurers. (Reuters)
  3. Can regs become machine-readable? (FinTech Global)
  4. Investment firms say AI is their top compliance concern. (Investment News)
  5. FDA rulebook for AI in drug trials. (The Clinical Trial Vanguard)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: July 30, 2026, The Milli Vanilli Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top AI stories include:

  • Defense lawyers claim DOJ FCPA case is a ‘Milli Vanilli’ offering.  (Law360) sub req’d
  • eBay and execs agree to pay $55.7 MM in settlement for harassment. (Law360) sub req’d
  • Teva can’t whine about agreed-to admissions. (Law360) sub req’d
  • 1st Circuit skeptical that hiring SW is a lie detector. (Law360) sub req’d

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

The Final Frontier of Compliance Training: Five Lessons from Star Trek’s “Is There in Truth No Beauty?”

Corporate compliance is not just about rules, regulations, and policy manuals. At its core, compliance is about people—their perceptions, blind spots, willingness to communicate, and, above all, their ability to learn from each other in the face of risk and ambiguity. No franchise has dramatized the struggles of understanding, ethics, and communication better than Star Trek: The Original Series (TOS). And no episode is more apt for compliance professionals seeking to elevate their training and communications program than the third-season gem, “Is There in Truth No Beauty?”

Set aboard the USS Enterprise, the episode revolves around the arrival of Dr. Miranda Jones and the enigmatic Medusan ambassador, Kollos. The Medusans are a race of beings whose appearance is so alien that to gaze upon them causes madness. It’s a parable about the dangers and necessity of confronting the unknown, understanding difference, and building bridges across divides.

As compliance professionals, we can mine “Is There in Truth No Beauty? ” for powerful lessons on how to build a culture of effective training”forcommunications that prepares our teams for the uncharted territory of tomorrow’s risks. Today, we set our phasers to “inspire” and explore five key compliance training and communications lessons from this classic Trek tale.

Lesson 1: Embrace the Limits of Human (and Organizational) Perception

Illustrated by: The crew’s first briefing about the Medusan ambassador is laden with warnings: “No one may look upon a Medusan with the naked eye.” To the Medusan, human forms are equally incomprehensible, but they have developed technology, a protective visor, that allows safe interaction. Dr. Miranda Jones, specially trained and equipped, serves as a living bridge between the two species.

Compliance Lesson. Every organization has its own “Medusans” risks, regulations, and even people whose perspectives are so different they can seem incomprehensible. Too often, compliance training assumes everyone shares the same baseline understanding and comfort level. That is a dangerous assumption.

Your training must recognize the limits of perception, both cognitive and cultural. Not everyone will see risk the same way; not everyone will feel empowered to ask questions or speak up. Just as Dr. Jones brings specialized knowledge and equipment to the table, your compliance communications should equip employees with tools to recognize their blind spots and to bridge those gaps. This can mean scenario-based learning, peer-led discussions, or visual tools that help explain complex risks from multiple perspectives.

What should you do now? Acknowledge and proactively address the limits of human perception. Empower your team with adaptive tools and diverse viewpoints to “see” risk.

Lesson 2: Communicate Expectations—Don’t Assume Understanding

Illustrated by: Early in the episode, Captain Kirk assembles his crew for a detailed briefing. He explicitly warns, “You must not look upon the Medusan ambassador.” Spock and Dr. Jones reinforce the message, and the procedures for safe interaction are laid out.

Compliance Lesson. How many compliance failures begin with, “Well, I thought I understood what was required…”? In Star Trek, lives depend on explicit, repeated communication of expectations. In your organization, regulatory and reputational survival depends on it as well.

Effective compliance training requires more than a one-time email or a paragraph in the handbook. Clear, repeated, scenario-based communication is essential. Explain the “why” as well as the “what.” Don’t just say “do not do X,” but explain the risk, the rationale, and the real-world consequences. Use multiple formats, including live, digital, visual, and narrative, to reinforce the message.

What should you do now? Never assume understanding. Communicate expectations explicitly and often, and use stories, scenarios, and repetition to anchor key messages.

Lesson 3: Build Trust and Psychological Safety Before the Crisis

Illustrated by: The relationship between Dr. Jones and the crew is initially fraught. She is a telepath, guarded and secretive. Her sense of isolation is palpable. Yet as the episode progresses, Kirk and Spock earn her trust by inviting her into their confidence and acknowledging her unique expertise. This trust proves critical when disaster strikes.

Compliance Lesson. Effective communication is built on trust and psychological safety. If employees feel isolated, mistrusted, or afraid to speak up, no amount of “mandatory training” will make your compliance program effective. The Medusan can only safely interact through a trusted intermediary—just as employees will only engage with compliance if they feel respected and included.

Foster a compliance culture where people feel safe to voice concerns, ask questions, and share mistakes without fear of retaliation. Encourage managers to model vulnerability and openness. Use anonymous Q&A, “ask me anything” sessions, and real stories to build an environment of trust.

What should you do now? Trust is the engine of communication. Build psychological safety into your compliance training so that employees feel empowered to participate, especially when the stakes are high.

Lesson 4: Prepare for the Unexpected—And Practice the Protocols

Illustrated by: When Kollos’s container is accidentally opened, crew member Larry Marvick is exposed to the Medusan and descends into madness, nearly destroying the Enterprise. The emergency procedures are put to the test, and Spock’s preparation (and his use of the protective visor) is the difference between disaster and survival.

