Categories
Daily Compliance News

Daily Compliance News: June 30, 2026, The New Auditor Ethics Rule Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • WeWork grows up. (FT)
  • The unknown unknowns of using AI at work. (NYT)
  • How a new auditor ethics rule may reshape litigation. (Reuters)
  • More ex-NBA players indicted in gambling probe. (ESPN)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Cartels, Extortion, and the New FCPA Risk: Lessons from Millicom

For years, many companies treated cartel risk as a security issue rather than a compliance issue. That view is no longer sufficient. In Mexico, Central America, and Brazil, organized criminal groups do not simply threaten operations from outside the company. They can infiltrate markets through corrupted officials, cartel-linked intermediaries, compromised law enforcement, logistics providers, bankers, community leaders, and local political actors. This will be a significant topic at the upcoming ACI Cartels, TCOs & Compliance Conference in Latin America next month in Washington, D.C.

That is why the Millicom Cellular FCPA enforcement action is such an important enforcement lesson. The case was not simply about bribes paid to government officials. It was about the convergence of bribery, cartel money, cash controls, joint venture governance failures, political influence, money laundering, and accounting controls. The DOJ stated that TIGO Guatemala paid more than $118 million to resolve a long-running bribery investigation involving monthly cash bribes to Guatemalan members of Congress and that some cash used for bribe payments came from laundered narcotrafficking proceeds.

The Crossover Risk: When Cartel Risk Becomes FCPA Risk

The most dangerous risk is not always the obvious cartel member with a gun. It may be the official who is cartel-affiliated, cartel-controlled, cartel-compromised, or operating in a cartel-controlled territory. That person may hold a municipal permit, customs role, police function, legislative position, procurement seat, or regulatory gatekeeper role. For the company, the question is not only whether the demand comes from a public official. It is about whether the demand sits within a criminal ecosystem that can convert ordinary business activity into FCPA, AML, sanctions, books-and-records, internal controls, and even material support risks.

Mexico shows the point clearly. OSAC has warned that several Mexican transnational criminal organizations were designated as Foreign Terrorist Organizations and Specially Designated Global Terrorists and that paying extortion demands, including derecho de piso, can create material support concerns for U.S. organizations. Brazil presents a different but equally serious model. The U.K. Home Office reported that Brazil has more than 80 organized criminal groups, including the PCC and Comando Vermelho (CV), and that militia groups made up of current and former state agents extort populations under their control.

The US Treasury Department has described PCC as one of the largest organized crime groups in Latin America, involved in money laundering, extortion, murder-for-hire, and drug debt collection. Indeed, in May 2026, the US State Department designated both the PCC and CV as Foreign Terrorist Organizations.

Central America adds another layer. In a regional Extortion Report, the Global Initiative Against Transnational Organized Crime noted that corruption within state institutions is pervasive and that security officials may use institutional power to extort, while collusion by corrupt officials sustains extortion markets. That is the crossover risk for companies: the same demand can be an extortion event, a corruption event, and an accounting controls event.

Bribery Versus Extortion

The difference between a bribe and extortion is not always intuitive, but it is critical. A bribe is a corrupt payment made to obtain or retain business, secure an improper advantage, influence an official act, or induce the misuse of an official position. The payment can be requested by the official first. The fact that the official demanded the payment does not automatically make it extortion under the FCPA. The FCPA Resource Guide, 2nd edition, explains that corrupt intent exists when a payment is intended to induce the recipient to misuse an official position, including to obtain preferential legislation or regulations.

True extortion or duress is different. The FCPA Resource Guide states that payments made in response to true extortionate demands under imminent threat of physical harm do not give rise to FCPA liability because they are not made with corrupt intent or for the purpose of obtaining or retaining business. But the same guidance draws a hard line: mere economic coercion does not amount to extortion. A payment demanded as the price of market entry or contract award remains a bribery risk because the company can decide not to pay.

That distinction matters in cartel-heavy environments. A payment to stop an immediate threat to employees may be a duress-driven safety response. A payment to obtain a permit, avoid a regulatory delay, secure customs clearance, influence a municipal inspection, or win a contract is not transformed into lawful conduct merely because the official made the demand aggressively.

Derecho de Piso and Derecho de Paso

Derecho de Piso is generally understood as a criminal “floor tax” or protection payment required to operate in a territory. It may be demanded from retailers, agricultural producers, logistics companies, construction firms, miners, energy operators, or local distributors. Derecho de Paso means a “right of passage” payment, often framed as a toll to move people, trucks, cargo, or goods through a controlled area.

