Categories
Blog

When the CEO Has to Go: What Forced Departures Tell Boards and CCOs About Governance

CEO succession is usually discussed as a planning exercise. Boards identify potential successors, develop internal talent, periodically review the succession plan, and prepare for the orderly transition that eventually comes with retirement or another planned departure.

But succession does not always wait for the planning calendar. In an article in the Harvard Law School forum on Corporate Governance, titled Forced CEO Departures, the authors reported on a new study by The Conference Board, developed with ESGAUGE and other collaborators, that examined forced CEO departures among Russell 3000 and S&P 500 companies from 2024 through August 2026. Roughly one in seven CEO succession cases were classified as forced in both 2024 and 2025. In the Russell 3000, 49 forced departures occurred in 2024 and 55 in 2025. The S&P 500 recorded seven and 10, respectively. The forced departure numbers are interesting. The governance implications are more important.

This research on forced CEO departures reminds boards to prepare for unscheduled CEO transitions. For Chief Compliance Officers, the findings raise an equally important question: what information should the compliance function be providing to the board before a leadership problem becomes a leadership crisis?

Forced CEO departures demonstrate that succession planning, executive accountability, corporate performance, investor confidence, culture, and risk oversight cannot be separated into different governance boxes. They ultimately meet in the boardroom. For a Chief Compliance Officer (CCO), they also demonstrate why compliance must function as an organizational sensor capable of identifying patterns that individual incidents may not reveal.

Forced Succession Is a Governance Risk

The report defines a forced departure broadly enough to capture the realities of corporate governance. A departure is forced when evidence indicates that the board, activist investors, an investigation, performance concerns, misconduct, or strategic disagreement materially influenced the timing or terms of the CEO’s exit. Importantly, a departure publicly described as a resignation or retirement may still have been board-driven. That distinction matters.

Boards should not think about CEO succession solely as identifying the person who eventually replaces a successful CEO. Succession planning must also contemplate what happens when the board concludes that the current CEO can no longer lead the organization effectively.

The report’s 2024 and 2025 data make that point. Forced departures represented 14.7 percent and 14.8 percent of Russell 3000 succession cases, respectively. Among the S&P 500, the corresponding figures were 14.3 percent and 15.2 percent. Those figures should change the boardroom conversation.

The question is not simply, “Who succeeds the CEO someday?” It is also, “What happens if we need a new CEO next Monday?”

Performance Is Becoming a Governance Question

Perhaps the most significant finding concerns why CEOs were forced out. Underperformance accounted for 37 percent of Russell 3000 forced departures across the period studied. It increased from 31 percent in 2024 to 44 percent in 2025 and remained the largest category through August 2026. Underperformance, activist pressure, and termination without cause collectively accounted for 70 percent of forced departures during the full period.

For directors, that creates a difficult governance question. When does poor performance become a leadership problem? A single disappointing quarter should not automatically become a referendum on the CEO. External economic conditions, industry disruption, commodity prices, interest rates, geopolitical events, and other factors can affect performance.

Yet boards cannot allow those explanations to become permanent excuses. The report recommends establishing in advance the conditions that trigger a deeper assessment of CEO effectiveness. That assessment should extend beyond financial results to strategic milestones, competitive position, organizational capability, and how the CEO responds to setbacks. That is an important governance discipline. Agreeing on the indicators before the crisis reduces the danger of redefining success after performance deteriorates.

The CCO Has a Different Window Into CEO Effectiveness

Here the compliance function enters the discussion. The report is primarily about CEO succession and board governance. It does not assign the CCO responsibility for evaluating CEO performance. Nor should it. But compliance often sees organizational information through a different lens than Finance, Strategy, HR, or Investor Relations.

A CCO may see whether employees are becoming reluctant to speak up. Compliance may identify retaliation concerns involving senior management. Investigations may reveal recurring management override. Hotline data may show patterns concentrated around particular executives or business units. Third-party reviews may expose pressure to circumvent controls. Internal investigations may demonstrate that employees believe commercial performance is valued more highly than ethical conduct.

One event may mean little. Patterns can mean much more. This is why an effective CCO should not simply report hotline statistics to the board. The CCO should help directors understand what the information may be saying about organizational culture, controls, accountability, and risk.

The question becomes: What does the board need to know to discharge its oversight responsibilities?

That is a very different question from: What compliance information did management ask us to provide?

CEO Accountability and the Control Environment

CCOs should also pay attention to forced CEO departures. The CEO sits at the top of the organization’s control environment. The CEO’s conduct affects incentives, resources, accountability, escalation, management behavior, and whether employees believe controls are genuine requirements or obstacles to business performance.

That means directors assessing leadership should consider more than revenue growth and shareholder returns. They should understand whether management responds appropriately when controls identify problems. Some key questions a CCO might ask include:

Does the CEO support investigations even when they involve high-performing executives? Does management remediate identified weaknesses? Are compliance personnel adequately resourced and empowered? Are executives held accountable consistently? Does information reach the board without being filtered into insignificance?

These questions connect CEO oversight to compliance program effectiveness. They also reinforce why direct access between the CCO and the board or an appropriate board committee matters. The value of that relationship becomes clearest when the information the board needs is information senior management would prefer not to discuss.

Activists May Ask the Questions Boards Should Already Be Asking

The report contains another significant finding.

Among S&P 500 forced departures, activist pressure accounted for five of 10 departures in 2025. Across 2024 through August 2026, activists were associated with eight of 19 forced departures, or 42 percent. The report notes that activist campaigns frequently focus on matters already within the board’s remit, including performance, strategy, capital allocation, portfolio structure, governance, and confidence in management. Forced CEO Departures

There is a governance lesson here. A board should not need an activist investor to tell it which difficult questions to ask. Directors should periodically examine the company through an independent investor lens. Where is performance lagging? Which strategic assumptions have not proved correct? Where has capital allocation failed to produce expected results? What would a sophisticated outsider identify as the company’s vulnerabilities?

For the CCO, there is a parallel exercise. What would a regulator, whistleblower, investigative journalist, plaintiff’s lawyer, or enforcement authority see if they examined the same facts? These perspectives are not substitutes for the board’s business judgment. They are tools for challenging assumptions. Effective oversight requires directors to seek disconfirming information, not just information that supports management’s existing narrative.

Succession Planning Needs a Break-Glass Option

The report recommends that boards maintain an accelerated succession plan alongside traditional succession planning. That distinction is critical. A normal succession plan asks who might become CEO in several years. An accelerated plan asks who takes control tomorrow morning.

The board should know who can provide immediate continuity, which internal executives could become permanent successors, when an external search would be required, and how to retain key executives during the transition. The plan should also address interim authority, compensation, severance arrangements, and employee and investor communications. Compliance should be part of that contingency architecture.

Questions might include: If the departure involves misconduct or an investigation, who controls the investigation after the CEO leaves? Who has authority over document preservation? Who makes disclosure decisions? Who communicates with regulators? What happens if other senior executives are implicated? Does the CCO continue reporting through the same management structure, or should reporting temporarily move directly to the board?

The report itself does not address these questions, but they follow directly from the compliance risks created by an unexpected leadership transition. The worst time to design these protocols is during the crisis.

The Board and CCO Need an Early-Warning System

The larger lesson from the forced-departure data is not that boards should terminate CEOs more quickly. It is that boards should become better prepared to recognize and respond to deteriorating conditions.

The report found no consistent company-size profile for forced turnover. Elevated rates appeared across the revenue spectrum. The more meaningful indicators were company-specific factors, including persistent underperformance, strategic misalignment, and investor scrutiny. Forced CEO Departures

That suggests boards need an integrated early-warning system.

  • Financial performance is one signal.
  • Strategic execution is another.
  • Investor sentiment is another.
  • Compliance and culture data should be another.

The CCO can contribute by identifying trends in allegations, investigations, retaliation, control overrides, disciplinary decisions, third-party exceptions, and other indicators that may reveal stress inside the organization. The board then has the responsibility to connect the dots.

Questions for the Board and CCO

Boards should periodically ask whether they have defined the conditions that would trigger a reassessment of CEO effectiveness; whether they have a genuine emergency succession plan rather than simply a long-term succession plan; whether directors receive information about culture, investigations, controls, and retaliation without inappropriate management filtering; and whether they understand recurring concerns raised by shareholders, employees, auditors, compliance, and other stakeholders.

CCOs should ask different questions. Are we giving the board data or insight? Are recurring issues being presented as isolated events? Are senior executives subject to the same accountability standards as everyone else? Does the CCO have a practical route to the board when senior management itself presents the risk? If the CEO suddenly departed tomorrow because of an investigation, could Compliance continue operating without interruption?

Those can be uncomfortable questions. Yet, they are also precisely the questions effective governance requires. Forced CEO departures are not simply stories about executives losing their jobs. They stress-test the governance system around those executives.

The board’s responsibility is to ensure it can recognize when leadership circumstances have materially changed and act deliberately, not reactively. The CCO’s responsibility is different but complementary: ensure that compliance, culture, control, and investigation information that can inform that judgment reaches the board clearly and promptly.

A board should never discover during a CEO crisis that the warning signs were there all along. A better governance model identifies those signals early, understands what they mean, maintains credible succession alternatives, and establishes decision processes before they are needed. That is not planning for failure. It is planning for effective oversight.

Categories
Blog

When an Effective CCO Is Labeled Difficult

A business leader calls a Chief Compliance Officer (CCO) difficult after a proposed distributor fails to provide basic ownership information. The transaction is important to the quarter. The CCO has asked for the missing information, explained the concern, and identified what is needed to proceed. In the performance discussion that follows, the focus shifts to whether the CCO understands the business.

This hypothetical presents a governance question. Did the CCO handle the matter poorly, or did an appropriate challenge expose a business practice management would prefer to leave alone? The answer requires evidence about the decision, the CCO’s conduct, and the operating environment. A label provides none of that.

Luis Velasquez examines this diagnostic problem in Why Effective Leaders Get Branded as Problems, published in Harvard Business Review. He identifies four sources of leadership friction: genuine skill deficits, historical reputation, overextension of a leadership strength, and organizational barriers. His framework provides a useful starting point for evaluating CCO effectiveness while protecting the independence necessary to perform the role. The compliance applications below build on his analysis.

Diagnose the Conflict Before Evaluating a CCO

Velasquez describes an evaluation trap in which organizations treat visible behavior as the explanation for friction while giving insufficient attention to context. Once a leader acquires a negative reputation, subsequent assessments can reinforce it without testing whether the original diagnosis was sound.

For compliance, this creates a particular risk. A CCO’s responsibilities include raising concerns that may complicate a transaction, challenge an executive, or require management to change an established practice. Friction can arise while the function is doing its job. It can also arise when compliance communicates poorly, applies inconsistent standards, or takes too long to decide. An effective evaluation must examine both possibilities.

Start with the event behind the criticism. What decision was required? What information was available? What did the compliance request say, when, and why? What alternatives did a CCO identify? Which actions by the business affected the outcome? These questions create a basis for assessing performance without assuming the conclusion.

Address Genuine Skill Gaps Directly

Velasquez’s first category recognizes that leaders sometimes lack a necessary capability. Applied to CCOs, relevant gaps may include unclear communication, weak prioritization, insufficient business knowledge, or ineffective delegation. Consider a CCO who repeatedly sends lengthy technical explanations without identifying the decision management must make. Executives may reasonably struggle to act on the advice. Similarly, a compliance team that treats every request as equally urgent can consume resources while delaying matters that warrant immediate attention.

Those are legitimate performance concerns when supported by recent examples and a clear account of their consequences. Agree on the improvement required, provide support, and assess the result. Independence does not excuse disrespectful conduct, poor execution, or unsupported recommendations. It gives a CCO room to exercise judgment while remaining accountable for the work’s quality and delivery. A sound review evaluates whether a CCO explains concerns clearly and helps the business identify acceptable ways forward where they exist.

Replace Old Reputation With Current Evidence

Velasquez’s second category concerns historical reputation. A leader may change while the organization still relies on an outdated account of how that person operates. A CCO who joined during a serious control failure may initially have imposed tight review requirements. Years later, colleagues may still describe the function as inflexible even after it has introduced clearer thresholds, delegated decisions, and improved turnaround times.

The evaluation process should test whether the criticism reflects current experience. Ask for specific recent interactions, the applicable requirements, and the outcome. Compare those accounts with evidence of how the process now works. Older incidents may remain relevant, but explain their continued significance rather than assume it.

A CCO can contribute by demonstrating improvement through current service measures, examples of resolved issues, and feedback from people who use the process. The objective is an accurate assessment. Favorable anecdotes alone are no more sufficient than a repeated negative label.

Recognize When a Strength Needs a Different Application

Velasquez distinguishes a missing skill from a strength used too broadly. That distinction matters for a compliance leader whose career has rewarded detailed review and personal control of important decisions. Those habits may help stabilize a troubled program. As the business grows, the same approach can create bottlenecks if routine matters still require a CCO’s personal involvement. The leader needs to develop the team and establish clear decision authority while retaining appropriate escalation for significant concerns.

The response should specify where judgment can be delegated, what standards apply, and how quality will be checked. This preserves the value of careful review while changing how it is delivered. A CCO should be willing to examine this possibility candidly. A complaint about delay may reveal poor business planning, an overly centralized compliance process, or both. Correcting one cause does not remove the need to address the other.

Examine Whether the Organization Undermines the Role

Velasquez’s fourth category addresses organizational barriers involving culture, resources, incentives, and decision rights. This is where the implications for compliance independence become particularly significant.

A company may require review before engaging a third party while rewarding executives who commit to start dates before review begins. It may expect timely investigations while restricting access to relevant records. It may ask a CCO to escalate serious concerns and then criticize the escalation as a failure to collaborate.

In each case, evaluate the contradiction alongside a CCO’s response. Coaching the leader to communicate more effectively may help, but it cannot supply missing authority or correct an incentive that rewards bypassing controls. A CCO should document the constraint, its practical consequences, and the proposed correction. Management should identify who will resolve it and by when. Repeated, material barriers belong in discussions with the responsible board committee, particularly when they prevent the function from carrying out agreed responsibilities.

Make Board Support Concrete

Board support for a CCO should be visible in the governance process. Directors need access to an account of significant compliance concerns that explains the facts, management’s response, and any unresolved differences. The responsible committee should also understand the basis for material criticism of a CCO’s performance. Where criticism arises from an executive whose conduct or decisions compliance has challenged, that context warrants examination. It does not automatically invalidate the criticism or establish retaliation.

An appropriately independent review should consider the substance of the concern, how it was raised, and the evidence behind any proposed personnel action. Human resources, legal, and the relevant board leadership should have clear roles consistent with the company’s governance arrangements. Regular private discussions between a CCO and ELT leadership (or the appropriate board committee) can help surface barriers before a performance dispute becomes entrenched. Directors should ask whether compliance has the access, resources, and authority needed to deliver what management expects.

Evaluate Effectiveness With Measures That Fit the Role

An evaluation based heavily on executive satisfaction can discourage necessary challenge. A review based solely on activity counts provides an equally incomplete picture. Assess the quality and timeliness of advice, the prioritization of risk, the development of the team, and the follow-through on significant issues. Consider whether recommendations are supported and whether remediation addresses the underlying problem. Business feedback remains useful when it is specific and examined in context.

The central discipline is to evaluate the work and its consequences. Agreement with management is not a reliable measure of effectiveness; disagreement alone does not demonstrate courage or sound judgment.

Action Steps for the CCO

Use Velasquez’s framework to improve how performance concerns are examined:

  1. Ask for specific evidence. Identify recent events, decisions, and consequences behind broad criticisms. Respond to substantiated concerns directly.
  2. Test all four explanations. Examine skill gaps, outdated reputation, overused strengths, and organizational constraints. Recognize that more than one may contribute.
  3. Agree on meaningful performance measures. Include advice quality, timeliness, prioritization, team capability, and remediation follow-through alongside contextualized business feedback.
  4. Document barriers to effective execution. Record missing resources, restricted access, conflicting incentives, or unclear authority, with proposed corrections and accountable owners.
  5. Establish a credible board review process. Clarify escalation and evaluation arrangements so significant concerns about a CCO and constraints on the role receive informed consideration.

Effective compliance leadership requires both sound judgment and the ability to make that judgment understood. Organizations strengthen accountability when they evaluate those capabilities fairly and address the conditions that prevent a CCO from using them.

Categories
Blog

Does Your Board Have the Expertise and Independence to Oversee Compliance

A board can have impressive credentials and still lack the experience needed to challenge management on the company’s most significant compliance risks. Directors may understand finance, strategy, and operations in broad terms while struggling to recognize how misconduct could arise within a particular business model. Effective oversight requires relevant knowledge and the willingness to use it when the answers become uncomfortable.

For the chief compliance officer, that makes board capability a practical program issue. The quality of oversight influences the questions management must answer, the resources compliance receives, and what happens when a concern conflicts with a commercial priority. Today we examine board composition in the article Measuring Board Fit — Evidence from Elliott’s Campaign at Norwegian Cruise Line, from the Harvard Law School Forum on Corporate Governance. Their analysis uses AI to compare directors’ professional backgrounds with company strategy and with one another. It offers a starting point for a broader compliance question: Does this board have the expertise and independent judgment to oversee the risks this company actually faces?

Look Beyond the Skills Matrix

DesJardine and Mertens argue that conventional skills matrices can conceal meaningful differences in experience. Two directors may receive the same designation for operations or risk management while bringing very different capabilities to the boardroom.