Compliance Lesson. Crises never unfold according to plan, but they reveal the effectiveness of your training and protocols. Star Trek demonstrates that it’s not enough to have a policy in the binder; you must train, rehearse, and test those protocols until they are second nature.

Use tabletop exercises, drills, and “what if” scenarios in your compliance training. Walk teams through incident response steps—debrief after near-misses or actual compliance failures. Emphasize not just the letter of the protocol, but the spirit, why each step matters, and how it protects the organization and its people.

What should you do now? Prepare, practice, and stress-test your compliance protocols. When the unthinkable happens, your team must be ready to act, not just recite policy, but live it.

Lesson 5: Embrace Diversity—and the Value of the Outsider’s View

Illustrated by: The Medusan, Kollos, is physically incomprehensible to humans, yet he is also a being of great intelligence and empathy. Spock, uniquely Vulcan and human, can serve as a bridge—merging with Kollos to save the ship. In the process, both gain insight from the other’s perspective.

Compliance Lesson:

Homogeneity is a hidden compliance risk. Diverse teams bring broader perspectives, challenge assumptions, and spot blind spots that a monoculture would miss. In Star Trek, survival depends on learning from the outsider; in compliance, innovation, and vigilance depend on the same principle.

Include voices from across your organization and beyond in your compliance training and communications. Seek out the vigilance, theys” who can question the status quo. Value the contributions of people from different backgrounds, departments, and experiences. Remember: your “Medusan” might hold the key to your next compliance breakthrough.

What should you do now? Diversity is your compliance superpower. Embrace the outsider’s perspective and make inclusion a pillar of your training and communications.

Final ComplianceLog Reflections

Is There in Truth No Beauty? “is a meditation on the limits of perception, the power of communication, and the necessity of embracing difference. For compliance professionals, it offers a road map for building training and communications programs that are clear, inclusive, practical, and resilient.

As you chart the course for your compliance initiatives, ask yourself:

  • Are we equipping our people to see risk from every angle?
  • Do we communicate expectations repeatedly and meaningfully?
  • Is trust the foundation of our compliance culture?
  • Are we truly ready for the unexpected?
  • Are we harnessing the power of diverse perspectives?

The universe of compliance is ever-expanding. Let’s train and communicate so our teams are ready to go where no one has gone before boldly.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 60 – Unmasking Compliance Blind Spots: Lessons from ‘Is There in Truth No Beauty?’

No TOS episode is more apt for compliance professionals seeking to elevate their training and communications program than the third season gem, “Is There in Truth No Beauty?”

As compliance professionals, we can mine “Is There in Truth No Beauty?” for powerful lessons on building a culture of effective training and communications that prepares our teams for the uncharted territory of tomorrow’s risks. Today, we set our phasers to “inspire” and explore five key compliance training and communications lessons from this classic Trek tale.

Lesson 1: Embrace the Limits of Human Perception

Illustrated by: The crew’s first briefing about the Medusan ambassador is laden with warnings: “No one may look upon a Medusan with the naked eye.”

Compliance Lesson. Every organization has its own “Medusans” risks, regulations, and even people whose perspectives are so different they can seem incomprehensible. Too often, compliance training assumes everyone shares the same baseline understanding and comfort level. That is a dangerous assumption.

Lesson 2: Communicate Expectations—Don’t Assume Understanding

Illustrated by: Early in the episode, Captain Kirk assembles his crew for a detailed briefing. Spock and Dr. Jones reinforce the message, and the procedures for safe interaction are laid out.

Compliance Lesson. How many compliance failures begin with, “Well, I thought I understood what was required…”? In Star Trek, lives depend on explicit, repeated communication of expectations. In your organization, regulatory and reputational survival depends on it as well.

Lesson 3: Build Trust and Psychological Safety Before the Crisis

Illustrated by: The relationship between Dr. Jones and the crew is initially fraught. She is a telepath, guarded and secretive. Her sense of isolation is palpable. Yet as the episode progresses, Kirk and Spock earn her trust by inviting her into their confidence and acknowledging her unique expertise. This trust proves critical when disaster strikes.

Compliance Lesson. Effective communication is built on trust and psychological safety. If employees feel isolated, mistrusted, or afraid to speak up, no amount of “mandatory training” will make your compliance program effective.

Lesson 4: Prepare for the Unexpected—And Practice the Protocols

Illustrated by: When Kollos’s container is accidentally opened, crew member Larry Marvick is exposed to the Medusan and descends into madness, nearly destroying the Enterprise.

Compliance Lesson. Crises never unfold according to plan, but they reveal the effectiveness of your training and protocols. Star Trek demonstrates that it’s not enough to have a policy in the binder; you must train, rehearse, and test those protocols until they are second nature.

Lesson 5: Embrace Diversity—and the Value of the Outsider’s View

Illustrated by: The Medusan, Kollos, is physically incomprehensible to humans, yet he is also a being of great intelligence and empathy.

Compliance Lesson:

Homogeneity is a hidden compliance risk. Diverse teams bring broader perspectives, challenge assumptions, and spot blind spots that a monoculture would miss. In Star Trek, survival depends on learning from the outsider; in compliance, innovation, and vigilance depend on the same principle.

Final ComplianceLog Reflections

Is There in Truth No Beauty?” is a meditation on the limits of perception, the power of communication, and the necessity of embracing difference. For compliance professionals, it offers a road map for building training and communications programs that are clear, inclusive, practical, and resilient.

The universe of compliance is ever-expanding. Let’s train and communicate so our teams are ready to boldly go where no one has gone before.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI generated voice