Both are dangerous because they blur lines. A company may believe it is facing a security threat. In reality, it may be funding a designated organization, recording a false business expense, using a third party as a payment conduit, or allowing a cartel-linked official to convert extortion into a corrupt advantage. The compliance lesson is not that employee safety should take a back seat. It should not. The lesson is that safety-driven decisions must still be documented truthfully, escalated appropriately, and controlled through legal, compliance, security, finance, and senior management.

Millicom as the Centerpiece

The Millicom FCPA enforcement action demonstrates how these risks manifest in practice. TIGO Guatemala’s scheme ran from at least 2012 to 2018 and involved efforts to influence Guatemalan legislators, including support for radiofrequency renewals and “Ley TIGO,” a telecommunications law that benefited the company. The company earned at least $58 million in profits from the schemes.

The mechanics were extraordinary. Cash was delivered by helicopter to the TIGO Guatemala helipad in duffel bags. A $15 million put-call execution fee was used as part of a bribery slush fund. A $12 million inflated contract and backdated invoices created the appearance of legitimate services. Most troubling, a banker laundered narcotrafficking proceeds and funneled cash to support TIGO Guatemala bribe payments.

This is the compliance lesson. The company did not face a single bad invoice. It faced a criminal infrastructure. Cash, shell companies, backdated contracts, cartel-linked funds, compromised governance, and political influence worked together. That is the modern FCPA risk environment in cartel-affected markets.

The Accounting Provisions Cannot Be an Afterthought

The FCPA accounting provisions are where many companies will face their hardest questions. The FCPA Resource Guide explains that issuers must keep books and records that accurately and fairly reflect transactions and maintain internal accounting controls sufficient to provide reasonable assurances over authorization, recording, accountability, and access to assets. It also states that it is never appropriate to mischaracterize transactions and that bribes are often hidden as consulting fees, commissions, petty cash withdrawals, vendor payments, or miscellaneous expenses.

This is especially important for extortion. A payment made under duress should never be hidden as a logistics fee, community relations expense, consulting payment, security charge, donation, customs support fee, or facilitation-style cost. Even where the anti-bribery analysis turns on duress, the books-and-records analysis turns on accuracy. The internal controls analysis turns on whether the company had reasonable controls over cash, third parties, approvals, documentation, payment channels, escalation, and post-event review.

Millicom’s remediation shows what DOJ expects after such a failure. DOJ credited remediation that included root cause analysis, termination of involved personnel, new management and compliance personnel, enhanced third-party onboarding and transaction monitoring, data analytics, testing of more than 250 transactions, an ephemeral messaging policy, training, a direct compliance reporting line, and an 800 percent increase in dedicated compliance headcount. The attached analysis rightly frames this as organizational reinvention rather than ordinary remediation.

The Cartels, TCOs & Compliance in Latin American conference will feature these topics and many more. For information and registration, click here. For a complete list of the agenda, click here. You can receive 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
Blog

Compliance Command: Essential Leadership Strategies Inspired by ‘Amok Time’

In the vast universe of compliance lessons gleaned from the timeless classic Star Trek: The Original Series, few episodes hold as much richness in leadership insights as “Amok Time.” In this iconic episode, we see Captain Kirk navigate complex interpersonal dynamics, regulatory procedures, and ethical dilemmas under the most extraordinary circumstances. As compliance professionals, we can appreciate the parallels between our complex corporate environments and the challenges of navigating rules, managing teams, and making ethical decisions under pressure. Today, we look at five key leadership lessons from “Amok Time” that are directly applicable to the challenges compliance officers face.

Lesson 1: Prioritize Transparency and Open Communication

Illustrated by Spock’s erratic behavior, caused by his biological imperative, Pon Farr leads to initial confusion and potential risk aboard the USS Enterprise. Spock’s reluctance to share his predicament with Kirk initially creates a misunderstanding, complicating the crew’s operations.

Compliance Lesson: Compliance leaders must foster an environment of transparency and encourage open communication. Like Spock, team members might hesitate to disclose issues due to embarrassment, fear of reprisal, or simply uncertainty. Creating psychological safety within teams enables early disclosure of problems, preventing issues from escalating into larger compliance violations or operational risks.

