Categories
Innovation in Compliance

Innovation in Compliance: AI Compliance at the Speed of Content with Kunal Vankadara

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits Kunal Vankadara, CEO & Co-founder of Haast, to discuss how AI can help regulated organizations scale compliance as content volume explodes and regulatory scrutiny increases.

Vankadara believes AI-powered compliance automation is especially valuable in content review because many decisions are subjective and context-driven, such as judging whether a disclaimer is sufficiently prominent. In his view, LLMs can be trained on a company’s risk tolerance to apply those standards consistently at scale, reducing false positives and sending only gray-area issues to human experts. As AI-driven content creation and regulatory scrutiny continue to grow, he sees this approach as a way to make compliance faster, more reliable, and less of a bottleneck.

Key highlights:

  • AI-driven content surge overburdens compliance teams
  • Training Agents to Match Company Risk Tolerance
  • Teaching AI Risk Tolerance Beyond False Positives
  • Compliance agents as digital twins for content
  • Sanctions and Regulatory Changes into Actionable Intelligence

Resources:

Connect with Kunal Vankadara on LinkedIn

Haast

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts.

Categories
AI Today in 5

AI Today in 5: July 14, 2026, The Bank Run in Seconds Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Star Compliance reshapes ELT. (FinTechGlobal)
  2. Agentic compliance issues: AI v. Humans. (Security BLVD)
  3. Meta drops AI photoshopping feature. (TechCrunch)
  4. AI could create new divides in financial services. (ETFStream)
  5. Could AI trigger a bank run in seconds? (Banking Dive)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Everything Compliance - Shout Outs and Rants

Everything Compliance: Shout Outs and Rants – Supreme Court Power, Curiosity in Compliance, and Metrics on the Pitch

Welcome to a revamped Everything Compliance Shout Out & Rants. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, who joins returning regulars Matt Kelly, Jonathan Armstrong, and Karen Moore for the next iteration of Everything Compliance Shout Outs and Rants.

  • Adam Turteltaub rants about flopping in the World Cup.
  • Matt Kelly rants about the Supreme Court’s Slaughter decision for allowing the president to fire independent agency commissioners, warning it will end bipartisan stability, drive away minority-party commissioners, and create volatile, hyper-partisan regulation.
  • Rebecca Walker shouts out about curiosity, citing Harvard graduate Noah Eckstein’s speech “The Punchline” and the advice to “listen like you might be wrong,” applying it to investigations, risk assessment, and compliance decision-making; a book and TED Talk on being wrong are recommended.
  • Jonathan Armstrong highlights Slaughter’s implications for EU/UK/Swiss-US data transfers and gives a football transfer shout-out.
  • Karen Moore shouts out to America ahead of its 250th birthday and to her child’s partner, Ren Nguyen, for training to become a certified air traffic controller.

Everything Compliance Shout Outs and Rants is a production of the Compliance Podcast Network.

Categories
Blog

The Odyssey and Compliance, Part 2 – The Lotus-Eaters: Culture Drift and the Comfort of Forgetting

We continue our series of compliance lessons from The Odyssey. Today, we consider the tale of the Lotus-Eaters and the drifting of corporate culture.

Odysseus and his crew did not always face monsters with teeth. Sometimes the danger was softer. After leaving Troy, Odysseus and his men came to the land of the Lotus-Eaters. There was no battle. No ambush. No roaring beast. No angry god hurling thunderbolts. The locals simply offered the crew lotus flowers. Those who ate them lost all desire to return home. They forgot the mission. They forgot Ithaca. They forgot the purpose of the journey.

That is what makes the episode so unsettling. The Lotus-Eaters did not defeat Odysseus’s crew by force. They defeated them through comfort, distraction, and forgetfulness. Welcome to one of the most common compliance risks in modern corporate life: culture drift.

Not every compliance failure begins with greed. Not every ethical collapse starts with a suitcase of cash, a fake invoice, or someone whispering, “Let’s take this offline.” Some failures begin when people simply forget why the rules matter. They remember the annual training deadline. They remember the attestation. They remember where the Code of Conduct lives, assuming the intranet search function is having a good day. But they no longer connect compliance to the company’s mission. That is the lotus.

The Corporate Translation

Every organization has its own version of the island of the Lotus-Eaters. It may be a high-performing business unit that hits its numbers, avoids obvious scandal, and quietly stops engaging with compliance. It may be a remote office that has not seen a live compliance conversation in years. It may be a leadership team that talks about values during onboarding, but never mentions them again unless there is an investigation. It may be a group of employees who click through training modules while answering emails, eating lunch, and wondering whether the quiz has unlimited attempts.

Everyone is pleasant. Everyone is busy. Everyone is productive. Everyone is slowly detaching from the company’s stated values. This is the direct analogy: the lotus is the business unit where nothing looks obviously wrong, but no one can explain how compliance connects to the work they actually do. That is a dangerous place. Not because people are evil. Because they are comfortable.

Risk Assessment: Finding the Islands Before People Forget

A good compliance program begins with risk assessment, not vibes. Odysseus had to know where his crew was vulnerable. Were they hungry? Exhausted? Demoralized? Homesick? Easily distracted by local hospitality? The answer, unfortunately, was yes.

Companies need the same kind of self-awareness. Where are employees most likely to forget the mission? Where are they under the most pressure? Where are the policies most disconnected from daily operations? Where has training become a ritual instead of a reinforcement?

The DOJ’s Evaluation of Corporate Compliance Programs emphasizes risk-tailored compliance and asks how a company identifies, assesses, and addresses risks, including whether it updates policies, procedures, and training as those risks evolve. It also asks whether training is tailored, whether employees understand it in practice, and whether the company measures effectiveness rather than merely delivering content.

That is an important distinction. A weak risk assessment asks, “Did everyone receive the training? “A better risk assessment asks, “Who needs what training, on which risks, at what level of depth, in what language, through what format, and how do we know it changed behavior? “That is the difference between counting lotus flowers and understanding why people are eating them.

Policies: The Mission Written Down

Policies are supposed to tell employees how the company expects them to act. But too many policies are written as if they were designed to survive litigation rather than to guide human beings. They are long, dense, passive, and beloved mainly by the people who drafted them. Employees do not use them. Managers do not reinforce them. Business teams treat them like airport terms and conditions: technically available, rarely read, and accepted under pressure.

That is a policy failure by design. A policy is not effective because it exists. It is effective when employees can find it, understand it, apply it, and believe the company expects them to follow it. The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether policies and procedures are accessible, searchable, communicated to employees and relevant third parties, integrated into operations, and reinforced through internal control systems. It also asks whether gatekeepers receive guidance and training on what misconduct to look for and when to escalate concerns.

That is practical compliance. Policies should not be museum pieces. They should be field guides. The anti-corruption policy should help a sales manager understand what to do before a government customer asks for “support.” The data privacy policy should help an operations team understand when customer information can be shared. The conflicts policy should help a procurement employee understand why her cousin’s consulting firm is not just “a good local option.” The speak-up policy should help employees know where to go before silence becomes complicity. Policies should bring people back to Ithaca. They should remind the organization: this is who we are; this is how we do business; and this is the route home.

Training: More Than the Annual Click-Through

Now we come to training, the place where many compliance programs go to become lotus farms. You know the scene. An employee gets an email: “Mandatory Compliance Training Due Friday.” The employee opens the module, clicks through the slides, answers a few questions, and receives a certificate. Somewhere, a dashboard turns green. The compliance team exhales. The business moves on.

But did anyone learn anything? That is the uncomfortable question. As Ronnie Feldman continually reminds us, training is not effective because it was assigned. Training is not effective because completion rates are high. Training is not effective because the quiz average was 94 percent, especially if the questions were written so that “Do not commit fraud” was the challenging option.

Effective training helps employees recognize risk in the moment. It gives managers language to lead. It teaches employees how to pause, ask, escalate, and document. It uses realistic scenarios, not cartoon villains. It respects the audience’s time without insulting their intelligence. The ECCP specifically points to tailored training and communications, including practical advice, case studies, shorter, targeted sessions, opportunities for employees to ask questions, and measures of employee engagement and learning. It also asks whether training affects employee behavior or operations. The goal is not training completion. The goal is better decisions.

Ethical Fatigue Is Real

There is another reason the Lotus-Eaters matter. They remind us that people get tired. Employees face pressure, complexity, change, layoffs, new systems, reorganizations, market stress, and competing messages from leadership. Then compliance arrives with another policy update, another module, another certification, another “quick reminder” that is neither quick nor memorable.

