Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – July 17, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending July 17, 2026, include:

  1. Moving AI from pilot to production in pharma. (Lab Manager)
  2. Autonomous AI and patient safety. (Digital Journal)
  3. Compliance in AI home healthcare. (MedCityNews)
  4. Mark Cuban says AI is making healthcare worse. (BusinessInsider)
  5. Healthcare needs to simplify its AI stack. (HealthCareITNews)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Probing the Unknown: Investigative Lessons from Star Trek’s “The Immunity Syndrome”

Probing the Unknown: Investigative Lessons from Star Trek’s “The Immunity Syndrome”

There is a moment in every compliance professional’s career when you must venture into the unknown: a new country, a new business line, or a merger with a company whose culture, controls, and risks you only dimly perceive. Even with all our policies, controls, and frameworks, nothing can fully prepare us for the complexity, ambiguity, and risks of these new frontiers.

For me, no episode of Star Trek: The Original Series better illustrates the challenge of entering uncharted territory than “The Immunity Syndrome.” In this classic, the USS Enterprise is sent to investigate the mysterious loss of the starship Intrepid. The crew finds itself confronting a massive, deadly space organism—a threat it does not understand, cannot immediately combat, and that operates according to rules entirely foreign to its experience.

In many ways, this is the compliance professional’s dilemma when launching operations in a new jurisdiction or pursuing a new business venture. Old assumptions may no longer apply—hidden dangers lurk where we least expect. And survival, not just success, depends on investigative skills, adaptability, and a willingness to challenge everything we think we know.

Today, we examine the investigative lessons from “The Immunity Syndrome” that every compliance professional should heed when boldly going where their organization has never gone before.

Lesson 1: Question Your Assumptions—The Risks May Be Invisible

Illustrated by: The Enterprise receives a distress call and learns that the Intrepid, a ship crewed entirely by Vulcans, has been destroyed by an unknown force. As they approach the affected sector, Spock, usually calm and logical, is deeply unsettled, sensing the deaths of hundreds of Vulcans—a phenomenon that neither science nor sensors can explain.

Compliance Lesson: When entering a new country or business venture, the most dangerous risks are often the ones you cannot see or do not know how to measure. Local compliance risks, fraud schemes, or cultural taboos may be invisible to standard due diligence or data analytics. Before launch, question your risk map. What don’t you know? Who can help you see the invisible? Consider local partners, whistleblower channels, and open-ended interviews to reveal hidden hazards.

  • Investigative Takeaways:
    • Do not assume that past success in other markets guarantees future safety.
    • Leverage local knowledge just as Spock’s unique connection gave the Enterprise vital early warning.
    • Use multiple investigative approaches: don’t rely solely on established data or processes.

Lesson 2: Conduct a Deep Diagnostic—Surface Scans Are Never Enough

Illustrated by: The Enterprise, it finds a “zone of darkness” in space—a void with no energy, no light, and no readings at all. Standard scans and probes reveal nothing. Kirk, Spock, and McCoy debate theories and send increasingly sophisticated diagnostics before realizing they are up against a living, immune organism of unprecedented scale.

Compliance Lesson: Too many compliance failures occur because companies mistake a clean policy review or background check for a full investigation. New ventures require deep diagnostics that probe beneath the surface to understand not only what is there but also what is missing. Design investigative protocols that go beyond checklists: site visits, employee interviews, unannounced audits, and third-party verification. The darker the zone, the deeper you must probe.

  • Investigative Takeaway:
    • Supplement traditional due diligence with on-the-ground investigations and “boots on the ground” audits.
    • Look for the absence of evidence as well as the presence—missing records, unusual silence, or gaps in documentation can be just as telling as a smoking gun.
    • Enlist specialists (just as Kirk uses Spock and McCoy’s unique skills) to delve into complex risks, whether legal, cultural, or operational.

Lesson 3: Trust but Verify—Local Expertise Is Essential, But Not Infallible

Illustrated by Kirk, who is forced to choose between Spock and McCoy for a dangerous reconnaissance mission into the organism’s interior. Both men are experts, but each brings different strengths, blind spots, and biases to the investigation. Kirk weighs their counsel but ultimately makes his call.

Compliance Lesson:

Local advisors, consultants, and employees are critical assets when entering new regions. However, their perspective is necessarily shaped by local norms and may not fully align with your organization’s risk appetite or ethical standards. Seek out a variety of perspectives, and always keep “tone from the top” and corporate values as your North Star. Investigative rigor means striking a balance between trust and verification at every turn.

