Categories
Sunday Book Review

Sunday Book Review: September 7, 2025, The Top Business Books for September Edition

In the Sunday Book Review, Tom Fox considers books that would interest compliance professionals, business executives, or anyone curious about the subject. It could be books about business, compliance, history, leadership, current events, or any other topic that might interest Tom. Today, we review four top new business books for September 2025.

  • Smarter: 10 Lessons for a More Productive and Less-Stressed Life By Emily Austen
  • Mission Driven: The Path to a Life of Purpose By Mike Hayes
  • Move. Think. Rest.: Redefining Productivity & Our Relationship with Time By Dr. Natalie Nixon, Ph.D
  • The Collective Edge: Unlocking the Secret Power of Groups By Colin Fisher

Resources:

The Next Big Idea Club’s September 2025 Must-Read Books

The Sunday Book Review was recently honored as one of the world’s Top 100 Book Podcasts.

Categories
10 For 10

10 For 10: Top Compliance Stories For the Week Ending September 6, 2025

Welcome to 10 For 10, the podcast that brings you the week’s Top 10 compliance stories in one podcast each week. Tom Fox, the Voice of Compliance, brings to you, the compliance professional, the compliance stories you need to be aware of to end your busy week. Sit back, and in 10 minutes, hear about the stories every compliance professional should be aware of from the prior week. Every Saturday, 10 For 10 highlights the most important news, insights, and analysis for the compliance professional, all curated by the Voice of Compliance, Tom Fox. Get your weekly filling of compliance stories with 10 for 10, a podcast produced by the Compliance Podcast Network.

  • Whistleblower leads to Nestlé dismissal. (WSJ)
  • Is Intel’s stake in corruption? (Bloomberg)
  • Court holds hearing on Boeing NPA (Law360)
  • EU fines Google $553.9 Million over cookie abuse. (WSJ)
  • Nestle dismisses CEO for ‘inappropriate relationship’. (NYT)
  • How Indonesia can tackle corruption. (SCMP)
  • 70% of the Philippine flood money was lost to corruption. (Bloomberg)
  • Disney was illegally collecting children’s data. (Reuters)
  • War Hero and corrupt Congressman dies. (NYT)
  • Texas says Chinese can’t own land in Texas. (BBC)

You can check out the Daily Compliance News for four curated compliance and ethics-related stories each day, here.

Connect with Tom 

Instagram

Facebook

YouTube

Twitter

LinkedIn

You can purchase a copy of my new book, Upping Your Game, on Amazon.com.

Categories
AI Today in 5

AI Today in 5: September 5, 2025, The Apple and AI Episode

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories:

  • Legal Developments for AI in the Workplace in the US. (Cooley)
  • Commentary on Clinical Compliance. (PressWire)
  • USAA selects Quavo for its compliance function. (FinTechGlobal)
  • Will Apple ever have AI? (Bloomberg)
  • OpenAI to offer certification. (Bloomberg)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com.

Categories
FCPA Compliance Report

FCPA Compliance Report – Special Edition on Is the US Going Socialist

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, we discuss President Trump’s review of other interests in US business and its implications for compliance.

The panel explores the evolving landscape of government involvement in major U.S. corporations and the resulting compliance and anti-corruption risks. With recent actions by the Trump administration to acquire stakes or exert control over companies like US Steel and Intel, the discussion centers on the implications for FCPA enforcement, the definition of “instrumentality,” and the challenges facing compliance professionals as the boundaries between public and private sectors blur. The episode also examines international perspectives, potential conflicts of interest, and the impact on global business relationships.

Key highlights:

  • Introduction: Are We Becoming Socialist?
  • Golden Share and Control Mechanisms
  • Anti-Corruption Risks and FCPA Instrumentality
  • International Law and Foreign Supplier Risks
  • Conflicts of Interest and Board Representation
  • International Perspectives: UK and EU Compliance
  • Politically Exposed Persons and Due Diligence
  • Closing Thoughts: Navigating Uncharted Territory

Resources:

Matt Kelly in Radical Compliance

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – The Board and a Trust Framework for AI

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we continue our look at Board issues and conclude by considering how a Board of Directors should establish a trust framework for AI.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Daily Compliance News

Daily Compliance News: September 5, 2025, The Wells Notice Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • EU fines Google and Shein a total of $553.9 million over cookie abuse. (WSJ)
  • EU prosecutor and Brussels elite go head-to-head over corruption. (ftm.eu)
  • What CEOs think of Stankey Memo. (Business Insider)
  • Reforming the Wells Notice process. (Bloomberg Law)
Categories
Regulatory Ramblings

Regulatory Ramblings: Episode 77 – Financial Inclusion and Sustainability/Legal & Compliance Recruitment Trends with Lotte Schou Zibell, Ian Morrison , and Raoul Montgomery

In the initial spotlight segment of this episode, we speak with London-based Ian Morrison of search and recruitment firm Arion House, and his Hong Kong colleague Raoul Montgomery to get a broader perspective on hiring trends in the legal and compliance space for the remainder of this year and into 2026 – with an eye towards global hubs such as London, Hong Kong, and Singapore.

Following that, we chat with Lotte Schou Zibell, formerly of the Asian Development Bank (ADB), to discuss the importance of financial inclusion and sustainability – including her thoughts on how something as seemingly mundane as the bamboo plant can be part of the solution.

Ian Morrison has over 18 years of experience in executive search and market intelligence, spanning Europe and Asia. Having placed legal, compliance, and financial crime professionals at the vice president, managing director, and partner levels globally, he has worked with many of the world’s leading investment banks, asset managers, hedge funds, law firms, and corporate clients.

Before establishing Arion House, Ian spent three years running the Asia Pacific business for Leathwaite International. He holds a degree in history from the University of Newcastle.

Raoul Montgomery joined as a research consultant in September 2019, with a focus on the APAC markets. He joined the University of Hong Kong, where he graduated with a Bachelor of Arts degree in History, Politics, and Public Administration. Having worked with numerous non-governmental organizations (NGOs), he is currently pursuing a JD degree in law at HKU. He is also fluent in English, Hindi, and Spanish.

Lotte Schou Zibell is a veteran international expert on sustainable finance, digital financial innovation, and financial inclusion. Lotte has played a key role in shaping policies and leading initiatives addressing emerging challenges in capital markets and financial systems.

For 19 years, she held various leadership positions at the Asian Development Bank, including serving as an advisor in the Finance Sector Office, as regional director for the Bank’s Pacific Liaison and Coordination Office, and as its chief of finance.

Before joining the ADB, she served as Director for International Economic Policy at the Swedish Ministry of Finance. She held positions at the Swedish Financial Supervisory Authority and the Swedish Central Bank. She has also worked as a consultant for the International Monetary Fund (IMF).

Lotte holds a master’s degree in economics from Lund University and a bachelor’s degree in international relations from George Mason University in the US state of Virginia. Her career reflects a deep commitment to strengthening financial systems and fostering economic resilience on a global scale.

Discussion:

With recruitment budgets for compliance and legal hires already set for the remainder of this year and into 2026, Ian and Raoul begin the conversation by discussing their observations on hiring trends in London, Hong Kong, and Singapore. As Ian tells Regulatory Ramblings host Ajay Shamdasani, hiring appears most robust in the insurance sector relative to other parts of the financial world.

A common refrain is that even with compliance, many organizations want to keep headcounts lean. Many employers seem willing to hire at the very senior levels, yet for middle management to junior hires, they are in retention mode. Simply put: if someone leaves, they are generally not replaced.

Worse still, stories of layoffs and hiring freezes at banking and financial institutions, as well as multinational corporations (MNCs), abound. For example, HSBC’s recent decision to shut its regional geopolitical risk unit caused quite a stir.

The spotlight chat concludes with a discussion of what knowledge and soft skills, other than being savvy in legal and regulatory matters, in-house counsel, and compliance, should possess. Ian noted that a greater awareness of political and economic risk was now firmly part of the remit of many in-house lawyers and compliance professionals at financial institutions and other multinational corporations.

We then proceed to our discussion with Lotte, who shares her experiences growing up in Sweden and spending time abroad in the US due to her father’s postings. She discusses what drew her to work for the IMF and ADB, as well as her commitment to developmental economics.

Having run Bank’s financial sector development projects for the past 20 years, Lotte comments on her achievements and how awed she is by the developments in fintech that she has seen during her tenure.

Acknowledging her current status as a consultant with the ADB, she discusses how it is to still work with her former colleagues, albeit in a less formal capacity, outside of the organization’s official hierarchy. As Lotte notes, being a consultant enables her to devote time to other interests.

She also elaborates on a post she authored for the ADB website, entitled “Five Ways Bamboo Can Revolutionize Finance, Housing, and Sustainability.” She noted that: “Bamboo’s fast growth and carbon capture abilities offer a sustainable solution to financial inclusion, housing affordability, and economic resilience in developing countries. Integrating modern technologies with bamboo cultivation can drive economic development while mitigating environmental impacts.”

The chat then drifted to another one of her posts entitled “Banks Without Borders: How AI, IDs, and Innovation Are Changing the Game.” Lotte wrote: “Rising compliance costs, regulatory fragmentation, and de-risking are limiting cross-border banking access, but technology-driven solutions offer a path to restore connectivity and resilience.”

Regulators often advise banks to adopt a risk-weighted approach to compliance and refrain from engaging in wholesale derisking. Yet, correspondent banking and related AML/KYC issues for certain sectors are a perennial issue, Lotte admits.

Acknowledging the problem’s entrenched nature, the sad truth is that derisking occurs when the compliance costs for banks maintaining particular correspondent banking relationships are too great. This can be due to the meager profit from serving them, resulting from small business volumes, or to the enhanced risk associated with serving a particular client or category of clients.

Lotte noted that there is often a lack of basic infrastructure in many emerging markets and that the developed world needs to provide those nations without capital, technology, and know-how the means to catch up.

Sadly, biometric safeguards are often not there in the developing world, she said. Many do not have identity cards or smartphones. In that regard, she thinks India’s Aadhaar card initiative is a triumph.

Their chat concludes with a reflection on a more recent ADB website post by Lotte entitled “Strengthen Compliance to Safeguard Pacific Banking Access.” She said: “Addressing gaps in financial compliance, upgrading digital infrastructure, and improving regulatory capacity can help Pacific countries build economic resilience and protect vital financial links.”

She added, however, that the resources required for compliance and risk management invariably affect a banking or financial institution’s bottom line.

Regulatory Ramblings podcasts is brought to you by The University of Hong Kong – Reg/Tech Lab, HKU-SCF Fintech Academy, Asia Global Institute, and HKU-edX Professional Certificate in Fintech, with support from the HKU Faculty of Law.

Useful links in this episode:

  • Follow Lotte Schou Zibell on LinkedIn

  • Check out Asia Finance Forum (ADB Manila) at: website

  • Follow Ian Morrison on LinkedIn

  • Follow Raoul Montgomery on LinkedIn

  • Visit Arion House at: website

You might also be interested in:

Connect with RR Podcast at:

LinkedIn: https://hk.linkedin.com/company/hkufintech 
Facebook: https://www.facebook.com/hkufintech.fb/
Instagram: https://www.instagram.com/hkufintech/ 
Twitter: https://twitter.com/HKUFinTech 
Threads: https://www.threads.net/@hkufintech
Website: https://www.hkufintech.com/regulatoryramblings 

Connect with the Compliance Podcast Network at:

LinkedIn: https://www.linkedin.com/company/compliance-podcast-network/
Facebook: https://www.facebook.com/compliancepodcastnetwork/
YouTube: https://www.youtube.com/@CompliancePodcastNetwork
Twitter: https://twitter.com/tfoxlaw
Instagram: https://www.instagram.com/voiceofcompliance/
Website: https://compliancepodcastnetwork.net

Categories
Blog

Speed as a Compliance Decision: Lessons from Amazon’s Andy Jassy

When Andy Jassy succeeded Jeff Bezos as CEO of Amazon in 2021, many questioned whether the company could maintain its legendary momentum. Four years later, Jassy has not only sustained but also accelerated growth, adding more than $230 billion in revenue, expanding AI initiatives, and reinventing the management culture of one of the world’s most complex enterprises. That is why I was intrigued by an article in the Harvard Business Review (HBR) entitled, Speed Is a Leadership Decision,” where reporter Adi Ignatius interviewed Andy Jassy.

For compliance professionals, Jassy’s insights about speed, risk, culture, and innovation offer timely lessons. Too often, compliance leaders fall back on the excuse that “we’re too big, too regulated, too constrained to move quickly.” Jassy flips that script: speed, he insists, is a leadership decision. And the same is true for compliance.

Today, we look at five key lessons compliance professionals can draw from Jassy’s leadership playbook.

1. Speed Is a Leadership Decision

Jassy bluntly states that “speed disproportionately matters in every business at every time”. He challenges leaders to stop accepting bureaucracy and regulation as excuses. Instead, leaders must actively identify and remove barriers, empowering teams to act with urgency.

For compliance professionals, the lesson is clear: do not let the weight of regulations, policies, or oversight structures become a drag on effectiveness. Yes, compliance requires controls, documentation, and approvals, but speed is also important. Think of third-party due diligence reviews, hotline triage, or incident investigations. When compliance moves slowly, it signals indifference or ineffectiveness, and risks fester.

The decision to prioritize speed, backed by streamlined processes, real-time monitoring, and empowered teams, can transform compliance from a bureaucratic bottleneck into a proactive partner to the business.

2. Risk-Taking and Failure Are Essential to Innovation

Jassy observes that as companies grow, they tend to become risk-averse. Achievement-oriented professionals “play not to lose” rather than take chances. He emphasizes that the only way to build something truly unique is to take risks, make mistakes, and learn from them. Compliance teams face this challenge daily. The instinct is to avoid risk entirely, to say “no” rather than take a chance. But compliance innovation, whether adopting AI for monitoring, piloting new training formats, or embedding compliance into business processes, requires taking calculated risks. This means that risk management strategies must be implemented, monitored, and updated as necessary.

Failure in compliance is not about missing a regulatory requirement. It is about learning that a new process does not resonate with employees, or a monitoring tool generates too many false positives. Leaders should create safe zones for experimentation. If you never fail, you are not pushing hard enough. Compliance innovation must be iterative, and tolerance for small, recoverable failures is the price of true progress.

3. Flattening Bureaucracy Fuels Accountability

Jassy highlights Amazon’s initiative to flatten its organization and empower individual contributors. By increasing the ratio of builders to managers, reducing layers of decision-making, and encouraging employees to own “two-way-door decisions”. Those are choices that can easily be reversed. With this strategy, Amazon streamlined processes and accelerated innovation.

Compliance functions are often drowning in pre-meetings and approval chains. A compliance officer identifies a risk, drafts a recommendation, and waits while three levels of committees review it. Meanwhile, the risk festers. The compliance profession should adopt Jassy’s model: empower frontline employees to make two-way decisions in real-time. For example, a compliance manager in Brazil should have the authority to pause a suspicious vendor engagement without waiting for headquarters. Flattening decision-making structures creates accountability, agility, and credibility. Compliance must be a builder’s mindset: see the problem, fix the problem, move forward.

4. Culture Must Be Reinvented Continuously

“Culture is not our birthright,” Jassy warns. As companies scale, their culture stretches and must be deliberately reinforced. At Amazon, this means reasserting ownership, accountability, and a customer-centric approach, even as new layers of management emerge. For compliance professionals, this is a powerful reminder: culture is not static. A “speak-up” culture may flourish in year one and decay by year five if it isn’t nurtured. New geographies, acquisitions, and technologies stretch corporate culture in unpredictable ways.

The compliance function must continuously assess cultural health: are employees still raising concerns? Do managers still model ethical behavior? Are incentive structures still aligned with compliance values? A strong compliance culture requires constant reinvention: new training, new channels, new metrics; so that employees see it as living and evolving, not stale or perfunctory.

5. AI, Innovation, and Responsibility Must Go Hand in Hand

Jassy views AI as the biggest transformation since the internet, with the power to reinvent every customer experience. He emphasizes that progress is inevitable, so leaders must focus on using AI responsibly and productively.

Compliance professionals face the same dual imperative. On the one hand, AI tools, such as automated transaction monitoring, predictive analytics, and natural language chatbots, can make compliance faster, smarter, and more effective. On the other hand, AI introduces new risks, including bias, opacity, privacy breaches, and increased regulatory scrutiny.

The compliance leader’s role is not to resist AI but to guide its responsible adoption. Establish AI governance frameworks. Ensure transparency and explainability. Audit data inputs and outputs. Partner with business units to embed compliance guardrails into AI development. If compliance can keep pace with AI’s speed while safeguarding ethics, it will become indispensable to the business.

Compliance at the Speed of Leadership

Andy Jassy’s mantra, “speed is a leadership decision,” rings true far beyond Amazon. For compliance professionals, it reframes the mission. Compliance does not require slow responses, being bureaucratic, or being risk-averse. (Always remember, you do not have brakes on a car to drive slowly; instead, you have brakes on a car to drive fast.) Leaders can choose speed by empowering their teams, flattening the decision-making process, fostering a culture of ownership, tolerating smart failures, and embracing technology responsibly.

The stakes are high. Compliance must move at the same speed as the business, not the other way around. Regulators expect swift detection and remediation. Employees expect rapid answers to ethics and compliance questions. Boards expect real-time risk visibility. Compliance that lags will be seen as irrelevant or ineffective.

The lesson from Amazon’s Jassy is that compliance speed is not about cutting corners. It is about clarity of leadership, empowerment of people, and continuous cultural reinvention. In an era of accelerating technology and mounting risk, compliance professionals must embrace speed as a core leadership choice.

Categories
Blog

Agentic AI, Data Discipline, and Cross-Functional Governance: Compliance Insights for the Modern Era

As compliance professionals, we often inherit the boundaries that IT, Legal, and Security established long before we arrived. But what happens when those lines are out of date? I recently had a far-ranging conversation with cybersecurity author and educator Robert Meyers, who has spent more than three decades transitioning from “plain IT” to a world where cybersecurity and privacy have become distinct, high-impact disciplines. He explains why the old map no longer matches the terrain. Meyers’ vantage point spans early dial-up remote access fiascos, modern breach response, philosophical differences between U.S. and EU privacy regimes, and the tidal shift that agentic AI is bringing to accountability and data governance.

This blog post distills that conversation for a corporate compliance audience, focusing on practical, board-relevant governance and the day-to-day tactics that make privacy and security work together before, during, and after incidents.

From “IT Does Everything” to “Risk, Roles, and Accountability”

Meyers started in an era when “cybersecurity” did not exist. There was just “IT,” and everyone did everything. That lack of specialization produced preventable harm;  misconfigured remote access where a “guest” credential quietly had admin rights, cavalier attitudes toward email and user surveillance (Remember when “I read your email” bumper stickers were a thing.), and a culture that treated privacy as a corporate secrecy issue rather than a people-protection mandate. The lesson for compliance? Risk thrives in ambiguity. When roles and ownership are unclear and authority is not defined, controls are merely a facade.

Meyer contrasts the U.S. and EU not as a legal vs. legal comparison, but as a philosophical split. In Europe, privacy is government-centric and procedurally channeled through regulators; in the U.S., it is more individual-centric and notification-driven. California’s rules can even exceed the practical strictness of the GDPR in certain respects. For compliance leaders, that means your privacy posture must be designed around intent (IE., who is protected), governance (IE., who decides), and operational execution (IE., who does the work) and not just a citation list.

Data Has a Life Cycle—Treat It That Way

One of Meyers’ most pointed critiques is that organizations hoard data without a purpose or end-of-life discipline. If you keep 30 years of email, do not be surprised when eDiscovery asks for all 30. The habit of “keep it all, we might need it” is the enemy of proportional risk. Compliance should drive a business-backed data minimization program with explicit retention schedules tied to legal, operational, and risk rationales and then audit for enforcement. If the business cannot articulate why it needs a dataset today and in the future, that data is a liability, not an asset.

Fix the Operating Model: Privacy Is Not a Side Gig for Security

Meyers has observed the exact misalignment play out repeatedly: privacy responsibility is often assigned to Legal or Compliance, but Cybersecurity typically handles the work and associated expectations. CISOs are asked to “own” controls for which they lack budgetary authority or policy ownership. Legal “owns” privacy on paper, but it is not integrated into cyber operations. Meyer is clear that the cure is governance, not heroics: establish a cross-functional steering committee (including Legal, Security, Compliance, IT Ops, and the business) with clear charters, shared KPIs, and defined decision rights. Diversity matters here; mix senior leaders with younger employees and varied backgrounds to avoid blind spots. The first agenda item of that committee should be ruthless purpose-alignment: “Why do we have this data? Do we still need it?”

Put Risks on One Page—and Make It Everyone’s Page

While cybersecurity tooling is often automated and technical, Meyers recommends one deceptively simple instrument to unite the disciplines: a shared risk register. GRC teams already live in this world. You should bring Security into it and treat security events, control weaknesses, and privacy exposures as entries that share owners, mitigations, and review cadences. If the CISO, Chief Compliance Officer, and General Counsel are not reading, updating, and arguing over the same risk register, you do not have a single source of truth or a shared sense of urgency.

Breach Reality: Precision Beats Blanket Notification

“Assume breach” is not fatalism; it is a sign of professional maturity. Meyers highlights the emergence of data security posture management (DSPM) solutions that not only identify exposures but also determine who actually owns the data that was accessed. That allows for targeted notifications — “these 15 people, not 500,000 customers” — and saves both real money and reputation. For the compliance function, the key point is proportionality; your incident playbook should pair legal thresholds with data lineage and ownership maps, ensuring a fast, accurate, and respectful response to individuals.

Agentic AI: Accountability Without a Face

Agentic AI changes the rules. Agents act without asking, talk to other agents, and traverse systems and data at machine speed. They also obscure accountability because the human “operator” may interact with one agent while three others are making consequential decisions out of view. This breaks the legacy consent and audit paradigms, demanding new guardrails: identity and authorization that can follow agents, granular logging of agent-to-agent interactions, and data lineage that respects privacy scopes. From a compliance lens, agentic AI requires you to rewrite playbooks on consent, purpose limitation, and lawful processing, before deployment, not after the first mishap.

Storytelling: The Culture Carrier for Security and Privacy

Meyers’ long connection to San Diego Comic-Con may seem far removed from cybersecurity. Yet when you see a cybersecurity team finally “get it” when you swap a nameless attacker for “Lex Luthor” in a tabletop. That is not playing to pop culture; rather, it is cultural engineering. Humans adopt guardrails that they emotionally understand. If your privacy training or AI oversight policy can be told as a story, with villains, flawed heroes, and a clear “why,”  you improve retention, reduce resistance, and create connective tissue across silos. Compliance is, at its core, applied storytelling backed by controls.

Robert Meyers traces the evolution from undifferentiated IT to today’s specialized privacy and cybersecurity disciplines, emphasizing how poor role clarity and indiscriminate data retention have caused preventable harm for decades. He frames the U.S.–EU divide as a philosophical one, between individual-centric versus regulator-centric approaches, while urging companies to stop treating privacy as a side project for Security when Legal nominally “owns” it. The solution involves a cross-functional steering committee, a shared risk register, and purpose-driven data lifecycle governance.

Meyers underscores “assume breach” realism and highlights new DSPM tooling that enables precise, owner-level breach notification instead of blanket, costly responses. Looking ahead, agentic AI creates accountability gaps as autonomous agents act and collaborate out of human view, demanding fresh guardrails for identity, consent, lineage, and logging. Finally, Meyers champions storytelling (yes, even Comic-Con-style narratives) to make security and privacy relatable, and advocates for cross-training, with privacy professionals learning security and vice versa, so organizations can speak a single operational language from the boardroom to the SOC.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – The Board and an AI Framework for Governance

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we continue our look at Board issues. We continue to consider how BODs need to think through AI governance. Today, we will consider a framework for AI governance.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which was recently released by LexisNexis. It is available here.