Lesson 2: Understand and Respect Cultural and Regulatory Nuances

Illustrated by: Kirk and Dr. McCoy, Spock accompanies them to Vulcan, where they find themselves involved in a highly formalized and ritualistic duel. Kirk’s unfamiliarity with Vulcan traditions nearly costs him his life.

Compliance Lesson: Effective compliance leadership requires a thorough understanding of the cultures, traditions, and regulatory environments in which your organization operates. Whether navigating international jurisdictions or managing diverse internal policies, compliance officers must exhibit sensitivity and comprehension to avoid costly misunderstandings and regulatory missteps.

Lesson 3: Flexibility and Adaptability in Crisis

Illustrated by: Initially believing he would merely witness a ceremony, Kirk unexpectedly finds himself in combat against Spock. Despite the confusion and imminent danger, Kirk quickly adapts, seeking ways to manage the unexpected.

Compliance Lesson: The ability to adapt rapidly to unforeseen challenges is crucial in compliance leadership. Regulatory changes, sudden internal crises, or external investigations often require quick pivots and decisive action. Developing agility and cultivating adaptability in your compliance team ensures your organization can respond effectively and mitigate risks.

Lesson 4: Empower Your Team Through Trust

Illustrated by: Dr. McCoy cleverly uses a sedative to simulate Kirk’s death, thereby creatively resolving the dangerous situation. Kirk implicitly trusts McCoy’s judgment and skill, empowering him to take decisive action without explicit orders.

Compliance Lesson: Trust and empowerment are fundamental to strong compliance leadership. Compliance leaders must trust their team’s expertise and decision-making abilities, empowering them to act swiftly and confidently. Fostering trust encourages innovative problem-solving and timely action, which are essential in mitigating compliance risks and addressing issues proactively.

Lesson 5: Ethical Decision-Making Under Pressure

Illustrated by Kirk, he chooses to respect Vulcan customs despite personal risk, demonstrating his commitment to ethical principles, diplomatic integrity, and respect for others’ traditions. His moral stance sets a standard for the crew and maintains the integrity of the Federation’s core values.

Compliance Lesson: Leaders must consistently uphold ethical standards, especially under pressure. Ethical lapses often occur in high-stress situations when compliance obligations seem most cumbersome. By consistently modeling ethical behavior, compliance leaders reinforce the organization’s commitment to integrity and set a powerful example for employees.

Final ComplianceLog Reflections

The Star Trek episode “Amok Time” offers a compelling exploration of leadership under duress, rich with insights applicable to compliance professionals. Kirk’s handling of transparency issues, cultural nuances, unexpected crises, empowered teamwork, and ethical integrity highlights timeless leadership qualities that translate seamlessly into today’s corporate compliance landscape.

As compliance professionals, we can draw valuable inspiration from Captain Kirk and his crew. Embracing transparency fosters proactive issue management. Understanding diverse cultural and regulatory landscapes prevents costly misunderstandings. Flexibility ensures effective responses to dynamic compliance challenges, while trust empowers your teams to innovate and proactively address compliance issues. Finally, unwavering ethical decision-making reinforces your organization’s commitment to integrity and compliance.

Just as the Enterprise crew boldly faced extraordinary challenges, compliance leaders must boldly navigate the complexities of regulatory environments and corporate ethics. By internalizing these lessons, compliance professionals can enhance their leadership capabilities, develop resilient compliance programs, and preserve their organization’s integrity in the face of any challenge.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Trekking Through Compliance

Trekking Through Compliance: Compliance Insights from Operation: Annihilate

In corporate compliance, investigative techniques are not merely about uncovering facts; they’re about discerning patterns, identifying root causes, and mitigating risks effectively. We can glean powerful investigative insights from unexpected sources. Today, it is from the classic Star Trek TOS episode “Operation: Annihilate!

Today, we delve deeper into five critical investigative lessons from “Operation: Annihilate!” and see how compliance officers can leverage these insights in their daily practice.

Lesson 1: Rapid Identification and Response

Illustrated by: Upon arriving at Deneva, the Enterprise crew discovers widespread hysteria, confusion, and aggressive behavior among inhabitants.

Compliance Lesson. In compliance investigations, rapid identification and response are crucial. Much like the Enterprise crew swiftly pinpointing the cause of the planet’s chaos, compliance officers must quickly ascertain the origin of any compliance violation.

Lesson 2: Holistic Evidence Gathering

Illustrated by: Dr. McCoy examines infected individuals and conducts meticulous tests to understand the parasite’s biological impact.

Compliance Lesson. Like Dr. McCoy and Spock, compliance officers must go beyond surface appearances, collecting a diverse range of evidence, including interviews, financial records, and digital data, to piece together an accurate narrative. 

Lesson 3: Objective Analysis and Validation

Illustrated by: The Enterprise team initially hypothesizes that the parasites must be eradicated through extreme measures, including potentially destructive ones.

Compliance Lesson. Compliance professionals must rigorously test assumptions and hypotheses against facts and evidence to ensure that remedial actions are both effective and proportionate to the issue at hand. 

Lesson 4: Courage in the Face of Difficult Decisions

Illustrated by: Captain Kirk faces an agonizing choice: risk Spock’s eyesight or delay action that could save millions.

Compliance Lesson. Compliance leaders, like Kirk, must demonstrate courage and decisiveness, recognizing that hesitation or indecision can exacerbate the situation. 

Lesson 5: Clear and Transparent Communication

Illustrated by: Throughout the crisis, Captain Kirk maintains open and transparent communication with his crew, explaining strategies, risks, and expectations clearly and candidly.

Compliance Lesson. Effective communication is vital in compliance investigations. Transparency fosters trust among stakeholders and ensures clarity on investigative processes and outcomes. 

Final ComplianceLog Reflections

The Star Trek TOS episode “Operation—Annihilate!” may seem an unconventional source of compliance wisdom. Yet, its lessons in rapid response, holistic evidence collection, objective analysis, courageous decision-making, and transparent communication are profoundly relevant. These insights underscore the universal nature of investigative best practices, applicable across disciplines and eras. Compliance professionals, like the Enterprise crew, frequently operate under pressure, confronting unpredictable challenges that demand innovative thinking and swift, informed decisions. 

By internalizing these lessons, compliance officers can enhance their ability to manage investigations effectively, mitigate risks, and strengthen their organization’s resilience. Ultimately, these principles reinforce the importance of preparedness, adaptability, and ethical integrity. Compliance teams that embrace these lessons will be well-positioned to safeguard their organizations, foster a culture of transparency, and uphold the highest standards of conduct, boldly going where responsible and proactive governance dictates.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
AI Today in 5

AI Today in 5: June 29, 2026, The Farmers Embracing AI Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. AI governance in commercial insurance. (FinTechGlobal)
  2. Farmers embracing AI. (NYT)
  3. China matches Anthropic in AI cybersecurity. (WSJ)
  4. Tackling AI compliance through a multipart framework. (BloombergLaw)
  5. Make AI regs more patient-centered. (NewsMedical)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
FCPA Compliance Report

FCPA Compliance Report: Managing Compliance and National Security Risks When Doing Business in the DRC, Part 2

In this episode, Tom Fox welcomes David Simon, Partner at Foley & Lardner; Jack Korba, Of Counsel at Foley & Lardner; and Olivier Bustin, a Partner at Pinsent Masons, to discuss doing business in and with the Democratic Republic of the Congo (DRC). This is the second part of a two-part series on this topic, which presents a detailed approach to evaluating and managing travel to a high-risk country or region.

They discuss how companies investing in high-risk jurisdictions like the Democratic Republic of the Congo should treat diligence as ongoing risk management, using tailored controls, audits, and continuous monitoring informed by geopolitical developments and government/regulatory priorities (including signals such as announcements and sector focus, such as critical minerals). The speakers emphasize pragmatism: accepting some ambiguity while designing jurisdiction-specific compliance frameworks, rather than placing standard programs on “autopilot” and maintaining active C-suite and board engagement. They stress building and documenting a rational, risk-tolerant decision process that can be explained to regulators (e.g., DOJ/SEC), including knowing counterparties and local dynamics, implementing real controls, and escalating decisions appropriately. Key pitfalls to avoid include overcommitting to projects beyond risk tolerance and entering transactions without sufficient preparation. The panel also urges compliance leaders not to be paralyzed by fear, to shape opportunities early, and to note market opportunities and signals of U.S. engagement, such as financing for the Lobito railway corridor.

Key highlights:

  • Ongoing Risk Controls
  • Pragmatism In High Risk
  • Regulator Ready Diligence
  • Mistakes To Avoid
  • Where To Start

Resources:

David Simon

Jack Korba

Olivier Bustin

Foley & Lardner

Pinsent Masons

The Democratic Republic of the Congo as a Near-Term Strategic Opportunity for U.S. Companies Part 1

Part 2

Part 3

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Daily Compliance News

Daily Compliance News: June 29, 2026, The Judge Wants More Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Top Milei official resigns over corruption allegations. (FT)
  • Judge wants more info on DOJ’s dismissal of Adani. (NYT)
  • Corruption crackdown in Iraq. (Reuters)
  • China removes 6 generals in additional corruption crackdown. (SCMP)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Cartels, TCOs, and Compliance in Latin America: Why 2026 Is a Watershed Moment

For compliance professionals, some years mark an evolution. Others mark a turning point. In 2026, corporate compliance in Latin America has reached that turning point. For the past two decades, most companies approached regional risk through a familiar lens: anti-corruption. The focus was on government touchpoints, customs interactions, licensing, permits, state-owned enterprises, and third-party intermediaries. That framework is still important. But it is no longer sufficient.

Today, the risk landscape has expanded dramatically. Cartels, transnational criminal organizations, foreign terrorist organization designations, sanctions, anti-money laundering exposure, and supply chain infiltration have all moved to the center of the compliance conversation. What was once a specialized concern has become a board-level issue.

That is why the upcoming ACI Forum on Cartels, TCOs, and Compliance in Latin America is so timely. It is also why compliance officers need to understand that this is not simply another enforcement trend. It is a structural change in how risk must be assessed, governed, and managed. I recently had the opportunity to visit with Matt Ellis, Member at Miller & Chevalier and co-Chair of the Forum. You can listen to Ellis’ remarks on this episode of the FCPA Compliance Report on the Compliance Podcast Network.

The New Risk Equation

The Trump administration has made clear that cartels, fentanyl trafficking, organized crime, and the influence of China in Latin America are policy priorities. That focus has brought multiple enforcement tools to bear, including sanctions, anti-money laundering authorities, FTO designations, and a broader integration of these issues into the compliance and enforcement landscape.

Ellis said that companies, the old model of regional compliance risk must be rethought. The issue is no longer limited to whether a payment was made to a foreign official. The question now is whether a company’s supply chain, transportation provider, security arrangement, or local commercial partner could create exposure under anti-terrorism, sanctions, or AML frameworks.

Mexico Is the Opening Chapter, Not the Whole Book

Much of the current focus is on Mexico, and for good reason. That is where the enforcement spotlight is currently brightest. But compliance professionals should not make the mistake of thinking this challenge begins and ends there.

The risks extend across Latin America, including Central America, Venezuela, Colombia, Brazil, Panama, and other markets where cartel activity, organized crime influence, sanctions risk, or opaque commercial structures may create significant exposure. Each country carries its own risk profile, but the common lesson is clear. Mexico may be the first chapter, but it will not be the last.

For boards and executive teams, that means regional strategy must be reviewed through a broader lens. Market entry, third-party engagement, logistics routes, security providers, and local partnerships all need to be reassessed.

Why the Supply Chain Has Become a Compliance Flashpoint

One of the most important lessons from this discussion is that cartel risk can be embedded in the supply chain. This is where compliance professionals need to recalibrate their thinking. In the anti-corruption world, companies typically focus on agents, distributors, customs brokers, and other third parties that have direct government interactions. In the cartel and TCO context, risk can be embedded within ordinary business operations. Transportation vendors, warehouse providers, local suppliers, labor relationships, and security services may all present hidden risk if they are controlled by, connected to, or exploited by organized crime.

That changes the role of compliance. Procurement, logistics, operations, and security can no longer be treated as peripheral functions. They are now front-line participants in risk identification and mitigation. This is where the compliance function must show leadership. The CCO must bring these disciplines together and translate legal and enforcement developments into practical operational controls.

Due Diligence Must Move Beyond Check-the-Box

If there is one message compliance professionals should take from Ellis’ podcast, it is this: traditional due diligence is not enough. In anti-corruption compliance, companies have become skilled at identifying common red flags. They know how to screen for politically exposed persons, government connections, unusual payment terms, and opaque ownership structures. Those tools still matter, but they will not always surface cartel-linked risk. Organized crime does not announce itself in a database hit.

Instead, companies need a more nuanced and operationally grounded approach. Are there local security concerns being raised by employees? Are there unusual labor dynamics in a region where those patterns do not make commercial sense? Is there persistent chatter about a vendor, route, or business partner that cannot be ignored? Are operations in a community producing concerns that legal and compliance have not fully explored? These are not traditional diligence questions, but they are increasingly the right ones.

Under the DOJ’s Evaluation of Corporate Compliance Programs (ECCP), regulators continue to ask whether a company’s program is designed, implemented, and tested in a manner that addresses actual risk. This is precisely where program effectiveness will now be measured in high-risk operations in Latin America.

The Importance of Listening to the People on the Ground

One of the most practical insights from the interview was the emphasis on local intelligence. Employees who live and work in these communities often know far more than any desktop diligence report will reveal.

That point should resonate deeply with compliance professionals. A company’s speak-up culture is not simply about hotline metrics or case closure rates. It is about whether employees trust the organization enough to raise concerns that may not yet fit into a neat legal category. It is about whether the company listens when local personnel say that something does not add up. This is where compliance, culture, and internal controls intersect.

If a company has not built mechanisms to capture and escalate local concerns, then it is not simply missing information. It is missing one of the most effective risk detection tools available to it. These are not abstract governance questions. They go directly to program effectiveness, risk ownership, and business sustainability.

A Whole-of-Government Enforcement Model

Another important takeaway is the multidimensional nature of this risk environment. In the FCPA era, companies often focused on the DOJ and the SEC. That framework no longer captures the full picture. Now the compliance professional must think across Treasury, OFAC, FinCEN, Homeland Security, DEA, and other agencies, all of which may be interested in the same underlying conduct. This level of coordination matters because it means the government’s expectations are no longer siloed. Enforcement, intelligence, sanctions, and AML concerns can converge quickly. For compliance officers, this demands a more integrated risk management model. Silos within the company will not work when the government itself operates in a coordinated manner.

Is There More Room for Government Engagement?

One of the more interesting themes from the discussion was whether companies may have more room to engage with the government than they traditionally would in the anti-corruption context. That does not mean every issue should be self-disclosed. It does mean that in high-risk environments, thoughtful engagement may sometimes be part of a sound compliance strategy.

The key is judgment. No company should rush into a conversation with the government without understanding the facts and the implications. But where risks are ambiguous, stakes are high, and the legal regimes overlap, strategic dialogue may help demonstrate good faith, show the absence of criminal intent, and allow a company to explain the reasonable steps it is taking. That is not leniency. That is credibility.

The Bottom Line

This is the next generation of Latin America compliance risk. It does not replace anti-corruption compliance. It expands it, hardens it, and operationalizes it. The lesson for compliance professionals is clear. You cannot address cartel and TCO risk with yesterday’s playbook. You need broader risk assessments, deeper third-party diligence, stronger local reporting channels, tighter cross-functional coordination, and more informed board oversight.

In 2026, the companies that succeed will not be the ones with the longest policy manuals. They will be the ones who can demonstrate a compliance program built for the reality of where they operate. For the CCO, that is the challenge. For the board, that is the oversight mandate. For the business, that is the cost of operating responsibly in a changed enforcement environment. The future of compliance in Latin America is already here. The only question is whether your program is ready for it.

Check out the ACI Forum on Cartels, TCOs, and Compliance in Latin America by clicking here. You can receive a 10% off the price by using the Discount Code D10-999-CPN26.

ACI is the sponsor of today’s blog.

Categories
Blog

Compliance Lessons at Warp Speed: Insights from Operation: Annihilate!

In corporate compliance, investigative techniques are not merely about uncovering facts; they’re about discerning patterns, identifying root causes, and mitigating risks effectively. Surprisingly, we can glean powerful investigative insights from unexpected sources, including the classic Star Trek TOS episode “Operation: Annihilate!” This iconic episode sees Captain Kirk and the crew of the Enterprise arrive at the planet Deneva, only to discover it has been gripped by mass hysteria, violence, and suffering triggered by a parasitic infestation. These creatures induce unbearable pain and extreme aggression, driving the population toward chaos and destruction. The crew faces an immense challenge: quickly identifying, analyzing, and neutralizing the threat before it gets out of control.

For compliance professionals, this storyline provides compelling parallels to real-world investigative scenarios. The episode emphasizes the importance of swift and precise identification of underlying issues, comprehensive evidence gathering, objective validation of findings, courageous decision-making in crises, and clear, transparent communication throughout the investigation. Mastering these investigative lessons ensures that compliance teams can effectively manage risks, uphold integrity, and maintain organizational stability. Let’s delve deeper into the five critical investigative lessons from “Operation: Annihilate!” and see how compliance officers can leverage them in their daily practice.

Lesson 1: Rapid Identification and Response

Illustrated by: Upon arriving at Deneva, the Enterprise crew finds widespread hysteria, confusion, and aggressive behavior among the inhabitants. The source? A mysterious parasite is causing intense pain and erratic behavior.

In compliance investigations, rapid identification and response are crucial. Much like the Enterprise crew swiftly pinpointing the cause of the planet’s chaos, compliance officers must quickly ascertain the origin of any compliance violation. Time is of the essence in containing the problem, mitigating risks, and preventing escalation.

Lesson 2: Holistic Evidence Gathering

Illustrated by: Dr. McCoy examines infected individuals and conducts meticulous tests to understand the parasite’s biological impact. Spock, despite personal risk, also subjects himself to the parasite’s influence to gather essential firsthand evidence.

A rigorous compliance investigation requires the collection of holistic evidence. Like Dr. McCoy and Spock, compliance officers must go beyond surface appearances, collecting a diverse range of evidence, including interviews, financial records, and digital data, to piece together an accurate narrative. Comprehensive data collection is essential in determining the full scope and impact of any compliance issue.

Lesson 3: Objective Analysis and Validation

Illustrated by: The Enterprise team initially hypothesizes that the parasites must be eradicated through extreme measures, including potentially destructive ones. However, through disciplined testing and validation, they discovered that high-intensity light effectively neutralizes the parasites without destroying the host organisms.

Objectivity in analysis and validation is a cornerstone of effective compliance investigations. Compliance professionals must rigorously test assumptions and hypotheses against facts and evidence to ensure that remedial actions are both effective and proportionate to the issue at hand. This disciplined approach prevents unnecessary collateral damage and ensures ethical responses.

Lesson 4: Courage in the Face of Difficult Decisions

Illustrated by: Captain Kirk, who faces an agonizing choice: risk Spock’s eyesight or delay action that could save millions. Kirk makes the tough call, and although Spock is temporarily blinded, the decision ultimately saves countless lives.

Compliance investigations often present challenging ethical and professional dilemmas. Compliance leaders, like Kirk, must demonstrate courage and decisiveness, recognizing that hesitation or indecision can exacerbate the situation. Though difficult decisions may carry significant implications, courageous leadership ensures that integrity and organizational trust remain intact.

Lesson 5: Clear and Transparent Communication

Illustrated by: Throughout the crisis, Captain Kirk maintains open and transparent communication with his crew, explaining strategies, risks, and expectations clearly and candidly.

Effective communication is vital in compliance investigations. Transparency fosters trust among stakeholders and ensures clarity on investigative processes and outcomes. Compliance officers must regularly communicate investigative findings and recommendations to facilitate understanding, cooperation, and organizational alignment.

Final ComplianceLog Reflections

The Star Trek TOS episode “Operation: Annihilate!” may seem an unconventional source of compliance wisdom. Yet, its lessons in rapid response, holistic evidence collection, objective analysis, courageous decision-making, and transparent communication are profoundly relevant. These insights underscore the universal nature of investigative best practices, applicable across disciplines and eras. Compliance professionals, like the Enterprise crew, frequently operate under pressure, confronting unpredictable challenges that demand innovative thinking and swift, informed decisions.

By internalizing these lessons, compliance officers can enhance their ability to manage investigations effectively, mitigate risks, and strengthen their organization’s resilience. Ultimately, these principles reinforce the importance of preparedness, adaptability, and ethical integrity. Compliance teams that embrace these lessons will be well-positioned to safeguard their organizations, foster a culture of transparency, and uphold the highest standards of conduct, boldly going where responsible and proactive governance dictates.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

Compliance on the Edge: Lessons from Star Trek’s Ethical Frontier in City from the Edge of Forever

Today, we delve into perhaps the most iconic Star Trek: The Original Series episode, “The City on the Edge of Forever.” Doubling as my favorite Star Trek episode of all time (not just TOS), the episode not only represents a pinnacle in science fiction storytelling but also provides timeless lessons for corporate compliance professionals.

In this episode, the USS Enterprise crew encounters the Guardian of Forever, a mysterious gateway to the past. A temporarily insane Dr. McCoy alters history, and Captain Kirk and Mr. Spock must follow him to restore the timeline, ultimately facing profound moral dilemmas. Let’s dive into five compliance lessons from this episode, using scenes to illuminate essential insights into corporate ethics and compliance.

Lesson 1: The Importance of Immediate Response

Illustrated by: Dr. McCoy leaps through the Guardian of Forever, drastically altering history, and Captain Kirk immediately decides to follow him.

Compliance Lesson. One of the first critical lessons from the episode is the importance of a prompt response in crisis management. When Dr. McCoy leaps through the Guardian of Forever, drastically altering history, Captain Kirk immediately decides to follow him. Kirk recognizes that swift action is required to mitigate and correct the risk posed by McCoy’s actions to the timeline.

In compliance, the ability to react swiftly and decisively can prevent minor compliance issues from becoming significant crises. Compliance officers must cultivate readiness and decisive leadership, ensuring teams are prepared to act promptly and effectively when compliance risks emerge.

Lesson 2: Understanding the Root Cause

Illustrated by: Mr. Spock constructs a rudimentary device using primitive 1930s technology to identify the critical historical alteration that would have led to Edith Keeler’s survival.

Compliance Lesson. Mr. Spock, using a rudimentary yet effective device built with 1930s technology, painstakingly investigates and identifies the critical historical alteration—Edith Keeler’s survival —which inadvertently allows a catastrophic global conflict to occur. By clearly identifying the root cause, Kirk and Spock can focus their remediation strategy effectively.

Root cause analysis remains central in compliance programs. Without accurately identifying the source of compliance issues, organizations risk implementing ineffective solutions that fail to address the root cause. Compliance teams must rigorously investigate incidents, understand underlying causes, and ensure that corrective actions address the genuine drivers of non-compliance.

Lesson 3: Ethical Decision-Making

Illustrated by: Kirk realizes that Edith Keeler, a compassionate woman with whom he has fallen in love, must die to restore the timeline.

Compliance Lesson. Arguably, the most poignant compliance lesson emerges when Kirk realizes that Edith Keeler, a compassionate and visionary woman with whom he has fallen in love, must die to restore the timeline. Kirk’s agonizing decision underscores a critical ethical compliance lesson: adherence to principles must transcend personal emotions and relationships.

Compliance officers frequently face challenging ethical dilemmas that require difficult decisions. Upholding integrity might sometimes mean making unpopular choices. Like Kirk, compliance professionals must prioritize ethical commitments, understanding that integrity and moral responsibility are paramount.

Lesson 4: Clear Communication and Collaboration

Illustrated by: Kirk and Spock, they demonstrate teamwork and clear communication, effectively navigating their challenging environment and limited resources.

Compliance Lesson. Throughout the episode, Kirk and Spock demonstrate extraordinary teamwork and clear communication. Despite their challenging environment and limited resources, their consistent collaboration ensures effective decision-making and the implementation of strategic plans. Their communication is concise, targeted, and based on mutual understanding and respect.

Effective compliance programs similarly depend on transparent communication and seamless collaboration across departments. Compliance officers must foster a culture where team members communicate openly, share vital information promptly, and collaborate cohesively to uphold compliance standards.

Lesson 5: Proactive Monitoring and Preventive Measures

Illustrated by: The Enterprise first encounters the Guardian of Forever, which provides glimpses into historical events, illustrating its monitoring capabilities.

Compliance Lesson. When the Enterprise first encounters the Guardian of Forever, it provides glimpses into various historical events, demonstrating its ability to monitor and foresee critical junctures in history. This scene symbolizes the value of proactive monitoring and preventive measures.

Compliance professionals must adopt proactive monitoring strategies, leveraging technology and analytics to anticipate and mitigate risks before they materialize. Compliance programs should include continuous monitoring mechanisms to ensure the early identification of potential issues and swift corrective actions.

Final ComplianceLog Reflections

“The City on the Edge of Forever” delivers profound insights into ethical dilemmas, crisis response, communication, root cause analysis, and proactive monitoring. Captain Kirk’s heart-wrenching decision to prioritize the greater good, despite the personal cost, epitomizes the ethical resolve compliance professionals must emulate.

By integrating these Star Trek lessons into your compliance program, you can strengthen your organization’s ability to navigate complex ethical landscapes and maintain robust compliance standards. After all, as the Guardian of Forever reminds us, understanding and respecting history and ethics help shape a more stable and compliant future.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha