Categories
FCPA Compliance Report

FCPA Compliance Report: Episode 808 – Building a Life Sciences Compliance Law Firm with Edye Edens

In this episode, Tom Fox welcomes Edye Edens about launching her Life Sciences Law Group (“Eedee Law”) after years of contracting in life sciences compliance across multiple firms.

Edye explains she founded the firm to better align her practice with supporting clinical trial sites, vendors, and academia, which often lack the budgets and in-house legal resources of sponsors and CROs. She describes a multidisciplinary team model that includes non-attorney quality, TMF, regulatory, and inspection-readiness professionals with deep study-operations experience, enabling rapid, practical support at different price points, including fractional engagements and urgent FDA inspection support. Edye outlines four core client segments: independent sites/site networks, academic medical centers’ research compliance functions, NCI-designated cancer centers, and vendors entering clinical trials who need guidance on Part 11, HIPAA, QMS, and vendor qualification. She discusses growing AI-related client needs, emphasizing evolving regulatory expectations and “compliance at the speed of business,” and shares how to connect via website, LinkedIn, and email.

Key highlights:

  • Building A Different Firm
  • Indy Roots National Reach
  • Lessons From Academic Medicine
  • AI Vendors And Regulation

Resources:

Edye Edens on LinkedIn

Eedee Law

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

May the Controls Be With You: Compliance Lessons from Star Wars: Episode IV – A New Hope

Every May 4, the business world pauses, smiles, and says, “May the Fourth be with you.” For compliance professionals, that phrase carries more than nostalgia. It can also remind us that every organization faces a recurring struggle between power and accountability, command and control, culture and fear, risk and resilience.

Star Wars: Episode IV – A New Hope is not simply a space adventure. It is a story about governance failure, ethical courage, institutional blindness, weak controls, overconfidence, and the power of a small group committed to a mission larger than themselves. In other words, it is fertile ground for the modern compliance professional.

The Galactic Empire had scale, resources, technology, command authority, and a massive enforcement apparatus. What it lacked was ethics, accountability, transparency, and trust. The Rebel Alliance had far fewer resources, but it had purpose, shared values, disciplined intelligence, and a willingness to challenge a system that had become corrupt at its core.

That is the compliance lesson. Size is not strength if governance fails. Technology is not protection if culture is broken. Authority is not leadership if fear replaces trust. And no control environment is effective if the people inside the system are afraid to speak, unwilling to escalate, or conditioned to obey without question.

The Empire as a Case Study in Governance Failure

The Empire offers a powerful example of what happens when power operates without accountability. Its leadership model is command-driven, opaque, and fear-based. Decisions flow from the top, dissent is punished, and risk information is filtered through hierarchy rather than tested through independent challenge.

This is not a sustainable operating model for any corporation. It may produce short-term compliance with directives, but it does not produce ethical performance. Employees may follow orders, but they will not raise concerns. Managers may execute instructions, but they will not challenge flawed assumptions. Leaders may believe they are in control, but they are really operating inside an echo chamber.

That is a classic governance breakdown. Under the DOJ’s Evaluation of Corporate Compliance Programs (ECCP), prosecutors ask whether compliance has adequate authority, access, and resources. They also ask whether the company’s culture encourages ethical conduct and whether employees can report concerns without fear of retaliation. The Empire would fail that test before the first audit interview began. A culture of fear is not control. It is a risk multiplier.

The Death Star and the Danger of Overconfidence

The Death Star is the ultimate symbol of institutional overconfidence. It is massive, technologically advanced, expensive, and terrifying. It is also vulnerable because its designers and leaders failed to take a critical weakness in the system seriously.

For compliance professionals, this is a familiar issue. Organizations often build impressive frameworks: policies, systems, committees, dashboards, training platforms, risk registers, and reporting structures. Yet one untested assumption, one ignored warning, one undocumented exception, or one poorly monitored third party can create a vulnerability that undermines the entire program. The lesson is not that complexity is bad. The lesson is that complexity must be tested.

A compliance program cannot be judged solely by its architecture. It must be judged by whether it works in practice. Do controls operate as designed? Are exceptions reviewed? Are risk assessments updated? Are third-party red flags escalated? Are investigations tied to root cause analysis? Are lessons learned incorporated back into the program? The Death Star failed because its leadership confused scale with effectiveness. Compliance leaders should never make the same mistake.

Princess Leia and the Importance of Speak-Up Culture

Princess Leia is one of the great figures to speak up in popular culture. She sees the Empire’s reality clearly, acts with courage, preserves critical information, and refuses to be intimidated by power. In a corporate setting, she represents the employee, executive, or compliance professional who raises a concern when the organization would rather look the other way. She also reminds us that a speak-up culture is not built by having a hotline. It is built by protecting those who use it.

A company can have a hotline, a Code of Conduct, annual training, and posters in every break room. None of that matters if employees believe reporting will lead to retaliation, career damage, isolation, or indifference. The real measure of a speak-up culture is whether people trust the system enough to use it before a problem becomes a crisis. Leia’s courage mattered. But in a corporation, courage should not be the only control. The system itself must make reporting safe, trusted, and effective.

Obi-Wan Kenobi and the Role of Ethical Leadership

Obi-Wan Kenobi does not lead through fear. He leads through wisdom, restraint, discipline, and example. He understands risk. He understands history. He understands that values must be taught, modeled, and passed forward. That is the leadership lesson. Slogans do not create an ethical culture. It is transmitted through conduct. Employees watch what leaders reward, tolerate, ignore, and punish. They listen to speeches, but they believe in actions.

For boards and senior executives, this is a central compliance obligation. Tone at the top must be matched by conduct at the top. Middle management must reinforce the message. Incentives must align with ethical behavior. Discipline must be consistent. Performance pressure must not overwhelm controls. Obi-Wan understood that leadership is stewardship. Compliance leaders should view their work the same way.

Luke Skywalker and the Development of Compliance Judgment

Luke Skywalker begins as inexperienced, impatient, and uncertain. He does not yet understand the broader conflict, the risks, or his own role. Over time, he learns judgment. He listens, observes, trains, fails, and grows. That is how compliance capability develops inside a company. Employees don’t come to work knowing about conflicts of interest, third-party risk, gifts and hospitality, data governance, sanctions exposure, procurement controls, or escalation protocols. They must be trained, guided, and supported.

Effective compliance training is not a once-a-year exercise in legal coverage. It is a business process for building judgment. The goal is not simply to tell employees the rules. The goal is to help them recognize risk in real time, pause before acting, ask better questions, and escalate when necessary. Compliance is not merely knowledge. It is judgment under pressure.

Han Solo and the Third-Party Risk Lesson

Han Solo is charismatic, capable, and useful. He is also a third-party risk case study waiting to happen. He has unclear loyalties, questionable business relationships, financial pressure, and a complicated history with counterparties. Every compliance professional knows this profile. The company needs a third party because that party can get things done. The business sponsor trusts the relationship. The third party knows the market, has access

to it, and can move quickly. But the risk indicators are visible: opaque ownership, unusual payment terms, reluctance to provide documentation, government touchpoints, reputation concerns, or unexplained urgency.

The answer is not to avoid all third parties. The answer is to manage them. Due diligence must be risk-based. Contracts must include compliance obligations, audit rights, and termination rights. Payment controls must be disciplined. Services must be documented. Red flags must be resolved before onboarding and monitored after onboarding. Han Solo eventually becomes aligned with the mission. In corporate life, however, hope is not a third-party control. Documentation is.

The Rebel Alliance and the Power of Mission

The Rebel Alliance wins not because it is larger, better funded, or more technologically sophisticated. It wins because it has clarity of mission, trust, shared purpose, and the ability to turn intelligence into action. That is the best compliance program at work. They are not bureaucratic overlays. They are mission-aligned business systems. They help the organization grow the right way. They identify risk earlier. They protect trust. They support better decisions. They turn values into controls and controls into evidence.

A mature compliance program should operate like the best parts of the Rebel Alliance: focused, informed, agile, disciplined, and mission-driven. It should gather information from across the enterprise, analyze risk, escalate concerns, and act before the organization faces regulatory, reputational, or operational harm. Compliance is not the department of “no.” It is the discipline of sustainable performance.

Five Key Takeaways for Compliance Professionals

  1. Fear is not a compliance culture. It may produce silence, but it will not produce trust, transparency, or early reporting.
  2. Scale is not effective. A large compliance program must still prove that its controls work in practice.
  3. Speak-up systems must be trusted. Employees need safe channels, anti-retaliation protections, and confidence that concerns will be addressed.
  4. Third-party risk requires discipline. Useful intermediaries can also create serious exposure if diligence, contracts, payments, and monitoring are weak.
  5. Governance must challenge overconfidence. Boards and executives should ask hard questions about assumptions, vulnerabilities, escalation, and control testing.

Final Thought

On May 4, we can enjoy Star Wars Day. But for compliance professionals, A New Hope offers something more durable than a pop culture reference. It reminds us that ethics, accountability, controls, culture, and courage matter. The Empire had power. The Rebels had purpose. In compliance, purpose supported by controls is the real force multiplier.

May the Fourth be with you.

Categories
Sunday Book Review

Sunday Book Review: May 3, 2026, The Top Star Wars Books Edition

In the Sunday Book Review, Tom Fox considers books that would interest compliance professionals, business executives, or anyone curious. It could be books about business, compliance, history, leadership, current events, or anything else that might interest Tom. In this episode, to honor all those who celebrate May 4 each year, we look at 4 top books that expand the Star Wars canon.

  1. Heir to the Empire by Timothy Zahn
  2. Dark Force Rising by Timothy Zahn
  3. Thrawn (Star Wars) by Timothy Zahn
  4. Star Wars: Darth Plagueis by James Luceno

Resources:

The 100 Best Star Wars Books of All Time on Shortform

Categories
AI Today in 5

AI Today in 5: May 1, 2026, The May Day for OpenAI in Canada Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. OpenAI sued over Canada massacre. (WSJ)
  2. What is AI in compliance? (MobileAppDaily)
  3. AI governance starts with ownership. (CCI)
  4. Using AI in decision-making. (Forbes)
  5. Can AI deliver real productivity gains? (FinTechGlobal)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending May 1, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include:

  1. Banks are growing increasingly concerned with Mythos. (Reuters)
  2. Agentic AI reshaping bank compliance. (AI.Magazine)
  3. US AI regulations in the financial sector. (SIA)
  4. AI development for financial pros. (MIT)
  5. The future of AI in finance. (Intuit)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Betting the Game

Betting the Game: Athlete as Bettor – Governance, Education, and Integrity Risk in a Mobile Betting Era

Betting the Game is a 10-part podcast series exploring how sports gambling reshaped the business, culture, and integrity of athletics across professional and amateur sports. Hosted by Tom Fox and Mike DeBernardis, the series examines the real-world collisions between betting markets, athlete conduct, institutional oversight, and public trust. Each episode looks at a different pressure point, from player betting and college sports to prop bets, insider information, and the governance failures that can put the credibility of competition at risk. At its core, the series asks a simple but urgent question: as gambling became mainstream in sports, did ethics, compliance, and oversight keep pace?

In episode two of “Betting the Game,” Tom and Mike examine athlete gambling as a sensitive threat to sports integrity in a legal, mobile, and normalized betting environment, arguing that the issue is fundamentally one of legitimacy and governance rather than optics alone. They discuss how frictionless app-based wagering increases the risk for insiders with access to information and influence over outcomes, even in the absence of match-fixing. Using NFL suspensions (e.g., betting from team facilities or on prohibited sports), the Jontay Porter NBA case (alleged manipulation of player prop outcomes, lifetime ban, and wire fraud charges), and MLB’s lifetime ban of Tucupita Marcano for betting on baseball, they emphasize that punishment must be paired with year-round, scenario-based training, aligned commercial and integrity messaging, early-warning monitoring and escalation systems, confidential Q&A channels, club accountability, and a culture that reinforces integrity before violations occur.

Key highlights:

  • Why Leagues Must Act
  • Jontay Porter Integrity Crisis
  • Baseball Zero Tolerance
  • Integrity Of Gambling Markets
  • Mobile Betting Temptation
  • Building Prevention Frameworks
  • Five Point Governance Plan

Resources:

Mike DeBernardis on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

References:

List of NFL players suspended for violating gambling policies

Jontay Porter pleads guilty in case tied to NBA betting scandal

Tucupita Marcano gets lifetime MLB ban for betting on baseball

Categories
Creativity and Compliance

Creativity and Compliance: Compliance 6-Pack: Part 2 – The Listen Like a Thief

Tom and Ronnie continue their six-part series highlighting the role of improv in compliance. This series links improv lessons to corporate compliance and some of the key tools and strategies Ronnie has brought from his former world of improv to the corporate compliance communications realm. In today’s Improv & Compliance Lesson 2, they focus on “listen like a thief” as a core active-listening skill for leaders and compliance professionals.

Ronnie explains that when authority figures formulate answers too quickly, they miss verbal and nonverbal cues and critical late-breaking “doorknob comments,” undermining trust when people perceive inattentiveness. He recommends listening with the whole body, avoiding interruptions, using a “last word” silent repeat to create a pause, silently saying thank you, and asking clarifying questions before responding. They extend the concept to organizational listening through ethics ambassador/compliance champion networks, a tracking hotline, consultative questions, and surveys that assess speak-up awareness, perceived safety, organizational justice, and trust. They emphasize closing the loop by communicating outcomes through anonymized stories and metrics, so employees know they were heard.

Resources:

Ronnie

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Creativity and Compliance is a multiple podcast award-winning show and was recently honored as one of the Top 35 Podcasts on Creativity by Feedspot.

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week, May 1, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a Weekly Briefing of the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending May 1, 2026, include:

  1. Trust in AI Healthcare. (HealthcareToday)
  2. AI is moving into daily healthcare operations. (FastCompany)
  3. AI training for rural healthcare workers. (FierceHealthcare)
  4. AI is moving into healthcare. (McKinsey)
  5. Building healthcare infrastructure with AI. (Forbes)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Daily Compliance News

Daily Compliance News: May 1, 2026, The May Day Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Insiders winning on polymarkets? (FT)
  • KNDS investigates bribery allegations ahead of IPO. (FT)
  • OpenAI is sued over the Canada massacre. (WSJ)
  • DOJ wins access to KKR and its lawyers’ emails. (Bloomberg)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Isaac Newton and the Hidden Forces Behind Misconduct

Today, we conclude our exploration of Enlightenment Thinkers to see their influence on modern compliance programs. This week’s category is broader than philosophers, as many of these men excelled in numerous fields, including science, mathematics, calculus, and medicine. However, each contributed a key component that relates directly to our modern compliance regimes. In this concluding post, we consider Isaac Newton’s theorem that misconduct is rarely random.

If Francis Bacon taught us that a compliance program must be grounded in evidence, René Descartes taught us that evidence must be examined with rigor, John Locke taught us that the system must be legitimate, and Thomas Hobbes taught us that institutions need order, Isaac Newton brings this series to its final and perhaps most powerful insight: misconduct is rarely random. Forces drive it. Pressures. Incentives. Structural weaknesses. Repeated patterns. Hidden relationships. The most mature compliance programs understand that reality and act on it.

Newton is remembered as the great scientist of motion, force, and causation. He gave the world a way to understand that observable events are often the result of underlying principles that can be identified, studied, and predicted. His work was not simply about describing what happened. It was about explaining why it happened and how the same forces might operate again. For the compliance professional, that is a profoundly useful way to think. A hotline complaint, a bribery incident, a books-and-records failure, a retaliation claim, or a control breakdown should never be seen as a one-off event. The real question is Newtonian: what forces produced this result? In a best practices compliance program, that question is the bridge from reaction to prevention.

Why Newton Matters to Compliance

Newton helps compliance professionals move beyond event-based thinking. Too often, organizations respond to misconduct by focusing only on the visible incident. Someone violated policy. Someone approved a bad payment. Someone ignored a red flag. Someone retaliated against a whistleblower. Those facts matter, of course, but they are usually only the surface expression of deeper conditions. Newton would urge us to ask what was acting beneath the surface.

Was the employee under intense sales pressure? Were performance incentives designed in a way that rewarded output but ignored process? Was a business unit growing so quickly that controls were bypassed in the name of speed? Did management tolerate workarounds because the local market was too important to slow down? Was the company relying on outdated monitoring tools in a rapidly changing business model? Were risk signals present but scattered across functions with no one connecting them?