The compliance application is straightforward. A risk management designation should prompt further inquiry into the nature, relevance, and recency of that experience. Has the director overseen a business using intermediaries in difficult markets? Has the director managed the integration of acquired companies? Examined an investigation involving senior leadership? Challenged a compensation structure that encouraged questionable conduct? No director needs to possess every capability. The board and its committees do need an informed basis for questioning management across the company’s priority risks.

The CCO can help define that basis. Translate the risk assessment into the experience and understanding needed for oversight. Where third-party conduct creates substantial exposure, explain the commercial relationships, payment practices, and escalation decisions directors need to understand. This gives the nominating and governance committee a more useful description than a generic request for compliance expertise.

Read the Norwegian Findings Carefully

The authors apply their method to Norwegian Cruise Line Holdings before and after Elliott Investment Management’s campaign, comparing its board with those of three cruise industry peers. They report that the company’s board-to-company similarity score increased from 0.382 to 0.396 following the changes. Average director-to-board similarity declined from 0.729 to 0.701, which they interpret as more distinct professional perspectives.

Those results describe changes in the authors’ measures of professional alignment and overlap. They do not establish that the reconstituted board became more effective at compliance oversight, that individual directors exercised greater independence, or that misconduct risk declined. That distinction matters for CCOs. An assessment can identify questions about composition without answering how directors perform. A board with relevant backgrounds still needs reliable information, sufficient time, and the resolve to follow an issue through. The practical response is to combine an examination of credentials with evidence of the board’s oversight process.

Examine Independence Through the Oversight Process

The authors acknowledge that their method cannot assess integrity, interpersonal skills, or willingness to challenge a chief executive. Those limitations point directly to the independent judgment compliance oversight requires. Consider a hypothetical board discussion about a distributor generating substantial revenue while repeatedly failing to provide requested ownership information. Management recommends extending the relationship during further review. A director with relevant experience may recognize how significant the missing information is. The next question is whether the board presses management to explain the proposed safeguards, decision authority, and consequences of continued delay.

The CCO should help create the conditions for that discussion. Present the facts, uncertainties, available options, and recommendation clearly. Identify who owns the decision and what would trigger escalation. Provide access to the underlying analysis where needed.

Direct access to the responsible committee and opportunities for discussion without management present can support candid oversight. Follow-up is equally important. An unresolved concern should return with updated evidence and a clear account of management’s actions. A difficult question has value when the governance process ensures it receives an adequate answer.

Make Expertise Usable Through Better Information

Even an experienced director can struggle with reports that emphasize activity while obscuring unresolved risk. Assess board capability and reporting quality together. A presentation may show that due diligence reviews are complete without explaining the exceptions approved. Investigation statistics may omit repeated issues within one business unit. Remediation updates may describe actions as finished without showing whether the revised controls work.

A CCO should organize reporting around decisions and consequences. Explain the issue, the evidence, management’s response, and what remains unresolved. When a commercial objective conflicts with a compliance recommendation, make that tension clear. Directors can then apply their experience to a concrete problem. Does the proposed response address the cause? Is the responsible executive accountable for delivery? What evidence will show that the correction is working? These questions help convert professional knowledge into oversight of program effectiveness.

Preserve Perspectives That Challenge Assumptions

The authors examine both alignment with company strategy and similarity among directors. That combination highlights a tension: a board needs relevant experience while retaining perspectives that question the organization’s assumptions. For compliance, industry familiarity can help a director spot questionable practices. It can also leave accepted business conventions insufficiently examined. Experience from another sector may expose weaknesses in customer treatment, escalation, or control ownership that insiders have normalized.

A CCO should therefore avoid equating a closely matched background with superior judgment. Ask what the board needs to understand and where a different perspective could improve its questions. Director education can help close specific knowledge gaps. Sessions built around the company’s actual processes, anonymized matters, and emerging business changes can give directors a better foundation for challenge. Persistent gaps may also warrant discussion of committee expertise or board recruitment, with those decisions remaining with the appropriate governance bodies.

Use AI Assessment as a Diagnostic Input

DesJardine and Mertens use contextualized word embeddings, a technique that turns text into numerical representations, to compare professional and company profiles. The approach can surface similarities that broad categories miss. For a board considering such analysis, the CCO and governance team should ask what information supports each profile and what the resulting score actually measures. Public biographies and media coverage provide an incomplete record of a director’s contributions. The volume and character of available material may differ substantially between candidates.

Company disclosures also describe the organization through a particular lens. Similarity to that description does not necessarily establish the expertise needed to address an overlooked risk or challenge an unsuccessful strategy. Use the output to inform interviews, reference discussions, and committee deliberations. Ask how sensitive the result is to source selection and whether the underlying evidence supports the interpretation. Record significant limitations. A numerical score should help the board investigate a capability question; appointment and evaluation decisions require accountable human judgment.

Action Steps for the CCO

Bring a practical assessment of oversight capability to the next discussion with the committee chair:

  1. Map priority risks to oversight knowledge. Identify what directors need to understand about the company’s business practices, controls, and escalation decisions.
  2. Provide evidence of capability gaps. Work with the corporate secretary and general counsel to inform education and composition discussions, using specific examples rather than broad labels.
  3. Strengthen the conditions for independent challenge. Establish clear access, candid reporting, and follow-up arrangements for unresolved concerns, including matters involving senior management.
  4. Test the usefulness of board reporting. Ensure directors can see material exceptions, recurring issues, remediation evidence, and decisions requiring their attention.
  5. Apply scrutiny to AI assessments. Examine source quality, missing information, and the limits of similarity measures before incorporating results into governance decisions.

Effective compliance oversight depends on directors who understand the company’s risks and are prepared to question how management addresses them. The CCO can strengthen that oversight by making capability needs explicit and ensuring the board receives the evidence needed to exercise its judgment.

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance: The Farewell to Dolly Edition

What happens when two top compliance commentators get together? They talk compliance, of course. Join Tom Fox and Kristy Grant-Hart on 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Stories This Week Include:

  • Meta Settles NYT
  • Dolly Parton Passes Away. NYT
  • Hemma Lomax does it again. FCPA Compliance Report
  • 4 things states can do to combat federal corruption. Just Security
  • AI for email compliance. NJIT
  • JPMorgan Ended Banking Relationship With Polymarket Over Regulatory Concerns – WSJ
  • FTC Warns Retailers on Using Private Consumer Data to Raise Prices – WSJ
  • Why Do Boards Keep Giving Misbehaving CEOs Second Chances? – WSJ
  • Unannounced Compliance Audits: Good, bad or “it depends”? – Ideas & Answers
  • Smokey Bear aids arrest of man accused of stealing, reselling signs of iconic mascot from Florida parks – Click Orlando

Resources:

Kristy

Kristy Grant-Hart on LinkedIn

Order Kristy’s updated 10-year new edition of How to Be a Wildly Effective Compliance Officer by clicking here.

Tom

Check out Tom on LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

Odyssey Week: Leadership – Odysseus the Brilliant Problem: Tone at the Top

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Matt Damon was great as Odysseus.

Odysseus is the kind of leader every board says it wants. He is brave, strategic, persuasive, resilient, creative under pressure, and very good at producing results when the situation looks impossible. He wins wars. He escapes monsters. He talks his way out of death more than once. He is the executive you send into the room when the deal is collapsing, the market is hostile, and everyone else has run out of slides.

He is also, on occasion, his own biggest compliance risk. That is what makes Odysseus so useful for business leaders and compliance professionals. He is not a cartoon villain. He is not reckless in the simple sense. He is brilliant. And brilliance can be dangerous when no one is willing to challenge it.

Odysseus reminds us that tone at the top is not only about what leaders say in polished town halls. It is about how leaders behave when the pressure is real, the stakes are high, and the rules feel inconvenient. The corporate lesson is straightforward: high-performing leaders can create high-performing risk. The organization must be able to challenge its stars.

The Corporate Translation

Every company has an Odysseus. Sometimes he is the rainmaking sales leader who always makes the number. Sometimes she is the visionary founder who can charm investors, customers, regulators, and the board in a single afternoon. Sometimes it is the regional head who delivers growth in difficult markets. Sometimes it is the product leader who moves faster than the control functions can process. The organization loves this person because they win. And that is precisely the problem.

Success can become a shield. Results can become a permission structure. A leader who delivers extraordinary outcomes may slowly become exempt from ordinary scrutiny. Questions that would be asked of anyone else are softened, delayed, or skipped entirely.

  • “How did we win that deal? ”
  • “Why was that third party necessary? ”
  • “Who approved that discount? ”
  • “Why was Legal brought in so late? ”
  • “Why are employees afraid to challenge this person? ”
  • “Why does Internal Audit keep finding exceptions in this business unit? ”

In a healthy culture, these questions are routine governance. In a weak culture, they sound like betrayal. That is the Odysseus problem. He saves the quarter, dazzles the board, and leaves Internal Audit wondering why no one asked how he did it.

