Categories
Daily Compliance News

Daily Compliance News: October 7, 2026, The FT Business Book of the Year Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world: compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • More sanctions against Jackson Walker coming? (Reuters)
  • China hacks South Korean banks. (WSJ)
  • Can Trump throw Disney off air for Kimmel? (NYT)
  • FT and Standard Chartered Business Book of the Year shortlist is out. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Blog

Modern Philosophers and Compliance: Part 3 – John Rawls and Fairness in the Corporate Compliance Program

This week we will conclude our lengthy exploration of the philosophical underpinnings of the modern corporate compliance program. We have examined Hannah Arendt and her concepts of personal responsibility and how they relate to the modern compliance program, and Simone de Beauvoir and the conditions for ethical action in a corporation. We will review Jürgen Habermas and the governance of speaking up and Hans Jonas and responsibility for the future of corporate compliance. Today we continue with John Rawls and the twin concepts of Institutional Justice and Institutional Fairness in a corporate compliance program.

A compliance program promises how the company will exercise power. Employees are asked to follow rules, disclose concerns, cooperate with investigations, and accept consequences when misconduct is established. In return, they should be able to expect a process whose protections and standards do not depend on their commercial value or proximity to leadership. John Rawls gives compliance professionals a practical way to examine that promise.

In the first two posts, we considered personal responsibility through Hannah Arendt and the conditions for ethical action through Simone de Beauvoir. Today, in Part 3, Rawls brings us to the design of the institution itself. Would employees accept its rules if they did not know which position they would occupy when those rules were applied?

Justice as Fairness and the Corporate Institution

Rawls was an American political philosopher whose A Theory of Justice, published in 1971, developed an account of justice as fairness. His theory addresses society’s basic structure, including the institutions that distribute rights, opportunities, and advantages. It prioritizes equal basic liberties and addresses fair opportunity and the conditions under which economic inequalities can be justified.

A corporation is a different kind of institution. Rawls’s principles cannot simply be converted into an employee handbook. The useful connection is an approach to justification: examine institutional arrangements from a standpoint that limits the influence of personal advantage.

Rawls developed this approach through the original position, a hypothetical situation in which people select principles behind a veil of ignorance. They lack knowledge of their own social position and particular advantages, while retaining general knowledge relevant to institutional design. The restriction prevents them from tailoring principles to their individual circumstances.

In compliance, we can adapt that thought experiment. Imagine designing a disciplinary process without knowing whether you will be a junior employee, a regional executive, a witness, or the person accused. What protections would you require? Which differences in treatment could you defend? The exercise asks policy owners to step outside the interests associated with their current roles.

Designing the Process Before Knowing the Employee

Consider this hypothetical. A multinational company discovers that a regional sales director submitted personal expenses as business entertainment. The investigation establishes that he knowingly mischaracterized the expenses and had received clear training. He has no prior disciplinary record. His business unit produces a significant share of company revenue.

Six months earlier, the company dismissed a junior account manager for knowingly submitting comparable personal expenses. Assume the amounts, evidence of intent, training, and disciplinary history are materially similar, and no relevant legal difference exists. The sales director’s sponsor now recommends a warning because losing him could disrupt customer relationships.

The CCO faces a concrete governance question. Is the proposed distinction consistent with a defensible standard, or has commercial importance become a private exemption? The hypothetical deliberately holds relevant factors constant so that management must address the remaining reason for different treatment.

Apply the veil of ignorance. Would employees endorse a policy under which the consequences for deliberate expense falsification depend on how difficult the offender is to replace? Would leaders accept that principle if they expected to occupy the junior role? Asking those questions before deciding the case makes the underlying rule visible.

The company must still manage business continuity. It can plan customer coverage and succession while determining an appropriate response. Those operational responsibilities should be distinguished from the criteria used to assess misconduct. Otherwise, the need to retain an individual can quietly become the standard for deciding accountability.

The DOJ Connection Through Consistent Discipline

The Department of Justice’s Evaluation of Corporate Compliance Programs (ECCP) explicitly examines whether discipline and incentives are applied fairly and consistently. In Rawlsian terms, these map to what we call Institutional Fairness and Institutional Justice. The ECCP asks whether comparable misconduct received different treatment, why differences occurred, and how consistency is assessed across organizational levels and locations.