That is Newton’s great gift to compliance. He reminds us that forces shape behavior, and if you want to reduce misconduct, you must understand and address the forces that make misconduct more likely.

The DOJ Expects Companies to Understand Causes, Not Just Outcomes

The Department of Justice’s Evaluation of Corporate Compliance Programs (ECCP) reflects this Newtonian logic with remarkable consistency. The ECCP asks whether a company performs root cause analysis, adapts its program based on lessons learned, uses data to identify patterns, aligns incentives with ethical conduct, and can demonstrate that controls are responsive to emerging risks. These are not narrow enforcement questions. There are questions about causation.

The ECCP is not satisfied when a company says it found the bad actor and imposed discipline. Regulators want to know what the company learned. Why did the misconduct happen? Were there prior warning signs? Was the conduct enabled by poor oversight, flawed incentives, weak middle management, insufficient resources, or ineffective controls? Did the company identify those drivers and change the system? That is exactly the sort of inquiry Newton would have appreciated.

Root Cause Analysis Is Newton in Practice

If there is one place where Newton’s influence should be front and center, it is root cause analysis. In compliance, root cause analysis is the discipline of looking beyond the immediate violation to identify the pressures, structures, incentives, and system weaknesses that created the conditions for failure. This is where many companies still fall short.

A company uncovers improper payments and concludes that an employee acted dishonestly. Perhaps that is true. But Newton would ask what else was in motion. Was there a compensation model that encouraged aggressive behavior without corresponding control discipline? Were finance and compliance understaffed relative to expansion? Did business leadership send signals that revenue mattered more than process? Had similar concerns surfaced in audit findings or prior investigations? Was a third-party oversight process designed for a smaller and less risky operating model? A true root cause analysis keeps asking until the organization understands the forces at work.

Incentives Are Among the Strongest Forces in Any Organization

Newton’s framework is especially valuable when thinking about incentives. Every organization generates motion through what it rewards, measures, and celebrates. If those incentives are poorly designed, they can push employees and managers toward decisions that undermine the compliance program even when the formal policy language is sound. This is one of the most underappreciated truths in compliance.

A company may say all the right things about integrity, but if promotions, bonuses, and recognition go disproportionately to people who hit aggressive numbers regardless of how they achieved them, employees receive a different message. If managers are evaluated on speed and volume but not on control discipline, they will often treat process as friction. If local market leaders are given extraordinary flexibility without matching oversight, the organization may create precisely the pressures and blind spots that breed misconduct.

The ECCP has increasingly focused on compensation structures, clawbacks, and incentive alignment for precisely this reason. Regulators understand that culture is shaped not only by leadership’s words, but also by tangible rewards that guide daily conduct. Newton helps compliance professionals explain why this matters. Incentives are not background conditions. They are active forces inside the corporate system.

Analytics Help the Company See What the Eye Misses

A Newtonian compliance program also leverages analytics more effectively. Newton’s work showed that patterns in motion could be identified through disciplined observation and analysis. Modern compliance can do something similar. Data analytics, trend reviews, and integrated monitoring allow a company to detect patterns that an isolated human review might miss. That does not mean technology replaces judgment. It means technology can help reveal the forces and relationships that judgment must then interpret.

Consider a multinational company reviewing third-party spend, travel, and entertainment data, hotline trends, and investigation outcomes. Each data set alone may show only limited information. But when viewed together, patterns may emerge. A particular region may show above-average use of high-risk intermediaries, greater discounting, delayed documentation, and increased employee complaints about management pressure. No single data point proves misconduct. But together they may reveal a system under strain.

This is where Newton connects back to Bacon. Bacon tells us to gather evidence. Newton tells us to study how patterns and causes operate across the system. Together, they produce a compliance function that is empirical, analytical, and forward-looking.

Misconduct Is Often a Systems Failure, Not Merely an Individual Failure

One of the most valuable lessons Newton offers the compliance profession is that misconduct is frequently systemic. This does not excuse individual wrongdoing. Personal accountability remains essential. But if a company stops with personal accountability, it may miss the broader organizational truth.

An employee may make an improper payment, but the surrounding system may have made that outcome easier, more predictable, or more likely. A senior manager may retaliate against a reporter, but the broader culture may have conditioned leaders to treat bad news as disloyalty. A financial control breakdown may involve one approving official, but the deeper problem may be a long-standing tolerance for informal overrides. In each case, the misconduct event should prompt a systems review.

This is particularly important in fast-changing environments. Growth, acquisitions, digital transformation, remote work, AI deployment, and market stress all alter the forces acting on the organization. Controls designed for one operating model may not be sufficient for the next. A Newtonian compliance officer understands that governance must evolve as the system changes. The question is never just whether the policy still exists. The question is whether the underlying forces have shifted in ways the compliance program has not yet caught up to.

Newton and the Future of Compliance

Newton is particularly relevant today because the modern compliance landscape is increasingly defined by complexity. Third-party ecosystems are larger. Data flows are faster. Business models shift more quickly. AI and automated decision-making create new risks that can change over time through drift, scale, and changing use cases. In that world, static compliance is not enough. A company needs to understand how moving systems work.

This is where frameworks like NIST and ISO/IEC 42001 become useful companions to Newtonian thinking. They emphasize lifecycle governance, ongoing monitoring, documented accountability, testing, and adaptation. In the AI context, especially, the lesson is clear: a control that works on day one may not be enough on day two. Risks evolve—inputs change. Vendors change. User behavior changes. Governance must therefore be dynamic, evidence-based, and attentive to emerging forces.

The same is true across compliance more broadly. Companies cannot assume that yesterday’s control environment will manage tomorrow’s pressures. Newton teaches that motion continues unless acted upon, and in the corporate setting, that means risk patterns will continue to develop unless governance actively intervenes.

The Compliance Officer as Interpreter of Organizational Forces

If Bacon casts the compliance officer as an institutional scientist, Descartes as a guardian of clear thinking, Locke as a steward of legitimacy, and Hobbes as an architect of order, Newton casts the compliance officer as an interpreter of organizational forces. That is a sophisticated and necessary role.

The compliance officer must ask what is really driving conduct across the enterprise. Which incentives are shaping decisions? Which processes are creating blind spots? Which managers are transmitting pressure? Which data trends suggest a deeper problem? Which repeated “isolated incidents” are no longer isolated at all? Which changes in the business model have altered the risk environment without corresponding updates to governance?

Those are not merely compliance questions. They are strategic governance questions. That is why Newton is such a fitting conclusion to this series. He pulls together all that came before. Evidence matters. Rigor matters. Legitimacy matters. Order matters. But ultimately, the mature compliance program does something more. It understands how these elements interact inside a living system. It seems that misconduct does not fall from the sky. It emerges from forces that can be studied, anticipated, and changed. Isaac Newton would have understood that a well-governed institution learns to read its own motion.

Five Lessons Learned for the Modern Compliance Professional

First, misconduct is rarely random. It is usually the product of identifiable pressures, incentives, weaknesses, and structural conditions.

Second, root cause analysis must go beyond the visible event. The goal is to understand the forces that made the event more likely.

Third, incentives are among the strongest drivers of conduct. A company must align compensation, promotion, and recognition systems with ethical and compliant behavior.

Fourth, analytics and trend analysis are essential tools for seeing patterns across the system. They help the company detect pressure points before they become crises.

Fifth, the most mature compliance programs are systemic and preventive. They do not simply respond to incidents. They study the organization well enough to reduce the conditions that produce misconduct.

Closing It Out

This five-part journey through Bacon, Descartes, Locke, Hobbes, and Newton shows that the architecture of a modern compliance program is not merely legal or procedural. It is intellectual. Bacon teaches us to demand evidence. Descartes teaches us to examine it with discipline. Locke teaches us that the system must be legitimate. Hobbes teaches us that institutions require order. Newton teaches us to understand the forces that shape outcomes.

Together, they offer a powerful framework for the compliance professional, the board, internal audit, legal, and business leadership. A best practices compliance program is not simply a collection of policies. It is a way to see the organization clearly, govern it credibly, and continuously improve it. That is as true now as it would have been revolutionary in their own time.