Tone at the Top Is Conduct, Not Content

Companies are very good at producing leadership messages. The CEO video. The annual ethics letter. The opening paragraph of the Code of Conduct. The carefully scripted statement that “integrity is our highest value” usually releases the same week everyone is being told to accelerate growth, reduce costs, launch faster, and stop bringing problems without solutions.

Leadership messaging isn’t wrong. It matters. Employees do take cues from senior leaders. The FCPA Resource Guide states that compliance begins with the board and senior executives setting the proper tone and that managers and employees take cues from corporate leaders. It also emphasizes that senior management should clearly articulate standards, communicate them unambiguously, adhere to them, and disseminate them throughout the organization.

Indeed, the Evaluation of Corporate Compliance Programs (ECCP) asks some specific questions. Regarding Conduct at the Top, these questions include: How have they modeled ethical behavior to subordinates? Have managers tolerated greater compliance risks in pursuit of new business or greater revenues? Have managers encouraged employees to act unethically to achieve a business objective or impeded compliance personnel from effectively implementing their duties?

But employees are sophisticated. They listen to the speech, then watch the calendar, the budget, the promotions, the exceptions, and the discipline decisions. They notice who gets praised. They notice who gets protected. They notice whether compliance concerns change decisions or merely create additional paperwork. They notice whether the high performer who bullies employees, ignores controls, or plays games with approvals is treated as a problem or as “complicated.” Tone at the top is not what leadership says when the cameras are on. Tone at the top is what leadership tolerates when the revenue is attractive.

The Danger of the Heroic Exception

Odysseus lives by exception. That is part of his greatness. He survives because he improvises. He adapts. He reads the room, the monster, the god, the storm, and the weakness in every opponent. He does not always follow the obvious path because the obvious path often leads directly into the sea. Unfortunately, exceptions, not properly managed, are what get companies into hot water.

Business needs leaders who can adapt. Compliance should not become a shrine to rigidity. A company that cannot make decisions, approve thoughtful exceptions, or move with commercial urgency will not be admired for its purity. It will simply become irrelevant. But there is a difference between disciplined exception management and heroic exception culture.

Disciplined exception management asks, “What is the risk?” Who owns it? Who approves it? Is the exception documented? Is it time-limited? Are there compensating controls? Will we monitor it? What precedent does it create? Heroic exception culture says, “Odysseus has it handled.” That is not governance. That is mythology with a travel budget. The ECCP asks, “What exceptions to these policies has an organization permitted?”

When organizations build around heroic exceptions, they become dependent on personality rather than process. The leader’s instincts replace controls. Their confidence replaces documentation. Their track record replaces scrutiny. Their urgency replaces escalation.

Eventually, the organization is no longer asking whether the decision is right. It is asking whether it trusts the hero. That is a dangerous way to run a company. Always remember: trust, but verify.

Pressure to Perform Changes the Ethical Weather

Tone at the top is inseparable from pressure. Leaders may say all the right things about ethics and compliance, but if every business conversation ends with “just get it done,” employees hear the real message. If compensation rewards only revenue, employees hear the real message. If managers who raise concerns are labeled as blockers, employees hear the real message. If compliance is praised in public and bypassed in private, employees hear the real message.

The ECCP asks how senior leaders, through words and actions, have encouraged or discouraged compliance, how they have modeled ethical behavior, and whether managers have tolerated greater compliance risks in pursuit of new business or greater revenues. It also asks whether managers encouraged employees to act unethically to achieve a business objective or impeded compliance personnel from doing their jobs.

That is an excellent test for any leadership team. Not, “Did we say integrity matters? But did our conduct make integrity practical? “A leader who sets impossible targets and then expresses surprise when employees cut corners has not created a compliance culture. He has created plausible deniability. Odysseus often survives impossible pressure. Companies should be careful about asking employees to do the same.

Challenging the Star Performer

The true test of tone at the top is whether the organization can challenge its stars. Can compliance question the top sales executive? Can internal audit review the founder’s favorite business unit? Can Legal slow down the CEO’s preferred acquisition? Can HR investigate a high-performing manager accused of retaliation or harassment? Can Finance reject revenue recognition pressure from a powerful regional leader?

Or does the organization quietly apply one standard to ordinary employees and another to those who deliver? Employees do not need a formal policy memo to understand a double standard. They see it immediately. If a junior employee is disciplined for a policy violation while a senior leader is “coached” for comparable conduct, the culture learns. If a high-performing executive is allowed to mistreat people because “the business is too important,” the culture learns that compliance matters only when it doesn’t affect the powerful. If compliance concerns disappear when they involve influential leaders, the culture learns that compliance matters only when it doesn’t affect the powerful.

The ECCP looks at whether compliance is enforced consistently and whether consequences apply regardless of an employee’s position or title. It also asks whether managers are held accountable for misconduct that occurred under their supervision and for supervisory failures. That is not just enforcement logic. It is cultural logic. A company cannot claim integrity as a value while treating performance as immunity.

What a Better Program Does

A better compliance program does not try to eliminate Odysseus. That would be both impossible and unwise. Organizations need bold leaders. They need commercial courage, strategic imagination, persuasive ability, and the confidence to act in uncertainty. The goal is not to make leaders timid. The goal is to make leadership accountable.

A better program builds controls around high-risk authority. It monitors exceptions. It reviews pressure points. It includes compliance in strategic decisions early. It gives the board visibility into recurring overrides, hotline trends, audit findings, employee turnover, and control failures in high-performing units. It trains senior leaders not only on rules but also on how their behavior shapes risk. It also asks uncomfortable questions about success.

Where are results unusually good? Where are margins unusually high? Where are approvals unusually fast? Where are complaints unusually low? Where do people say, “That is just how that leader operates”? Where does the company rely on one person’s relationships, instincts, or influence more than on process? Those are Odysseus questions. The point is not to assume misconduct. The point is to understand that extraordinary performance deserves thoughtful scrutiny, not blind applause.

The Compliance Takeaway

Odysseus is brilliant. That is why he is dangerous. He shows us that leadership risk does not always arrive as laziness, incompetence, or obvious corruption. Sometimes it arrives as charisma. Confidence. Commercial success. Strategic genius. The leader who always finds a way.

Tone at the top means ensuring that even the most successful leaders operate within the company’s values, controls, and accountability structures. It means the Board of Directors and senior executives must model ethical conduct not only in speeches but also in decisions. (Talk the Talk but also Walk the Walk.) It means performance is celebrated but not worshiped. It means the organization can ask its heroes hard questions before the journey turns into an investigation. Every company needs leaders who can win. But no company should become so dazzled by Odysseus that it forgets to check the map, inspect the ship, and ask what happened to the crew.

Join Us Tomorrow

Odysseus reminds us that brilliance can become risk when success turns into a shield, exceptions become heroic, and no one is willing to challenge the leader who always finds a way. But even the most brilliant leader eventually leaves the room, and that is when the next compliance test begins: whether governance survives without the hero. Telemachus inherits the house Odysseus left behind, where authority is uncertain, informal power has filled the gaps, and bad actors have grown comfortable at the table. If Odysseus asks whether top performers are held to the same standards as everyone else, Telemachus asks the follow-up question every board should fear: when the indispensable leader is gone, does the compliance program still work, or was it only working because Odysseus was there?

Categories
Blog

Odyssey Week: Leadership – Athena in the Boardroom: Independent Oversight and Counsel

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Zendaya was great as Athena.

Athena does not row the ship. She does not lash herself to the mast, fight the Cyclops, navigate Scylla and Charybdis, or drag Odysseus’s crew away from every bad decision they seem determined to make. She is not in the trenches every day. She does not submit expense reports, approve vendors, review discount requests, or sit through the quarterly business review where someone explains why this deal is “strategic.” But Athena changes the journey.

She sees what Odysseus cannot see. She warns. She guides. She challenges. She protects. She appears at decisive moments when courage alone is not enough, and cleverness is about to become self-harm with better branding. That is why Athena belongs in the boardroom.

For corporate compliance, Athena represents independent oversight and wise counsel: the person, function, or governance body able to say, “That may win the deal, but it may also wreck the kingdom.” A compliance function that cannot challenge leadership is not Athena. Rather, it is simply decoration to meet a legal, statutory, or contractual requirement.

The Corporate Translation

Every company says it values compliance independence. The question is what that means when the business wants something. It is easy to celebrate compliance when compliance supports the decision already made. It is easy to invite the Chief Compliance Officer (CCO) to the meeting after the deal is signed, the press release is drafted, and the train has left the station with several questionable third parties in the dining car. That is not independence. That is archaeology.

Independent oversight means compliance has the authority, access, and resources to influence decisions before risk is accepted. It means the board hears directly from compliance. It means escalation does not depend on whether a business leader feels emotionally prepared for bad news. It means compliance can challenge high performers, powerful executives, and sacred business strategies without being treated as disloyal.

Athena does not exist to admire Odysseus. She exists to help him survive himself.

Access Is Not the Same as Influence

Many compliance officers technically have access to leadership. They attend meetings. They submit reports. They provide updates. They own several slides in the board deck, usually after cybersecurity and before “other business.” But access is not the same as influence.

