Categories
Innovation in Compliance

Innovation in Compliance: Pamela Gupta on Closing the AI Governance Implementation Gap

Innovation comes in many areas and compliance professionals need to not only be ready for it but embrace it. Join Tom Fox, the Voice of Compliance as he visits with top innovative minds, thinkers and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom welcomes Pamela gupta, the author of De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook.

Pamela Gupta, is the founder of Trusted AI and author. She and tom discuss the closing the AI governance implementation gap between high-level frameworks (e.g., NIST AI RMF, ISO 42001) and use-case execution under rapid AI rollout pressure. Gupta argues organizations struggle to translate principles into actionable, risk-based decisions involving many stakeholders (security, privacy, legal, audit, business, IT, data science), leading either to unmanaged risk or stalled innovation. She emphasizes AI-specific risks such as bias, transparency, explainability, and accountability, illustrating with Humana’s nH Predict claims system (alleged bias; 90% reversals) plus Amazon’s scrapped hiring model and Air Canada’s chatbot ruling. Gupta outlines her AI TIPS framework (eight pillars, ~80 controls) and contends AI governance can accelerate adoption by defining intake, evidence, and decision processes, even as agentic AI raises risk and uncertainty.

Key Highlights

  • AI Governance Gap
  • Assessing AI Risk
  • Bias and Ethics Ownership
  • Humana Case Study
  • AI TIPS Framework
  • Governance as Accelerator

Resources

Pamela Gupta on LinkedIn

De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook

Website: TrustedAI.AI

Podcast: Trustworthy AI: De-Risk Business Adoption of AI

Trusted AI Feed: TrustedAI.AI/feed/

X/Twitter: @OutsecureCom

LinkedIn: OutSecure Inc.

YouTube: OutSecure Inc.

Facebook: OutSecure Inc.

 

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

 

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

 

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
AI Today in 5

AI Today in 5: October 6, 2026 the AI Pesonalization Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. Humans must remain in the loop.(HealthcareFinance)
  2. NYC grills AI execs. (WSJ)
  3. What’s next on the AI personalization front? (FinTechGlobal)
  4. The myth behind the AI agent hacks.  (FT)
  5. AI in compliance seen as MSP advantage. (Channele2e)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County Texas which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival and resilience. It is available on the following sites:

 Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

Categories
FCPA Compliance Report

FCPA Compliance Report: IIA President Anthony Pugliese on the IIA’s Expanding Role in AI, Cybersecurity, and Geopolitical Risk

In this episode, Tom Fox welcomes Anthony Pugliese, President and CEO of The Institute of Internal Auditors Inc.

We begin with the IIA’s global footprint, with boards in 122 countries; its role in setting internal audit standards; certifications, including the Certified Internal Auditor credential with about 225,000 holders; and education. Pugliese describes how internal audit is shifting from primarily financial controls to a broader focus on non-financial risks, including cybersecurity, AI and disruptive technologies, sustainability reporting, business resilience, and geopolitical risk. He emphasizes internal audit’s growing prospective/advisory role, particularly in assessing whether AI governance is keeping pace with rapid adoption and in communicating complex risks to boards and audit committees. Cybersecurity is cited as chief audit executives’ top concern and increasingly requires continuous monitoring. Pugliese notes members want more industry-specific guidance and expanded GRC resources relevant to compliance and directs listeners to iia.org and the free annual Risk in Focus report.

Key highlights:

  • What the IIA Does
  • Risk Landscape Shifts
  • From Assurance to Advisory
  • Geopolitical Risk in Practice
  • Cyber Threats and Continuous Auditing
  • Why Compliance Pros Should Join

Resources:

Anthony Pugliese on LinkedIn

Institute of Internal Auditors

 Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
AI Today in 5

AI Today in 5: October 5, 2026, The Legal Risk Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Could AI stunt lawyers’ training? (Reuters)
  2. Jay Clayton to be named AI Czar. (WSJ)
  3. Compliance purpose-built AI. (Thomson Reuters)
  4. Legal risks piling up for OpenAI. (FT)
  5. Should private AI agents run your life? (WSJ)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Compliance and AI

Compliance and AI: Kunal Chopra on Compliance as Market Access

What is the intersection of AI and compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, host Tom Fox visits Kunal Chopra, CEO of Certivo, an AI-native regulatory intelligence and compliance management platform for supply chains.

Chopra brings nearly two decades of experience across technology leaders like Amazon, Microsoft, and Groupon to the conversation on AI-powered compliance and regulatory intelligence. Drawing on his supply chain background, he argues that compliance should be treated as a market access function that helps companies enter markets faster, protect revenue, and manage global regulatory change more effectively. He believes AI can transform compliance from a reactive, manual burden into a proactive business enabler by continuously tracking rules, extracting key data from documents, and coordinating communication across the supply chain. In his view, this shift frees teams from repetitive work and makes compliance a strategic driver of growth rather than just a legal necessity.

Key highlights:

  • Scrambling for Certificates to Secure Market Access
  • August Deadlines Drive EU Market Access Risk
  • Visibility Gap Threatening Revenues, Projects, and Market Access
  • AI-Native Compliance Platform with Real-Time Audit Trail
  • Deterministic AI Extracting Supplier Documents, Preventing Hallucinations

Resources:

Connect with Kunal Chopra on LinkedIn

Certivo

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
AI Today in 5

AI Today in 5: October 2, 2026, The Going to the Dark Side Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 AI stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. How much of compliance spend will go to AI?(FinTechGlobal)
  2. Data privacy issues are holding patients back from AI. (HealthcareDive)
  3. Google releases the most advanced Gemini model. (FT)
  4. Using AI governance to move compliance to an advantage.  (LewisSilkin)
  5. Banks may soon face the dark side of AI. (Reuters)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

Frankenstein and Compliance: Part 1 – It’s Alive: Innovation Without Governance

Ed. Note: This month, on my podcast series Popcorn and Compliance, I am taking a deep dive into the first five Frankenstein movies. Over October, I will consider Frankenstein, The Bride of Frankenstein, The Son of Frankenstein, The Ghost of Frankenstein, and Frankenstein Meets the Wolfman. The blog post is a companion to the podcast series.

The most famous moment in Frankenstein (1931) comes when Henry Frankenstein’s experiment succeeds. Electricity surges through his laboratory, the body on the table begins to move, and Frankenstein celebrates what he believes is an extraordinary scientific achievement.

“It’s alive!”

For the corporate compliance professional, however, the critical decisions occurred before Henry ever activated his equipment. He had decided to proceed without an adequate risk assessment, effective oversight, meaningful challenge, or a plan for managing the consequences if his experiment succeeded. Viewed through that lens, Frankenstein is not simply a horror movie about a scientist and the Monster he creates. It is a case study in innovation without governance.

That lesson is especially relevant as companies accelerate the adoption of AI and other emerging technologies. Businesses are appropriately focused on innovation, productivity, efficiency, growth, and competitive advantage. Yet technological capability can develop faster than the governance structures needed to manage the resulting risks. The compliance issue is not whether companies should innovate. They must. The issue is whether governance keeps pace with innovation.

The Business Case Was Clear. The Governance Case Was Not.

Henry Frankenstein has a compelling objective. He believes he can accomplish something no one has accomplished before. He assembles the equipment, obtains the materials, develops the technical capability, and builds a team capable of executing the project. In corporate terms, Henry has a strategy, resources, technical expertise, and executive sponsorship. He lacks an effective governance framework.

Before activating his creation, Henry conducts no meaningful risk assessment. He does not identify potential failure scenarios or establish control requirements. He does not define stopping criteria or determine who has authority to challenge the project. No meaningful contingency plan exists for an adverse outcome. This is precisely where compliance should enter the business process.

An effective compliance function should not first encounter a significant new technology when the business seeks approval immediately before deployment. Compliance needs to participate early enough to understand the business objective, identify the associated risks, and help determine appropriate controls.

That does not mean Compliance should own innovation or assume responsibility for the underlying business decision. Risk ownership should remain with the business. Compliance should help ensure that management understands the legal, regulatory, ethical, and control implications of the decision before significant commitments are made.

For the CCO, this raises a practical question: When does Compliance become involved in our company’s innovation process? If the answer is immediately before launch, the organization may already be too far downstream.

AI Has Made the Frankenstein Problem Immediate

Artificial intelligence makes the Frankenstein governance issue particularly relevant. Companies are deploying AI to analyze information, generate content, assist customer service, support investigations, screen candidates, evaluate transactions, enhance due diligence, identify suspicious activity, and improve decision-making. These applications can generate significant business value. They also raise governance questions that organizations must address before deployment.

Organizations need to understand what data an AI application uses, how it obtained that information, who approved the use case, and which regulatory requirements apply. They should determine how outputs are validated, where human review is required, how confidential information is protected, and what happens when a system produces an unexpected or inappropriate result.

There must also be clear accountability. Someone should own the business risk associated with the use case, and the organization should understand who has authority to suspend or terminate the application if circumstances warrant.

The NIST AI Risk Management Framework provides one useful approach through its Govern, Map, Measure, and Manage functions. ISO/IEC 42001 similarly treats AI through a management-system framework emphasizing governance, accountability, risk management, and continual improvement.

Both approaches reinforce a broader compliance principle: technology risk needs governance throughout the lifecycle. Henry Frankenstein has no lifecycle governance. His approach is essentially to build the system, activate it, and evaluate the consequences afterward. That is not an acceptable corporate control environment.

The Abnormal Brain and the Importance of Validating Inputs

One of the film’s most useful compliance scenes occurs before the Monster comes to life. Henry needs a brain for his creation. His assistant Fritz obtains one, but the intended specimen is destroyed. Rather than report what happened, Fritz substitutes another brain, identified in the film as abnormal, without telling Henry. (Abbey Normal—if you know, you know.) The project therefore proceeds after a critical input has changed without the project leader’s knowledge.

For compliance professionals, the scene provides a useful analogy for third-party risk, supply-chain controls, due diligence, and data governance. Organizations routinely rely on information others provide. A distributor provides beneficial ownership information. A vendor completes a compliance certification. An employee submits an expense report. An acquisition target makes representations during due diligence. A supplier certifies compliance with contractual obligations. An AI application relies upon data obtained from multiple sources.

The relevant control question is not simply whether the required information was received. It is whether the organization appropriately validated important information based on risk. Fritz completed his assignment in the narrowest sense. He returned with a brain. The process failed because nobody verified that he returned with the correct brain. That distinction is important for compliance program effectiveness. A completed checklist demonstrates that an activity occurred. Appropriate validation assures that the control achieved its purpose.

Dr. Waldman and Credible Challenge

Henry is not entirely without oversight. Dr. Waldman understands what Henry is attempting and recognizes the potential danger. He raises objections. Henry proceeds anyway. This takes the film from risk assessment into the effectiveness of the challenge function. Many companies can demonstrate that compliance participated in a significant decision. That does not necessarily establish that a compliance professional had meaningful influence over the outcome. A CCO can attend meetings, review proposals, identify concerns, and recommend additional controls. If commercial leadership can routinely disregard those concerns without escalation, the company may have consultation without credible challenge.

This is why the authority, stature, resources, independence, and access of the compliance function matter. The effectiveness of a corporate compliance program becomes most visible when it disagrees with an important business proposal. Boards should therefore look beyond whether your compliance function was consulted. They should understand what happens when a compliance officer disagrees with the business. They need to ask such questions as: Can the CCO escalate a significant concern? Does the CCO have appropriate access to the Audit Committee or board? Are material disagreements documented? Who has authority to accept significant compliance risk? Can commercial management override a compliance objection without further review?

If a CCO can raise a concern but nobody with decision-making authority has to address it, the organization has created the appearance of challenge without its substance. Dr. Waldman had a voice. He lacked the influence to change the decision.

Maria and the Risk of Unintended Consequences

Next we consider one of the most poignant scenes in the movie. The encounter between the Monster and young Maria provides another important business lesson. This is certainly one of the most unforgettable, and indeed tragic, scenes in all the Frankenstein movies. If you have ever seen it, you will never forget it. A small child, Maria, shows the Monster how flowers float on the lake. He imitates what he observes. When the flowers are gone, he throws Maria into the water, apparently expecting her to float as the flowers did. The consequences are tragic. The Monster recognizes a pattern without understanding its context.

That distinction has obvious relevance for artificial intelligence and automated decision-making. A system may identify patterns, generate recommendations, and produce technically consistent outputs without understanding their broader legal, ethical, or business implications. A technically accurate output can still create an inappropriate result.

This is why human oversight cannot exist merely as language in an AI policy. Companies need to determine where human judgment is required, who provides that judgment, what qualifications reviewers need, when automated recommendations can be overridden, and how significant exceptions are documented.

Management should also understand whether human review is substantive or simply procedural. An employee clicking an approval button after an automated recommendation does not necessarily constitute meaningful oversight. The relevant control question is not simply whether the technology performed as designed. It is whether the resulting decision was appropriate.

Innovation Requires Accountability

Henry eventually discovers that creating something and controlling it require different capabilities. Corporate leaders should understand the same distinction. Management establishes incentive structures, sales strategies, compensation plans, technology deployments, acquisition strategies, third-party relationships, and performance expectations. Those decisions shape employee behavior and create risk. Leadership accountability therefore does not begin only after misconduct occurs. It begins with the decisions that establish the operating environment.

For the CCO, this means integrating compliance risk into strategic business decisions. For management, it means risk ownership remains with the business. For the board, oversight should focus on whether management has reasonable systems to identify, manage, monitor, and escalate significant risks. Compliance does not own a business risk simply because the compliance function identifies it. Management remains responsible for the business decision and the risks it creates.

That principle becomes particularly important with emerging technology. The CCO should contribute expertise regarding regulatory requirements, ethical considerations, controls, monitoring, and escalation. Technology leaders should contribute technical expertise. Legal, Privacy, Information Security, HR, Internal Audit, and other functions may have roles depending on the application. Business leadership remains accountable for the decision to deploy the technology and the resulting business risk.

Practical Actions for the CCO

Frankenstein suggests a practical agenda for compliance leadership. Compliance should move upstream and identify significant business processes where its participation adds the most value before making commitments. Emerging technology, acquisitions, market entry, compensation design, significant third parties, and new products are obvious candidates.

Risk assessment should occur before deployment and should address foreseeable legal, compliance, ethical, operational, and reputational consequences. High-risk inputs supplied by employees, vendors, third parties, acquisition targets, or technology systems should receive risk-based validation.

The organization should also define what credible challenge means in practice. Escalation procedures should be clear when Compliance and business leadership disagree about significant risk.

Finally, treat approval as the beginning of governance rather than its conclusion. Test controls, monitor outcomes, analyze exceptions, and update risk assessments as the business and technology evolve. The objective is not to slow innovation. It is to make innovation governable.

The Compliance Lesson

Frankenstein is not an argument against innovation. It is an argument for governance.

Henry Frankenstein failed not because he attempted something extraordinary. He failed because his technical ambition outpaced his ability to identify, understand, govern, and control the resulting risk.

Companies face the same challenge today. Technology will advance. Business models will change. New markets will open. Competitive pressure will accelerate decision-making. New risks will emerge. Compliance’s role is not to stand outside the laboratory and demand that the electricity be turned off.

It is to help ensure that management has assessed the risk, validated critical inputs, established appropriate controls, defined accountability, created meaningful challenge, and determined how the organization will respond if the initiative produces an unexpected result. The best time to build that governance structure is before deployment.

Our next installment moves the compliance analysis forward. In Bride of Frankenstein, Henry no longer faces an unknown risk. He has already experienced the consequences of his original experiment and understands what can go wrong. Then Dr. Pretorius persuades him to return to the laboratory.

The compliance issue is no longer whether leadership identified the risk. It is what happens when leadership knows better, but pressure, ambition, and rationalization push the organization toward the same risk again.

Check out Timothy and Fiona’s commentary on Frankenstein here.

Categories
Daily Compliance News

Daily Compliance News: October 1, 2026, The Welcome to Q4 Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • PwC refuses to sign off on Nidec books. (FT)
  • Trump defends no-touch regulation for AI. (WSJ)
  • Hungary’s reckoning with corruption speeds up. (DW.com)
  • US exits from EU ABC working group. (AP News)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
AI Today in 5

AI Today in 5: September 30, 2026,  The AI in Space Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Space-based property management oversight. (FinTech Global)
  2. OpenAI scraps Astra release. (NYT)
  3. The AI data squeeze. (LawAsia)
  4. Compliance lessons on AI in debt collection. (Inside ARM)
  5. Using AI to monetize compliance. (CRN)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Innovation in Compliance

Innovation in Compliance: Doni Hoti on Embedding Advertising Compliance Into Content Creation

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom welcomes Doni Hoti, co-founder and CEO of Adclear.

Hoti brings a fascinating perspective on embedding compliance directly into content creation. He begins with the shift in advertising and marketing compliance from a slow, “checkpoint” back-office function to an embedded, revenue-enabling capability. Hoti explains that modern content creation involves many stakeholders and must move at near-real-time speed, while enforcement risk and the cost of losing customer trust keep rising. He describes how AI has broken traditional review models by increasing both content volume and speed expectations and how Adclear uses horizon scanning across global regulators, agentic AI, and company-specific policies to deliver more deterministic, auditable compliance guidance tied to rulebooks. Fox and Hoti then turn to third-party and affiliate challenges, regulator-ready documentation and audit trails, and business outcomes such as reduced review SLAs, scalable approvals, and revenue uplift, with marketing increasingly owning the process alongside legal and compliance.

Key highlights:

  • Compliance Disconnect
  • Trust and Shopfront
  • Embed Compliance
  • Third-Party Risks
  • AI as Solution
  • Audit Trail Proof

Resources:

Adclear

Doni Hoti on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.