That inquiry aligns with the practical question raised by our hypothetical: can the company explain the distinction using relevant facts and established criteria? Rawls supplies a philosophical lens for examining the justification. The ECCP supplies an enforcement framework for scrutinizing actual practice.

Consistency requires judgment. An inadvertent mistake and deliberate concealment can warrant different responses. Supervisory responsibility, repeated misconduct, cooperation, harm, and applicable legal requirements may also matter. The organization should identify the factors it considers and document how they affect the outcome.

Return to the sales director. The decision-makers should examine the earlier case and any genuinely relevant distinctions. They should also consider whether the earlier response was itself appropriate. Fairness does not require repeating an unjustified sanction merely to preserve a record of identical outcomes. If the standard needs correction, the company should explain the correction and, with counsel and human resources, consider its implications for prior cases.

Fair Investigations Protect the Credibility of Findings

Institutional Fairness depends on a credible investigation. An organization cannot justify a consequence through careful reasoning if favoritism, prejudgment, or a refusal to examine contradictory evidence shaped the underlying inquiry.

The ECCP examines whether investigations are independent, objective, appropriately scoped, and documented. Applying Rawls’s thought experiment adds a practical design question: what process would we accept without knowing whether we would make the allegation or have to answer it?

Both positions deserve consideration. A reporter should have a reliable route for raising concerns and protection against retaliation. An accused person should have an appropriate opportunity to respond to material allegations before final findings, subject to legitimate investigative and legal constraints. Witnesses should be treated respectfully, and credibility assessments should rest on evidence.

These are proposed governance safeguards, rather than a claim that Rawls or the ECCP establishes a uniform corporate procedure. Companies must adapt their protocols to the circumstances and applicable law. They should nonetheless be able to explain why any significant departure was necessary and who authorized it.

In our hypothetical, an investigator whose promotion depends on the sales director may face a conflict. An independent assignment can protect the inquiry. The executive sponsor should supply relevant information without controlling findings. Clear roles reduce the opportunity for commercial pressure to influence the factual record before a disciplinary decision is even considered.

Exceptions Need Reasons That Survive Scrutiny

Policies inevitably encounter circumstances their authors did not anticipate. A mature compliance program needs a disciplined method for handling exceptions. The question is whether the justification would apply to another similarly situated person.

Consider a policy requiring advance approval for certain travel. An emergency evacuation and a preferred executive’s scheduling convenience present different reasons for an exception. The decision record should identify the relevant circumstances, the authority approving the departure, and any compensating safeguards. A personal relationship with the approver is not a defensible criterion.

Rawls also used reflective equilibrium, a method of working toward coherence among considered judgments and principles through revision. Applied by analogy, it encourages the CCO to examine difficult cases alongside the stated policy. A recurring, well-founded exception may reveal a defective rule. A convenient exception may reveal unwillingness to enforce a sound one.

The response should follow the evidence. Revise an impractical requirement where warranted, communicate the change, and preserve the underlying control objective. Where the rule is appropriate, address unauthorized departures. Employees should be able to understand how the company reaches these conclusions without needing personal access to influential decision-makers.

Testing Fairness and Reporting It to the Board

Fairness should be examined through case review and data. The ECCP addresses disciplinary transparency and monitors consistency in investigations and discipline. This is Institutional Justice in practice. For the same misconduct, does an employee in Brazil face the same consequences as your top salesperson in the United States? A practical review can compare similar matters while preserving the factual differences needed to interpret outcomes.

Start with a defined category, such as deliberate expense falsification. Compare findings, disciplinary history, role responsibilities, sanctions, and the reasons recorded for departures from the usual approach. Also review investigation duration and decision ownership. An unexplained delay involving an influential leader can warrant scrutiny even before determining a sanction.

Differences in outcomes signal the need for inquiry. Small samples, different legal requirements, and materially different conduct can make aggregate comparisons misleading. A dashboard should help reviewers identify questions that require examination of the underlying cases. It should not assign a fairness score that disguises unresolved factual distinctions.