Real access means compliance can raise concerns in a setting where they matter. It means there are private sessions with the board or audit committee. It means compliance can speak without management filtering, softening, or translating the message into something more comfortable. It means the board asks questions that go beyond “Any major issues?” which is the governance equivalent of asking a teenager whether school was fine.

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) focuses directly on whether compliance and control functions have autonomy and resources, including sufficient stature, sufficient staffing and resources, and autonomy from management, such as direct access to the board or audit committee. That is not a technical footnote. It is a central governance point. If the compliance function only reaches the board through management, the board may be hearing the music after someone else has adjusted the volume.

Authority Must Be Real

A compliance function without authority is like Athena without wisdom: impressive in name only. Authority means compliance can stop, modify, or escalate a transaction. It means policies are not optional when revenue is large enough. It means compliance concerns are documented, tracked, and resolved. It means the business must explain why it wants to proceed despite risk, not merely pressure compliance to “be practical.”

Practical compliance is not weak compliance. Practical compliance helps the business find a lawful and ethical path forward. But there is a difference between being practical and being domesticated. A good compliance function does not say no for sport. It says no when the facts, risks, and values of the company require it. It says, “not that way.” It says, “not with that intermediary.” It says, “not without diligence.” It says, “not until we understand the data, the customer, the payment, the conflict, or the control failure.”

The ECCP specifically asks how a company has responded when compliance raised concerns and whether transactions or deals have been stopped, modified, or further scrutinized because of compliance concerns. That is the right question. The ECCP states at one point, “Have they persisted in that commitment in the face of competing interests or business objectives?” Not whether compliance attended the meeting. Whether compliance changed the outcome. The ECCP further asked, “What role has compliance played in the company’s strategic and operational decisions? How has the company responded to specific instances where compliance raised concerns? Have some transactions or deals been stopped, modified, or further scrutinized as a result of compliance concerns?”

Resources Are a Statement of Values

Companies reveal what they value through budget. A board can praise compliance all day long. Still, if the function lacks staffing, technology, data access, training budget, investigative resources, and experienced personnel, the message is clear: “We support compliance, but preferably at a discount.”

No one would ask sales to grow revenue without systems, people, and market data. No one would ask finance to close the books with three spreadsheets, two interns, and a heroic attitude. Yet compliance teams are often expected to monitor global risk with underpowered tools and just enough headcount to keep the training completion dashboard from turning red.

That is not empowerment. That is wishful thinking. The ECCP asks whether compliance personnel have sufficient staffing to audit, document, analyze, and act on compliance efforts, whether resources are comparable to other parts of the company, and whether compliance has access to relevant data for timely monitoring and testing. Regarding funding and resources, the ECCP asks, “Has there been sufficient staffing for compliance personnel to effectively audit, document, analyze, and act on the results of the compliance efforts? Has the company allocated sufficient funds for the same? Have there been times when requests for resources by compliance and control functions have been denied, and if so, on what grounds? Does the company have a mechanism to measure the commercial value of investments in compliance and risk management?”

Those questions should make boards uncomfortable in a productive way. If the business has world-class tools to capture opportunity but outdated tools to detect risk, that imbalance is itself a governance decision.

Escalation: The Road from Concern to Action

Athena’s guidance matters because it reaches Odysseus when action is still possible. That is also the purpose of escalation. A well-designed escalation process moves concerns to the right people at the right time with enough information to make a decision. A weak escalation process traps concerns in email chains, local management reviews, or “let’s monitor this” limbo until the problem becomes a reportable event, a whistleblower complaint, or a headline.

Escalation should not depend on personality. It should not depend on whether the compliance officer is unusually persistent, politically skilled, or willing to become unpopular before breakfast. It should be built into governance.

What must be escalated? To whom? Within what timeframe? With what documentation? What happens when business and compliance disagree? Who decides? How are unresolved concerns reported to senior leadership or the board? These are not theoretical questions. They are the mechanics of wise counsel. Because without escalation, Athena is whispering in a locked room.

The Board’s Role: Ask Better Questions

Boards do not need to manage the compliance program day to day. That is not their role. But boards do need to oversee whether the program is real. That means asking better questions. The board should also pay attention to the moments when compliance loses. If compliance raised concerns and the business proceeded anyway, what happened? Was the decision documented? Were compensating controls added? Was the board informed? Did the risk later materialize? You learn a great deal about culture by examining what happens when wise counsel is inconvenient.

The Compliance Takeaway

Athena does not represent bureaucracy. She represents judgment. That distinction matters. Compliance officers are sometimes caricatured as the people who slow things down, complicate decisions, or drain the romance out of heroic commercial ambition. But the best compliance functions do something far more important: they help the organization see clearly before it acts.

They bring risk into the room. They challenge assumptions. They protect the company from cleverness without discipline. They help leaders understand that winning the deal, entering the market, launching the product, or pleasing the customer is not success if the path taken damages the company’s integrity.

Independent oversight is not ceremonial access. It is authority, resources, escalation, data, board engagement, and the organizational courage to let compliance challenge power. Odysseus needed Athena because brilliance has blind spots. So does every company.

The question is whether your Athena is truly in the boardroom or merely listed on the org chart.

Join us Tomorrow

Athena teaches that independent oversight is not ceremonial access but real authority, resources, escalation, data, board engagement, and the courage to let compliance challenge power. But that lesson only matters if the organization is willing to apply it to its most celebrated leaders, not merely its easiest targets. That brings us to Odysseus: the brilliant, strategic, results-driven leader every board wants and the very leader who can become the company’s most dangerous compliance risk when success becomes a shield. If Athena is the voice saying, “That may win the deal, but it may also wreck the kingdom,” Odysseus is the leader who wins the deal and forces the organization to ask whether anyone had the authority, courage, and independence to challenge how he did it. I hope you will join us tomorrow.

Categories
Blog

Dolly Parton and the Compliance Value of a Life Well Governed

Dolly Parton died this week. Her death closed one of the most remarkable careers in American entertainment, but it did not close the institutions, ideas, and expectations she built. For corporate compliance professionals, that durability is what makes her story more than a tribute. It becomes a lesson in how values can be converted into governance. Today I want to honor Parton, what she did, and what she stood for, and perhaps hope that her life will inspire all of us to be just a little better.

Parton was one of twelve children. Parton began singing on local radio and television as a child and appeared at the Grand Ole Opry at thirteen. She wrote her first song at age 6. She moved to Nashville after high school, established herself as a songwriter, and became a national star through The Porter Wagoner Show. She then built a solo career that crossed country, pop, film, television, theater, publishing, tourism, and philanthropy. She recorded more than fifty albums, wrote roughly 3,000 songs, won ten Grammy Awards, and created works such as “Jolene,” “I Will Always Love You,” and “9 to 5” that became part of the American vocabulary. One of the most amazing facts I learned while researching this piece was that “Jolene” and “I Will Always Love You” were written on the same day. How is that for creative inspiration?

Parton did not run a corporate compliance program, and her career should not be forced into that frame. Yet she demonstrated something every CCO and Board of Directors needs to understand: culture becomes credible when stated values, hard decisions, operating systems, and visible conduct reinforce one another over time. Her public identity rested on kindness, independence, dignity, humor, and respect. She repeatedly made those commitments tangible in contracts, businesses, philanthropy, and crisis response.

Her entrepreneurship deserves equal attention. Parton moved from performer to owner, producer, publisher, and partner, most visibly through Dollywood and the enterprises built around it. The portfolio was diverse, but it was not random. Music, storytelling, family entertainment, Appalachian identity, hospitality, and community investment all reinforced a coherent promise. Compliance professionals should recognize the governance advantage of that clarity. Diversification creates new legal, operational, third-party, and reputational risks, but a stable purpose helps leaders decide which opportunities fit, which controls must travel with the business, and which deals to decline.

Independence Before Applause

Parton understood the difference between access to power and surrender to it. She left Porter Wagoner in 1974 to build an independent career, expressing gratitude for the partnership without allowing it to define her future. She later declined an opportunity for Elvis Presley to record “I Will Always Love You” when his manager demanded a share of the publishing rights—saying no cost her an extraordinary short-term opportunity. Retaining ownership preserved the long-term value of her work, especially when Whitney Houston’s recording became a worldwide success. Business Insider called it “her smartest business move.”

That decision should resonate with compliance leaders. Independence is not a paragraph in a charter. It is the authority to resist pressure when revenue, status, or a powerful executive makes acquiescence attractive. A CCO needs direct access to the board, control over investigative escalation, sufficient resources, and protection against retaliation. Chuck Watson once said, “Sometimes the best deal is the one you don’t make.” A board should test whether that independence works when it is expensive, inconvenient, and unpopular. If compliance can say no only when nothing important is at stake, it is not independent.

Purpose Made Operational

Parton’s philanthropy offers an equally powerful lesson in program effectiveness. She created the Dollywood Foundation in 1988 to improve educational outcomes in her home county. Its Buddy Program paired students and offered a financial incentive for graduation; the dropout rate for the participating classes fell from 35 percent to 6 percent. In 1995, inspired by her father’s inability to read and write, she launched the Imagination Library. What began in Sevier County became a network operating across five countries that has delivered more than 300 million free books to young children.

This was not the purpose of branding. It was purpose translated into a defined population, a repeatable delivery model, local partnerships, funding, data, and measurable results. That is the same transition the Department of Justice asks companies to make when it evaluates whether a compliance program is well designed, adequately resourced, and working in practice. A value in the code of conduct must become an owner, a control, an escalation path, testing, and remediation. Intent is the beginning of a compliance program, not proof of one.

Listen to the People Who Experience Power

Parton’s film and song “9 to 5” gave popular form to workplace realities many employees already knew: power can be abused, unfairness can become routine, and people with the least authority often carry the greatest burden. The song endured because it recognized the lived experience behind organizational charts. It made a workplace issue visible without turning the people affected into abstractions.

Compliance programs fail when they listen only upward. Hotline statistics, exit interviews, culture surveys, investigation themes, retaliation allegations, and manager-level trends must reach leaders in a form that supports action. Boards should ask whether employees believe they can speak without losing status, opportunity, or employment. They should also ask whether the organization learns from weak signals before they become red flags. A speak-up system is not effective because a telephone number exists. It is effective when people trust the process and see consistent, fair outcomes.

Trust Earned Through Response

Parton’s businesses remained closely connected to the community that formed her. Dollywood became Sevier County’s largest employer, while its stated operating culture emphasizes hospitality, authenticity, collaboration, and respect. The company supports employee development, including tuition assistance. When wildfires devastated East Tennessee, Parton helped organize direct support for affected families. During the COVID-19 pandemic, her $1 million gift established a Vanderbilt research fund that supported work connected to the Moderna vaccine.

The compliance lesson is that reputation is a lagging indicator of accumulated conduct. Trust is built before a crisis through thousands of ordinary decisions about employees, customers, communities, and counterparties. A crisis tests it through the speed, fairness, transparency, and competence of the response. A company cannot purchase credibility with a campaign after years of contrary conduct. The best crisis communication remains a well-governed response supported by facts, accountable owners, and visible follow-through.

A Board Agenda Worthy of the Lesson

Parton’s legacy was unusually broad, but its organizing logic was simple. Know what matters. Protect it when pressure arrives. Build systems that carry values beyond the founder. Listen to people whose voices are easiest to overlook. Measure whether the work changes outcomes. Repeat the conduct long enough that stakeholders can rely on it.

  • For directors, that logic produces five practical questions. What principles will the company not trade away for a transaction or quarterly target?
  • Does the CCO possess real independence, resources, information, and access?
  • Which data prove that stated values operate at the employee and third-party level?
  • Are speak-up and investigation systems producing trust, learning, and remediation?
  • When the company faces a crisis, can the board see decisions, owners, deadlines, testing, and closure rather than a record showing only that management made a presentation?

Dolly Parton understood that a carefully created image can open a door, but only character and performance can keep it open for seven decades. Compliance leaders often describe their goal as building a culture of integrity. Her career reminds us what that requires: independent judgment, operational discipline, attention to the less powerful, measurable impact, and consistency when no applause is guaranteed. That is not only a fitting business lesson from her life; it is a demanding standard for every organization that wants to be trusted.

Categories
Blog

Boeing, Caremark, and the Evidence of Good-Faith Oversight

On August 13, 2026, the Delaware Court of Chancery dismissed claims arising from the January 2024 Alaska Airlines door-plug blowout. A door plug left Boeing’s factory without four securing bolts, the FAA grounded the aircraft, and investigations identified production and quality problems. Yet corporate trauma did not establish bad-faith board oversight. The question was what the directors knew, what systems delivered that information, and how the company responded. For a Chief Compliance Officer, that distinction is the heart of the case. Boeing showed what evidence of conscientious oversight can look like. The Boeing Derivative Litigation, Consol. C.A. No. 2024-1210-MTZ (Del. Ch. Aug. 13, 2026) (the “Opinion”).

This decision continues the evolution of the Caremark Doctrine and details what Boards of Directors need to consider to meet their obligations under the Caremark Doctrine. For compliance professionals, this case should be studied for not only its substantive analysis but also for how you will need to train.

Caremark Still Asks Two Hard Questions

Caremark liability is rooted in the duty of loyalty and bad faith, not negligence or a poor outcome. Directors may face liability if they fail to implement a reporting system or if they establish one but consciously fail to monitor it, preventing themselves from learning about problems that require attention. The required state of mind is an intentional dereliction of duty or conscious disregard of known responsibilities. A flawed effort is not the same as no good-faith effort.

That standard should not become a message that directors are protected unless they do nothing. Directors must demonstrate how they tried. Fiduciaries who implement and attend to a reasonable board-level reporting system meet the baseline duty. Even for mission-critical operations, “Caremark does not demand omniscience.” The Board’s task is therefore not perfect foresight. It is disciplined attention.

The Record That Protected the Board

The most useful part of the Opinion for compliance professionals is its description of Boeing’s governance machinery. The board met at least every two months, and airplane safety was discussed at every meeting. Management provided commercial-airplane updates on safety, quality, operational performance, and production targets. A Chief Aerospace Safety Officer delivered global safety updates twice each year.

Boeing also had an Aerospace Safety Committee with directors experienced in engineering, manufacturing, aerospace, aviation, or safety. It met at least 23 times from January 2022 through July 2024. Reporting included safety risk registers, in-service safety reports, Speak Up updates, and special-attention reports. Significant safety incidents or regulatory actions were to be reported to the board or committee within 24 hours or as soon as reasonably practicable. The Audit Committee separately monitored internal controls, legal compliance, the DOJ deferred prosecution agreement, and FAA obligations.

After the door plug incident, the Aerospace Safety Committee met within a day, met again twice during the following week, and arranged an onsite factory inspection. That record did not erase the operational failure. It demonstrated an active reporting and response system.

An analysis from the law firm of Sullivan & Cromwell, whose authors’ firm represented Boeing and the defendants, makes the same point: mission-critical reporting, clear committee mandates, escalation channels, and contemporaneous records can be decisive when a court examines good faith. “Delaware Court of Chancery Reinforces Limits on Oversight Liability; Stresses Importance of Conscientious Board Oversight,” Harvard Law School Forum on Corporate Governance (the “S&C Analysis”).

Train Directors to Distinguish Red from Yellow

Plaintiffs characterized dozens of reports on manufacturing and safety risks as ignored red flags. The Court rejected that theory because it threatened to convert the “volume and depth” of reporting from a best practice into evidence of disloyalty. As the defendants put it, “If everything is a red flag, then nothing is.”

Recurring adverse information is not harmless, but the board must classify and connect it. A Caremark red flag must put directors on notice that the company is violating law or headed toward specific corporate trauma. It must also connect to the misconduct that caused the loss. General operational risks under active remediation may instead show that reporting is functioning. The Court described yellow flags involving operational risk, management responses, or matters insufficiently tied to the door-plug incident.

Board training should therefore require directors to ask three questions whenever adverse information arrives: Is this a business risk or a legal compliance risk? What is management doing about it? What facts would require escalation, independent verification, or a change in strategy?

Business Judgment Has a Boundary

The Opinion also distinguished business risk from positive law. Production schedules and the management of ordinary operational risk generally receive business-judgment deference. Directors, however, have no discretion to cause the company to violate the law knowingly.

The plaintiffs argued that Boeing’s production goals favored profits over safety. The Court found no particularized allegation that the targets themselves violated the law or that directors pursued a lawbreaking strategy. The record also showed that Boeing adjusted targets, delayed production increases, and evaluated staffing, quality, supply chain, and factory-health risks. Those actions supported an inference of good-faith business judgment, not conscious disregard.

For directors, the training point is not that every production decision is insulated. The board should understand where business discretion ends, and legal obligation begins. Compliance should identify the applicable mandates, show how they enter board reporting, and specify which thresholds require action rather than monitoring.

Books and Records Are Part of the Control Environment

The plaintiffs obtained extensive books and records describing committee responsibilities, recurring reports, risk metrics, remediation, and post-incident response. The record used to challenge the directors also demonstrated their engagement.

This is not a reason to create defensive minutes. It is a reason to create accurate, decision-useful records. Minutes should capture material questions, requested follow-up, commitments, and unresolved issues. Dashboards should show trends and control effectiveness, not merely activity. Closed items should include validation. Elevate persistent issues rather than repeatedly relabeling them. As the S&C Analysis observes, contemporaneous records can be critical because the court examines what the board received, whether it signaled obvious illegality or specific trauma, and how directors and management responded.