  • Investigative Takeaways:
    • Respect local expertise, but always cross-check against independent sources.
    • Build diverse investigative teams, including insiders and outsiders, as well as headquarters and field personnel, such as lawyers and auditors.
    • Establish clear escalation protocols when local advice contradicts global standards.

Lesson 4: Monitor for Emerging Risks—What Starts as a Small Threat Can Escalate Rapidly

Illustrated by: Once inside the organism, the Enterprise is quickly overwhelmed. The ship’s energy is drained, the crew is incapacitated, and the threat escalates far faster than anticipated. Kirk and his team must improvise and respond dynamically as new threats emerge.

Compliance Lesson:

When operating in new markets, small, manageable issues can quickly become existential threats if left unchecked. Corruption, weak controls, or legal ambiguities that seem minor at first can balloon if they are not caught early. Design your investigations and monitoring to see not only current misconduct but also early signs of trouble. Do not wait for the threat to fully materialize before taking action; by then, the momentum in your program may have been lost.

  • Investigative Takeaways:
    • Establish early-warning systems for compliance and operational risks.
    • Monitor not just for violations, but for near-misses, rumors, and signs of stress within the local business.
    • Use “pulse checks”—quick, frequent assessments—to catch emerging issues before they escalate.

Lesson 5: Have an Exit Strategy—Sometimes the Best Move Is to Retreat and Reassess

Illustrated by: As the Enterprise is nearly destroyed, Kirk orders a desperate gambit: injecting antimatter into the organism to destroy it, even if it means risking the ship. The plan works, but only after carefully considering—and ultimately rejecting—the possibility of a strategic withdrawal.

Compliance Lesson: Not every business venture or market entry can (or should) be salvaged. Sometimes, the risk is too great, the red flags too numerous, or the compliance gaps too wide to close. A good investigator knows when to recommend pulling back or declining to proceed. The hallmark of an effective compliance investigation is the willingness to tell leadership when the risk is not worth the reward. Better a temporary retreat than a catastrophic loss.

  • Investigative Takeaways:
    • Continually assess the risk/reward calculus of continuing versus exiting.
    • Prepare senior management for “no-go” recommendations, supported by clear evidence and risk assessments.
    • Document your investigations, findings, and decision rationale thoroughly, especially when choosing to walk away.

Final ComplianceLog Reflections

The Immunity Syndrome is more than a science fiction adventure; it is a meditation on the perils of confronting the unknown. For compliance professionals entering new countries or launching new ventures, the lessons are clear: question assumptions, dig deep, leverage local knowledge while scrutinizing it, monitor constantly, and know when to cut your losses.

In every new venture, there is a “zone of darkness.” It is a realm of unknown risks and unexpected threats. The only way to navigate it is through rigorous investigation, humility in the face of uncertainty, and the courage to act, whether that means pushing forward or pulling back.

May your investigative journeys be bold, your questions relentless, and your commitment to integrity unwavering. As the crew of the Enterprise discovered, survival in the unknown depends on never accepting the status quo, never ceasing to probe, and always being ready to chart a new course if the facts demand it.

Boldly investigate where no compliance professional has gone before.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

The Odyssey and Compliance, Part 5 – Peace in Ithaca: Building the Program After the Crisis

Today, we conclude our five-part series on some of the intersections of. On Monday, we began with the Trojan Horse as a control failure. On Tuesday, we looked at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we reviewed The Cattle of Helios, Non-Negotiables, and Control Breaches. Today, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Odysseus finally makes it home. After ten years of war and ten more years of wandering, he returns to Ithaca, confronts the suitors, reclaims his house, and restores his position. The bow is strung. The suitors are defeated. The great crisis is over. Roll credits, cue heroic music, and let everyone go back to normal. Except, of course, that is not how governance works.

The story does not really end when Odysseus wins. Ithaca still has to be governed. The household has to be restored. Trust has to be rebuilt. Loyalties have to be sorted out. The damage done by years of disorder has to be addressed. Penelope, Telemachus, the servants, the suitors’ families, and the broader community all have to live with what comes next.

That is the overlooked compliance lesson at the end of The Odyssey: winning the confrontation is not the same as rebuilding the system. For corporate compliance, Ithaca is the company after an enforcement action, a scandal, a cyber breach, a restatement, a leadership crisis, a whistleblower investigation, a failed audit, or a major control breakdown. The dramatic event may be over. The press release may be issued. The investigation may be closed. The bad actors may be gone. But the real question remains: what changes must be made so that the same story does not happen again?

The Corporate Translation

Every organization wants to believe that removing the wrongdoer solves the problem. Terminate the employee. Discipline the manager. Replace the vendor. Restate the numbers. Settle the matter. Announce new leadership. Launch a refreshed values campaign. Hold a town hall. Add a slide to the annual training deck. All of those may be necessary.

None of them is sufficient. A crisis reveals more than individual misconduct. It reveals how the organization enabled the misconduct, overlooked it, tolerated it, rationalized it, or failed to respond sooner. It exposes weaknesses in governance, incentives, supervision, reporting, monitoring, controls, culture, and accountability.

That is why post-crisis remediation cannot be treated as corporate housekeeping. It is not the ceremonial sweeping of the hall after the suitors have been removed. It is the hard work of rebuilding Ithaca so the suitors do not return wearing different badges. The corporate lesson is simple: winning the investigation is not the same as rebuilding trust.

“Works in Practice” Is the Hard Question

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks three core questions: whether the program is well designed, whether it is adequately resourced and empowered to function effectively, and whether it works in practice. The ECCP makes clear that prosecutors consider how a company’s program performed at the time of misconduct and at the time of a charging decision or resolution.

That third question—does it work in practice? —is the Ithaca question. It is one thing to have a Code of Conduct. It is another thing to know whether employees believe it. It is one thing to have a hotline. It is another thing to know whether people trust it. It is one thing to discipline misconduct. It is another matter to know whether discipline is consistent across ranks, geographies, and revenue contributions.

A compliance program does not work because it is beautifully documented. A compliance program works when it changes decisions, identifies risks, encourages escalation, supports ethical behavior, and improves when reality proves that the initial design was not enough. Odysseus could reclaim the palace in a day. Rebuilding confidence in the palace would take longer. So it is with compliance.

Remediation Is Not a Memo

One of the great corporate temptations after a crisis is to confuse activity with remediation. There will be committees. There will be project plans. There will be executive updates. There will be dashboards in shades of green, yellow, and red. There will be a new policy with a title long enough to require its own table of contents. But the question is not whether the company became busier. The question is whether the company has become better.

Effective remediation begins with root cause analysis. What happened? Why did it happen? Who was involved? Who should have known? Which controls failed? Which controls did not exist? Were employees trained? Were managers supervising? Were incentives distorting behavior? Were prior warnings ignored? Were similar issues found elsewhere?

Then, remediation must move from diagnosis to design. Policies may need to change. Controls may need to be strengthened. Reporting channels may need to be rebuilt. Training may need to be targeted. Third-party relationships may need review. Compensation systems may need adjustment. Governance committees may need clearer authority. Data analytics may need to identify patterns earlier.

And then comes the part companies sometimes skip: testing and ongoing monitoring. A control is not considered remediated just because someone wrote that it was. A control is remediated when it has been implemented, tested, validated, and shown to work. Otherwise, Ithaca has merely repainted the door.

Monitoring and Testing: Trust, but Verify Ithaca

After a crisis, leadership often wants to move on. That impulse is understandable. No one wants to live forever in the investigation report. Employees are tired. Managers are defensive. The board wants assurance. Customers want stability. Regulators want evidence. The business wants to get back to business. But moving on too quickly is how organizations repeat themselves.

Monitoring and testing are the tools that keep memory alive without keeping the organization trapped in the past. Monitoring asks, “What are we seeing now? Testing asks, “Do the controls actually work?” Together, they turn compliance from a promise into evidence.

This is where ISO 37301 offers a useful management-system lens. ISO describes ISO 37301 as a compliance management systems standard for establishing, developing, implementing, evaluating, maintaining, and improving an effective and responsive compliance management system. That language matters because it treats compliance as a cycle, not a shrine. Establish. Implement. Evaluate. Maintain. Improve.

Culture Reset Requires More Than New Words

After misconduct, companies often rediscover culture with the enthusiasm of a traveler who has just realized the map was upside down. Suddenly, everyone wants to talk about values. Tone at the top. Speak-up culture. Accountability. Transparency. Trust.

But a culture reset requires more than new words from senior leadership. Employees are sophisticated consumers of corporate messaging. They know when a town hall is sincere and when it is theater. They know whether leaders who caused the pressure are still being rewarded. They know whether people who raised concerns were protected or isolated. They know whether the company wants the truth or merely closure.

A real culture reset asks hard questions. Are managers rewarded for ethical leadership? Are employees comfortable escalating concerns? Are investigations fair and timely? Are lessons learned communicated without unnecessary secrecy? Are senior leaders held accountable? Are compliance and audit findings taken seriously? Are business goals achievable without cutting corners? Culture is not reset by announcing that trust has been restored. Trust is restored when employees see different behavior over time.

Governance After the Storm

Ithaca’s problem was not only that the suitors behaved badly. It was the governance structure that allowed them to occupy the house for too long. That is a corporate issue as well.

After a crisis, boards and executive teams should examine whether governance failed. Did the right committees receive the right information? Did compliance have sufficient independence? Were risk owners clearly identified? Did internal audit, legal, HR, finance, security, and compliance coordinate effectively? Were red flags escalated? Did leadership understand the risk, or were they receiving sanitized reporting?

Governance redesign is not glamorous. It lacks the narrative thrill of Odysseus stringing the bow. But it is what prevents the next group of suitors from discovering that no one is really watching the door.

The Compliance Takeaway

The end of The Odyssey is not just about return. It is about restoration. That distinction matters for compliance officers and business leaders. After a crisis, the organization must resist the urge to declare victory too soon. The investigation may identify what happened. Discipline may address who was responsible. But remediation must answer the deeper question: what will be different? A mature compliance program uses a crisis as evidence. It monitors. It tests. It learns. It redesigns governance. It strengthens controls. It resets culture through action. It measures whether the program works in practice, not merely whether it exists on paper.

Odysseus came home and won back Ithaca. The compliance challenge is harder. You have to make Ithaca governable again.

Categories
AI Today in 5

AI Today in 5: July 16, 2026, The Simplifier Stack Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Texas AI law: a business guide. (Hackernoon)
  2. AI resistance as a matter of faith. (CCI)
  3. AI deepfakes compromise hiring compliance. (SIA)
  4. AI is fueling the start-up boom. (Bloomberg)
  5. Healthcare needs to simplify its AI stack. (HealthCareITNews)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: July 16, 2026, Just A Big Misunderstanding Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Goldman GC says her emails with Epstein were taken ‘out of context.’ (WSJ)
  • A Goldilocks approach to FCPA enforcement. (Bloomberg Law)
  • Elon Musk ‘likely’ violated WI election law through bribery. (WPR)
  • Surprise Surprise. The Supreme Court said the 4th Amendment still exists. (Reuters)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Everything Compliance

Everything Compliance: The Around the World and Close to Home Edition

Welcome to a revamped Everything Compliance. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, who joins returning regulars Matt Kelly, Jonathan Armstrong, and Karen Moore for the next iteration of Everything Compliance.

  • Matt Kelly analyzes Bosch’s export controls violations involving Huawei under the foreign direct product rule, resulting in a $36 million BIS penalty, DOJ declination after self-disclosure, and major remediation hiring.
  • Karen Moore covers the UK Commercial Payments Bill, aimed at protecting SMEs via a 60-day payment cap, mandatory late-payment interest, dispute-timing rules, a stronger Small Business Commissioner, and “name and shame” disclosures with potential ESG/fraud implications for supplier-treatment claims. Rebecca Walker shares NAVEX 2026 survey findings linking leadership “say vs. do” gaps to higher violations.
  • Jonathan Armstrong covers a recent speech by the Director of the Serious Fraud Office, Graeme McNulty, who said the SFO intends to be a more active enforcer and to use the new failure-to-prevent-fraud offense with practical tips on policies, role-based training, fast tip-off response, properly resourced investigations, self-reporting, tone from the top, and third-party due diligence.
  • Rebecca Walker focuses on speak-up culture, emphasizing post-report communications, lessons from KPMG Australia, and Navex data showing higher report volumes and longer investigation closure times.

The members of Everything Compliance are:

The award-winning Everything Compliance is a part of the Compliance Podcast Network.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 46 – Compliance Across Cultures: “A Piece of the Action” as a Guide for Global Ethics

Any compliance professional who has ever led a team into a new country, or even a new region, knows that the journey is never as simple as applying the same playbook. Corporate values may be universal, but their application, reception, and risk profile shift dramatically with local context. Cross-cultural compliance isn’t just about checking legal boxes; it’s about building trust, ensuring fairness, and embedding institutional justice in systems often shaped by histories and norms foreign to headquarters. No pop culture episode illustrates this challenge better than Star Trek: The Original Series’ classic, “A Piece of the Action.”

For the compliance professional, this episode serves as a mirror to our modern experience of entering new regulatory territories. It forces us to ask: How do you enforce ethical standards in a place where the “rules of the game” are so different? How do you model institutional justice when even the definitions of “fairness” and “justice” seem up for grabs?

Lesson 1: Don’t Assume Your Ethics Are Universal

Illustrated by: Kirk, Spock, and McCoy are bewildered as they realize the entire Iotian society is based on a book about Earth’s 1920s gangsters.

Compliance Lesson: The first mistake many organizations make is assuming their ethical and compliance frameworks are immediately translatable.

Lesson 2: Institutional Justice Depends on Transparent Processes

Illustrated by: Kirk tries to “play the game,” cutting a deal with mob boss Bela Okmyx for the greater good, but quickly learns that without clear rules, every agreement is subject to double-cross and confusion.

Compliance Lesson: The absence of a transparent and impartial system leads to chaos. Each boss claims to enforce their version of “justice,” but it’s arbitrary and self-serving.

Lesson 3: The Dangers of Imposed Systems and the Need for Adaptation

Illustrated by: Kirk realizes that simply imposing Federation law will not work. The Iotians are not ready for those systems, and the crew’s heavy-handed attempts nearly spark more violence and instability.

Compliance Lesson: When entering new markets, resist the temptation to impose home-country rules without considering the local context.

Lesson 4: Speak the Local Language—Literally and Culturally

Illustrated by: Spock tries to explain Federation rules logically, but it’s Kirk’s willingness to “talk the talk,” even using gangster slang, that opens doors and earns a modicum of respect.

Compliance Lesson: Effective compliance communications must be locally relevant. This is more than translation; it’s cultural adaptation. What resonates in Houston might be meaningless (or counterproductive) in Hanoi.

Lesson 5: Leave a Positive Legacy—Don’t Repeat “Book Mistakes”

Illustrated by: In the final act, McCoy discovers he’s left his communicator behind, prompting a worried Kirk and Spock to realize the Iotians might reverse-engineer the technology and reshape their society once again.

Compliance Takeaway: Every compliance professional leaves a legacy. When you introduce policies, training, or reporting mechanisms, they will be interpreted and possibly misused by future leaders.

Final ComplianceLog Reflections

Cross-cultural compliance is ultimately about humility, adaptability, and respect for institutional justice as it’s lived and experienced on the ground. “A Piece of the Action” teaches us that leadership is not about enforcing rules by fiat, but about fostering a culture where fairness and justice are owned locally, embedded in hearts, not just in handbooks.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

The Odyssey and Compliance, Part 4 – The Cattle of Helios: Non-Negotiables and Control Breaches

We continue our consideration of the intersection of The Odyssey and compliance by reviewing the tale of the Cattle of Helios.

Odysseus’s crew had been warned and not casually warned. Not “check the policy when you get a minute,” warned the manager. Not “Legal would prefer we avoid this,” warned. They were told clearly: do not touch the cattle of Helios. The cattle were sacred. The instruction was simple. The consequences were severe. Then hunger arrived.

Odysseus’s men were stranded. Supplies ran low—pressure built. Rationalizations followed. The crew looked at the sacred cattle and began doing what employees, managers, and executives have done in companies since the dawn of internal controls: they explained why the rule should not apply this time. They were desperate. The situation was unusual. The risk was theoretical. Surely the gods would understand. Surely survival mattered more than procedure. So they slaughtered the cattle. It did not end well.

For corporate compliance, the Cattle of Helios is a story about red-line rules: the things an organization says are non-negotiable. Do not falsify records. Do not retaliate. Do not bypass sanctions screening. Do not misuse customer data. Do not make unapproved payments. Do not obstruct an investigation. Do not conceal a conflict. Do not alter documents. Do not ignore a legal hold. Do not approve what you do not understand. Every company has sacred cattle. The real question is whether employees believe they are actually sacred.

The Corporate Translation

The Cattle of Helios are the company’s non-negotiables. They are not ordinary preferences. They are not “best practices.” They are not aspirational values printed on lobby walls next to a tasteful photograph of diverse employees pointing at a laptop. They are the rules that protect the organization’s license to operate.

In a strong compliance culture, employees know these rules. Managers reinforce them. Controls support them. Violations are escalated. Discipline is consistent. Pressure is acknowledged but does not excuse misconduct. In a weak compliance culture, everyone knows the words, but no one believes the consequences will be enforced. That is how red-line rules become folklore. A rule everyone knows, but no one enforces, is not a rule. It is a campfire story.

Pressure Does Not Create Character. It Reveals Controls.

Odysseus’s crew did not break the rule while comfortable, rested, and well-fed. They broke it under pressure. Most compliance breaches do not occur in calm conference rooms where everyone has read the policy, reviewed the risk matrix, and enjoyed a sensible lunch. They occur when the quarter is closing, the shipment is stuck, the customer is angry, the regulator is asking questions, the system is down, the executive is impatient, or the team is exhausted.

Pressure is the great compliance stress test. It reveals whether policies are operational or decorative. It reveals whether managers know how to supervise. It reveals whether employees believe escalation is safe. It reveals whether the organization has built controls that work when humans are hungry, tired, ambitious, afraid, or behind target.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a company’s compliance program is not only well-designed but also applied earnestly and is working in practice. It also notes that prosecutors look at whether policies, reporting lines, training, incentives, and discipline are integrated into operations and the workforce. That is the key point. A red-line rule cannot live only in the Code of Conduct. It must live in approvals, workflows, monitoring, supervision, training, investigations, and consequences. Otherwise, when hunger comes, the cattle are on the menu.

Supervision Is Not a Ceremonial Role

There is another uncomfortable part of the myth. Odysseus is absent when the crew crosses the line. Depending on the telling, he is asleep or away praying. Either way, the leader is not effectively supervising when the critical decision is made. That should make every business leader shift slightly in their chair.

Many control breaches happen in the gap between policy and supervision. Senior leadership announces the rule. Compliance writes the policy. Legal reviews the language. Training pushes the module. Then the real decision is made by a frontline team under pressure, with a manager who either does not know, does not ask, or does not want to know. That is not a paperwork problem. That is an accountability problem.

Managers are the first line of ethical translation. They turn corporate expectations into daily behavior. If they treat compliance as an administrative burden, so will employees. If they reward results without asking how those results were achieved, employees will notice. If they punish bad news, problems will go underground. If they look away from “small” violations, they teach the business that red lines are negotiable.

Supervision is not hovering. It is not micromanagement. It is the disciplined act of identifying where the real risks lie and ensuring that employees have guidance, resources, and accountability before a breach occurs. Odysseus’s men knew the rule. What they lacked was effective control at the decisive moment.

Reporting Before the Cattle Are Slaughtered

A mature compliance program wants to hear about pressure before it becomes misconduct. That means employees need trusted ways to raise concerns, ask questions, and report violations. The ECCP identifies confidential reporting and investigation processes as hallmarks of a well-designed program, including mechanisms for reporting suspected misconduct, protection against retaliation, proper routing of complaints, timely investigations, and appropriate follow-up and discipline.

The reporting question is not simply, “Do we have a hotline? “The better question is, ‘Would the crew have used it before dinner?’ Would an employee say, ‘We are being asked to ship without required approval’? “Would a finance analyst say, “This invoice looks wrong”? Would a sales manager say, “The customer is pushing us to use an unapproved intermediary”? Would an IT employee say, “Someone wants access they shouldn’t have”? Would anyone say, “We are about to cross a line”? If the answer is no, the reporting mechanism may exist, but trust does not.

That is where anti-retaliation becomes central. Employees will not report sacred cattle violations if the organization quietly punishes the person who notices the knife. A speak-up culture is not built by posters. It is built on what happens to the first person who speaks up when the business does not want to hear it.

Discipline Must Be Consistent, Not Theatrical

After a breach, companies often want to show seriousness. That is understandable. But discipline must be more than corporate thunderbolts. It must be fair. It must be consistent. It must be documented. It must address both supervisors and direct actors. It must consider incentives and pressure. It must ask whether the rule was clear, whether training was adequate, whether controls failed, and whether leaders tolerated or encouraged the behavior.

The ECCP specifically focuses on consequence management, including procedures to identify, investigate, discipline, and remediate violations, consistent enforcement across the organization, and consequences regardless of position or title. It also asks whether companies track disciplinary outcomes and measure consistency across levels, geographies, units, and departments. That is where many companies stumble.

They discipline the employee who touched the cattle but ignore the manager who set impossible targets. They terminate the junior person but coach the rainmaker. They punish the region that got caught but ignore similar conduct elsewhere. They announce “zero tolerance” and then create exceptions for people with large books of business.

Employees are excellent readers of organizational reality. They know whether discipline is consistent. They know whether some people are protected. They know whether “non-negotiable” means non-negotiable or merely “please do not embarrass us.” A compliance program loses credibility when consequences depend on rank, revenue, geography, or internal politics.

Incentives: Who Made the Crew Hungry?

The crew was hungry. That does not excuse what they did, but it helps explain why the rule failed. Corporate compliance must ask similar questions. Were employees under unrealistic sales targets? Were bonuses tied only to revenue? Were managers rewarded for speed without regard to control quality? Were teams understaffed? Were approvals too slow? Was the policy clear but operationally impossible? Did leadership create pressure and then act shocked when employees cut corners?

The ECCP asks whether companies have considered the impact of financial rewards and other incentives on compliance, including whether commercial targets are achievable while operating in a compliant and ethical manner. That question should be posted in every executive compensation meeting. If the business model requires employees to choose between meeting targets and following the rules, do not be surprised when the cattle start disappearing.

What a Better Program Does

A better program defines its non-negotiables clearly and repeats them often. It trains employees on real pressure moments, not abstract policy language. It gives managers supplemental guidance. It builds controls around red-line rules. It monitors for breaches and near misses. It makes escalation easy. It investigates fairly. It disciplines consistently. It addresses root causes. It tests whether employees actually understand which rules cannot be bent. Most importantly, it refuses to let pressure become a universal solvent.

Pressure may explain why misconduct occurred. It should not erase accountability. When a red-line rule is breached, the organization should ask four questions.

First, did the employee know the rule?

Second, did the controls make compliance practical?

Third, did supervision reinforce the rule?

Fourth, did incentives or leadership pressure make violations more likely?

Those questions move the company beyond blame and toward remediation.

The Compliance Takeaway

The Cattle of Helios remind us that non-negotiable rules are only real when they survive pressure. It is easy to honor sacred cattle when the pantry is full. The test comes when the team is hungry, the deadline is looming, and someone says, “We have no choice.” That is when compliance has to mean something.

A company’s most important rules must be known, operationalized, monitored, and enforced. They must apply to senior leaders and junior employees. They must survive business urgency. They must be supported by reporting channels, investigations, discipline, and incentives that tell the same story.

Do not falsify records.

Do not retaliate.

Do not bypass screening.

Do not misuse data.

Do not make unapproved payments.

Do not conceal misconduct.

Do not touch the cattle.

Because if the organization says a rule is sacred but treats violations as negotiable, employees will soon learn the real policy. And by then, dinner may already be served.

Join us tomorrow as we conclude our series with a homecoming in Ithaca.

Categories
Blog

Lessons in Cross-Cultural Compliance: Star Trek’s “A Piece of the Action” and the Challenge of New Frontiers

Any compliance professional who has ever led a team into a new country, or even a new region, knows that the journey is never as simple as applying the same playbook. Corporate values may be universal, but their application, reception, and risk profile shift dramatically with local context. Cross-cultural compliance isn’t just about checking legal boxes; it’s about building trust, ensuring fairness, and embedding institutional justice in systems often shaped by histories and norms foreign to headquarters.

No pop culture episode illustrates this challenge better than Star Trek: The Original Series’ classic, “A Piece of the Action.” In this memorable hour, Captain Kirk and crew beam down to Sigma Iotia II, a planet whose entire society has been shaped by a 1920s Chicago gangster book accidentally left behind by an earlier Earth expedition. The result? A world where the “rules” are alien, an uneasy blend of familiar legality, foreign morality, and institutional chaos.

For the compliance professional, this episode serves as a mirror to our modern experience of entering new regulatory territories. It forces us to ask: How do you enforce ethical standards in a place where the “rules of the game” are so different? How do you model institutional justice when even the definitions of “fairness” and “justice” seem up for grabs?

Today, we boldly go where few compliance professionals have gone before: into the heart of cross-cultural lessons inspired by Kirk, Spock, and McCoy’s misadventures on the planet Vulcan.

Lesson 1: Don’t Assume Your Ethics Are Universal

Illustrated by: Kirk, Spock, and McCoy are bewildered as they realize the entire Iotian society is based on a book about Earth’s 1920s gangsters. What is “normal” here is extortion, double-crossing, and violence.

Compliance Lesson: The first mistake many organizations make is assuming their ethical and compliance frameworks are immediately translatable. On Sigma Iotia II, Kirk’s appeals to law, order, and morality fall flat. Here, the “institutional justice system” is a patchwork of mob bosses, each enforcing their version of fairness.

For Compliance Pros:

  • Start by listening and observing. Before launching training or rolling out policies, invest in local cultural assessments.
  • Engage local stakeholders. They can provide insights into what “justice” and “fairness” mean in practice.
  • Translate—not just language, but values. If your hotline program, reporting mechanisms, or disciplinary systems rely on local trust, learn what earns (or erodes) that trust.

Lesson 2: Institutional Justice Depends on Transparent Processes

Illustrated by: Kirk tries to “play the game,” cutting a deal with mob boss Bela Okmyx for the greater good, but quickly learns that without clear rules, every agreement is subject to double-cross and confusion.

Compliance Lesson: The absence of a transparent and impartial system leads to chaos. Each boss claims to enforce their version of “justice,” but it’s arbitrary and self-serving. For compliance professionals, this is a cautionary tale: if your processes aren’t transparent and predictable, your program risks devolving into selective enforcement or, worse, simply window dressing.

For Compliance Pros:

  • Ensure transparency in policies and procedures. Local teams should understand not only what is expected but also why and what will happen if expectations aren’t met.
  • Communicate the process for raising and resolving concerns. Is there an appeal? Who reviews the case? How are outcomes explained?
  • Build in fairness at every step. Avoid any appearance of “playing favorites” or tailoring decisions to the powerful.

Lesson 3: The Dangers of Imposed Systems and the Need for Adaptation

Illustrated by: Kirk realizes that simply imposing Federation law will not be effective. The Iotians are not ready for those systems, and the crew’s heavy-handed attempts nearly spark more violence and instability.

Compliance Lesson: When entering new markets, resist the temptation to impose home-country rules without considering the local context. This is not just ineffective. It can backfire, causing resentment or noncompliance.

For Compliance Pros:

  • Adapt, don’t transplant. Find ways to harmonize your code of conduct with local customs while upholding core values.
  • Use a risk-based approach. Focus first on the highest-risk behaviors that truly endanger your organization or people.
  • Empower local leaders. Give them ownership over adapting processes and communications so that they are effective and resonate with their audience.

Lesson 4: Speak the Local Language—Literally and Culturally

Illustrated by: Spock tries to explain Federation rules logically, but it’s Kirk’s willingness to “talk the talk,” even using gangster slang, that opens doors and earns a modicum of respect.

Compliance Lesson: Effective compliance communications must be locally relevant. This is more than translation; it’s cultural adaptation. What resonates in Houston might be meaningless (or counterproductive) in Hanoi.

For Compliance Pros:

  • Leverage local stories and examples. Bring policies to life through scenarios that employees recognize.
  • Use local champions. The right messenger can make or break your training or reporting program.
  • Culturally tailor your hotline and reporting mechanisms. In some cultures, direct reporting is perceived as a form of betrayal; consider culturally sensitive alternatives (e.g., mediation or ombuds channels).

Lesson 5: Leave a Positive Legacy—Don’t Repeat “Book Mistakes”

Illustrated by: In the final act, McCoy discovers he’s left his communicator behind, prompting a worried Kirk and Spock to realize the Iotians might reverse-engineer the technology and reshape their society once again.

Compliance Takeaway: Every compliance professional leaves a legacy. When you introduce policies, training, or reporting mechanisms, they will be interpreted and possibly misused by future leaders. Are you leaving behind tools for justice or weapons for the next “mob boss” to exploit?

For Compliance Pros:

  • Train for sustainability. Do not just deliver training; build local capacity for ongoing education and oversight.
  • Monitor unintended consequences. Regularly review your program’s impact on local dynamics.
  • Commit to continuous improvement. Don’t just “set it and forget it.” Be prepared to revisit, revise, and reinforce your approach as conditions change.

Final ComplianceLog Reflections

Cross-cultural compliance is ultimately about humility, adaptability, and respect for institutional justice as it’s lived and experienced on the ground. “A Piece of the Action” teaches us that leadership is not about enforcing rules by fiat but about fostering a culture where fairness and justice are owned locally, embedded in hearts, not just in handbooks.

When we boldly enter new markets, we do so not as conquerors but as collaborators. Listen, learn, adapt, and, above all, build compliance programs that leave a legacy of justice, fairness, and integrity. Only then will our actions, however small, become a positive piece of the action for years to come.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Compliance Into the Weeds

Compliance into the Weeds: The Slaughter Ruling, Regulatory Volatility and a Healthcare Compliance Fraud Case

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the June 29 Supreme Court decision in Trump v. Slaughter.

This decision upheld the president’s power to fire independent agency commissioners at will (with a carve-out for the Federal Reserve), overturning long-standing protections from Humphrey’s Executor. Kelly argues the ruling will politicize and degrade regulatory agencies, deter qualified minority-party commissioners, increase rulemaking volatility, and shift power away from Congress toward courts as rules are challenged. As an example, they cite the SEC’s proposal to allow semi-annual rather than quarterly reporting, which drew about 80,000 comments, with roughly 99% opposed, yet they predict it may proceed and later be reversed, creating compliance burdens. They then cover Georgia author Jean Wilson, sentenced to 10 years for a $66 million Medicare fraud scheme while writing healthcare compliance books.

Key highlights:

  • The Slaughter Ruling
  • Regulatory Volatility Ahead
  • Who Will Serve as Commissioners
  • Fed Carve-out and Court Power
  • Compliance Impact and No Easy Answers
  • Healthcare Compliance Fraud Story (Or is it from The Onion?)

 Resources:

Matt in Radical Compliance

 Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.