The board needs visibility into material exceptions and management’s response to unexplained disparities. Directors should ask whether a disciplinary recommendation involving a senior leader was changed, who changed it, and why. The answer should include the relevant evidence and the standard applied, with appropriate protection for confidential information.

Communication with employees also deserves deliberate attention. The company can explain its decision criteria and use carefully anonymized examples without exposing private case details. When confidentiality limits disclosure, explain the process that supports accountability. Leaving employees to infer the rules from departures and rumors weakens the company’s ability to demonstrate fairness.

Five Key Rawls Takeaways for the Compliance Professional

  1. Test policies without assuming your own position. Ask whether you would accept a process as a junior employee, reporter, witness, or accused executive. Use the answers to identify protections that should not depend on influence.
  2. Define the reasons that justify different outcomes. Document relevant distinctions such as intent, responsibility, prior conduct, and legal requirements. Examine claims of commercial indispensability with particular care.
  3. Protect the integrity of the investigation. Identify conflicts, assign appropriate independence, examine contradictory evidence, and provide a fair opportunity to respond. Record the reasons for significant procedural departures.
  4. Review exceptions as evidence about the program. Determine whether they expose a policy defect or selective enforcement. Correct flawed rules transparently and address departures that lack a defensible basis.
  5. Give the board a clear account of consistency. Present material disparities, executive exceptions, and corrective actions with sufficient context to assess them. Use case evidence to explain what aggregate measures cannot resolve.

Rawls gives the compliance professional a demanding question: could we justify this rule before knowing whom it would benefit? For boards, the corresponding test is whether the company applies standards it would defend to employees at every level. The program’s credibility depends on the answers demonstrated in actual decisions.

In Part 4, we will turn to Jürgen Habermas and the role of reasoned dialogue in corporate compliance. Having examined fair institutional rules with Rawls, we will consider how employees can question those rules, challenge decisions, and have their concerns meaningfully considered. That discussion takes us into speak-up culture and the governance of disagreement.

Categories
FCPA Compliance Report

Natural Disaster Expo 2026 Speaker Series: Amy Forsythe on Crisis Leadership and Media Communication

Welcome to Natural Disasters Expo Houston! For its fifth year, Natural Disasters Expo USA comes back to Houston on October 14–15, 2026, at the George R. Brown Convention Center. And there’s no better place. This city knows what it takes to prepare for disasters, respond, and rebuild afterward.

For two days, industry leaders, government agencies, first responders, and resilience professionals will come together with one shared goal: helping communities weather the next storm stronger than the last. Explore new solutions and technology, learn from front-line experts, and meet the partners who will help you turn preparedness into action. Whether you’re here to learn, share, or collaborate, you’re part of the effort to build a more resilient nation.

In this speaker series, Tom Fox interviews retired US Navy Reserve officer Amy Forsythe ahead of her Disaster Expo keynote, “When Crisis Calls: Leadership, Communication & Community in the Moments That Matter.”

Forsythe describes her 33 years of service, beginning as a Marine Corps combat photographer and later retiring as a Navy public affairs officer, with extensive experience coaching senior leaders on media engagement and crisis response. She and co-presenter Mandy Feindt will combine Feindt’s firsthand experience from the Red Hill fuel spill crisis in Hawaii with Forsythe’s lessons on building trust, honest communication, humility, and effective interagency coordination during disasters. Forsythe notes these principles apply to businesses and leaders whose viability can be impacted by crisis communication, including the risk of “one bad interview.” She aims to share hard-learned lessons, including from the 2017 Santa Rosa, California, fires, and to connect with practitioners in Houston.

Resources:

Connect with Amy Forsythe on LinkedIn

Natural Disasters Expo USA

Get your Ticket

Conference Agenda

Speakers 2026

Categories
Daily Compliance News

Daily Compliance News: October 6, 2026, The No Claims Paid Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Are insurers moving to a ‘no claims paid’ policy? (WSJ)
  • Big Bend don’t need no stinkin’ wall. (Reuters)
  • Does Big Oil own the Supreme Court? (NYT)
  • Slovakia makes testimony of corruption illegal. (Bloomberg)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Innovation in Compliance

Innovation in Compliance: Pamela Gupta on Closing the AI Governance Implementation Gap

Innovation comes in many areas, and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovators, thinkers, and creators on the award-winning Innovation in Compliance podcast. In this episode, host Tom welcomes Pamela Gupta, the author of De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook.

Pamela Gupta is the founder of Trusted AI™ and an author. She and Tom discuss closing the AI governance implementation gap between high-level frameworks (e.g., NIST AI RMF, ISO 42001) and use-case execution under rapid AI rollout pressure. Gupta argues organizations struggle to translate principles into actionable, risk-based decisions across many stakeholders (security, privacy, legal, audit, business, IT, and data science), leading to either unmanaged risk or stalled innovation. She emphasizes AI-specific risks such as bias, transparency, explainability, and accountability, citing Humana’s nH Predict claims system (alleged bias; 90% reversals), Amazon’s scrapped hiring model, and Air Canada’s chatbot ruling. Gupta outlines her AI TIPS framework (eight pillars, ~80 controls) and contends AI governance can accelerate adoption by defining intake, evidence, and decision processes, even as agentic AI raises risk and uncertainty.

Key highlights:

  • AI Governance Gap
  • Assessing AI Risk
  • Bias and Ethics Ownership
  • Humana Case Study
  • AI TIPS Framework
  • Governance as Accelerator

Resources:

Pamela Gupta on LinkedIn

De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook

Website: TrustedAI.AI

Podcast: Trustworthy AI: De-Risk Business Adoption of AI

Trusted AI Feed: TrustedAI.AI/feed/

X/Twitter: @OutsecureCom

LinkedIn: Trusted AI™

YouTube: @trustedai

 Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
AI Today in 5

AI Today in 5: October 6, 2026, The AI Personalization Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 AI stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Humans must remain in the loop. (Healthcare Finance)
  2. NYC grills AI execs. (WSJ)
  3. What’s next in AI personalization? (FinTechGlobal)
  4. The myth behind the AI agent hacks. (FT)
  5. AI in compliance seen as MSP advantage. (ChannelE2E)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
Red Flags Rising

Red Flags Rising: S01 E46: “Knowledge” Masterclass

Mike Huneke and Brent Carlson revisit and synthesize in one episode everything trade compliance teams need to know about the “knowledge” standard under the US Export Administration Regulations (EAR).

After starting the episode with Brent’s own journey in website design and announcing free resource materials (now) available at www.redflagsrising.com (01:05), Mike and Brent specifically discuss the full definition of “knowledge” under the EAR, including its three-tiered definition of actual knowledge, reason to know, and an awareness of a high probability (08:36); the “collective knowledge doctrine” under US law (14:14); parallels to US Foreign Corrupt Practices Act (FCPA) enforcement (15:06); misperceptions regarding the Bureau of Industry & Security’s KYC Guidance (16:25); other common misunderstandings (18:11); where KYC screening programs go wrong (24:23); the limited application of the “legally distinct” rule under the Entity List catch-all (25:33); why we accepted self-certifications when national security was served by global integration (26:36); the suspended BIS Affiliates Rule and its core problems (30:43); entity-shifting (34:10); risks associated with distributors and resellers (35:10); and the potential restrictions on remote access (40:49). They then conclude with this episode’s installment of Brent Carlson’s “Managing Up” segment (46:22).

Brent’s improved website and free resources

“Knowledge”

General Prohibition 10 

Brent Carlson, When Loopholes Create Liability Pitfalls (Aug. 25, 2023)

Contact Brent

More about Brent

Connect with Brent on LinkedIn

Contact Mike

More about Mike

Connect with Mike on LinkedIn

Categories
Blog

Modern Philosophers and Compliance: Part 2 – Simone de Beauvoir and the Conditions for Ethical Action

This week we will conclude our lengthy exploration of the philosophical underpinnings of the modern corporate compliance program. We have examined Hannah Arendt and her concepts of personal responsibility and how they relate to modern compliance programs. We will look at John Rawls and institutional justice and fairness in a corporate compliance program; Jürgen Habermas and the governance of speaking up; and Hans Jonas and the responsibility for the future of corporate compliance. Today we continue with Simone de Beauvoir and the conditions for ethical action in a corporation.