Five Questions For Your Board

  1. Mission-critical risk. Which legal, safety, compliance, cybersecurity, or operational risks could threaten the company’s viability, customers, or license to operate? The board should identify these risks based on the company’s industry, regulatory obligations, business model, and risk profile. Directors should understand which controls address each mission-critical risk and which executives are accountable for operating them. Compliance should periodically test whether the board’s risk priorities remain aligned with changing regulations, business operations, and emerging threats.
  2. Reporting architecture. Which committee owns each risk, what information reaches it, and through which escalation channel? Committee charters should assign clear oversight responsibility and prevent material risks from falling into gaps between the board and its committees. Directors should receive decision-useful information, including trends, control failures, remediation progress, and emerging exposure, rather than raw operational data. The reporting architecture should also define when management must escalate an issue from a committee to the full board.
  3. Red-flag discipline. What criteria distinguish ordinary variance, a yellow flag requiring remediation, and a red flag requiring Board action? Management and the board should establish objective escalation thresholds based on legal exposure, customer harm, financial impact, recurrence, control failure, and the possibility of significant corporate trauma. Yellow flags should receive documented remediation plans, accountable owners, deadlines, and continuing monitoring. Red flags should trigger prompt board attention, independent inquiry where appropriate, and documented decisions about containment, investigation, disclosure, and corrective action.
  4. Response evidence. Do minutes and dashboards show questions, decisions, owners, deadlines, testing, and closure, or only that a presentation occurred? Board records should demonstrate that directors engaged with material information, challenged management assumptions, and requested appropriate follow-up. Dashboards should track remediation through completion and include evidence that corrective actions were tested for effectiveness. Minutes should accurately capture the substance of your Board’s oversight without becoming defensive narratives or sanitized accounts of difficult discussions.
  5. Speak-up integrity. Can employees raise concerns without retaliation, and does the board receive meaningful information about allegations, investigations, trends, and corrective action? Directors should understand how reports are received, triaged, investigated, escalated, and resolved across the organization. Board reporting should address substantiation rates, recurring allegations, investigation delays, retaliation claims, root causes, and remediation effectiveness. Your Board should also evaluate whether employees trust the reporting system and whether management responds consistently regardless of the seniority or business importance of the individuals involved.

Boeing continues to provide a wealth of lessons learned for compliance professionals. The Delaware Court Opinion reminds us that the Caremark Doctrine offers neither immunity nor a checklist safe harbor. It reminds boards that the Caremark Doctrine is tested through evidence of good-faith effort. Compliance must build that effort into governance before the next crisis and ensure the record shows that directors received, understood, challenged, and followed through on critical information.

Categories
Blog

From Policy to Proof: Six Compliance Priorities for the Next 90 Days

Editor’s note: I am a columnist for Compliance Week.

Compliance Week recently released its Practitioner’s Briefing, which “is crafted as a high-level recap of Compliance Week’s 2026 National Conference (CW 26), held in Washington, D.C., in May. Whether you were there or wished to be, this briefing will bring you up to speed. The briefing captures the six themes that pervaded three days of panel discussion and the networking conversations between them, with practical actions you can implement in the next ninety days.”

The compliance profession is entering the proof era. Policies still matter, but regulators, boards, and employees are asking a harder question: Can the organization demonstrate that its controls operate in practice? That is the central lesson from the Practitioner’s Briefing. Across six themes, the briefing describes a function under pressure from rapid AI adoption, faster whistleblower timelines, redistributed enforcement, expanding third-party exposure, and sharper board expectations.

Today I want to explore the themes and initiatives from the Practitioner’s Briefing. This is not about six disconnected initiatives covered at CW 26. It is an operating model that connects governance, data, accountability, and escalation around existing risks. You can use the next 90 days to produce evidence that the program knows where its risks sit, who owns the controls, how failures surface, and what happens next.

AI Governance: Accountability Must Follow Adoption

AI makes the policy-to-proof gap visible. The Practitioner’s Briefing reports that 83 percent of compliance functions have AI in production, while only 25 percent of leaders are confident in the governance controls. That is not primarily a policy problem. It is an ownership and control-design problem.

Start with your AI inventory. A defensible AI register should identify the tool, approved use case, business owner, data involved, vendor, model, access rights, validation method, human reviewer, retention rule, incident path, and kill-switch authority. Tool approval by IT cannot substitute for use-case approval by Legal, Compliance, Privacy, Security, and the accountable business leader. One platform may be acceptable for drafting training content and unacceptable for evaluating employees or third parties.

The NIST AI Risk Management Framework and ISO/IEC 42001 can help organize this work, but a framework is not the control. The control is the approval record, test result, exception log, monitoring evidence, and documented decision. Compliance should also assume that prompts, summaries, transcripts, and agent logs are discoverable business records. Retention and legal hold procedures must catch those artifacts before the first dispute or investigation forces the question.

AI in Compliance Operations: Redesign the Work

The Practitioner’s Briefing draws a useful line between AI enablement and AI theater. Strong programs redesign a workflow around AI. Weak programs bolt AI onto a slow process and call it transformation. Due diligence, regulatory tracking, training development, and self-service policy guidance are sensible starting points because the work can be scoped, tested, and measured.

Each deployment needs acceptance criteria. Validate performance against known outcomes, constrain source material where accuracy matters, monitor drift, require human review for high-risk decisions, and define escalation when the system is uncertain. Measure return on investment first in hours returned to higher-value work. Faster output that creates more review, remediation, or false confidence is not efficiency. It is control debt.

Speak-Up and Investigations: Trust Is the Control

The Practitioner’s Briefing reports that eight in ten US employees witnessed misconduct during the prior year, yet fewer than three-quarters reported it. That gap is not solved by adding another intake channel. It is solved by showing employees that reporting is safe, fair, and consequential.

One of the Practitioner’s Briefing’s most practical recommendations is to audit the career outcomes of the last 20 employees who raised concerns. Review performance ratings, promotions, transfers, compensation, leave, and departures. Patterns in those records may reveal retaliation or career stagnation that hotline statistics will never show. Pair that review with defined post-report monitoring and documented check-ins with reporters.

Speed is now part of program effectiveness. The briefing highlights a 120-day DOJ window to investigate qualifying internal reports and decide whether voluntary self-disclosure is appropriate. CCOs should calendar that period, establish rapid triage, identify decision rights, preserve evidence immediately, and maintain a standing disclosure team. The goal is not a rushed conclusion. The goal is to prevent delay, unclear ownership, or inadequate resources from deciding for the company.

Enforcement Has Shifted, Not Disappeared

Lower federal case counts are not a safe harbor. The Practitioner’s Briefing describes enforcement as redistributed across state Attorneys General, self-regulatory organizations, the False Claims Act, and future matters still inside applicable limitation periods. A quieter headline environment can encourage exactly the wrong management response: reduced staffing, deferred remediation, and lower investment in controls.

The business discipline is straightforward. Monitor the full enforcement ecosystem, not one federal docket. Maintain the strictest applicable standard as the practical global baseline. Preserve the ability to investigate, cooperate, remediate, and disclose. Most importantly, do not confuse a change in enforcement cadence with a change in underlying legal or ethical risk. Today’s control gap may simply be tomorrow’s case.

Third-Party Risk: Manage the Entire Lifecycle

Third-party risk management is no longer a narrow anti-bribery process. The Practitioner’s Briefing places sanctions, forced labor, transnational crime, material support exposure, supply-chain integrity, and embedded AI inside the modern TPRM remit. That expansion requires a move from onboarding diligence to lifecycle control.

Monitor material relationships from selection through offboarding, with risk-based refreshes, event-driven alerts, beneficial ownership checks, adverse media review, and clear remediation ownership. For AI-enabled vendors, procurement should require disclosure of material fourth- and fifth-party dependencies. Contract terms should address model provenance, data lineage, audit rights, incident notice, control changes, and the ability to explain consequential decisions.

List screening alone is increasingly thin protection. High-risk supply chains may require route mapping, chokepoint analysis, and source-verified information reviewed in context by humans. AI can compress the initial diligence cycle, but it does not replace judgment on coercion, shell companies, access payments, or other facts that demand legal and operational analysis.

Board Reporting and Culture: Lead With the Problem

Directors want a compliance report that begins with bad news, explains the risk, and shows the response. That is the board-reporting message in the Practitioner’s Briefing. Activity counts belong in the appendix. The main discussion should address control failures, investigation aging, retaliation indicators, overdue high-risk diligence, AI exceptions, remediation status, and emerging exposure compared with peers.

This approach also supports a Caremark-style oversight record. The board needs credible information systems, timely escalation of red flags, and evidence that management and directors responded. A between-meetings protocol with the audit or risk committee chair is therefore a control, not a courtesy.

Culture is equally operational. The briefing reports that direct managers and immediate colleagues exert the strongest influence on 80 percent of employees, while only 58 percent of organizations evaluate how results were achieved. Compliance should train managers to receive concerns, audit incentives as rigorously as financial controls, and make conduct part of performance and promotion decisions. The real code of conduct is what the organization rewards, tolerates, and corrects.

