Categories
Innovation in Compliance

Innovation in Compliance: Brian Holyfield on Reducing Cybersecurity Blast Radius

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom visits with Brian Holyfield, Co-Founder & Chief Product Officer at SendSafely.

Holyfield discusses why the right compliance question on cybersecurity is not whether a breach will happen but when and what data will be exposed, often through vendors. He explains “blast radius” as the scope of access and data reachable during an incident and argues organizations should prioritize architecture, data minimization, and retention controls alongside prevention. He also highlights risks from accumulated file attachments, overbroad user access, interconnected systems using OAuth tokens, and “standing access” via long-lived machine credentials that can be abused without obvious login anomalies. Holyfield discusses examples involving ServiceNow and Salesforce that illustrate platform vulnerabilities, trusted upstream vendor connections, and end-user compromise, and advises leaders to inventory connections, define retention/archiving, and move sensitive data out of frontline platforms; SendSafely positions itself as an end-to-end encrypted trust layer, including for AI chatbot attachments.

Key highlights:

  • Assume the Breach
  • Blast Radius Explained
  • ServiceNow and Salesforce Lessons
  • Board-Level Questions
  • AI Changes the Game
  • Compliance and Governance Fit

Resources:

SendSafely

Brian Holyfield on LinkedIn

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts

Categories
Everything Compliance - Shout Outs and Rants

Shout Outs and Rants: AI, Investigations, Kickbacks and Kids

Welcome to a new season of Everything Compliance – Shout Outs and Rants. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, who joins returning regulars Jonathan Armstrong and Karen Moore for the next iteration of Everything Compliance Shout Outs and Rants.

  • Adam shouts out to the Boeing documentary Free Fall and Peter Robison’s book Flying Blind for lessons on culture, whistleblowers, and safety, and praises United Airlines for returning a plane to address a mechanical issue.
  • Rebecca raises a compliance training dilemma: employees using company AI tools to answer test or “test-out” questions, which may look like cheating and undermine training records in an investigation, yet could mirror desired real-world behavior if employees are expected to consult policies, compliance, or an AI chatbot when issues arise.
  • Jonathan recounts a scandal involving Scotland’s First Minister John Swinney, including FOI-revealed travel costs (about £45,000 in flights and significant car hire) allegedly contrary to policy and justified as meetings in Kentucky.
  • Karen shouts out to the 25 incoming Fordham MSL Introduction to Corporate Compliance students and reflects on the shift from accidental to intentional compliance careers.

Everything Compliance Shout Outs and Rants is a production of the Compliance Podcast Network.

Categories
AI Today in 5

AI Today in 5: August 25, 2026, The AI Governance Has Named Accountability Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. AI governance for health services. (Yahoo! Finance)
  2. AI for email compliance. (NJIT)
  3. AI in quality management. (ARC Advisory Group)
  4. AI governance is becoming a named accountability. (CCI)
  5. Bank-grade AI for compliance. (FinTechGlobal)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

Private Company, Public Risk: Building Defensible AI Governance Before the Rules Arrive

For private companies, the central question about artificial intelligence is no longer whether the technology is in the business. It is whether anyone can explain where it is, what it does, what data it touches, and who is accountable when it fails.

That is the warning in “AI Governance for Private Companies,” by Hillary Flynn, Drew Morales, and Courtney Hugger of Wellington Management, which was recently posted in the Harvard Law School Forum on Corporate Governance. The authors report that nearly three in four companies plan to deploy agentic AI within two years, while only one in five has a mature governance model for autonomous agents. That is not merely a technology gap. It is a governance gap.

Private ownership does not make AI risk private. The consequences arrive through customers, employees, regulators, investors, lenders, insurers, and business partners. A company may not yet face a single comprehensive AI law, but it can still face a privacy complaint, contract dispute, cyber incident, customer loss, or damaged valuation. For compliance professionals, governance should precede scale.

Private Does Not Mean Exempt

Private companies are moving quickly because AI can increase productivity, improve customer service, accelerate analysis, support coding, and help a growing company scale. The article also identifies a critical lesson from Wellington’s portfolio companies: the largest barriers are often organizational, not technical. Companies making the strongest progress combine AI investment with employee training, clear governance, and defined expectations.

This is where the Chief Compliance Officer can reframe the discussion. AI governance is the discipline that allows useful experimentation without unmanaged legal and business exposure. The goal is not a thick policy on a shared drive. The goal is an operating system for accountable decisions.

The European Union AI Act is being implemented in phases through 2027, with expectations around transparency, human oversight, documentation, risk management, monitoring, and AI literacy. In the United States, NIST guidance, ISO standards, sector rules, state laws, and customer requirements are shaping expectations, even without a federal AI statute. A private company can therefore face AI governance demands through a contract or transaction long before a regulator knocks on the door.

Begin With the Business Objective

One of the article’s strongest recommendations is also one of the simplest: start with the business problem, not the AI tool. This is precisely what Carl Hahn has consistently maintained: always ask, “What is the Business Value?”Teams should define the desired outcome before selecting a model or vendor. Is it lower cost, faster response, better quality, increased revenue, fewer errors, or reduced risk?

Governance cannot evaluate an undefined promise. A measurable objective gives management a basis for deciding whether the use case works and whether its benefits justify its risks. It also creates stopping rules. Approval should identify what failure, customer impact, control breakdown, or scope change will trigger redesign, escalation, suspension, or retirement.

Compliance should insist on this discipline, particularly when an AI use case affects payments, eligibility, claims, pricing, employment, healthcare, education, financial products, or customer communications. Those are not ordinary software deployments. They are decisions and interactions with consequences for real people.

Inventory First, Then Tier the Risk

A company cannot govern what it cannot see. The foundation is an inventory of models, vendors, internal tools, embedded features, customer-facing systems, employee-built applications, and known shadow AI. It does not need to be perfect. It needs an owner, an update process, and enough information to support risk decisions.

Each use case should then be placed into a risk tier. Relevant factors include data sensitivity, degree of autonomy, importance of the business process, impact on customers or employees, regulatory exposure, ability to explain the result, and ease of reversing an error. Low-risk uses can follow a streamlined path. High-impact uses should receive enhanced testing, documented approval, human oversight, monitoring, and senior-level escalation.

Risk tiering prevents two failures. Treating every use as equally dangerous overwhelms review and encourages employees to route around it. Treating every use as ordinary technology leaves consequential applications without meaningful controls. Good governance applies greater rigor where potential harm is greater.

Put a Name Next to the Risk

Every AI system should have a business owner who remains accountable for its outcome. Accountability cannot be delegated to the model, the data science team, or the vendor. The owner should understand the intended purpose, approved users, permitted data, performance standard, escalation route, and circumstances under which the system must be paused.

Higher-risk applications should receive cross-functional review involving the business, product, engineering, legal, compliance, privacy, cybersecurity, procurement, and risk functions. This does not require a new bureaucracy. It requires a repeatable process with recorded approvals and clear responsibility.

Agentic AI raises the stakes because the risk moves from a wrong answer to a wrong action. Permissions should be limited, high-stakes actions should require human approval, and activity should be logged. Test override and shutdown mechanisms. The chatbot manipulated into agreeing to sell a vehicle for one dollar shows how weak boundaries turn a novelty into an operational event.

Treat Vendors as Part of the System

Most private companies will rely on external models, platforms, and software. That makes AI governance inseparable from third-party risk management. Traditional security questionnaires are not enough. Diligence should address how vendors use data, whether customer data trains models, how model changes are communicated, what transparency is available, how performance is tested, who bears liability, and whether data and workflows can be moved if the relationship ends.

The company should monitor model updates, service degradation, changes in terms, and features that expand access or autonomy. A tool approved for summarization should not silently become authorized to send messages, approve transactions, or alter customer records.

Monitor the System in Practice

AI governance does not end at approval. Model updates, new data, and user behavior can alter performance. Companies should monitor accuracy, reliability, bias, drift, misuse, repeated failures, and customer impact. An incident protocol should define how to pause the system, preserve evidence, escalate, remediate harm, and communicate with affected stakeholders.

This is where AI governance meets familiar compliance principles. The DOJ’s Evaluation of Corporate Compliance Programs asks whether a program works in practice. COSO emphasizes control activities, information, monitoring, and accountability. NIST’s AI Risk Management Framework helps organizations govern, map, measure, and manage AI risk. ISO/IEC 42001 offers a management-system approach. A company should select a coherent baseline and produce evidence that its controls operate.

A Practical Agenda for Boards and CCOs

Establish ownership. Name an executive accountable for AI governance and identify the board committee that will oversee material AI risk.

Build the inventory: capture sanctioned tools, embedded vendor capabilities, customer-facing uses, agentic applications, and known shadow AI.

Tier the use cases. Apply enhanced review where AI affects sensitive data, consequential decisions, critical operations, or autonomous action.

Strengthen the vendor process. Add AI-specific diligence, contractual protections, change controls, exit planning, and ongoing monitoring.

Test the failure plan. Confirm that the company can detect a harmful outcome, stop the system, preserve evidence, assign responsibility, and remediate the impact.

The author’s bottom line is the right one for compliance leaders: the winners will not necessarily be the companies that deploy AI fastest. They will be the companies that combine innovation with accountability, customer awareness, and disciplined execution. For a private company, defensible AI governance is not preparation for some distant regulatory future. It is how management protects value today.

Categories
AI Today in 5

AI Today in 5: August 24, 2026, The AI Phobia Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. On the evolution of voice-to-text AI. (NYT)
  2. Nvidia to build an alternative to Chinese AI models. (WSJ)
  3. OpenAI slow development in light of the Hugging Face hack. (Reuters)
  4. AI phobia in America. (FT)
  5. Is an AI slowdown finally coming? (Bloomberg)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Daily Compliance News

Daily Compliance News: August 24, 2026, The Racing into Venezuela Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • AI for email compliance. (NJIT News)
  • TikTok settles for $400MM. (Reuters)
  • New GRC products. (CCI)
  • Racing to get into Venezuela. (WSJ)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

From Policy to Proof: Six Compliance Priorities for the Next 90 Days

Editor’s note: I am a columnist for Compliance Week.

Compliance Week recently released its Practitioner’s Briefing, which “is crafted as a high-level recap of Compliance Week’s 2026 National Conference (CW 26), held in Washington, D.C., in May. Whether you were there or wished to be, this briefing will bring you up to speed. The briefing captures the six themes that pervaded three days of panel discussion and the networking conversations between them, with practical actions you can implement in the next ninety days.”

The compliance profession is entering the proof era. Policies still matter, but regulators, boards, and employees are asking a harder question: Can the organization demonstrate that its controls operate in practice? That is the central lesson from the Practitioner’s Briefing. Across six themes, the briefing describes a function under pressure from rapid AI adoption, faster whistleblower timelines, redistributed enforcement, expanding third-party exposure, and sharper board expectations.

Today I want to explore the themes and initiatives from the Practitioner’s Briefing. This is not about six disconnected initiatives covered at CW 26. It is an operating model that connects governance, data, accountability, and escalation around existing risks. You can use the next 90 days to produce evidence that the program knows where its risks sit, who owns the controls, how failures surface, and what happens next.

AI Governance: Accountability Must Follow Adoption

AI makes the policy-to-proof gap visible. The Practitioner’s Briefing reports that 83 percent of compliance functions have AI in production, while only 25 percent of leaders are confident in the governance controls. That is not primarily a policy problem. It is an ownership and control-design problem.

Start with your AI inventory. A defensible AI register should identify the tool, approved use case, business owner, data involved, vendor, model, access rights, validation method, human reviewer, retention rule, incident path, and kill-switch authority. Tool approval by IT cannot substitute for use-case approval by Legal, Compliance, Privacy, Security, and the accountable business leader. One platform may be acceptable for drafting training content and unacceptable for evaluating employees or third parties.

The NIST AI Risk Management Framework and ISO/IEC 42001 can help organize this work, but a framework is not the control. The control is the approval record, test result, exception log, monitoring evidence, and documented decision. Compliance should also assume that prompts, summaries, transcripts, and agent logs are discoverable business records. Retention and legal hold procedures must catch those artifacts before the first dispute or investigation forces the question.

AI in Compliance Operations: Redesign the Work

The Practitioner’s Briefing draws a useful line between AI enablement and AI theater. Strong programs redesign a workflow around AI. Weak programs bolt AI onto a slow process and call it transformation. Due diligence, regulatory tracking, training development, and self-service policy guidance are sensible starting points because the work can be scoped, tested, and measured.

Each deployment needs acceptance criteria. Validate performance against known outcomes, constrain source material where accuracy matters, monitor drift, require human review for high-risk decisions, and define escalation when the system is uncertain. Measure return on investment first in hours returned to higher-value work. Faster output that creates more review, remediation, or false confidence is not efficiency. It is control debt.

Speak-Up and Investigations: Trust Is the Control

The Practitioner’s Briefing reports that eight in ten US employees witnessed misconduct during the prior year, yet fewer than three-quarters reported it. That gap is not solved by adding another intake channel. It is solved by showing employees that reporting is safe, fair, and consequential.

One of the Practitioner’s Briefing’s most practical recommendations is to audit the career outcomes of the last 20 employees who raised concerns. Review performance ratings, promotions, transfers, compensation, leave, and departures. Patterns in those records may reveal retaliation or career stagnation that hotline statistics will never show. Pair that review with defined post-report monitoring and documented check-ins with reporters.

Speed is now part of program effectiveness. The briefing highlights a 120-day DOJ window to investigate qualifying internal reports and decide whether voluntary self-disclosure is appropriate. CCOs should calendar that period, establish rapid triage, identify decision rights, preserve evidence immediately, and maintain a standing disclosure team. The goal is not a rushed conclusion. The goal is to prevent delay, unclear ownership, or inadequate resources from deciding for the company.

Enforcement Has Shifted, Not Disappeared

Lower federal case counts are not a safe harbor. The Practitioner’s Briefing describes enforcement as redistributed across state Attorneys General, self-regulatory organizations, the False Claims Act, and future matters still inside applicable limitation periods. A quieter headline environment can encourage exactly the wrong management response: reduced staffing, deferred remediation, and lower investment in controls.

The business discipline is straightforward. Monitor the full enforcement ecosystem, not one federal docket. Maintain the strictest applicable standard as the practical global baseline. Preserve the ability to investigate, cooperate, remediate, and disclose. Most importantly, do not confuse a change in enforcement cadence with a change in underlying legal or ethical risk. Today’s control gap may simply be tomorrow’s case.

Third-Party Risk: Manage the Entire Lifecycle

Third-party risk management is no longer a narrow anti-bribery process. The Practitioner’s Briefing places sanctions, forced labor, transnational crime, material support exposure, supply-chain integrity, and embedded AI inside the modern TPRM remit. That expansion requires a move from onboarding diligence to lifecycle control.

Monitor material relationships from selection through offboarding, with risk-based refreshes, event-driven alerts, beneficial ownership checks, adverse media review, and clear remediation ownership. For AI-enabled vendors, procurement should require disclosure of material fourth- and fifth-party dependencies. Contract terms should address model provenance, data lineage, audit rights, incident notice, control changes, and the ability to explain consequential decisions.

List screening alone is increasingly thin protection. High-risk supply chains may require route mapping, chokepoint analysis, and source-verified information reviewed in context by humans. AI can compress the initial diligence cycle, but it does not replace judgment on coercion, shell companies, access payments, or other facts that demand legal and operational analysis.

Board Reporting and Culture: Lead With the Problem

Directors want a compliance report that begins with bad news, explains the risk, and shows the response. That is the board-reporting message in the Practitioner’s Briefing. Activity counts belong in the appendix. The main discussion should address control failures, investigation aging, retaliation indicators, overdue high-risk diligence, AI exceptions, remediation status, and emerging exposure compared with peers.

This approach also supports a Caremark-style oversight record. The board needs credible information systems, timely escalation of red flags, and evidence that management and directors responded. A between-meetings protocol with the audit or risk committee chair is therefore a control, not a courtesy.

Culture is equally operational. The briefing reports that direct managers and immediate colleagues exert the strongest influence on 80 percent of employees, while only 58 percent of organizations evaluate how results were achieved. Compliance should train managers to receive concerns, audit incentives as rigorously as financial controls, and make conduct part of performance and promotion decisions. The real code of conduct is what the organization rewards, tolerates, and corrects.

A 90-Day Agenda for CCOs

  1. Build the evidence map. Select the highest-risk obligations in AI, investigations, and third-party management. For each one, identify the owner, control, evidence, escalation path, and board metric.
  2. Test AI governance. Reconcile the official AI inventory with procurement records, browser access, expense data, and employee attestations. Review several approved use cases from request through monitoring.
  3. Stress-test investigations. Tabletop a significant internal report against the 120-day decision window. Confirm preservation, privilege, staffing, disclosure authority, and board communication.
  4. Rebuild TPRM around lifecycle risk. Segment critical third parties, define continuous-monitoring triggers, review AI dependencies, and assign remediation deadlines with accountable owners.
  5. Change the board report. Put the three most significant problems first. Add peer comparison, trend data, remediation aging, and decisions required from the board or management.

The Compliance Lesson

The Practitioner’s Briefing is not fundamentally a technology story or an enforcement story. It is a program-effectiveness story. The effective compliance function can identify risk, assign accountability, test controls, learn from failures, and show its work. Policies establish expectations. Evidence establishes credibility. In the next 90 days, that distinction should drive the agenda of every CCO, executive team, and board committee responsible for corporate integrity.

Categories
AI in Healthcare

AI in Healthcare: Five Healthcare AI Stories You Need to Know This Week – August 21, 2026

Welcome to AI in Healthcare in 5 Stories. This podcast is a weekly briefing on the five most important AI developments shaping healthcare, medicine, and life sciences. Each week, Tom Fox breaks down the latest stories on clinical innovation, regulation, privacy, compliance, patient safety, and operational transformation through a practical, business-focused lens. Designed for healthcare compliance professionals, executives, legal teams, clinicians, and industry leaders, the podcast moves beyond headlines to explain what each development means in the real world.

The top five stories for the week ending August 21, 2026, include:

  1. Maine looking at AI for rural health. (Bangor Daily News)
  2. AI helping patients solve mystery ailments. (WSJ)
  3. Guiding Principles for AI in healthcare. (UVA Health)
  4. From Pilot to Profit: AI in Pharma. (PharmaExec)
  5. Can AI make your hospital a Mayo Clinic? (Health Exec)

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI in Financial Services in 5 Stories

AI in Financial Services in 5 Stories – Week Ending August 21, 2026

Welcome to AI in Financial Services in 5 Stories. A practical weekly roundup of the five most important AI developments affecting banking, insurance, payments, asset management, and fintech. Each Friday, Tom Fox will break down the top stories that matter most through the lenses of compliance, risk management, governance, and business strategy. Designed for compliance professionals, executives, legal teams, and financial services leaders, it goes beyond headlines to explain why each development matters in a highly regulated industry. The result is a concise weekly briefing that helps listeners stay current on AI innovation while asking sharper questions about oversight, accountability, and trust.

This week’s stories include the following:

  1. AI and the lending experience. (CNBC)⁠
  2. How AI infiltrated the FED. (⁠Bloomberg Law)⁠
  3. What forensic accounting can teach finance about AI. (⁠Treasury & Risk)⁠
  4. AI enabled internal audit fieldwork. (⁠PwC⁠)
  5. The rise of ‘shadow finance’. (⁠CFO)⁠

For more information on the use of AI in Compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
AI Today in 5

AI Today in 5: August 20, 2026, The Between Scylla and Charybdis Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. AI for compliance in the trucking industry. (CCJ Digital)
  2. 6 top AI tools for compliance. (Impakter)
  3. Don’t let AI strategy outpace your network strategy. (Fedscoop)
  4. FTC puts companies between Scylla and Charybdis. (Law.com)
  5. AI governance and data analytics in healthcare. (Healthcare Innovation)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.