A company that asks employees to act ethically must examine the conditions under which they make decisions. An employee may understand the code of conduct, recognize a problem, and know how to report it, yet reasonably fear that speaking up will jeopardize a livelihood. That fear is a governance issue. Simone de Beauvoir helps compliance professionals understand why.

In Part 1, Hannah Arendt brought personal responsibility into the corporate approval process. We examined whether individuals exercise judgment when organizational routines encourage deference. Beauvoir takes the discussion further by asking how circumstances affect the ability to act on that judgment. Responsibility matters, and so does the distribution of power around the person expected to exercise it.

For the chief compliance officer, this means examining the distance between what a policy permits and what employees believe they can safely do. A reporting mechanism becomes credible when the company understands that distance and takes concrete steps to reduce it.

Freedom Exists Within Real Circumstances

Beauvoir was a French philosopher whose work explored freedom, responsibility, and oppression. In The Ethics of Ambiguity, published in 1947, she examined human beings as both capable of choosing and constrained by circumstances they did not choose. We pursue our own projects while depending on a world shared with other people. Ethical responsibility includes concern for their freedom as well as our own.

Ambiguity, in this sense, does not make every choice equally acceptable. It describes a condition of human life: we act with limited knowledge and within circumstances we cannot fully control, yet our decisions affect others. We must take responsibility without assuming that a simple formula will resolve every conflict.

In The Second Sex, published in 1949, Beauvoir examined how women were defined in relation to men and constrained by social expectations, institutions, and material dependence. Her analysis of women as the Other challenged the treatment of one group’s experience as the norm against which everyone else was measured.

The compliance application interprets these ideas. Beauvoir did not prescribe hotline procedures or investigation protocols. Her work asks us to attend to people’s actual circumstances. Inside a corporation, that means considering who controls pay, work assignments, advancement, and access to decision-makers. Those relationships can shape whether an employee sees an ethical option as practically available.

The Employee Who Knows How to Report

Consider this hypothetical. A junior procurement analyst discovers that a supplier submitted invoices for services without supporting documentation. Her manager directs her to process them before the reporting period closes. He says the supplier is important and that asking further questions will make the department look uncooperative.

The analyst has completed compliance training. She knows the hotline number. She also knows that the manager controls desirable assignments and will soon recommend whether her temporary position becomes permanent. A colleague who challenged him previously lost important responsibilities. She does not know whether that change was retaliatory, but she understands its warning value.

From headquarters, the reporting system appears accessible. From her position, the choice carries immediate economic consequences. The uncertainty about those consequences affects her decision even before anyone makes an explicit threat.

Beauvoir helps us examine that difference. The analyst retains responsibility for her conduct, while management remains responsible for the conditions it creates. Telling her to demonstrate courage leaves the governance problem unresolved. The company must examine how managerial discretion, employment insecurity, and prior experience shape how controls are used.

For the CCO, this requires asking whose perspective informed the policy. A senior employee with financial security and direct access to legal matters may experience the same reporting procedure very differently from someone whose continued employment depends on the person named in the concern.

The DOJ Connection Through Trusted Reporting

The Department of Justice’s Evaluation of Corporate Compliance Programs (ECCP) examines whether reporting mechanisms are trusted and whether employees feel comfortable using them. It also asks whether organizational practices discourage reporting and whether the company assesses employees’ willingness to raise concerns.

These inquiries create a substantive connection to Beauvoir’s emphasis on circumstances. Publishing a telephone number establishes an available channel. To understand whether employees can use it, you need evidence of their experience. The ECCP’s attention to proactive retaliation prevention reinforces that distinction.

In our hypothetical, the CCO should examine whether the analyst can reach someone outside the manager’s reporting line, whether temporary employees understand the available protections, and how concerns involving powerful managers are routed. The company should also explain the limits of confidentiality. In a small team, the facts themselves may reveal who reported.

An effective response could include an independent contact, a documented protection plan proportionate to the circumstances, and follow-up with the analyst. Those are practical design choices flowing from the identified risk. The organization should explain what it can do and who will act, rather than offer assurances that nobody can reliably deliver.

Whose Experience Shapes the Compliance Program

Beauvoir’s analysis of the Other offers another lesson for policy design. Organizations can mistake the experience of their most influential employees for the experience of the workforce. A policy written around headquarters staff may overlook workers who lack private computer access, work overnight, or depend on a supervisor to interpret company communications.

The ECCP asks about language and other barriers to accessing policies, as well as how the company confirms that employees know where to find them. Compliance professionals can use those questions to investigate whether the program works across different employment conditions.

Review a reporting process with employees who actually use it. Can a warehouse worker obtain guidance without leaving a visible record on a shared terminal? Can an employee working through a staffing agency identify the correct reporting route? Does the policy clearly explain where a concern about a supervisor should go? Answers should inform the process design.

This work requires listening without assuming that a category determines someone’s experience. Employees facing similar constraints may make different choices. The objective is to identify specific barriers and address them. Participation in policy testing gives the company evidence that a headquarters review cannot supply.

Protection Must Extend Beyond the Initial Report

A report begins a period of heightened responsibility for the organization. Once the analyst raises her concern, management decisions about her assignments, evaluation, and employment status may require additional scrutiny. The practical risk extends beyond formal dismissal.

Retaliation can take forms that appear routine when viewed separately: exclusion from meetings, reduced access to training, undesirable shifts, or a sudden change in performance assessments. Such actions require fact-specific investigation. Their occurrence after a report does not automatically establish retaliation, but it can justify closer review.

The ECCP examines retaliation policies, training, complaint handling, and follow-up. It also asks whether investigations are independent, objective, appropriately conducted, and documented [3]. A company should translate those expectations into assigned responsibilities for protecting reporters and assessing concerns about adverse treatment.

In our hypothetical, compliance and human resources could arrange an independent review of material employment decisions concerning the analyst during an appropriate monitoring period. The review should consider existing performance evidence and legitimate business reasons. Protection should preserve fair management processes while reducing the risk that discretionary decisions become instruments of punishment.

The analyst should also have a named contact and a realistic explanation of what follow-up to expect. A company can communicate that it has addressed a concern without disclosing confidential personnel information. Silence after intake can leave a reporter uncertain about both the investigation and personal safety within the organization.

Power Must Be Part of the Investigation

Beauvoir’s perspective also changes the questions investigators ask. If the analyst processed unsupported invoices before reporting, the investigation should establish the instructions she received, how she understood them, the authority she had, and the options she believed were available. Pressure is relevant evidence. It does not predetermine the outcome.

Investigators should examine the manager’s conduct with the same care. Did he discourage inquiry? Had employees raised similar concerns? Did commercial targets reward removing inconvenient checks? Were previous complaints dismissed because his department delivered strong results?

The ECCP examines whether managers encouraged unethical conduct or tolerated greater compliance risk to pursue business objectives. It also addresses consistent discipline and accountability for supervisory failures. These expectations support an investigation that follows power and responsibility through the organization.

A Board should receive enough information to assess whether influential managers are obstructing the program. Relevant reporting might identify repeated concerns within a business unit, unresolved retaliation allegations, or exceptions involving senior personnel. Aggregate results should be interpreted carefully. Few reports can reflect confidence in local management, fear of reporting, or other conditions requiring inquiry.

A useful governance discussion therefore asks what the company knows about the employees least able to challenge authority. The answer should connect employee experience with management action, including who owns unresolved issues and when the board will receive an update.

Five Key Beauvoir Takeaways for the Compliance Professional

  1. Assess the conditions surrounding ethical choices. Examine who controls an employee’s income, assignments, evaluation, and future opportunities. Use that understanding to identify situations where dependence may discourage questions or reporting.
  2. Test policies with employees in different circumstances. Include workers with limited access to technology, language barriers, insecure employment, or little access to senior leaders. Ask them to demonstrate how they would obtain guidance or report a concern.
  3. Treat reporter protection as an assigned responsibility. Establish independent contacts, appropriate follow-up, and proportionate review of potentially adverse treatment. Explain confidentiality limits and avoid promises the organization cannot keep.
  4. Investigate power alongside individual conduct. Determine what instructions, pressures, and authority shaped decisions. Preserve fair accountability for employees while examining managers’ actions and supervisory responsibilities.
  5. Give the board evidence about barriers to ethical action. Report material retaliation risks, repeated concerns involving influential leaders, and progress on corrective action. Explain what remains uncertain and how the company will investigate it.

Beauvoir’s contribution to compliance is practical: ethical expectations must be considered alongside the conditions in which people are asked to fulfill them. The CCO should ask which employees face the greatest personal cost when they follow the code. The board should ask what management has done to reduce that cost.

In Part 3, we turn to John Rawls and the twin concepts of institutional justice and institutional fairness. After considering responsibility with Arendt and the conditions for ethical action with Beauvoir, Rawls shows a compliance professional how a company can design policies, investigations, and discipline that employees can regard as fair, regardless of their position or influence.

Categories
FCPA Compliance Report

Natural Disaster Expo 2026 Speaker Series: Dr. Joseph Colaco Reducing Hurricane Damage in Houston’s High-Rise Environment

Welcome to Natural Disasters Expo Houston! For its fifth year, Natural Disasters Expo USA comes back to Houston on October 14–15, 2026, at the George R. Brown Convention Center. And there’s no better place. This city knows what it takes to prepare for disasters, respond, and rebuild afterward.

For two days, industry leaders, government agencies, first responders, and resilience professionals will come together with one shared goal: helping communities weather the next storm stronger than the last. Explore new solutions and technology, learn from front-line experts, and meet the partners who will help you turn preparedness into action. Whether you’re here to learn, share, or collaborate, you’re part of the effort to build a more resilient nation.

In this speaker series, Tom Fox interviews Dr. Joseph Colaco about Reducing Hurricane Damage in Houston’s Expanding High-Rise Environment.

Dr. Colaco is a tenured University of Houston architecture professor and president of Dr. Colaco Engineers. He visits with Tom about his upcoming presentation on reducing hurricane damage in Houston’s growing high-rise environment. Dr. Colaco describes assessing building performance during Hurricane Alicia in 1983, including firsthand observations downtown, documentation of facade damage, and visits to the Galleria area and Galveston. He explains that Houston’s increased density and taller buildings create new wind-flow conditions, making some older wind-tunnel results less applicable; he notes Houston began wind-tunnel and window-wall facade testing in the 1970s to inform design and construction. Dr. Colaco values conferences for networking and for transferring lessons learned across generations and cites Chicago’s periodic inspection requirements for tall buildings as a model for improving building safety and living conditions in Houston.

Resources:

Natural Disasters Expo USA

Get your Ticket

Conference Agenda

Speakers 2026

Categories
FCPA Compliance Report

FCPA Compliance Report: IIA President Anthony Pugliese on the IIA’s Expanding Role in AI, Cybersecurity, and Geopolitical Risk

In this episode, Tom Fox welcomes Anthony Pugliese, President and CEO of The Institute of Internal Auditors Inc.

We begin with the IIA’s global footprint, with boards in 122 countries; its role in setting internal audit standards; certifications, including the Certified Internal Auditor credential with about 225,000 holders; and education. Pugliese describes how internal audit is shifting from primarily financial controls to a broader focus on non-financial risks, including cybersecurity, AI and disruptive technologies, sustainability reporting, business resilience, and geopolitical risk. He emphasizes internal audit’s growing prospective/advisory role, particularly in assessing whether AI governance is keeping pace with rapid adoption and in communicating complex risks to boards and audit committees. Cybersecurity is cited as chief audit executives’ top concern and increasingly requires continuous monitoring. Pugliese notes members want more industry-specific guidance and expanded GRC resources relevant to compliance and directs listeners to iia.org and the free annual Risk in Focus report.

Key highlights:

  • What the IIA Does
  • Risk Landscape Shifts
  • From Assurance to Advisory
  • Geopolitical Risk in Practice
  • Cyber Threats and Continuous Auditing
  • Why Compliance Pros Should Join

Resources:

Anthony Pugliese on LinkedIn

Institute of Internal Auditors

 Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.