Categories
Blog

COSO’s Corporate Governance Framework: Component 6 – Resilience

We continue our exploration of the recently released COSO  Corporate Governance Framework (the Framework) as a Public Exposure Draft.  Today, we begin a deep dive into the six individual components with a discussion of Component 6—Resilience. In today’s volatile business climate, one thing is sure: disruption is no longer the exception; it has become the norm. Whether it’s a cybersecurity incident, regulatory upheaval, geopolitical instability, or reputational crisis, the organizations that thrive are those that can bend without breaking. That’s why Component 6 – Resilience in the COSO Corporate Governance Framework (CGF) is more than timely; it may well be foundational.

For the compliance professional, resilience isn’t just about bouncing back—it’s about designing governance systems that withstand, anticipate, and even leverage disruption. The CGF reframes resilience as an integrated model that weaves together risk management, compliance, internal control, and continuous monitoring. This final Component of the framework is where compliance moves from policy enforcement to value creation. It is where compliance becomes a partner in operational continuity, strategic foresight, and cultural durability.

What Is the Resilience Component?

COSO defines resilience as the ability to withstand disruption, adapt to change, seize opportunity, and sustain long-term value. It is not reactive firefighting but rather about proactive design. This Component is structured around four principles:

  1. Manage and Oversee Risks and Opportunities
  2. Manage Compliance Responsibilities
  3. Establish and Evaluate Internal Control
  4. Monitor Governance Effectiveness

These principles span strategic, operational, and cultural dimensions of governance, reinforcing that a single function doesn’t own resilience. It’s built collaboratively across the board, executive leadership, internal audit, risk, and yes, compliance.

Why Resilience Belongs to Compliance

Compliance has continuously operated at the intersection of policy, people, and process. But in the Framework view, compliance is a key architect of resilience. Why? Because of the following:

  • Compliance sees how risks evolve across geographies, regulations, and business lines.
  • Compliance manages escalation, remediation, and accountability processes.
  • Compliance helps define the thresholds for risk acceptance and control failure.
  • Compliance monitors ethics and behavior—early indicators of cultural cracks.
  • Compliance is a trusted communicator in times of crisis.

The Resilience Component is our invitation to lead not just to prevent harm, but to build strength.

Five Key Lessons for Compliance Professionals

Lesson 1: Governance Without Risk Integration Is Incomplete

Principle 21: Manage and Oversee Risks and Opportunities

Executive management, with board oversight, must establish a structured, dynamic risk management process that aligns strategy, performance, and risk appetite. The board must allocate oversight of risk areas across committees while maintaining integrated ownership of enterprise-level risks.

Compliance Tip: Engage with your risk management function to ensure your compliance risks, such as regulatory enforcement, third-party integrity, and misconduct, are embedded in enterprise risk registers and heatmaps. Use scenario planning to show how legal and compliance risks could disrupt strategic objectives. Partner with the CRO to lead cross-functional risk workshops that consider both downside risk and upside opportunity (e.g., entering new markets with strong compliance advantages).

Lesson 2: Compliance Is Not a Silo—It’s a System

Principle 22: Manage Compliance Responsibilities

Compliance must be embedded across the enterprise, with clear ownership, independent oversight, robust policies, and responsive change management. The CCO must have the authority, access, and independence to lead an effective compliance program that evolves with risk.

Compliance Tip: Ensure your program includes both centralized compliance (for policy and strategy) and decentralized compliance partners (within functions or geographies). Consistency is key, but so is contextualization. Build a compliance change management protocol that activates when laws shift or operations expand. This should include regulatory horizon scanning, impact assessments, stakeholder training, and updated controls. Resilience depends on staying current, not compliant with yesterday’s standards.

Lesson 3: Internal Control Is Not Just Finance—It’s Enterprise Resilience

Principle 23: Establish and Evaluate Internal Control

Internal controls must support the achievement of operational, reporting, and compliance objectives. Executive management must align controls with ethics, legal obligations, and the entity’s risk profile, and boards must oversee their design and effectiveness.

Compliance Tip: Expand your oversight of controls beyond SOX and financial reporting. Review controls around conflicts of interest, data protection, anti-corruption, and third-party oversight. Collaborate with internal audit and risk to integrate compliance controls into enterprise-wide control frameworks and control testing cycles. Use this alignment to identify duplication, streamline assurance, and enhance board visibility.

Lesson 4: Monitoring Isn’t About Activity—It’s About Insight

Principle 24: Monitor Governance Effectiveness

Governance must be continuously monitored, not just audited periodically. This includes reviewing trends, stakeholder expectations, and gaps in policy or performance. Both the board and management should receive real-time insights on culture, compliance, and risk exposure.

Compliance Tip: Build dashboards that combine hard compliance metrics (e.g., training rates, hotline activity) with qualitative indicators (e.g., engagement survey results, tone-at-the-top assessments). Present these to executive leadership as part of quarterly reporting. Lead a governance “lookback” exercise after key incidents, such as investigations, regulatory inquiries, or market shifts. What worked? What broke down? What signals were missed? This practice turns mistakes into muscle.

Lesson 5: Technology Is a Force Multiplier—Use It to Scale Resilience

COSO highlights the power of technology, like GRC systems, data analytics, and artificial intelligence, to drive smarter, faster governance. Resilience requires visibility and agility, which technology can deliver when thoughtfully deployed.

Compliance Tip: Leverage tech to automate monitoring of high-risk processes, such as gifts & hospitality, vendor onboarding, or export controls. Use exception alerts to flag potential issues before they escalate—pilot predictive analytics for culture and ethics risk. Combine internal data (e.g., survey responses, exit interviews, training patterns) with external signals (e.g., Glassdoor, whistleblower trends) to identify emerging hotspots. That’s how resilient organizations get ahead of reputation-damaging crises.

Building a Resilience-Driven Compliance Program

Use COSO’s Resilience Component as the blueprint for a more integrated, forward-looking compliance program. Here’s how to begin:

  • Risk Integration: Map compliance risks to strategic objectives and ensure alignment with ERM.
  • Compliance Ownership: Assign roles and responsibilities at all levels, with a clear reporting line to the board.
  • Controls Framework: Ensure compliance controls are part of your internal control evaluation process, not isolated.
  • Technology Enablement: Deploy automation and analytics to monitor, report, and adapt.
  • Monitoring Infrastructure: Create a system for real-time visibility and feedback across all six COSO governance components.

This is not simply about regulatory defense. It’s about strategic readiness and stakeholder trust.

What Boards Need to Hear from Compliance

Bring these messages to your next governance, audit, or risk committee meeting:

  • Resilience is the outcome of integrated governance, compliance, risk, internal control, and culture that must work together.
  • Compliance is a strategic partner in managing disruption, not just avoiding penalties.
  • The board should regularly review compliance monitoring dashboards alongside risk and financial data.
  • The compliance function must be properly resourced and independent to support resilience.
  • Resilience is not just bouncing back; it is about designing systems that do not fold under pressure.

When boards see compliance as an enabler of value, not just a cost center, they make better decisions and support stronger programs.

Final Thoughts: Resilience Is the Future of Compliance

The COSO Resilience Component confirms what many of us have been saying for years: compliance must evolve from a reactive function to a proactive pillar of enterprise stability.

Do not simply write the policy. Build the process. Don’t just monitor conduct. Predict behavior. Don’t just advise in hindsight. Prepare with foresight. Because in governance, resilience isn’t a buzzword; it is a business model. And compliance is right at the center of making it real.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes July 11, 2025.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Internal Control Improvement

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at internal control override. It’s not necessarily bad, but it may indicate that your controls need improvement.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Daily Compliance News

Daily Compliance News: July 10, 2025, The Loyalty Oath Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top compliance stories:

  • Fired officers accuse the NYC Mayor of all PD corruption. (NYT)
  • Goldman to demand loyalty oaths. (Bloomberg)
  • Linda Yaccarino leaving X. (CNN)
  • Measles is at its highest in the US since 1992. (FT)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief here.

Categories
Blog

COSO’s Corporate Governance Framework: Component 5 – Communication

We continue our exploration of the recently released COSO  Corporate Governance Framework (the Framework) as a Public Exposure Draft.  Today, we begin a deep dive into the six individual components with a discussion of Component 5—Communication. Suppose culture is the heart of an organization, and people are its muscle. In that case, communication is the circulatory system, carrying oxygen (information), nutrients (values), and antibodies (escalations and feedback) to every part of the governance body.

Most assuredly, it is not a side note. Communication is a core governance function, equally as critical as oversight, strategy, and culture. This component affirms something that compliance professionals have long known: poor communication creates risk, while effective communication fosters trust, resilience, and accountability. The Framework lays out a comprehensive roadmap for governing the quality, flow, and purpose of information both inside and outside the enterprise. It addresses communication as both a technical capability and a leadership responsibility, making it a perfect area for compliance professionals to lead from the front.

Today, we examine what Component 5 encompasses and identify five actionable lessons for compliance professionals who are ready to champion the communication function in governance.

What Does the Communication Component Cover?

COSO organizes this component around four principles:

  1. Commit to Information Quality
  2. Engage Stakeholders Strategically
  3. Communicate Effectively with Internal Stakeholders
  4. Communicate Effectively with External Stakeholders

Taken together, these principles stress that communication is strategic, multidirectional, and accountable. It is not just about what is said; rather, it is about who says it, how it is said, where it flows, and whether the message enables ethical decision-making, risk awareness, and stakeholder engagement.

Why Communication Matters to Compliance

For compliance professionals, communication is both a tool and a test. How we communicate policies, processes, and expectations shapes how employees behave. How the board receives information determines the quality of its decisions. How stakeholders perceive our transparency defines our license to operate.

More than ever, regulators, investors, and employees demand not just disclosure but meaningful, timely, and values-driven communication. That means compliance must go beyond the whistleblower hotline and annual training; we must build communication systems that enable governance excellence.

Five Key Lessons for Compliance Professionals

Lesson 1: Information Quality Is a Governance Issue—Own the Integrity of the Message

Principle 17: Commit to Information Quality

Boards and management must ensure that all internal and external information is accurate, complete, timely, and relevant to the decisions being made. This includes maintaining systems and controls to validate data and eliminate ambiguity in terminology.

Compliance Tip: Perform a communication audit of compliance reporting. Are your dashboards jargon-heavy or decision-ready? Do your risk reports help the board prioritize issues or confuse the message? Work with IT, internal audit, and risk to deploy governance, risk, and compliance (GRC) platforms that centralize and standardize your reporting. Use these tools not just to track activities but to tell a governance story.

Lesson 2: Stakeholder Engagement Is Risk Management—Make Communication Strategic

Principle 18: Engage Stakeholders Strategically

Executive management must identify key internal and external stakeholders and ensure that appropriate channels exist to share information, solicit feedback, and address concerns. This includes employees, investors, regulators, customers, suppliers, and communities.

Compliance Tip: Map your stakeholder communication channels, including the messages sent to whom, when, and through which medium. Identify gaps where feedback isn’t captured or transparency is lacking. Lead a quarterly cross-functional stakeholder forum with representatives from legal, ESG, investor relations, operations, and compliance. Use it to review messaging consistency, flag potential disconnects, and align on communication strategy for high-impact governance topics.

Lesson 3: Internal Communication Must Flow in All Directions—Not Just Top-Down

Principle 19: Communicate Effectively with Internal Stakeholders

Effective communication within the entity must support timely, secure, and informed decision-making across all departments and levels. It must include not only top-down directives, but also cross-functional collaboration and bottom-up feedback.

Compliance Tip: Evaluate whether your policies and training materials are accessible and understandable to frontline employees. Simplify complex legal language. Reinforce messaging across multiple touchpoints, not just once a year. Establish a compliance “listening architecture.” This could include monthly manager check-ins, anonymous digital suggestion boxes, and cultural pulse surveys. Use the insights to adapt your messaging, identify unspoken risks, and refine your program in real-time.

Lesson 4: External Communication Requires Guardrails—Balance Transparency and Confidentiality

Principle 20: Communicate Effectively with External Stakeholders

Boards and executive management must govern external communications with care, thereby ensuring transparency while protecting sensitive information and aligning with legal, regulatory, and reputational considerations. This includes formal disclosures, media engagement, investor briefings, and even social media interactions.

Compliance Tip: Coordinate with legal, investor relations, and public affairs to ensure external compliance disclosures (e.g., investigations, regulatory actions, ESG updates) are accurate and strategically timed. Recommend creating or expanding the entity’s disclosure committee beyond financial reporting. Include ethics, cybersecurity, and ESG in its scope. This ensures consistent governance over all public-facing statements, not just 10-Ks and earnings calls.

Lesson 5: Escalation Protocols and Whistleblower Systems Are Core Communication Channels

COSO stresses that communication is not simply about planned messaging, but it is about creating pathways for critical issues to reach decision-makers quickly. That includes whistleblower programs, hotline escalation, and crisis protocols that support real-time visibility and accountability.

Compliance Tip: Review your escalation policy. Is it clear when, how, and to whom an issue must be reported? Is there redundancy if a leader is implicated? Does the board know what “red lines” exist? Include whistleblower trends and escalation effectiveness as standing items in your board or audit committee materials. Go beyond volume and share insights about culture, responsiveness, and process quality. That’s how you earn board confidence and budget support.

Building a Governance Communication Program

To operationalize COSO’s Communication Component, compliance leaders should help lead the development of an integrated governance communication program with the following features:

  • Message alignment across all internal and external platforms;
  • Defined roles for who speaks, who approves, and who responds;
  • Feedback mechanisms like surveys, listening sessions, and open-door policies;
  • Secure reporting systems that support anonymity and protect whistleblowers; and
  • Crisis playbooks that define escalation paths, communications teams, and messaging protocols.

The goal? To ensure that communication is not just noise, but a narrative that guides behavior, enables decisions, and builds trust with all stakeholders.

What Boards Need to Hear from Compliance

Here’s what to communicate to your board:

  • The quality of governance depends on the quality of information.
  • Misaligned or confusing communication creates regulatory and reputational risk.
  • Stakeholders expect timely, truthful, and values-aligned information, not just compliance.
  • Compliance has a unique view into cross-functional communication gaps and whistleblower data.
  • The board should actively monitor communication systems and protocols, just as it does financial reporting.

When the board understands that communication is a control, not just a convenience, they will begin to ask better questions and set higher expectations.

Final Thoughts: Communication Is Governance in Motion

To determine whether your governance program is effective, listen to what people say and, equally importantly, what they do not. COSO’s Communication Component reminds us that in governance, silence is a risk, confusion is a vulnerability, and transparency is a strength.

As compliance professionals, we are communicators by necessity, but COSO invites us to become communicators by design. That means building systems that convey messages, address concerns, and connect people to their purpose. Governance is not just about structure; in many ways, it is about story. Make sure yours is told well.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes July 11, 2025.

Categories
Hill Country Authors

Hill Country Authors – Exploring Texas History and Writing with Jack Woodville London

Welcome to a new season of the award-winning Hill Country Authors Podcast, sponsored by Stoney Creek Publishing. In this podcast, Hill Country resident Tom Fox visits with authors who live in and write about the Texas Hill Country. In this episode, Tom visits author Jack Woodville London, discussing his intriguing career and novels focused on Texas history.

London, a seasoned courtroom lawyer with a background in aviation accidents, delves into his journey from practicing law to writing creatively. They explore his experiences at Oxford University and his fascination with historical research. London shares insights into his books, particularly the ‘French Letters Series’ and ‘Dangerous Latitudes,’ highlighting lesser-known events in Texas history. The discussion also touches on public education, historical figures, and the Mexico-Texas conflicts, providing a rich tapestry of historical and literary insights.

Key highlights:

  • Jack’s Professional Background
  • Oxford Experience and Writing Journey
  • Books and Writing Process
  • Texas History and Dangerous Latitudes
  • Lamar and Texas Politics
  • Research and Publishing

Resources:

Dangerous Latitudes on Stone Creek Publishing

Dangerous Latitudes on Texas A&M University Press

Stoney Creek Publishing Website

Jack Woodville London Website

Podcast Cover Art

Nancy Huffman Fine Art

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Daily Compliance News

Daily Compliance News: July 9, 2025, The TACO Don Caves Again Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top compliance stories:

  • What happens when your bot goes antisemitic? (⁠NYT⁠)
  • Spanish PM announces new ABC laws amid graft probe. (⁠Bloomberg)⁠
  • Trump pushes back on tariff dates yet again. (⁠WSJ⁠)
  • Vibe coding for compliance. (⁠WSJ⁠)

You can donate to flood relief for victims of the Kerr County flooding by going to the Hill Country Flood Relief ⁠here⁠

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Lessons from Internal Control Failures

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we look at what happens when there is an internal control override that leads to a compliance failure.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
The Hill Country Podcast

The Hill Country Podcast – Lessons from Kerrville and Kerr County’s July 4th Disaster

Welcome to the award-winning The Hill Country Podcast. In this episode, Tom Fox is joined by Marc Duncan, a disaster recovery and prevention expert, and they take a deep dive into the details of what happened in Kerr County and Kerrville over the July 4th weekend. They discuss the similarities between frameworks used in the public sector and corporate risk management, exploring the complexities of coordinating multiple stakeholders during a disaster, the importance of training and awareness, and the crucial role of effective communication. They also discuss the integrated response of public and private organizations, as well as the ongoing efforts to manage both immediate and long-term recovery after a natural disaster. This episode offers valuable insights into the multifaceted field of emergency management, as well as the practical steps involved in responding to and recovering from major weather-related events.

Key highlights:

  • Understanding Risk Management
  • Challenges in Emergency Management
  • Training and Awareness
  • Handling Weather-Related Disasters
  • Post-Disaster Coordination and Recovery
  • Role of Private and Nonprofit Organizations

Resources:

Other Hill Country Network Podcasts

Hill Country Authors Podcast

Hill Country Artists Podcast

Texas Hill Country Podcast Network

Artwork

Nancy Huffman Fine Art

Please consider donating to support the rebuilding efforts that will be necessary following this tragic event. You can donate to flood relief for victims of the Kerr County flooding by visiting the Hill Country Flood Relief here: https://bit.ly/4klTYpz.

Categories
Hill Country Hustlers

Hill Country Hustlers: From Oaxaca to Hill Country: Jorge Salinas’ Journey in Youth Soccer Coaching

In this episode of the Hill Country Hustlers podcast, host Zachary Green interviews Jorge Salinas, an entrepreneur and youth soccer coach. Originally from Oaxaca, Mexico, Jorge shares his journey from immigrating to the United States with his mother to settling in the Hill Country and eventually thriving as a soccer coach. Despite numerous challenges and setbacks, Jorge highlights the importance of perseverance, community support, and staying true to one’s passion. He discusses the development of Vida Es Futbol, his soccer training program, and the significance of indoor soccer in youth development. The conversation emphasizes the importance of honesty, effective communication, and their impact on children’s lives as key elements of success.

Key highlights:

  • Inspirational Journey Highlights
  • Coaching & Leadership Impact
  • Family, Faith & Values
  • Community Building & Legacy
  • Overcoming Odds & Taking Initiative

Resources:

Zach Green on LinkedIn

Jorge Salinas on LinkedIn

Categories
Blog

COSO’s Corporate Governance Framework: Component 4 – People

We continue our exploration of the recently released COSO  Corporate Governance Framework (the Framework) as a Public Exposure Draft.  Today, we begin a deep dive into the six individual components with a discussion of Component 4—People. It was allegedly Warren Buffett who coined the phrase Culture eats strategy for breakfast. But let me tell you something else that’s equally true: people make or break both. In Component 4, the focus is squarely on people: how we attract, develop, compensate, and ultimately hold them accountable for creating long-term value.

This is a vital message for compliance professionals. Why? Because the most sophisticated compliance program on paper won’t protect your organization if the wrong people are making the wrong decisions for the wrong reasons. Compliance is not about abstract rules; it is about human behavior. And COSO’s People Component brings that reality home.

The framework outlines how boards and executive leadership must take responsibility for aligning people, systems, hiring, training, leadership development, compensation, and succession planning with the entity’s purpose, culture, and strategy. In other words, governance doesn’t end at the boardroom door; it extends to the front line.

Today, we break down COSO’s guidance and explore five key lessons for compliance professionals ready to lead on the people side of governance.

What Is the People Component?

COSO’s CGF defines the People Component as the foundational element that ensures the right individuals are in the right roles, with the proper support, and aligned to the right objectives. This component contains three key principles:

  1. Deploy People Strategy and Succession Planning
  2. Manage People and Compensation
  3. Drive Performance and Development

From the board to the front line, these principles focus on accountability, integrity, ethical leadership, and performance through the lens of talent governance.

Why This Matters to Compliance

This component affirms what we in compliance have always known: talent decisions are, in fact, ethical decisions. Incentives shape behavior. Leadership shapes tone. And people’s strategy shapes resilience.

For compliance professionals, the People Component is a golden opportunity to build bridges with HR, executive management, and the board. It empowers us to bring our risk lens to hiring, our ethics lens to incentives, and our accountability lens to performance management.

Five Key Lessons for Compliance Professionals

Lesson 1: People Strategy Is a Governance Issue—Be Part of the Planning Table

Principle 14: Deploy People Strategy and Succession Planning

Executive management must align people strategy with business goals, assessing future workforce needs, talent gaps, and leadership succession. The board provides oversight to ensure that the right talent is in place to deliver strategic objectives in an ethical and effective manner.

Compliance Tip: Partner with HR to understand how workforce planning encompasses compliance-critical roles, including data privacy, risk management, internal audit, and ESG. Ask how your company identifies future leaders who can model ethical conduct and resilience. Propose a compliance risk overlay in succession planning. Ask: “If this person moves into a high-impact role, do they have a track record of integrity and sound judgment under pressure? ”Build that into leadership assessments.

Lesson 2: Compensation Drives Behavior—So Monitor It Carefully

Principle 15: Manage People and Compensation

The board and executive management must ensure that compensation structures reward long-term value creation and ethical behavior, not just short-term results. This includes executive compensation, employee incentives, and total rewards strategies that align with core values.

Compliance Tip: Request visibility into compensation metrics, especially for sales, finance, and procurement teams. If employees are being rewarded solely based on volume or cost savings, that could signal a misalignment with ethical standards. Collaborate with HR and the compensation committee to include compliance and ethics indicators in bonus calculations. Consider investigation outcomes, training compliance, audit results, and peer feedback on values-based behavior.

Lesson 3: Onboarding and Offboarding Are Compliance Moments of Truth

The People Component makes it clear: onboarding and offboarding are governance checkpoints. Onboarding is your chance to set expectations. Offboarding is your last opportunity to capture lessons and protect integrity.

Compliance Tip: Work with HR to ensure onboarding includes live ethics training, culture orientation, and clear escalation procedures. Offboarding should include structured exit interviews with questions on pressure, misconduct, and retaliation risks. Review offboarding data for red flags. If high-performing employees are leaving due to ethical concerns or if leaders with compliance histories are going quietly, you need to escalate those patterns to leadership and the board.

Lesson 4: Performance Reviews Must Reflect How Results Are Achieved—Not Just What Is Achieved

Principle 16: Drive Performance and Development

The board and executive management are responsible for performance systems that reflect both outcomes and behaviors. Reviews must consider how goals were achieved in an ethical, collaborative, and aligned manner with core values.

Compliance Tip: Request that HR include ethics-based questions in performance reviews. For example: “Does this employee act as a role model for integrity? ” or “Does this person raise concerns appropriately? Pilot a 360-degree review process for leaders that includes peer, subordinate, and compliance input on tone, transparency, and trustworthiness. Utilize these results in succession planning and leadership development initiatives.

Lesson 5: Development Programs Must Include Ethics, Governance, and Risk Awareness

Too often, leadership development focuses on financial acumen and strategy but remains silent on ethics, oversight, and compliance. COSO advocates for executive and board education that enhances governance throughout the organization.

Compliance Tip: Offer to design or co-lead development sessions on ethical decision-making, speak-up culture, conflicts of interest, and stakeholder trust. Focus not just on what leaders should do, but on how they should think. Ask the board to adopt a continuing education policy that includes topics related to compliance and ethics. Bring in external experts, regulators, or thought leaders in ethics to refresh perspectives and address emerging risks.

Compliance’s Role in Talent Governance

Compliance professionals are not necessarily HR specialists, but they are the stewards of ethical risk, organizational culture, and accountability. COSO’s People Component gives us a clear lane to add value in three ways:

  1. Risk insight: Help assess where people-related risks are most concentrated, such as in high-pressure sales, international expansion, and acquisitions.
  2. Behavioral analytics: Use data to flag misaligned incentives, weak training completion, or trends in misconduct.
  3. Governance alignment: Support the board in aligning people, systems, and ethics with strategy and long-term value creation.

By engaging early and often in talent conversations, compliance can prevent misconduct, protect stakeholders, and promote resilience.

Educating the Board on People Governance

Bring these insights to your next board or audit committee session:

  • Governance includes oversight of people, not just policies.
  • Talent gaps in ethics, risk, or leadership can derail strategy execution.
  • The board must understand how people systems align with values.
  • Compliance can help assess whether compensation, performance, and succession planning are risk-aligned.

When boards connect people’s decisions to governance outcomes, compliance moves from operational support to strategic leadership.

Final Thoughts: People Are Governance in Action

Compliance is no longer just about controls. It is about character at every level of the organization. COSO’s People Component recognizes that the fundamental drivers of governance are people: directors who ask the hard questions, managers who model ethical behavior, and employees who speak up when something doesn’t feel right.

In the spirit of the Compliance Evangelist: Use this component to engage deeply with the human side of your organization. Help your company build a workforce that not only follows the rules but also embodies its values. That should be your legacy.

To read or comment on the full CGF Public Exposure Draft, click here. The comment period closes July 11, 2025.