Ethical fatigue sets in. When employees are exhausted, they do not necessarily become unethical. They become passive. They stop asking questions. They stop reading carefully. They assume someone else reviewed the issue. They treat compliance as background noise. This is where culture drift becomes dangerous. The organization may still have the right words, but the words no longer move anyone.

The solution is not more noise. It is better communication. Compliance teams should ask, “What does this audience need to know?” What decisions do they actually face? What mistakes are we seeing? What near misses have occurred? What questions are employees asking? What risks are emerging? What would make this guidance useful on Tuesday afternoon when the customer is angry, the deadline is real, and the manager wants an answer? That is where compliance becomes practical.

What a Better Program Does

A better program treats culture as something to be measured, tested, and renewed. It does not assume that because employees took training, they absorbed it. It does not assume that because a policy exists, employees know how to use it. It does not assume that because leadership talks about integrity, middle management reinforces it. A better program looks for signs of forgetting.

Are hotline reports dropping because misconduct is down, or because trust is down? Are policy questions coming from all regions or only headquarters? Are employees passing training but failing audits? Are managers escalating issues or solving them quietly? Are high-risk teams receiving generic training when they need tailored guidance? Are employees afraid to ask “basic” questions because they think they should already know the answer? The compliance function should use surveys, training analytics, audit results, hotline data, investigation trends, control testing, manager feedback, and employee questions to understand whether the message is landing. And when the message isn’t landing, the answer isn’t to blame the crew. Odysseus did not leave his men among the Lotus-Eaters and say, “Well, they should have remembered Ithaca.” He dragged them back to the ships. That is leadership.

The Compliance Takeaway

The land of the Lotus-Eaters is not a place of obvious corruption. That is why it is so dangerous. It is the place where mission fades into routine, where values become posters, where policies become files. Where training becomes a click, where employees are not hostile to compliance but simply detached from it.

For compliance officers and business leaders, the lesson is clear: culture must be refreshed before it drifts. Policies must be usable before they are needed. Training must be memorable before the crisis. Risk assessment must identify not only where misconduct could occur but also where people are most likely to forget why compliance matters.

Odysseus’s crew did not need a lecture. They needed to be reminded of the journey. So do organizations. The question is not whether your people have eaten the lotus. The question is whether your compliance program would know.

Join us tomorrow in Part 3, where we consider Circe’s Island: Third-Party Influence and Culture Capture.

Categories
FCPA Compliance Report

FCPA Compliance Report: Episode 815 – AI in Compliance and Eastward AI’s Continuous Risk “Reality Check”

Welcome to the award-winning FCPA Compliance Report, the longest-running podcast in compliance. In this episode, Tom welcomes back Gerry Zack, and they discuss the growing use of AI in compliance and the launch of Eastward AI.

Zack says many organizations are uncertain and paralyzed, while others range from using ChatGPT at a basic level to building or buying specialized tools rather than seeking a “big machine.” AI is now embedded across compliance functions, from hotline chatbots and policy/control mapping to monitoring, investigations (which Zack cautions against over-automating), and behavioral analytics. Eastward AI began as a CSRD double-materiality assessment tool but expanded to encompass broader enterprise and compliance risk management, aligned with frameworks including COSO ERM, DOJ expectations, ISO 37301, and ISO 31000. Zack describes development with a skilled programming team, beta “design partners,” and a “Reality Check” feature that rapidly scans global information to update risk assessments and support scenario modeling continuously. This combination has drawn interest from CCOs, CROs, GCs, and strategy leaders. Eastward.ai is now publicly available.

Key highlights:

  • AI in Compliance Today
  • Eastward AI Origin Story
  • MVP and Design Partners
  • Reality Check Feature
  • Scenario Modeling and Strategy
  • Expanding Compliance Remit

Resources:

Gerry Zack on LinkedIn

RiskTrek

Eastward AI

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

The FCPA Compliance Report was recently named the world’s Best Business Ethics Podcast by FeedSpot.

Categories
Daily Compliance News

Daily Compliance News: July 13, 2026, The Profoundly Corrupt Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • EU critic says FIFA is “profoundly corrupt.”  (Politico)
  • Indonesia ABC prosecutor found with $20MM in cash. (AlJazeera)
  • Atlassian illegally fired a worker who questioned policy changes. (NYT)
  • Apple sues OpenAI for information theft. (FT)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI Today in 5

AI Today in 5: July 13, 2026, The AI as Sludge Buster Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Blueprint for successful AI AML implementation. (FinTechGlobal)
  2. Ex-Mayo Director Alleges Retaliation After AI Dispute (Minnesota Lawyer)
  3. AI changing the build vs. buy Q. (BankingDive)
  4. AI can be a financial sludge buster. (FT)
  5. Apple alleges OpenAI stole confidential information. (Bloomberg)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 43 – In the Shadow of Doubt: Lessons from “Wolf in the Fold”

Every compliance professional, sooner or later, must confront the uncomfortable truth that sometimes the system gets it wrong. Whether due to circumstantial evidence, unconscious bias, or institutional inertia, there are moments when the innocent stand accused and the integrity of the investigative process itself is on trial. Star Trek: The Original Series’ “Wolf in the Fold” is a cautionary tale about just such a scenario, offering invaluable insights for anyone who cares about justice, fairness, and the reputation of their organization. Today, we explore the investigative and fairness lessons compliance professionals can glean from this classic Star Trek whodunit.

Lesson 1: Presume Innocence—Don’t Rush to Judgment

Illustrated by: After the first murder, all evidence seems to point to Scotty. He’s found with the victim, holding a knife, but claims to have no memory of the incident. The local authorities and some Enterprise personnel are quick to suspect him due to the seemingly damning circumstances.

Compliance Lesson: A foundational principle of any fair investigative process is the presumption of innocence. It’s easy to rush to judgment when circumstantial evidence piles up, especially under pressure from leadership or regulators. But professionalism and institutional integrity require that we suspend bias and keep our minds open until the facts are thoroughly explored.

Bake the presumption of innocence into your investigative policies and training. Remind every team member and stakeholder that even the most “obvious” cases demand impartial investigation. Document early assumptions and check for bias throughout the inquiry.

Lesson 2: Avoid Tunnel Vision—Expand the Investigative Lens

Illustrated by: As more murders occur and Scotty continues to be in the wrong place at the wrong time, suspicion remains fixed on him. However, Spock and Kirk resist the urge to focus solely on their friend. They consider alternate explanations, explore technical anomalies, and even question the possibility of non-human involvement.

Compliance Lesson: Tunnel vision is a persistent risk in any investigation, especially when a plausible suspect fits the facts. True institutional fairness demands that compliance professionals look beyond the immediate and obvious, systematically considering alternative scenarios and other suspects.

Develop “red team” protocols or assign a “devil’s advocate” role in major investigations to challenge prevailing theories deliberately. Require documentation of all hypotheses considered, and make alternate-scenario analysis part of your standard investigative checklist.

Lesson 3: Leverage Expertise and Technology—But Don’t Abdicate Human Judgment

Illustrated by: Kirk and Spock seek help from Sybo, the Argelian empath, and use the Enterprise computer to analyze the evidence, eventually exposing the supernatural entity Redjac as the true culprit. However, they do not blindly trust the results. Kirk and Spock synthesize the technological findings with their reasoning, refusing to let the investigation be dictated by technology alone.

Compliance Lesson: While data analytics, forensics, and investigative technology are powerful tools, they are not infallible. Technology should augment, not replace, the judgment of experienced investigators. Relying solely on computer output or external expertise without human analysis can lead to catastrophic mistakes, especially in nuanced, high-stakes cases.

Balance the use of forensic technology with critical thinking and seasoned judgment. Always validate technological findings using multiple sources and require human review before concluding. Foster a culture where “computer says so” is never an excuse for poor process.

Lesson 4: Champion Institutional Justice—Even When It’s Uncomfortable

Illustrated by: The Argelian prefect, Jaris, is pressured to resolve the case swiftly due to local customs and a desire to preserve order. Kirk, however, insists that the process be fair and thorough, even at the risk of offending local sensibilities or extending the investigation. He appeals to both Argelian law and Federation principles, ensuring that institutional justice, not expediency, prevails.

Compliance Lesson: Institutional justice means doing what’s right, not just what’s easy or convenient. The pressure to resolve allegations quickly to satisfy regulators, shareholders, or media can be immense. But caving to expediency undermines fairness, risks wrongful discipline, and erodes long-term trust in the compliance function.

Institute explicit policies prioritizing fairness over speed in investigations. Communicate to leadership that thoroughness is a core compliance value. Protect investigators from undue pressure to deliver quick “results” at the expense of real justice.

Lesson 5: Transparent Communication Restores Trust

Illustrated by: When Redjac is finally exposed, and Scotty’s innocence is proven, Kirk doesn’t just close the case and move on. He explains the whole sequence of events to both the Argelian authorities and his crew, restoring Scotty’s reputation and demonstrating that the investigative process, however difficult, was ultimately fair and transparent.

Compliance Lesson: When someone is wrongfully accused, it isn’t enough to quietly correct the record. Institutional fairness requires public restoration and clear communication about what happened, how the mistake was identified, and what steps will be taken to prevent recurrence. Transparency is about accountability, but it’s also about healing wounds and rebuilding organizational trust.

Develop protocols for communicating exonerations and corrective actions to all relevant stakeholders. Where privacy allows, share lessons learned broadly, emphasizing the organization’s commitment to justice and fairness. Make it clear that the compliance function values both truth and reputation.

Final ComplianceLog Reflections

“Wolf in the Fold” reminds us that even the most rigorous institutions are vulnerable to error, especially under stress, bias, or pressure. For compliance professionals, the episode is a touchstone for the values that must guide every investigation: presumption of innocence, investigative rigor, openness to alternative theories, balanced use of technology, commitment to institutional justice, and, above all, transparent communication.

Wrongful accusations are more than a risk; they are a litmus test for the soul of an organization’s compliance program. The real victory isn’t just exonerating the innocent but demonstrating to every employee, stakeholder, and regulator that fairness and justice are not negotiable.

So, the next time you face a difficult case or feel the pressure to resolve an issue quickly, remember the lesson of Scotty and the Argelians. Take the time, expand your lens, leverage every resource, and communicate your findings with integrity. In doing so, you’ll ensure that your compliance program isn’t just a set of rules but a living embodiment of the principles of justice and fairness.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Timothy and Fiona are AI-generated voices.

Categories
Blog

In the Shadow of Doubt: Institutional Fairness and Institutional Justice Lessons from Star Trek’s “Wolf in the Fold”

Every compliance professional, sooner or later, must confront the uncomfortable truth that sometimes the system gets it wrong. Whether due to circumstantial evidence, unconscious bias, or institutional inertia, there are moments when the innocent stand accused and the integrity of the investigative process itself is on trial. Star Trek: The Original Series’ “Wolf in the Fold” is a cautionary tale about just such a scenario, offering invaluable insights for anyone who cares about justice, fairness, and the reputation of their organization.

The episode places Chief Engineer Montgomery Scott (“Scotty”) in the center of a series of brutal murders on Argelius II. Despite the mounting evidence against him, the real story is about how Captain Kirk, Mr. Spock, Dr. McCoy, and the Argelian authorities pursue the truth—and how easily institutional justice can go astray.

Let’s explore the investigative and fairness lessons compliance professionals can glean from this classic Star Trek whodunit.

Lesson 1: Presume Innocence—Don’t Rush to Judgment

Illustrated by: After the first murder, all evidence seems to point to Scotty. He’s found with the victim, holding a knife, but claims to have no memory of the incident. The local authorities and some Enterprise personnel are quick to suspect him due to the seemingly damning circumstances.

Compliance Lesson: A foundational principle of any fair investigative process is the presumption of innocence. It’s easy to rush to judgment when circumstantial evidence piles up, especially under pressure from leadership or regulators. But professionalism and institutional integrity require that we suspend bias and keep our minds open until the facts are thoroughly explored.

Bake the presumption of innocence into your investigative policies and training. Remind every team member and stakeholder that even the most “obvious” cases demand impartial investigation. Document early assumptions and check for bias throughout the inquiry.

Lesson 2: Avoid Tunnel Vision—Expand the Investigative Lens

Illustrated by: As more murders occur and Scotty continues to be in the wrong place at the wrong time, suspicion remains fixed on him. However, Spock and Kirk resist the urge to focus solely on their friend. They consider alternate explanations, explore technical anomalies, and even question the possibility of non-human involvement.

Compliance Lesson: Tunnel vision is a persistent risk in any investigation, especially when a plausible suspect fits the facts. True institutional fairness demands that compliance professionals look beyond the immediate and obvious, systematically considering alternative scenarios and other suspects.

Develop “red team” protocols or assign a “devil’s advocate” role in major investigations to challenge prevailing theories deliberately. Require documentation of all hypotheses considered, and make alternate-scenario analysis part of your standard investigative checklist.

Lesson 3: Leverage Expertise and Technology—But Don’t Abdicate Human Judgment

Illustrated by: Kirk and Spock seek help from Sybo, the Argelian empath, and use the Enterprise computer to analyze the evidence, eventually exposing the supernatural entity Redjac as the true culprit. However, they do not blindly trust the results. Kirk and Spock synthesize the technological findings with their reasoning, refusing to let the investigation be dictated by technology alone.

Compliance Lesson: While data analytics, forensics, and investigative technology are powerful tools, they are not infallible. Technology should augment, not replace, the judgment of experienced investigators. Relying solely on computer output or external expertise without human analysis can lead to catastrophic mistakes, especially in nuanced, high-stakes cases.

Balance the use of forensic technology with critical thinking and seasoned judgment. Always validate technological findings using multiple sources and require human review before concluding. Foster a culture where “computer says so” is never an excuse for poor process.

Lesson 4: Champion Institutional Justice—Even When It’s Uncomfortable

Illustrated by: The Argelian prefect, Jaris, is pressured to resolve the case swiftly due to local customs and a desire to preserve order. Kirk, however, insists that the process be fair and thorough, even at the risk of offending local sensibilities or extending the investigation. He appeals to both Argelian law and Federation principles, ensuring that institutional justice, not expediency, prevails.

Compliance Lesson: Institutional justice means doing what’s right, not just what’s easy or convenient. The pressure to resolve allegations quickly to satisfy regulators, shareholders, or media can be immense. But caving to expediency undermines fairness, risks wrongful discipline, and erodes long-term trust in the compliance function.

Institute explicit policies prioritizing fairness over speed in investigations. Communicate to leadership that thoroughness is a core compliance value. Protect investigators from undue pressure to deliver quick “results” at the expense of real justice.

Lesson 5: Transparent Communication Restores Trust

Illustrated by: When Redjac is finally exposed, and Scotty’s innocence is proven, Kirk doesn’t just close the case and move on. He explains the whole sequence of events to both the Argelian authorities and his crew, restoring Scotty’s reputation and demonstrating that the investigative process, however difficult, was ultimately fair and transparent.

Compliance Lesson: When someone is wrongfully accused, it isn’t enough to quietly correct the record. Institutional fairness requires public restoration and clear communication about what happened, how the mistake was identified, and what steps will be taken to prevent recurrence. Transparency is about accountability, but it’s also about healing wounds and rebuilding organizational trust.

Develop protocols for communicating exonerations and corrective actions to all relevant stakeholders. Where privacy allows, share lessons learned broadly, emphasizing the organization’s commitment to justice and fairness. Make it clear that the compliance function values both truth and reputation.

Final ComplianceLog Reflections

“Wolf in the Fold” reminds us that even the most rigorous institutions are vulnerable to error, especially under stress, bias, or pressure. For compliance professionals, the episode is a touchstone for the values that must guide every investigation: presumption of innocence, investigative rigor, openness to alternative theories, balanced use of technology, commitment to institutional justice, and, above all, transparent communication.

Wrongful accusations are more than a risk; they are a litmus test for the soul of an organization’s compliance program. The real victory isn’t just exonerating the innocent but demonstrating to every employee, stakeholder, and regulator that fairness and justice are not negotiable.

So, the next time you face a difficult case or feel the pressure to resolve an issue quickly, remember the lesson of Scotty and the Argelians. Take the time, expand your lens, leverage every resource, and communicate your findings with integrity. In doing so, you’ll ensure that your compliance program isn’t just a set of rules but a living embodiment of the principles of justice and fairness.

Resources:

Excruciatingly Detailed Plot Summary by Eric W. Weisstein

MissionLogPodcast.com

Memory Alpha

Categories
Blog

The Odyssey and Compliance, Part 1 – The Trojan Horse: When Cleverness Becomes a Control Failure

There are few works in Western Literature more read than The Odyssey. While a cadre of passionate specialists prefer The Iliad, it is The Odyssey that is most generally taught in US high schools. Part travelogue, part adventure yarn, part social commentary, and part treatise on Greek morals and morality, it is still a rousing tale well worth the time to read. Now, Christopher Nolan is out with another movie version of The Odyssey. I have not yet seen the movie as of this writing.

I wanted to tackle The Odyssey from the compliance perspective. There are many things we can mine from this story. Over the course of this week, I will discuss five of them. Today, we consider where the story begins: the Trojan Horse as a failure of control. On Tuesday, we look at The Lotus-Eaters: Culture Drift and the Comfort of Forgetting. On Wednesday, Circe’s Island: Third-Party Influence and Culture Capture. On Thursday, we look at The Cattle of Helios: Non-Negotiables and Control Breaches. On Friday, we conclude with Odysseus making his way home to Ithaca and to his wife, Penelope, and their son, Telemachus, in the tale of Peace in Ithaca: Building the Program After the Crisis.

Today, we begin with The Odyssey, which directly follows the end of The Iliad. Here are a few business strategies more celebrated than the Trojan Horse. After ten long years of war, he looked at the walls of Troy and realized brute force had failed. The Greeks could not smash their way in. They could not negotiate their way in. They could not outlast their way in. So Odysseus did what clever leaders often do when conventional methods fail: he found a workaround. Build a great wooden horse. Hide soldiers inside it. Leave it outside the gates as a supposed gift. Sail away, or at least appear to. Let the Trojans make the fatal decision themselves.

While it was brilliant from a strategic perspective, it was an absolute nightmare from a compliance perspective. The Trojan Horse is usually remembered as a triumph of strategy. It should also be remembered as the original “trusted vendor attachment.” It arrived looking valuable, symbolic, and harmless. It came wrapped in a compelling story. It appealed to ego, fatigue, and optimism. And someone, somewhere inside Troy, approved bringing it through the gates.

The Gift That Bypassed Governance

Every organization has gates. Some are literal: firewalls, access controls, locked doors, badge readers, and vendor onboarding systems. Others are procedural: approval matrices, procurement rules, due diligence reviews, cybersecurity assessments, conflict checks, and escalation protocols. The problem is that business opportunities rarely arrive wearing a sign that says, “Hello, I am a control failure.”

They arrive as partnerships. Strategic investments. Technology platforms. Emergency exceptions. Pilot programs. Customer demands. Board-level priorities. Innovation initiatives. “Just this once” requests. Special access for a trusted consultant. A new AI tool that someone found useful. A supplier who can solve the problem quickly. A deal too good to slow down.

In other words, they arrive as gifts. The Trojans did not lose because they lacked walls. They lost because they made a poor risk decision at the gate. The control existed. The wall worked. The problem was judgment, governance, and process. A control environment is not only about having policies. It is about whether people use them when the pressure is on and the opportunity looks attractive.

When Cleverness Becomes the Risk

Odysseus was not a fool. He was a strategist. That is what makes this story so useful for compliance professionals and business leaders. Many compliance failures are not born from stupidity. They are born from intelligence used without discipline. A clever workaround can be useful. A clever workaround can also serve as a bypass of governance. The distinction matters.

Think about the employee who finds a faster way to onboard a vendor by skipping required due diligence. The sales executive who routes a discount through an unusual approval path to close the quarter. The business unit that adopts an unsanctioned software tool because IT is “too slow.” The senior leader who asks for an exception because “this is strategically important.” The team that shares sensitive information with a partner before the agreement is fully papered because “we trust them.”

Each decision may have a business rationale. Each may feel practical. Each may even produce a short-term win. But the compliance question is not simply, “Did it work? “The better question is, “What did it bypass? ”

That is the Trojan Horse problem. The horse worked because it bypassed the normal defenses. In a modern company, that may mean bypassing cyber review, procurement checks, legal review, data protection analysis, sanctions screening, financial controls, conflict review, or code of conduct expectations. When leadership celebrates only the result, the organization learns the wrong lesson. It learns that controls are for ordinary days, not important ones. That is how culture begins to drift.

The Cybersecurity Lesson Inside the Horse

The Trojan Horse is one of the oldest stories in Western literature, but it feels remarkably current in an age of cyber risk and social engineering. A malicious file. A fake vendor invoice. A compromised supplier account. A phishing email that appears to come from a trusted executive. A third-party platform with excessive access. A contractor credential that is never disabled. A software update from a source no one properly vetted. These are modern Trojan Horses.

They do not always break the wall. They persuade someone to open the gate. This is why cybersecurity is not merely an IT function. It is a governance issue. NIST’s Cybersecurity Framework 2.0 places significant emphasis on the Governance function, which addresses how an organization establishes, communicates, and monitors its cybersecurity risk management strategy, expectations, and policies.

That is compliance language as much as cyber language. Who owns the risk? Who approves exceptions? Who monitors access? Who understands the business context? Who has the authority to say no? Who makes sure the organization learns from near misses? If no one can answer those questions clearly, the horse is already inside the gate.

Attractive Risks Test the Control Environment

It is easy to say no to obviously bad ideas. The real test comes when the risk is attached to something the business wants. A lucrative customer. A prestigious partner. A promising technology. A powerful executive sponsor. A deadline. A crisis. A competitor is moving faster. A board presentation next week. That is when the control environment reveals itself.

In a strong control environment, the organization can move quickly without becoming careless. It can evaluate risk without killing innovation. It can escalate concerns without making people feel disloyal. It can approve exceptions, but only with transparency, documentation, and accountability.

In a weak control environment, speed becomes the excuse for opacity. Trust becomes the substitute for diligence. Seniority becomes the overriding control. Documentation comes later, which usually means never. Compliance is invited after the decision has already been made. That is not innovation. That is improvisation with a budget.

The code of conduct should matter most when the business case is compelling. Internal controls should matter most when the pressure is real. Cybersecurity should matter most when the new tool looks exciting. Risk assessment should matter most when everyone is tired of waiting. Troy did not need a better wall. Troy needed a better approval process.

The Insider Threat Dimension

There is another uncomfortable lesson in the Trojan Horse. The Greeks got inside Troy because the Trojans cooperated with the plan. Not intentionally, perhaps. Not corruptly, necessarily. But they cooperated all the same. That is the nature of many insider threats.

The insider is not always a villain. Sometimes the insider is rushed, flattered, distracted, pressured, or insufficiently trained. Sometimes the insider believes they are helping. Sometimes they trust the wrong person. Sometimes they assume someone else has checked. That is why compliance programs cannot rely solely on good intentions.

Good people need good systems. They need clear policies, practical training, escalation paths, and a culture that rewards thoughtful skepticism. They need permission to ask, “Why are we bringing this inside the walls? ”

This is especially important in organizations where questioning a business opportunity is viewed negatively. Compliance should not be the Department of No, but neither should the business become the Department of Please Do Not Ask Too Many Questions. Healthy skepticism is not cynicism. It is stewardship.

What a Better Program Does

A better compliance program does not ban wooden horses. It asks better questions before opening the gate. Who sent it? Why now? What access does it require? What data will it touch? What assumptions are we making? Has the vendor been reviewed? Has the technology been tested? Is there a conflict? Is there a regulatory issue? What is the worst-case scenario? Who approved the exception? How will we monitor it after approval?

The point is not to slow down every decision. The point is to prevent charm, urgency, and executive enthusiasm from replacing governance. A strong program also makes risk ownership visible. If the business wants to accept a risk, that decision should be documented. If a control is bypassed, there should be a reason, an approver, a time limit, and compensating controls. If a new tool, vendor, or relationship is brought inside the organization, someone should be accountable for monitoring it. The Trojan Horse teaches that the most dangerous risks are not always those from outside. Sometimes they are the ones we invite in because they look like success.

The Compliance Takeaway

Odysseus won because he understood human nature. He knew the Trojans would see what they wanted to see: victory, tribute, closure, and a symbol of their own endurance. That is the uncomfortable lesson for corporate compliance. Risk often enters through desire. The desire to win. To move fast. To close the deal. To trust the familiar. To avoid friction. To believe the story makes the opportunity easier to approve.

Not every gift is a threat. Not every workaround is misconduct. Not every clever idea is a control failure. But every organization needs the discipline to ask whether cleverness is serving governance or bypassing it. The horse may be beautiful. The story may be compelling. The business sponsor may be persuasive. Open the gate only after the controls have done their work.

Join us tomorrow, where we consider The Lotus-Eaters: Culture Drift and the Comfort of Forgetting.