Frankenstein and Compliance: Part 2 – Bride of Frankenstein: When Leaders Know Better

Ed. Note: This month, on his podcast series Popcorn and Compliance, Tom Fox takes a deep dive into the first five Frankenstein movies. Over October, he will cover Frankenstein, The Bride of Frankenstein, The Son of Frankenstein, The Ghost of Frankenstein, and Frankenstein Meets the Wolf Man. The blog post accompanies the podcast series.

The compliance problem in Frankenstein was innovation without governance. Henry Frankenstein became so focused on whether he could create life that he failed to consider adequately what would happen if he succeeded. He had extraordinary technical capabilities but almost no governance infrastructure around his experiment. There was no meaningful risk assessment, no effective challenge function, no contingency planning, and no clear accountability for the consequences. In Bride of Frankenstein (1935), the compliance problem is different and considerably more troubling. Henry now knows better.

Henry has survived the consequences of his original experiment. He has seen the Monster die and the destruction it caused. He understands that his scientific ambition created risks he could not control. At the beginning of the sequel, Henry appears ready to put his experiments behind him and build a life with Elizabeth. Then Dr. Pretorius arrives.

Pretorius is one of the great characters in the Universal horror canon, but anyone who has spent time in corporate compliance will recognize him. He is intelligent, sophisticated, persuasive, and completely convinced that conventional ethical boundaries should not interfere with extraordinary achievement. More importantly, he understands Henry. Pretorius knows which arguments will appeal to Henry’s ambition and which pressures will overcome his judgment.

This changes the compliance analysis. Henry cannot claim that the risk is unknown. He has already experienced the consequences. The question is whether he has learned from them. That distinction provides the central compliance lesson of Bride of Frankenstein. A significant difference exists between an organization that fails to identify a new risk and one that identifies it, experiences the consequences, and then allows the same underlying conduct to return.

Knowledge Changes the Governance Obligation

Corporate compliance programs generate information. Risk assessments identify vulnerabilities. Internal audits identify control weaknesses. Investigations identify misconduct. Hotline reports identify cultural problems. Due diligence identifies third-party risks. Compliance monitoring identifies patterns that may require further attention. The value of that information depends upon what the organization does with it.

An investigation that establishes what happened but produces no organizational change has limited compliance value. The same is true of an internal audit finding that is administratively closed without determining whether the underlying risk has been reduced. Knowledge must lead to action. This is where Henry fails. He possesses precisely the information that should prevent him from returning to the laboratory. He knows his previous experiment had catastrophic consequences. Nevertheless, Pretorius gradually pulls him back toward the same underlying conduct.

For a CCO, this raises an important question about repeat misconduct. When the same type of compliance problem appears more than once, the organization should ask whether the earlier incident was treated as an isolated event rather than a systemic warning. Questions you might ask include: Did the investigation identify root causes? Were controls changed? Were incentives examined? Was management behavior considered? Was remediation tested? Were lessons incorporated into the next risk assessment? Once an organization knows where a material risk exists, future failures become more difficult to characterize as unforeseeable.

The Pretorius Problem

Pretorius represents a particular type of organizational risk: an influential individual who consistently finds reasons why normal controls shouldn’t apply. Every experienced compliance professional has encountered some version of this problem. A business executive explains that a particular transaction is unique. A salesperson argues that a questionable practice is standard in the local market. A manager insists that due diligence must be completed after onboarding because the customer cannot wait or you will cause the company to miss the quarter’s numbers. None of those statements necessarily establishes misconduct. They should nevertheless cause a compliance professional to ask additional questions.

The danger often comes through rationalization rather than an explicit request to violate the law. The transaction is too important. The amount is too small. The customer relationship is too valuable. The competitor already does it. The process takes too long. The documentation can be completed later. Pretorius works on Henry in much the same way. He does not persuade Henry that the original experiment was harmless. He persuades him that there is a sufficiently compelling reason to cross the boundary again. That is a leadership problem because effective ethical leadership requires executives to recognize when commercial, personal, or organizational pressure is changing their risk tolerance.

When Exceptions Become the Business Process

One of the most important implications for a compliance program is managing exceptions. Most corporate policies need some mechanism for legitimate exceptions. Business circumstances are too complex to assume every rule applies equally in every situation. The problem arises when exceptions become routine.

Consider third-party due diligence. A distributor needs to begin work immediately because of a time-sensitive commercial opportunity. Management approves an exception that lets work begin before diligence is complete. The exception may be entirely defensible. Then another distributor receives the same treatment. Then another. Eventually, business personnel begin viewing due diligence as a process that can routinely be completed after onboarding. The written policy has not changed. The actual control environment has.

The same issue can arise with gifts and entertainment, conflicts of interest, expense approvals, sanctions screening, contracting requirements, AI approvals, cybersecurity requirements, or financial controls. Each exception may have a plausible business explanation. Taken together, the exceptions may demonstrate that the organization has developed an operating practice inconsistent with its stated policy.

Compliance should therefore monitor exceptions as data. How many are being granted? Which business units request them? Which executives approve them? Are the same reasons repeatedly used? Do temporary exceptions become permanent arrangements? A pattern of exceptions can early indicate the normalization of deviance.

Culture Becomes Visible When the Stakes Rise

Bride of Frankenstein also provides an important lesson about corporate culture. Culture is relatively easy to discuss when ethics and commercial objectives don’t conflict. The real test comes when the two appear to diverge.

Suppose Compliance identifies significant concerns about the company’s highest-revenue distributor. What happens next? Suppose an investigation substantiates allegations involving a senior executive responsible for a strategically important business. How does management respond? Suppose an AI application promises significant cost savings, but Legal, Privacy, Information Security, or Compliance recommends delaying deployment for additional testing. Does the company wait? Those decisions reveal more about corporate culture than a values statement.

Henry believes he has changed after the events of Frankenstein. Pretorius tests that belief. Once scientific ambition, pressure, and personal consequences enter the equation, Henry’s commitment to walking away begins to erode. Companies experience the same tension. A business may have strong written values and an extensive compliance program, but employees pay attention to what happens when adherence to those values becomes costly.

This is particularly important for boards. Boards cannot assess culture solely through training completion rates, hotline statistics, or employee surveys. Those metrics can help, but directors should also understand how management handles difficult decisions involving high performers, major customers, significant third parties, and substantial revenue. Culture becomes visible in decisions.

The Monster and the Importance of Organizational Experience

One of the most significant developments in Bride of Frankenstein is the Monster’s evolution. In the original film, he is largely reactive. In the sequel, he begins to learn about human relationships and the world around him. The sequence with the blind hermit is particularly important. The hermit does not judge the Monster by his appearance. He provides food, companionship, music, and kindness. The Monster responds to that environment. For a brief period, we see how different surroundings produce different behavior.

That provides a useful analogy for corporate culture. Employees learn what an organization values through experience. They observe how their supervisors behave. They see who receives promotions and bonuses. They notice whether high performers receive exceptions from policies. They see whether the organization respects or marginalizes people who raise concerns. They learn whether management wants bad news delivered promptly or prefers problems to stay below the surface.

Compliance should therefore pay particular attention to management behavior. Employee surveys, exit interviews, hotline data, investigation trends, turnover information, disciplinary records, and audit findings can help identify business units where the local management culture differs from the company’s stated expectations.

Incentives Can Become the Corporate Pretorius

Pretorius uses Henry’s ambition as leverage. Corporations use compensation and performance systems to influence employee behavior every day. That makes incentives a central compliance issue. A company may tell employees that integrity is its highest priority while evaluating them primarily on revenue, growth, margin, or quarterly performance. Employees will quickly determine which message matters more.

This does not mean financial incentives are inappropriate. Companies exist to generate economic value, and employees should be rewarded for performance. The compliance issue is whether the incentive structure unintentionally encourages excessive risk-taking or undermines controls.

Compliance should understand how significant employee populations are compensated. The Evaluation of Corporate Compliance Programs (ECCP) makes similar inquiries. Should questions include: Are sales targets realistic? Do employees get rewarded for the quality and sustainability of performance, or simply for the amount of revenue generated? Does compliance performance affect bonuses or promotion decisions? Are managers held accountable for control failures within their teams? Can compensation be reduced or recovered following significant misconduct? The goal is alignment. Employees should understand that how results are achieved matters as much as the results themselves.

High Performers Are the Real Test of Accountability

Perhaps the clearest test of ethical culture comes when a high-performing employee violates policy. If the organization disciplines junior employees while protecting commercially valuable executives, employees will understand that there are two compliance systems. One exists in the policy manual. The other exists in practice.

Consistency does not require identical discipline in every case. Facts, intent, seniority, cooperation, prior conduct, and other circumstances can legitimately affect disciplinary decisions. But commercial value should not create immunity. Boards should understand how management handles misconduct involving senior leaders and significant revenue producers. The issue is not whether directors should participate in routine disciplinary decisions. They should not. The governance question is whether accountability applies throughout the organization.

Pretorius operates as though ordinary ethical constraints are for other people. Companies should ensure they do not inadvertently create executives who reach the same conclusion.

The Compliance Lesson

Bride of Frankenstein is ultimately about organizational learning. Companies will make mistakes. Controls will fail. Employees will engage in misconduct. Compliance programs will occasionally fail to identify risks before those risks become problems.

Program effectiveness shows up in what happens next. An investigation should generate knowledge. That knowledge should inform root-cause analysis. Root-cause analysis should drive remediation. Remediation should change controls, incentives, training, supervision, or business processes where necessary. Those changes should then be tested to determine whether they work.

Henry Frankenstein fails because he doesn’t turn knowledge into durable change. He knows what happened the first time. He understands the consequences. Yet Pretorius finds the ambition, pressure, and rationalization needed to pull him back into the laboratory.

That is why Bride of Frankenstein provides such an important compliance lesson. The greatest organizational risk may not be the risk management failed to identify. It may be the risk management already knows about but has learned to tolerate.

The next stage of the Frankenstein story moves the problem forward again. Leadership changes. A new generation arrives. Wolf von Frankenstein did not create his father’s Monster and bears no responsibility for the decisions that originally brought him to life. Then Wolf discovers what he has inherited.

In Son of Frankenstein, the compliance question becomes one every acquiring company, new CEO, board member, and CCO should understand: You did not create the problem. Once you know it exists, what will you do about it?

Check out Timothy and Fiona’s commentary on the compliance lessons from the Bride of Frankenstein here.

Leave a Reply

Your email address will not be published. Required fields are marked *

What are you looking for?