Categories
AI Today in 5

AI Today in 5: August 7, 2025, The US v. China Episode

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

For more information on the use of AI in compliance programs, Tom Fox’s new book is Upping Your Game. You can purchase a copy of the book on Amazon.com

Categories
Blog

The Price of Ignorance: Five Due Diligence Lessons from Star Trek’s “Elaan of Troyius”

Today, let’s set our phasers to “analyze” and travel back to one of Star Trek: The Original Series’ most underrated diplomatic dramas: “Elaan of Troyius.” This episode is not just a space opera of culture clashes, hidden agendas, and diplomatic peril; it is a near-perfect parable for compliance professionals wrestling with the eternal question: Why is due diligence mandatory when considering a new business partner?

For those who have not revisited this classic, the USS Enterprise is assigned a high-stakes diplomatic mission: transport Elaan, the tempestuous Dohlman of Elas, to the planet Troyius, where her arranged marriage will seal a peace treaty between two warring worlds. As tensions flare between Elaan’s culture and that of the Federation, Captain Kirk, Spock, and the crew quickly realize that more than just a wedding is at stake; hidden motivations, subterfuge, and cross-cultural misunderstandings threaten to unravel the entire peace process. What seems a straightforward escort mission rapidly reveals layers of complexity and risk.

Let’s get into the heart of the episode and draw out five compliance lessons that every organization should heed before it signs that next contract.

1. First Impressions Are Deceptive: Always Probe Deeper

Illustrated By: Elaan’s arrival is marked by dramatic displays of power, arrogance, and cultural superiority. The Federation diplomats are immediately intimidated and distracted by her forceful presence and sharp temperament.

Compliance Lesson. How many times have we seen organizations swept off their feet by a potential partner’s surface credentials, market reputation, or charismatic leadership? In “Elaan of Troyius,” Kirk and his crew quickly learn that initial impressions, whether good or bad, can conceal much deeper realities. Due diligence is your organization’s safeguard against falling for the “Elaan effect”: the temptation to trust a partner’s public image without digging into their true character, operational practices, or hidden risks.

What should you do now? Do not accept a new partner at face value. Investigate their ownership structure, past conduct, litigation history, financial health, and compliance record. Unmasking the reality behind the reputation is the first step.

2. Cultural Blind Spots: Understand the Landscape Before You Leap

Illustrated By: The cultural gap between Elaan and the Federation nearly derails the mission. Misunderstandings abound, from differing customs around authority and gender to fundamental misalignments in values. The crew is blindsided by these gaps, leading to avoidable conflict.

Compliance Lesson. Entering into any partnership without understanding your partner’s culture, whether corporate, regional, or national, is asking for trouble. Seemingly minor cultural mismatches can lead to miscommunication, legal violations, or ethical lapses. In cross-border or third-party relationships, this risk is magnified: local customs may hide corrupt practices, labor abuses, or anti-competitive behaviors.

What should you do now? Include cultural and ethical risk assessments as part of your due diligence. Engage local experts, conduct interviews, and be ready to adapt your approach to fit the landscape without compromising your core values.

3. Hidden Agendas and Sabotage: Trust, But Verify

Illustrated By: The mission is sabotaged by Elaan’s retinue, her bodyguard conspires with the Klingons, hiding a device that compromises the Enterprise’s defenses. Kirk is nearly assassinated, and the entire mission teeters on the brink of disaster because no one anticipated internal betrayal.

Compliance Lesson. When evaluating new partners, you must assume that unseen risks may be lurking just below the surface. These could take the form of undisclosed beneficial ownership, connections to sanctioned parties, or corrupt insiders. Even a trusted contact within a partner organization can turn out to be a risk factor if not properly vetted. In “Elaan of Troyius,” failure to probe the intentions and backgrounds of all involved parties nearly results in catastrophe.

What should you do now? Conduct background checks not just on the company, but also on key personnel, agents, and ultimate beneficial owners. Use open-source intelligence, watchlists, and external investigators as needed. “Trust, but verify” is not simply good (Ronald Reagan) advice; it is mandatory.

4. Emotional Reactions Cloud Judgment: Stay Objective

Illustrated By: Kirk finds himself emotionally entangled with Elaan after being exposed to her tears, which act as a potent love potion. His objectivity and command judgment are compromised at a critical moment, nearly dooming the ship.

Compliance Lesson. Emotional responses, from excitement about a lucrative new market to personal connections with a partner’s leadership, can cloud even the best compliance professional’s judgment. In “Elaan of Troyius,” emotional manipulation nearly brings down the Federation’s flagship. In real-world business, emotional bias can cause teams to overlook red flags, downplay risks, or shortcut due diligence.

What should you do now? Build structured, objective processes for due diligence that minimize the risk of bias. Use checklists, outside counsel, and independent reviews to ensure no one is “drunk on the deal.” Compliance must be immune to infatuation.

5. The Price of Ignorance: Remediation Is Harder Than Prevention

Illustrated By: Only after chaos erupts do Kirk and the crew scramble to uncover the source of their problems, a hidden device sabotaging the Enterprise’s engines. They’re forced into a desperate race against time to fix what could have been prevented.

Compliance Lesson. If you do not invest in rigorous due diligence up front, you will inevitably spend much more time, money, and resources cleaning up the mess after something goes wrong. Investigations, regulatory fines, lost business opportunities, and reputational damage are all far more expensive than preventative action. Just as Kirk would rather have found the sabotage before launch, compliance professionals must treat prevention as their first line of defense.

What should you do now? View due diligence as an investment, not a cost. The price of ignorance, missed risks, surprise violations, or regulatory enforcement will always exceed the price of preparedness.

Final ComplianceLog Reflections

Elaan of Troyius” is a warning to any organization tempted to “wing it” when evaluating a new business partner. Diplomacy, optimism, and trust are essential, but they are not substitutes for due diligence. Hidden risks, cultural misunderstandings, and emotional biases can turn opportunity into disaster in a heartbeat. Kirk and the crew of the Enterprise ultimately succeed not because of luck, but because they confront hard truths, adapt, and persevere. In the world of corporate compliance, the same rules apply.

So, the next time your organization eyes a shiny new partnership, ask yourself: Are we seeing only what we want to see? Or are we committed to the hard work of real due diligence, the only sure path to success, and to a future where both sides prosper?

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Cross-Atlantic Fraud & Corruption Enforcement: Intersections and Divergences

In today’s dynamic compliance landscape, navigating the complexities of international corporate wrongdoing requires vigilance, foresight, and strategic action, as highlighted in A recent article entitled “Cross-Atlantic Impact: DOJ and SFO Self-Reporting and Enforcement Priorities,” by lawyers from McDermott, Will & Schulte. The article is an excellent review of areas where the fight against fraud and corruption aligns between the two countries and areas where they diverge. Today, I will review the article and consider what it means for the US company doing business in the UK or with UK companies.

The Serious Fraud Office (SFO) in the United Kingdom has made clear its expectations regarding self-reporting corporate misconduct, mainly aligning in philosophy, if not always in exact details, with its U.S. counterpart, the Department of Justice (DOJ). American companies must understand these nuances and adapt their compliance programs accordingly. Here are five critical reasons why U.S. businesses must closely monitor and adhere to the UK’s evolving fraud and bribery enforcement regime.

Prompt Self-Reporting Weighs Heavily in Favor of DPAs

The SFO guidance unequivocally states that companies demonstrating prompt self-reporting of corporate wrongdoing significantly increase their chances of obtaining a Deferred Prosecution Agreement (DPA). Conversely, any delay in self-reporting suspected wrongdoing “within a reasonable time of it coming to light” adversely impacts the company’s standing with the SFO.

Much like the DOJ, the SFO does not insist on complete internal investigations before self-reporting. Indeed, in many ways, both sets of prosecutors want companies to step forward as soon as possible. The degree of the inquiry expected depends on the clarity and strength of evidence. Where evidence indicates wrongdoing, companies are expected to self-report swiftly. Ambiguities may permit a more extensive preliminary investigation, but American companies should note that delays can risk losing the advantages offered by early disclosure.

Jurisdictional Triggers Demand Simultaneous Reporting

For American companies dealing with potential misconduct spanning jurisdictions, awareness and agility become paramount. According to SFO guidance, companies reporting suspected misconduct to another agency, such as the DOJ, should also inform the SFO simultaneously or immediately thereafter. Failure to do so negates any potential credit for self-reporting.

Consider a scenario where a company seeks a declination from the DOJ through prompt self-disclosure. Identifying a UK jurisdictional nexus, such as conduct occurring partly in the UK or financial impact felt within the UK, is crucial. The UK’s “failure to prevent bribery” and new “failure to prevent fraud” offenses can impose liability based on international conduct linked to a business presence or financial repercussions in the UK. Understanding and navigating these jurisdictional nuances quickly is imperative to safeguard against regulatory pitfalls and secure favorable treatment.

Increasingly Aggressive Fraud Enforcement

Fraud has emerged as a prominent enforcement priority for both the DOJ and SFO. American companies should pay particular attention to the UK’s new “failure to prevent fraud” (FTPF) offense, effective from September 1, 2025. This robust enforcement tool targets UK and non-UK entities whose associates engage in fraudulent conduct impacting UK interests.

American companies operating internationally must proactively establish “reasonable fraud prevention procedures” to counteract potential liability under this legislation. The urgency conveyed by the SFO, highlighted by senior officials expressing eagerness to utilize these new powers aggressively, cannot be overstated. Companies that neglect preparation risk being among the first prosecuted examples of this powerful legislation.

Coordination Between DOJ and SFO Enhances Risk Exposure

With the DOJ emphasizing fraud in areas affecting U.S. interests, ranging from healthcare and procurement fraud to investment scams, there is considerable overlap with misconduct addressed by the UK’s FTP fraud offense. The authors note that the US Supreme Court held in Kousisis v. United States that a defendant may be convicted of wire fraud for inducing a victim to enter a contract under material pretenses, even if there was no economic loss to the victim. This ruling may allow US prosecutors to pursue a broader range of fraud cases.”

A cross-jurisdictional approach is therefore essential. American companies uncovering fraud that victimizes both U.S. and UK entities or markets must carefully assess reporting obligations to both jurisdictions. The simultaneous or nearly simultaneous reporting requirements heighten the stakes and complexity, demanding robust internal mechanisms for rapid assessment and disclosure.

Continuing Vigorous Anti-Bribery Efforts Globally

Despite temporary uncertainties in the DOJ’s stance toward anti-bribery enforcement, global initiatives indicate relentless international focus. The SFO has intensified anti-bribery efforts through initiatives like the International Anti-Corruption Prosecutorial Taskforce, collaborating closely with French and Swiss authorities. The SFO’s involvement in the International Anti-Corruption Coordination Centre (IACCC) further underscores its commitment. The authors report that “the IACCC aims to facilitate international cooperation on ‘grand corruption’ investigations, including concerning intelligence and evidence gathering.”

In addition to the IACCC, “In March 2025, the SFO established an ‘International Anti-Corruption Prosecutorial Taskforce’ with the French Parquet National Financier (PNF) and the Office of the Attorney General of Switzerland (OAG) (Taskforce). Through the Taskforce, the SFO, PNF, and OAG commit to strengthening their existing cooperation and collaborating to deploy their wide-reaching anti-bribery legislation to prosecute overseas conduct.”

The DOJ’s recent reaffirmation of anti-bribery efforts through its White-Collar Enforcement Plan, highlighting bribery and money laundering harming U.S. interests, may complement these international initiatives. American companies must remain vigilant regarding potential liabilities under both the FCPA and the UK Bribery Act, carefully calibrating their compliance programs to meet rigorous enforcement expectations across jurisdictions.

Practical Steps for American Companies

Given these compelling reasons to pay close attention to the SFO guidance and evolving UK legislation, American companies must take proactive steps to fortify their compliance efforts:

  • Enhance Internal Controls: Companies must quickly develop comprehensive “reasonable fraud prevention procedures,” supported by thorough risk assessments and regularly updated policies.
  • Cross-Jurisdictional Risk Assessments: Implement rigorous processes for promptly assessing jurisdictional ties when misconduct emerges, allowing immediate and coordinated reporting where necessary.
  • Integrated Compliance Training: Ensure global compliance teams, legal counsel, and executive management understand SFO and DOJ expectations clearly, fostering prompt, informed responses.
  • Monitoring International Developments: Maintain continuous awareness of evolving enforcement policies and initiatives, particularly regarding fraud and bribery, to swiftly adapt compliance programs accordingly.
  • Preparedness and Responsiveness: Establish clear protocols for internal investigations and self-reporting decisions, emphasizing speed and comprehensiveness to maximize potential cooperation credit.

Conclusion

Navigating the intricate and often intersecting expectations of the SFO and DOJ presents ongoing challenges for American companies. However, understanding the strategic implications of prompt self-reporting, jurisdictional coordination, aggressive fraud enforcement, international collaboration, and robust anti-bribery efforts is vital.

Proactive compliance management, aligned closely with evolving international regulatory landscapes, is not merely advisable but something that every multinational needs to put in place. American corporations should approach compliance with the understanding that today’s oversight environment demands swift and strategic decision-making to mitigate risks effectively and position themselves favorably in the face of potential regulatory scrutiny.

Categories
AI Today in 5

AI Today in 5: August 6, 2025, The Rethinking Compliance Episode

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

  • AI for compliance and contract review. (Nucamp)
  • Will Big Tech comply with EU rules on AI? (RFI)
  • AI for workers’ comp compliance. (Press Release)
  • Redefining finance compliance with AI. (VettaFi)
  • Using AI to rethink compliance. (Ethisphere)

For more information on the use of AI in compliance programs, Tom Fox’s new book is Upping Your Game. You can purchase a copy of the book on Amazon.com

Categories
Compliance Into the Weeds

Compliance into the Weeds: A Deep Dive into Cadence Design Systems’ Export Control Violations

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent enforcement action against Cadence Design Systems for export control violations.

They explore the company’s illegal sales of sensitive technology to a Chinese university connected to the Chinese military, resulting in $140 million in penalties and a three-year probation. The conversation delves into topics like weak subsidiary governance, challenges in monitoring Chinese subsidiaries, and the complexities of conducting investigations in China. They also reflect on the broader implications for U.S. companies operating in China and the intractable risks involved.

Key highlights:

  • Cadence Design Systems Case Overview
  • Subsidiary Governance Issues
  • Details of the Misconduct
  • Resolution and Penalties
  • Challenges in Compliance and Monitoring
  • Complexities of Doing Business in China

Resources:

Matt Kelly in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Awards for podcast excellence.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Key M&A Enforcement Actions

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide you with bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

M&A under the FCPA is well-settled. Today, we consider three seminal enforcement actions.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing Your Compliance Program, 6th edition, which LexisNexis recently released. It is available here.

Categories
Daily Compliance News

Daily Compliance News: August 6, 2025, The Spanking Banks Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Stories include:

  • Trump wants to punish banks. (WSJ)
  • When ABC becomes corrupted. (FT)
  • Is the Comic Sans font evil? (FT)
  • Microsoft is going RTO. (Business Insider)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief here.

Categories
Great Women in Compliance

Great Women in Compliance – LATAM Compliance Update with Alejandra Montenegro Almonte

In this episode of Great Women in Compliance, Lisa speaks with Alejandra Montenegro Almonte, a member at Miller Chevalier. Alejandra is the Chair of their International Practice and Practice Co-Lead, Workplace Culture.

They discuss recent regulatory trends, workplace culture, and the evolving compliance landscape in Latin America and the United States, including the increased focus on Foreign Terrorist Organizations, False Claims Act enforcement, and the importance of addressing these changes and others proactively, including the DEI Executive Order requirements.

Alejandra also shares her insights about the shift towards addressing workplace culture and conduct issues proactively, and how this has evolved past looking just at litigation risk. She discusses employee engagement and the increasing use of ethical assessments.

Alejandra and Lisa reflect on the challenges of building authentic professional relationships in a predominantly remote work environment. They emphasize the need for intentionality, such as scheduling regular virtual coffees and employer-facilitated opportunities for connection, to foster networking and mentorship.

Alejandra and Lisa have known each other for a long time, and they discuss the value of the early career friendships that become a peer network. This is harder in a virtual age, and Alejandra shares some of her strategies to build networks.

Categories
Blog

The Intersection of Compliance and Crisis Communications

Earlier this week, I posted a podcast with Steve Vincze regarding his thoughts about responding to a corporate crisis similar to the recent one seen at a Coldplay concert, where a Kiss Cam caught two individuals canoodling and it sparked a viral frenzy. The incident serves as a timely reminder that the adage of having 24 hours to respond is long gone. Vincze spoke about how the company can begin to record from such a compliance and ethics miasma, as when your CEO is openly having an affair with the head of your Human Resources Department. Yet there are other considerations a company needs to consider, as in today’s hyper-connected digital environment, corporate compliance professionals find themselves navigating crises at unprecedented speed. Today, compliance and communications teams have mere milliseconds to act.

The viral Kiss Cam event during Coldplay’s performance in Boston quickly transcended entertainment, morphing into a crisis for the company involved as speculation, memes, and fake apologies rapidly filled the communication void. Silence became negligence, and by the time the company issued its response over 24 hours later, the damage had intensified. This case isn’t an anomaly; it’s a crystal-clear signal of the evolving nature of crisis communications and its profound implications for corporate compliance teams. I recently came across an article by Gini Dietrich, founder of Spin Sucks, which outlined everything you need to consider to be ready for such a PR crisis (and nightmare). I took her piece and adapted it for the compliance professional. Here are five key lessons compliance professionals must learn from this incident.

1. Speed is Non-Negotiable

The essence of crisis response in 2025 is rapidity. Compliance professionals can no longer wait for every fact or legal review to issue a holding statement. Hesitation allows misinformation to spread unchecked, rapidly escalating manageable issues into existential threats. By preparing pre-approved holding statements and designating empowered response teams ahead of time, compliance can ensure immediate, controlled communication, preventing narrative hijacking.

Speed protects accuracy, as immediate communication positions organizations as transparent and responsive. A prompt, initial statement doesn’t need exhaustive details but should acknowledge awareness and ongoing investigation. Such swift action conveys responsibility, minimizes uncertainty, and curtails speculative narratives before they gain momentum.

2. Internal Communications are Essential

In crises, employees are not just internal stakeholders; they become frontline communicators, responding to inquiries from customers, partners, and personal connections. Compliance professionals must prioritize internal communications, informing employees first, clearly, and quickly. Doing so avoids confusion, curbs misinformation, and positions employees as reliable ambassadors equipped to handle external conversations appropriately.

Effective internal communications demonstrate organizational respect and care for employees, reinforcing loyalty and trust. It empowers them to respond confidently and consistently, reducing the risk of inadvertent misinformation. Early internal updates also foster internal stability, safeguarding productivity and morale during uncertain times, ultimately strengthening organizational resilience and unity during crises.

3. Scenario Planning Must Broaden

Traditional crisis management often focuses on natural disasters and data breaches. However, modern scenarios like executive misconduct, white-collar crime, and viral moments must be integrated into risk matrices. Compliance professionals should proactively collaborate with communications teams to anticipate diverse risks. Regular scenario-based drills ensure preparedness and reveal potential weaknesses in response strategies, enabling continuous improvement.

By embracing a broader spectrum of potential crises, compliance teams can identify vulnerabilities and preemptively design response protocols tailored to each scenario. Continuous assessment and updating of these protocols foster adaptability, ensuring teams remain agile and prepared, significantly reducing reaction times and minimizing the scope of damage.

4. Control Your Owned Channels

Immediate access to and control of your communication channels—such as websites, LinkedIn, Twitter, and internal communications platforms—is critical. In the Coldplay Kiss Cam incident, the initial lack of communication enabled false narratives to dominate. Compliance and communication teams must maintain ready-to-use channels, ensuring the company narrative can be rapidly deployed, preserving control and credibility.

Owning and managing these channels allows companies to issue timely, authoritative messages directly to their audience without relying solely on external media coverage. By proactively maintaining these channels, companies ensure consistent messaging, prevent misinformation, and swiftly address emerging issues, thus safeguarding their reputation and maintaining stakeholder trust.

5. Continuous Monitoring and Readiness

Crises do not follow business hours. Compliance professionals must establish continuous monitoring, leveraging tools such as Google Alerts, Buffer, and structured internal monitoring schedules. Maintaining constant vigilance ensures early detection and rapid response, crucially limiting reputational damage. Regular training and simulations further cement readiness, creating an agile response capability able to manage real-time crises effectively.

Continuous monitoring facilitates early warning signs, enabling compliance teams to act preemptively rather than reactively. Additionally, cultivating readiness through regular drills builds organizational muscle memory, reducing response times and stress during real crises. This proactive stance transforms potential vulnerabilities into managed situations, enhancing overall organizational resilience.

The Coldplay Kiss Cam saga underscores that modern crisis communications are not reactive but proactive. Compliance teams prepared for rapid, effective responses not only survive crises—they shape the narrative. By embracing these five critical lessons, compliance professionals can confidently navigate the lightning-fast world of digital communications, turning potential vulnerabilities into opportunities for integrity and trust-building.

In today’s hyper-connected landscape, waiting is no longer a caution; it may be closer to malpractice. As compliance professionals, our responsibility is not merely reacting to crises but proactively preparing for the inevitable moments when reputations hang by a thread. Your employees, stakeholders, and the public do not expect perfection, but they do expect presence, transparency, and action. By investing now in responsive protocols, clear internal communications, and agile crisis teams, you ensure your voice isn’t drowned out by speculation. Speed is not simply an advantage; it may well be your most critical compliance control. Act swiftly, communicate authentically, and you will not just survive the storm; you and your team will shape the narrative.

Categories
AI Today in 5

AI Today in 5: August 5, 2025, The AI at the SEC Episode

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI. 

 

For more information on the use of AI in Compliance programs, Tom Fox’s new book is Upping Your Game. You can purchase a copy of the book on ⁠Amazon.com.