A 90-Day Agenda for CCOs

  1. Build the evidence map. Select the highest-risk obligations in AI, investigations, and third-party management. For each one, identify the owner, control, evidence, escalation path, and board metric.
  2. Test AI governance. Reconcile the official AI inventory with procurement records, browser access, expense data, and employee attestations. Review several approved use cases from request through monitoring.
  3. Stress-test investigations. Tabletop a significant internal report against the 120-day decision window. Confirm preservation, privilege, staffing, disclosure authority, and board communication.
  4. Rebuild TPRM around lifecycle risk. Segment critical third parties, define continuous-monitoring triggers, review AI dependencies, and assign remediation deadlines with accountable owners.
  5. Change the board report. Put the three most significant problems first. Add peer comparison, trend data, remediation aging, and decisions required from the board or management.

The Compliance Lesson

The Practitioner’s Briefing is not fundamentally a technology story or an enforcement story. It is a program-effectiveness story. The effective compliance function can identify risk, assign accountability, test controls, learn from failures, and show its work. Policies establish expectations. Evidence establishes credibility. In the next 90 days, that distinction should drive the agenda of every CCO, executive team, and board committee responsible for corporate integrity.

Categories
Blog

THE BERKO TRIAL – PART 5: From Case Study to Control Test: A Berko Compliance Playbook for CCOs and Boards

Today we conclude our 5-part deep dive into the Asante Berko trial and guilty verdict, using the trial not simply as a case study but as a mechanism to pressure-test your compliance regime.

A compliance program is not effective because the company eventually exits a troubled transaction. It is effective when leaders can show how quickly the system identified the risk, who had authority to act, whether related conduct was contained, what the investigation established, and how the organization changed afterward.

That is the governance test presented by the Berko trial. Prosecutors built their case from emails, payment patterns, personal communications, compliance questions, recorded statements, and financial evidence. The defense attacked the missing last mile. The jury convicted Asante Berko on all three counts in just over three hours. For CCOs and boards, the final lesson is not to retry the case. It is to determine whether their own program could identify the same pattern, develop reliable facts, impose accountability, and respond at the speed enforcement policy now demands.

Start With the Three Questions That Matter

The DOJ Evaluation of Corporate Compliance Programs (ECCP) organizes program effectiveness around three questions. (1) Is the program well designed? (2) Is it applied earnestly and in good faith, with adequate resources and authority? (3) Does it work in practice? Those questions should frame the board’s review of the Berko fact pattern.

A written third-party policy answers the first question only in part. The second asks whether compliance can pause a revenue-producing transaction, obtain records, challenge senior employees, and reach the board without management filtering. The third asks for outcomes: when the warning signs appeared, did the organization find them, act on them, preserve the evidence, and fix the control weakness?

The governance failure is often not the absence of a rule. It is the gap between ownership and authority. Management owns business conduct and risk decisions. The CCO advises, challenges, monitors, and escalates. Internal audit provides independent assurance. The board oversees the system and management’s response. If every party assumes another function owns the hard decision, the control exists on paper but fails in operation.

Align Incentives, Conflicts, and Consequences

High-risk transactions require a clear view of personal incentives. Employees should disclose and pre-clear outside interests, referral compensation, client-paid benefits, expected success fees, and post-employment opportunities connected to current transactions. Offboarding should preserve relevant data, review pending payments, close access, identify continuing client contacts, and obtain certifications concerning outside interests and retained information.

Compensation deserves the same scrutiny as third-party payments. A bonus plan that rewards closing without measuring risk quality invites employees to treat compliance as a cost of delay. Risk-adjusted incentives should account for diligence completion, control compliance, escalation quality, and the durability of the business outcome. The ECCP asks whether companies use incentives for ethical conduct and apply discipline consistently across seniority, geography, and business unit. It also asks whether compensation can be deferred, reduced, canceled, or recouped when misconduct is established, subject to applicable law.

Consequence management must reach more than the direct actor. A credible process examines supervisory failure, tolerated red flags, obstruction, and failure to install or use safeguards. It applies the same decision framework to rainmakers and junior employees. The board should receive trend information showing investigation cycle times, substantiation rates, disciplinary consistency, repeat issues, and whether managers were held accountable for control failures.

Build Investigation and Speak-Up Readiness

The defense’s attack on the Berko evidence offers an investigation lesson. A source may have motives. A recording may require translation. Emails may lack a witness who can explain context. Payments may be traceable to an intermediary but not to an ultimate recipient. Those are reasons to investigate carefully, not reasons to dismiss an allegation.

Separate source credibility from objective proof. Preserve native emails, attachments, metadata, messaging records, payment instructions, approval histories, and device data. Trace funds beyond the first recipient. Document translation choices, dialect issues, investigative prompting, and competing interpretations. Interview witnesses who can explain both the transaction and the communications. Record what was established, what remained disputed, and why each conclusion was reached.

Design the process before the crisis. Define triage criteria, independence, privilege, preservation, scope approval, board escalation, investigation timing, root-cause analysis, and remediation ownership. Provide reporting channels that employees and third parties know, trust, and can use without retaliation. DOJ treats a trusted reporting mechanism and timely, properly scoped, objective, and documented investigations as hallmarks of an effective program.

Prepare the Disclosure Decision Before the Clock Starts

Voluntary disclosure should not be improvised during a board emergency. The company needs a protocol that identifies decision owners, the role of counsel, the facts required, preservation steps, the escalation path, and the method for assessing seriousness, pervasiveness, seniority, ongoing harm, and potential collateral consequences.

The March 2026 Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) makes speed commercially significant. It provides a declination path when a company voluntarily self-discloses to the appropriate DOJ component, fully cooperates, timely and appropriately remediates, and lacks disqualifying aggravating circumstances, although prosecutorial discretion and the policy’s definitions still control. The policy also contains an exception for a whistleblower who reports both internally and to DOJ. A company may remain eligible if it reports as soon as reasonably practicable, no later than 120 days after the internal report, and satisfies the other requirements.

That is not a 120-day permission slip to wait. The operating standard is speed with discipline. The company must stop continuing harm, preserve evidence, protect privilege, develop facts, and keep decision-makers informed. A tabletop exercise should test whether the organization can do all five while the disclosure window is running.

Give the Board Evidence, Not Activity Counts

Boards do not need every hotline allegation or third-party file. They need a risk-based view of whether the system works. Reporting should cover high-risk transactions proceeding with incomplete diligence, unresolved politically exposed person relationships, payment holds, management overrides, aged investigations, remediation slippage, repeat control failures, off-channel communication exceptions, and risk acceptances by senior leaders.

Metrics should show speed, quality, and outcomes. Track time from red flag to triage, triage to transaction pause, allegation to investigation plan, finding to discipline, and remediation commitment to validated closure. Measure whether the company can match high-risk payments to legitimate services, verified beneficial owners, approved accounts, and evidence of performance. Show whether control testing changed behavior, not simply whether employees completed training.

The CCO should have regular direct access to the board or responsible committee, including private sessions when appropriate. The board should understand the CCO’s authority, resources, data access, and unresolved requests. DOJ asks what information directors examined, whether compliance concerns stopped or changed transactions, and whether compliance has the stature and autonomy to function effectively.

Run a 30/60/90-Day Berko Stress Test

Days 1 to 30: Replay one recent high-risk public-sector transaction against the Berko pattern. Inventory intermediaries, beneficial owners, politically exposed person relationships, success fees, conflicts, personal-email exceptions, cash exposure, payment destinations, incomplete diligence, and overrides. Identify which facts the current systems can retrieve and which depend on manual reconstruction.

Days 31 to 60: Close the most important design gaps. Add hard stops, fee benchmarking, conflict attestations, off-channel controls, evidence-preservation rules, payment analytics, investigation protocols, and an escalation matrix giving compliance documented pause authority. Assign one accountable owner and a deadline to each remediation item.

Days 61 to 90: Test the program. Sample transactions, trace selected payments end to end, test the hotline from intake through closure, and conduct an investigation and voluntary-disclosure tabletop. Present the results to senior management and the board, including accepted risks, overdue actions, resource needs, and evidence that completed remediation operates in practice.

The board should ask, “Which Berko warning signs would we detect today?” How quickly could we freeze a payment? Who may override compliance, and what evidence is required? Can investigators collect personal-device communications lawfully and preserve multilingual evidence? Which repeated control failures have affected compensation or promotion?

The CCO should ask one final question: Would our program find this pattern because the controls work, or only because an external source eventually brings it to us?

This Berko FCPA trial blog post series began with the prosecution’s evidentiary mosaic and the defense’s missing-last-mile challenge. It ends with a practical conclusion. Compliance evidence becomes trial evidence. A defensible program must create that evidence through authority, trusted reporting, disciplined investigations, consistent accountability, measurable remediation, and active board oversight. That is how a case study becomes a control test and how a control test becomes proof that the program works.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy