Categories
Blog

Connected Compliance: Part 4 – From Hotline to Trust

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust them enough to speak. In Blog Post 1, we considered communication as a compliance control. Blog Post 2 showed how operational signals create a dynamic risk radar. In Blog Post 3, we explained why every investigation is a test of governance and culture. This final installment examines the front door to the entire system: the reporting program.

A company can buy a hotline in an afternoon. It cannot buy employee trust. That distinction is the starting point for an effective whistleblower program. The platform, policy, telephone number, and case-management system are necessary infrastructure. They are not the program. The real program is the experience an employee anticipates before reporting and receives after doing so.

The answers do not come primarily from policy language. They come from what employees see happen to colleagues who raise concerns. A mishandled report can teach an entire workplace that silence is safer.

The First Report Is the Real Program Test

One of the easiest ways to discourage reporting is to do a poor job after a report arrives. An ignored allegation, confidentiality breach, unexplained delay, dismissive intake, or retaliation can do more damage than an outdated hotline poster.

This is why the reporting program and investigation process cannot be separated. Intake creates an expectation of action. Investigation determines whether that expectation is met. Follow-up determines what the reporter tells others about the experience. The process should begin with prompt acknowledgment. Whenever possible, a trained person should thank the reporter, gather clarifying information, explain next steps, and set realistic expectations. An automated receipt confirms that the technology worked. Personal contact demonstrates that the organization is listening.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places confidential reporting within its evaluation of whether a compliance program is well designed. The 2024 Evaluation of Corporate Compliance Programs (ECCP) calls for an “efficient and trusted mechanism” for anonymous or confidential reports. The two words that matter most are efficient and trusted.

Efficiency requires accessible channels, proper routing, risk-based triage, qualified investigators, timely handling, documentation, and accountable remediation. Trust requires employees to believe that the company will take concerns seriously, limit information sharing, prevent retaliation, and respond consistently regardless of rank or commercial importance.

The DOJ asks whether employees know about the reporting mechanism, feel comfortable using it, and are willing to report misconduct. It also asks a difficult question: “Conversely, does the company use practices that tend to chill such reporting?” That directs compliance professionals beyond the hotline itself. Confidentiality agreements, manager behavior, performance systems, investigation delays, incentive structures, employment actions, and prior reporter experiences can all affect willingness to speak. The DOJ further asks whether the company tests hotline effectiveness by tracking a report from intake through disposition. This makes end-to-end testing a governance exercise, not a vendor-management task.

Design Channels Around the Workforce

A reporting system designed for headquarters may fail the people most likely to observe operational risk. Field employees, shift workers, remote personnel, contractors, and employees with limited computer access need channels that fit how they work. The answer is a meaningful choice. A mature program may include a telephone hotline, web portal, mobile access, email, QR codes, and in-person reporting to compliance, human resources, legal, internal audit, security, or management. Channels should be available in appropriate languages and accessible to employees with disabilities.

Placement matters. A QR code on an identification badge, break-room poster, or work-issued device may be more useful than a buried intranet link. A telephone line remains essential for employees who prefer to speak or lack reliable digital access. Many employees will first approach someone they trust. Compliance should analyze channel use by location, function, shift, language, and workforce type. A channel with no reports is not necessarily evidence that the location has no concerns. It may be evidence that the channel is unknown, inaccessible, or distrusted.

Make Speaking Up a Leadership Behavior

Tone at the top remains essential, but the employee’s immediate supervisor often controls the reporting climate. A chief executive may celebrate integrity while a frontline manager rolls their eyes, interrupts the employee, demands names, or warns that a report will hurt the team. The manager’s reaction becomes the company’s culture in that moment.

Managers need specific training. They should listen without investigating on the spot, avoid promises they cannot keep, preserve information, escalate promptly, and reinforce anti-retaliation expectations. A concern does not have to arrive through the hotline to require action. Leadership modeling should be visible. When leaders invite dissent, respond calmly to bad news, thank employees who identify risk, and communicate anonymized lessons, they show that speaking up protects the business. Regular field presence builds relationships, reveals access barriers, and provides context unavailable from a dashboard.

Tell the Truth About Confidentiality

Employees often use anonymity and confidentiality interchangeably, but they are different. An anonymous reporter does not disclose identity. Confidentiality means identity and related information are limited to people with a legitimate need to know. The company should never promise absolute secrecy when the facts make it impossible. In a small team, subject matter, timing, or witnesses may reveal who raised the concern. Overpromising creates a second breach of trust.

The better approach is candor. Explain that information will be restricted as far as reasonably possible, that some disclosure may be necessary to investigate fairly or meet legal obligations, and that retaliation is prohibited. Use role-based access, careful case notes, secure records, disciplined interview planning, and clear need-to-know rules. Confidentiality is not a slogan. It is an information-control process.

Communicate Without Compromising the Investigation

Silence during a long investigation can feel like indifference. Reporters do not need access to witness statements or confidential personnel decisions, but they do need evidence that the matter remains active. Set a communication cadence based on case risk and expected duration. Provide updates even when the update is that the review continues. Explain delays where appropriate, remind the reporter how to provide additional information, and repeat the anti-retaliation contact route.

At closure, confirm that the concern was reviewed and addressed as appropriate. Thank the reporter and reinforce anti-retaliation protection. The company may be unable to disclose findings or discipline, but it can close the human loop.

Treat Anti-Retaliation as an Active Control

An anti-retaliation policy is necessary, but it is not self-executing. Retaliation can be direct, such as termination, demotion, or loss of pay. It can also be subtle: exclusion from meetings, undesirable shifts, lost development opportunities, hostile supervision, damaged reputation, or social isolation. The company should assess retaliation risk throughout the matter. Compliance and human resources should preserve a baseline of the reporter’s role and treatment, monitor employment actions, schedule check-ins, and provide an escalation route outside the normal chain. Monitoring should continue after closure.

Protection does not mean immunity from legitimate performance management. It means employment decisions affecting a reporter receive appropriate review, are supported by contemporaneous evidence, and are not influenced by protected activity. When retaliation occurs, discipline should be prompt and visible enough, within confidentiality limits, to reinforce the rule.

Do Not Discredit the Difficult Messenger

Serial reporters and incomplete reports create operational challenges, but frequency, frustration, or poor drafting does not determine whether an allegation is true. Each concern should be assessed on its merits. A sparse report may still contain breadcrumbs. Investigators can review organizational charts, personnel changes, transactions, prior complaints, and control data before concluding that the matter cannot proceed. Multiple reports may reveal an unresolved environmental problem or weak earlier investigations.

Motivation can be relevant to credibility, but it should not replace evidence. Labeling someone a troublemaker is often an easy way to miss a difficult fact and an effective way to chill the next reporter.

Measure Trust, Not Just Volume

Hotline volume alone is a weak measure. A low number may reflect a healthy culture, a small risk population, inaccessible channels, fear, or lack of awareness. A rising number may reflect deteriorating conduct or growing confidence in the program. A useful dashboard combines volume with context: awareness and comfort survey results, reports by workforce segment, intake-to-acknowledgment time, triage time, case aging by risk, substantiation patterns, repeat allegations, reporter-update timeliness, retaliation concerns, remediation completion, and employee feedback after closure.

Compliance should test the entire system. Submit a controlled report, trace routing and access, review acknowledgments, confirm escalation rules, examine investigation handoffs, and verify closure and retention. Analyze whether reporting data changes risk assessment, controls, training, and resources. The objective is evidence that the program learns.

Closing the Connected Compliance Program

This four-part blog post series began with communication because employees cannot use a system they do not understand. It moved to dynamic risk assessment because organizations must recognize changing signals. It then examined investigations because allegations require independent facts, accountability, and remediation. Today we discussed whistleblower programs because none of those capabilities matter if people do not trust the company enough to speak. Join us tomorrow in our concluding Part 5 for a deeper discussion of how compliance truly is connected.

The connected compliance program is a loop. Communication builds awareness. Reporting supplies risk intelligence. Investigation converts allegations into reliable findings. Remediation improves controls. Feedback strengthens culture and makes future reporting more likely.

For the compliance professional, the final test is not whether the hotline exists. It is whether an employee facing a difficult choice believes that raising a concern will protect the organization, lead to a credible response, and not cost that employee a career. That is how a reporting channel becomes a trusted control and how culture becomes credibility.

Bonus Questions for Compliance Professionals

  1. Can every workforce segment access a reporting channel during the way and hours in which it actually works?
  2. Do employees know the available channels, understand external reporting rights, and say they feel comfortable using them?
  3. What happens during the first 24 hours after a report arrives, and who is accountable for acknowledgment, triage, and protection?
  4. Are managers trained to recognize and escalate concerns received outside formal reporting channels?
  5. Can the company show how reporter identity and case information are restricted to people with a legitimate need to know?
  6. How does the organization monitor direct and subtle retaliation during and after an investigation?
  7. Does the company communicate appropriately with reporters when an investigation is delayed and when it closes?
  8. Are serial, anonymous, and incomplete reports assessed on evidence and context rather than labels or assumptions?
  9. What reporting data has changed the risk assessment, controls, training, discipline, or resource allocation during the past year?
  10. Has the company recently tested one report from submission through routing, investigation, remediation, feedback, and retention?
Categories
Beyond the Label

Beyond the Label Podcast: Hope After the Flood: Surviving, Supporting, and Rebuilding Together

Co-hosts Tyler Townsend and Kelsi Wilmot of Beyond the Label pause their usual guest format to process the emotional toll of widespread flooding affecting all 19 counties, especially Kerr County, and to remind listeners that it’s okay not to be okay.

Tyler and Kelsi share lived experiences from last year’s floods and the recent July floods, including evacuations, work at reunification centers, deployments, volunteer coordination, and the lingering anxiety and “standby” stress that storms now trigger. They highlight community resilience, the importance of asking for help, and practical mental health resources, including 988, the crisis line (877-466-0660), free drop-in support at 819 Water Street, outreach teams, and therapist availability. They close by emphasizing hope, finding your “why,” avoiding isolation, and rebuilding together.

Key highlights:

  • Flooding Week Check-In
  • Hope and Holding On
  • Crisis Support Resources
  • Kelsi Flood Story
  • Tyler Response Journey
  • Aftereffects and Healing
  • Why We Do This Work
  • Find Your Why Helpers
  • Closing Together

Resources: 

Hill Country MHDD

Categories
Daily Compliance News

Daily Compliance News: July 29, 2026, The Advice of Counsel Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Raskin wants FIFA investigated for corruption. (USA Today)
  • Another South African ABC official resigns amid a cloud of suspicion. (Bloomberg)
  • The advice of counsel defense. (Law360) sub req’d
  • Meta fighting dozens of social media lawsuits. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Great Women in Compliance

Great Women in Compliance: GWIC x Everything Compliance – Summer 2026

We are back with another GWIC x Everything Compliance crossover, with Hemma and Lisa joining Kristy Grant-Hart and Karen Moore to talk about what’s on their minds and the compliance news of the day. They discuss everything from Scoular Company entering into a Deferred Prosecution Agreement and paying over $10m for FCPA violations, lessons for Ethics & Compliance professionals from the World Cup, the resolution of the allegations against Alibaba and AUS Merchant Services, and what we can take from the leaked draft of the EU’s New Public Procurement Regulations.

And, of course, it wouldn’t be Everything Compliance without the rants and raves.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 59 – Child’s Play and Serious Ethics from “And The Children Shall Lead”

Universally panned as perhaps the worst episode of Star Trek: The Original Series, “And the Children Shall Lead,” it nevertheless stands out for its disturbing exploration of power, manipulation, and ethical responsibility. Compliance professionals tasked with safeguarding their organizations from ethical lapses can draw powerful insights from this intriguing narrative. Today, we explore five key ethical lessons every compliance leader should internalize from this episode.

Lesson 1: Influence and Ethical Leadership

Illustrated by: The children aboard the Enterprise, manipulated by an alien entity known as Gorgan, exercise dangerous control over the crew, compelling them to abandon rational judgment.

Compliance Lesson: Leadership wields tremendous influence. Ethical leaders must recognize their power and consciously deploy it to uphold ethical standards rather than undermine them. A misuse of influence can erode trust and corrupt organizational culture.

Lesson 2: Recognizing and Addressing Manipulation

Illustrated by: Kirk and Spock realize that the children’s unnatural behavior stems from external manipulation by Gorgan, who exploits their innocence and vulnerability for his gain.

Compliance Lesson: Organizations must be vigilant against manipulative practices. Ethical compliance involves recognizing manipulation, whether internal or external, and actively counteracting it to protect the organization’s integrity.

Lesson 3: Ethical Courage in Speaking Truth to Power

Illustrated by: Nurse Chapel and Captain Kirk courageously confront the children with the harsh truths about their manipulated behavior and its devastating consequences.

Compliance Lesson: Speaking truth to power, especially in ethical matters, requires considerable courage. Compliance leaders must foster environments where employees feel empowered to speak openly, even against popular opinion or powerful interests.

Lesson 4: Awareness of Ethical Blind Spots

Illustrated by: Initially, the Enterprise crew underestimates the threat posed by the children, blinded by assumptions of innocence and vulnerability.

Compliance Lesson: Ethical blind spots often emerge from assumptions and biases. Organizations must cultivate awareness and self-reflection, understanding that ethical risks can arise unexpectedly from overlooked or underestimated sources.

Lesson 5: Responsibility and Accountability in Ethics

Illustrated by: After breaking Gorgan’s hold, Kirk ensures that the children confront and understand the severity of their actions, instilling a crucial sense of accountability.

Compliance Lesson: Ethical accountability must permeate all organizational levels. Leaders and employees alike should clearly understand their responsibilities and the consequences of unethical behavior.

Final ComplianceLog Reflections

And The Children Shall Lead” reminds compliance professionals that ethical vigilance and leadership are essential for organizational health. Through ethical influence, courageous confrontation of manipulation, awareness of blind spots, and unwavering accountability, organizations can protect their integrity and thrive. Compliance professionals must continually embody these lessons, creating robust ethical cultures that are resilient against manipulation, corruption, and ethical lapses. Let the lessons of the Enterprise crew guide us, fostering environments where integrity leads, and compliance thrives.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

Categories
Compliance Into the Weeds

Compliance into the Weeds: Scoular Company FCPA Settlement: Cartel Links, Border Trade Risks, and Compliance Lessons

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent FCPA resolution with the Scoular Company. Both Tom and Matt have blogged on this matter, so check out the Resources link below for additional discussions.

The recent FCPA enforcement action against Scoular Company involved a $10.2 million payment and a three-year deferred prosecution agreement over bribes by third-party customs brokers to Mexican border officials to expedite cross-border shipments. DOJ emphasized alleged cartel connections, including a strong statement from the U.S. Attorney for the Western District of Texas, which raised questions about expanded local U.S. attorney involvement and how cartel or potential FTO designations could heighten trade and compliance risks. The company received no voluntary self-disclosure credit but got a 25% discount, with remediation cited (including dropping brokers and strengthening tone at the top). They highlight off-channel WhatsApp use, the lack of released key documents (DPA, statement of facts, criminal information), and practical compliance takeaways on third-party oversight, data analytics, and risk assessments.

Resources:

Matt in Radical Compliance

Tom in FCPA Compliance and Ethics Blog

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
AI Today in 5

AI Today in 5: July 29, 2026, The Chief AI Officer Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. New CT AI Law creates compliance obligations. (CBIA)
  2. Healthcare needs to lean on security and integrity. (HealthcareITNews)
  3. Banks are appointing Chief AI Officers. (FinTechMagazine)
  4. Chief AI-Legal and compliance. (SimplyWallSt)
  5. AI applications in finance. (DataBricks)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

Guiding Integrity: Ethics Lessons from Star Trek’s ‘And The Children Shall Lead’

My winner for the worst of Star Trek: The Original Series is the episode “And the Children Shall Lead.” Yet there are clear ethical lessons, as the episode itself stands out for its disturbing exploration of power, manipulation, and ethical responsibility. Compliance professionals tasked with safeguarding their organizations from ethical lapses can draw powerful insights from this intriguing narrative. Today, we explore five key ethical lessons every compliance leader should internalize from this episode.

Lesson 1: Influence and Ethical Leadership

Illustrated by: The children aboard the Enterprise, manipulated by an alien entity known as Gorgan, exercise dangerous control over the crew, compelling them to abandon rational judgment.

Compliance Lesson: Leadership wields tremendous influence. Ethical leaders must recognize their power and consciously deploy it to uphold ethical standards rather than undermine them. A misuse of influence can erode trust and corrupt organizational culture. Ethical leadership requires self-awareness and a steadfast commitment to organizational values. Leaders who misuse their influence often set negative precedents, creating an environment where unethical behavior becomes normalized. Conversely, leaders who consistently demonstrate ethical decision-making inspire similar behavior in their teams, fostering a culture of integrity.

What can you do now? Ensure your leaders understand the impact of their actions. Implement regular leadership training focused on ethical decision-making and on raising awareness of how leaders’ actions affect company behavior and culture.

Lesson 2: Recognizing and Addressing Manipulation

Illustrated by: Kirk and Spock realize that the children’s unnatural behavior stems from external manipulation by Gorgan, who exploits their innocence and vulnerability for his gain.

Compliance Lesson: Organizations must be vigilant against manipulative practices. Ethical compliance involves recognizing manipulation, whether internal or external, and actively counteracting it to protect the organization’s integrity. Manipulation can manifest subtly through coercion, exploitation of vulnerabilities, or abuse of power dynamics. Compliance leaders must educate employees on the nuances of manipulation and how it undermines ethical practices, ultimately compromising organizational integrity. Early detection and proactive intervention are key to safeguarding the organization.

What can you do now? Develop training programs designed to empower employees to recognize and report manipulative behavior. Establish clear communication channels for safely and anonymously raising ethical concerns.

Lesson 3: Ethical Courage in Speaking Truth to Power

Illustrated by: Nurse Chapel and Captain Kirk courageously confront the children with the harsh truths about their manipulated behavior and its devastating consequences.

Compliance Lesson: Speaking truth to power, especially in ethical matters, requires considerable courage. Compliance leaders must foster environments where employees feel empowered to speak openly, even against popular opinion or powerful interests. It is crucial to establish a corporate culture that not only permits but actively encourages transparency and honesty. Compliance officers play a pivotal role in creating platforms where ethical concerns can be voiced without fear of retaliation. The ability to challenge unethical practices openly is essential for maintaining organizational integrity.

What can you do now? Create a robust whistleblower program that emphasizes protection and support for those who courageously voice ethical concerns. Celebrate instances where employees have demonstrated bravery in upholding ethical standards.

Lesson 4: Awareness of Ethical Blind Spots

Illustrated by: Initially, the Enterprise crew underestimates the threat posed by the children, blinded by assumptions of innocence and vulnerability.

Compliance Lesson: Ethical blind spots often emerge from assumptions and biases. Organizations must cultivate awareness and self-reflection, understanding that ethical risks can arise unexpectedly from overlooked or underestimated sources. Blind spots can be particularly dangerous because they often remain invisible until significant damage occurs. Compliance teams must foster an environment of continuous vigilance, in which assumptions are routinely challenged, and biases are openly discussed and addressed. Training programs should incorporate scenario-based exercises to reveal hidden ethical vulnerabilities.

What can you do now? Conduct regular ethics risk assessments to uncover hidden vulnerabilities. Encourage ongoing discussions and training sessions about implicit biases, assumptions, and overlooked ethical threats within the organization.

Lesson 5: Responsibility and Accountability in Ethics

Illustrated by: After breaking Gorgan’s hold, Kirk ensures that the children confront and understand the severity of their actions, instilling a crucial sense of accountability.

Compliance Lesson: Ethical accountability must permeate all organizational levels. Leaders and employees alike should clearly understand their responsibilities and the consequences of unethical behavior. Accountability ensures that ethical standards are consistently upheld and that violations are promptly and appropriately addressed. Leaders must make it clear that ethical breaches will have real and proportionate consequences, reinforcing the importance of personal and organizational integrity. Accountability measures help maintain trust within and outside the organization.

What can you do now? Establish transparent accountability systems that reinforce individual and collective responsibility for ethical behavior. Regularly communicate the importance of ethical accountability and the organizational commitment to enforce ethical standards uniformly.

You Must Lead With Ethics

And The Children Shall Lead” reminds compliance professionals that ethical vigilance and leadership are essential for organizational health. Through ethical influence, courageous confrontation of manipulation, awareness of blind spots, and unwavering accountability, organizations can protect their integrity and thrive.

Compliance professionals must continually embody these lessons, creating robust ethical cultures that are resilient against manipulation, corruption, and ethical lapses. Let the lessons of the Enterprise crew guide us, fostering environments where integrity leads, and compliance thrives.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Connected Compliance: Part 3 – Why Every Investigation Is a Culture Opportunity for Your Organization

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. In Blog 1, we examined communication as a compliance control. In Blog Post 2, we showed how those communications and other operational signals create a dynamic risk radar. Today in Blog Post 3, we ask what happens when a signal becomes an allegation as an introduction to how and why every investigation can be an opportunity to both pressure-test and build out your culture.

A hotline report, audit exception, control override, manager escalation, or unusual transaction may begin as just another compliance signal; once the company decides it requires investigation, the stakes change. The organization must establish what happened, protect people and evidence, make defensible decisions, and strengthen the program.

That makes an investigation more than a fact-finding exercise. It is a visible test of governance. Employees watch who is interviewed, how leaders behave, whether the process appears fair, whether high performers receive special treatment, and whether the company acts when misconduct is substantiated. Details should remain confidential, but the organization cannot erase the cultural impact. Every investigation sends a message.

Credibility Is Built Before the First Interview

The strongest investigations begin with disciplined triage. Before scheduling interviews or collecting data, the company should first identify the immediate risks that require action. Is anyone’s health or safety at risk? Could misconduct be continuing? Is evidence vulnerable? Does the allegation implicate financial reporting, government contracting, sanctions, corruption, product integrity, cybersecurity, privacy, or another obligation requiring prompt escalation?

Containment is not a conclusion. Suspending access, preserving records, pausing a payment, separating employees, or protecting a reporter may be necessary while the facts remain unresolved. The decision should be proportionate, documented, and revisited as evidence develops.

Triage should identify the functions that need to participate without turning the matter into a committee project. One person should own the process, one decision-maker should approve material scope changes, and communication lines should be defined at the outset.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places investigations squarely inside its test of program effectiveness. The 2024 Evaluation of Corporate Compliance Programs (ECCP) asks, “How does the company ensure that investigations are properly scoped?” It then asks what steps the company takes to ensure investigations are “independent, objective, appropriately conducted, and properly documented,” as well as how the company determines who should conduct an investigation.

Those words provide a practical quality standard. Proper scope means the investigation addresses the allegation and reasonably connected issues without drifting into an unlimited inquiry. Independence means the investigator is free from conflicts and improper business pressure. Objectivity requires a search for facts that may confirm or disprove the allegation. Appropriate conduct includes lawful evidence collection, fair treatment of witnesses, and proportionate methods. Proper documentation allows the company to explain what it did, why it did it, and how it reached its conclusions.

DOJ also asks whether the company applies timing metrics, monitors outcomes, and ensures accountability for findings and recommendations. Later, the ECCP describes a working program as having an “appropriately funded mechanism for the timely and thorough investigations” of allegations or suspicions of misconduct. The point is not speed at any cost. It is disciplined responsiveness supported by adequate resources.

Scope the Question, Not the Desired Answer

A written investigation plan should define the allegation, relevant policy or legal issues, time period, business units, people, data sources, immediate risks, and proposed work. It should identify the standard used to reach findings and the expected form of the report. It should also record what remains outside scope.

The plan must be flexible. Evidence may reveal additional conduct, another geography, a control failure, or management involvement. The investigator should document the new information, assess its materiality, identify any additional resources or conflicts, and obtain appropriate approval for expansion.

This discipline prevents a scope narrowed to contain the issue and investigation drift that delays a conclusion. A credible process follows the evidence while preserving a clear line of sight to the original allegation.

Choose the Investigator for the Risk

Not every matter requires outside counsel, and not every matter should remain inside the company. The choice should turn on credibility and capability, not habit. Internal investigators may understand the business and manage routine matters efficiently. External counsel or specialists may be appropriate when allegations involve senior leadership, significant legal exposure, government reporting, material financial impact, technical evidence, cross-border restrictions, litigation, or concerns about internal independence.

The company should establish decision criteria before a crisis. Who determines whether compliance, legal, human resources, internal audit, security, or outside counsel will lead? What conflicts require recusal? When does the audit committee or another independent authority oversee the matter? Which technical experts may be needed, and how will their work be directed? An outside law firm’s letterhead does not create independence. It comes from clear authority, freedom from interference, sufficient resources, access to evidence, and an escalation route when investigators encounter resistance.

Protect the Privilege with Precision

The attorney-client privilege can protect confidential communications seeking or providing legal advice, but an investigation is not privileged simply because a lawyer attends. Privilege rules are jurisdiction-specific, and careless circulation, unclear roles, or unnecessary third-party involvement can create risk.

At the beginning, counsel should define the legal purpose, identify the client and team, establish communication and documentation protocols, and explain confidentiality expectations. Team members should know which communications seek legal advice, where documents will be stored, and who may receive them. Over-labeling every document as privileged does not create stronger protection. It can undermine discipline and complicate later disclosure decisions. The better approach is to use privilege deliberately, involve counsel where legal advice is genuinely required, and preserve a reliable factual record that supports the company’s decisions.

Treat Witnesses as People, Not Evidence Containers

Witness interviews often determine whether employees experience the investigation as fair. The investigator should explain the purpose of the interview, the investigator’s role, expectations for truthful cooperation, applicable confidentiality limits, and the company’s prohibition against retaliation. The interviewer should not promise complete secrecy, prejudge the allegation, coach testimony, or imply that raising concerns created the problem.

Respect improves evidence quality. Employees are more likely to provide complete information when questions are neutral, and the interviewer listens before challenging inconsistencies. Cultural, language, disability, and power dynamics may affect participation and should be addressed thoughtfully.

Anti-retaliation protection requires more than an opening statement. Compliance and human resources should identify foreseeable risks of retaliation, monitor employment actions and workplace behavior, provide a safe escalation channel, and respond quickly to concerns. Retaliation may be subtle: exclusion, schedule changes, lost opportunities, hostile supervision, or reputational harm. A technically sound investigation can still damage culture if the reporter or witnesses pay a price for participating.

Preserve Evidence and Measure the Right Clock

Evidence management must begin early. Relevant emails, collaboration messages, mobile communications, transaction records, system logs, personnel documents, and physical evidence all require preservation. Collection should follow applicable law, privacy requirements, company policy, and forensic protocols. The team should document sources, custodians, dates, gaps, and chain of custody where necessary. Always remember the first question the DOJ will ask after you self-disclose is, “Do you have the documents tied down?

Timeliness should be measured, but the metric must support quality. Useful measures include time from intake to triage, time to investigator assignment, aging by risk category, days awaiting business action, time from finding to remediation, and overdue reporter updates. A single average completion target can create pressure to close simple matters quickly or rush complex ones. Status reviews should ask what is delaying the matter, whether scope remains appropriate, whether interim protections still work, and whether new risks require escalation. The objective is a process that explains delay, removes bottlenecks, and prioritizes higher-consequence matters.

Move Beyond the Bad Actor

An investigation that identifies who violated a policy but not why the system allowed it has completed only half the work. DOJ asks whether investigations identify “root causes, system vulnerabilities, and accountability lapses,” including those involving supervisors and senior executives.

Root-cause analysis should examine incentives, performance pressure, control design, access rights, training, supervision, third-party oversight, data availability, prior warnings, and the consistency of discipline. Did the policy prohibit the conduct but the workflow reward it? Did a manager ignore a red flag? Did an exception process become the normal process? Did earlier reports reveal the same weakness?

The answer should drive remediation, including discipline, control redesign, policy revision, monitoring, training, leadership changes, third-party action, disclosure, or resource reallocation. Each action needs an owner, deadline, evidence, and testing. Otherwise, the investigation becomes a historical record rather than a compliance control.

Close the Case and the Cultural Loop

A reasoned closure record should state the allegation, scope, steps taken, evidence considered, credibility analysis, findings, and approved response. Discipline should be consistent across ranks and levels of commercial importance, with deviations documented. Investigation data should then feed the risk assessment, training plan, control testing, and management reporting.

The reporting party also matters. Without disclosing confidential personnel information, the company can acknowledge that the review is complete, thank the person for speaking up, restate anti-retaliation protections, and provide a contact for further concerns. Silence after intake encourages employees to conclude that nothing happened.

This is the connection across the series. Communication brings information into the program. Dynamic risk assessment helps the company recognize its significance. Investigation converts allegations into facts, accountability, and learning. Therefore, join us for Part 4 tomorrow, as we will demonstrate the front door to that process: how an effective whistleblower program gives employees safe, accessible ways to report and confidence that speaking up will lead to credible follow-through.

Bonus Questions for Compliance Professionals

  1. Who has authority to triage an allegation and order immediate containment or preservation measures?
  2. What written criteria determine who should lead an investigation and when independent oversight or outside counsel is required?
  3. Can the company show that recent investigations were properly scoped, independent, objective, timely, and documented?
  4. Which stages of the investigation create the greatest delays, and are those delays risk-based or simply unmanaged?
  5. How does the organization monitor subtle retaliation against reporters and witnesses?
  6. Do investigation reports identify control failures, incentives, supervisory accountability, and root causes in addition to individual misconduct?
  7. What evidence shows that completed investigations changed controls, training, discipline, resources, or risk assessment?
  8. How does the company communicate appropriate closure to reporters without compromising confidentiality?
Categories
Innovation in Compliance

Innovation in Compliance: Compliance Evangelists Fighting Modern Slavery Together with Matt Friedman

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with Matt Friedman, who provides a 2026 update to the fight against the international scourge of human trafficking and modern slavery and discusses his latest book, Awakening the Advocate.

Friedman is a leading voice in the fight against human trafficking and modern slavery, known for founding and leading the Mekong Club and for more than 35 years of advocacy, policy work, and corporate engagement. He views modern slavery as a vast, still underaddressed crisis, where tens of millions remain trapped while the number of survivors helped and criminals convicted remains far too small to match the scale of the problem. Friedman believes the biggest barrier is not compassion but awareness and that educating employees inside companies can “wake up” lawyers, bankers, marketers, and other professionals who already have the instincts to help. From his perspective, ESG and compliance efforts can protect the business while also driving meaningful anti-slavery action, making corporate compliance a practical engine for both risk reduction and social change.

Key highlights:

  • Compliance Evangelists Fighting Modern Slavery Together
  • Leadership Briefings and Procurement Risk Assessments
  • Board-Level Awareness Protects Reputation and Brand Value
  • AI sifting data to uncover scam-center patterns
  • Modern Slavery Risks Make ESG’s Future Uncertain

Resources:

Matt Friedman on LinkedIn

The Mekong Club

Awakening the Advocate on Amazon.com

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts.