Categories
Compliance Tip of the Day

Compliance Tip of the Day – The Board and a Trust Framework for AI

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we continue our look at Board issues and conclude by considering how a Board of Directors should establish a trust framework for AI.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – The Board and an AI Framework for Governance

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we continue our look at Board issues. We continue to consider how BODs need to think through AI governance. Today, we will consider a framework for AI governance.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which was recently released by LexisNexis. It is available here.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – AI and the Board – The Solutions

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with concise, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we look at Board issues. In the second of a two-episode series, we consider the role of the Board in your corporate AI program. Today, we consider the problems that the Board must confront and explore some answers.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which was recently released by LexisNexis. It is available here.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – AI and the Board – The Problems

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

This week, we look at Board issues. In the first two episodes of this week, we consider the role of the Board in your corporate AI program. Today, we consider the problems. Tomorrow, we explore some answers.

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Board Oversight on Internal Controls

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

How can your board fulfill its role in oversight of your internal controls

For more information on this topic, refer to The Compliance Handbook: A Guide to Operationalizing Your Compliance Program, 6th edition, recently released by LexisNexis. It is available here.

Categories
Blog

Caremark as a Strategic Framework: Compliance Strategy for Business Executives

In a surprise to no one who has been watching, a group of institutional investors has filed suit against Boeing for another set of Caremark violations. I wrote about this eventuality back last summer around the court case the (then) Department of Justice (DOJ) brought against Boeing for violating its DPA around the 737Max crashes. I was therefore intrigued to see a new article looking at the Caremark Doctrine, entitled Caremark’s Fractured State by Itai Fiegenbaum.

The Caremark Doctrine has long been the bedrock of board-level oversight in corporate compliance, yet its application remains a subject of intense debate. Originally framed as a duty of care, Caremark obligations have since developed into a duty of loyalty, placing an increased burden on directors to monitor corporate compliance proactively. Through the 2018 ruling in Marchand v. Barnhill, the Delaware courts have reinforced that directors can be liable for failures in “mission-critical” areas. However, as this Fiegenbaum explores, the Caremark standard is far from universally applied across U.S. jurisdictions, leaving compliance officers and business executives with an uneven playing field.

Understanding the Caremark framework and its implications for corporate oversight is critical for compliance professionals. This article unpacked the evolution of Caremark, its inconsistent application outside Delaware, and how compliance strategies must adapt to varying levels of director accountability.

I. The Strategic Compliance Takeaways from Caremark’s Evolution

1. Compliance as a Board-Level Obligation

At its core, Caremark establishes that directors must ensure robust compliance systems are in place and actively monitored. This proactive duty means that corporate compliance is not just a legal safeguard but a strategic necessity. Boards that fail to implement adequate monitoring systems—or ignore known compliance risks—face potential liability. In today’s regulatory climate, companies cannot afford a passive approach to compliance oversight.

2. The Expanding Definition of Oversight Risk

Delaware courts have broadened their view of what constitutes a director’s duty under Caremark. The March decision, for example, held that directors overseeing “mission-critical” aspects of a business (such as food safety for an ice cream manufacturer) are presumed to have higher oversight obligations. This shift suggests that compliance programs must be tailored to each company’s core risks. Compliance officers should prioritize risk assessments that align with the company’s industry and regulatory landscape, ensuring that high-risk areas receive enhanced scrutiny.

3. Lessons from the Jurisdictional Divide

While Delaware leads in developing oversight liability, nearly half of U.S. jurisdictions provide directors with broader legal protection, making Caremark-based claims difficult to sustain. In many states, exculpation provisions shield directors from oversight liability unless they act intentionally. This discrepancy underscores the need for compliance teams to be well-versed in jurisdiction-specific director liability standards. Companies incorporated outside of Delaware should not assume they are insulated from oversight risk—regulators and investors are increasingly scrutinizing board-level compliance failures, regardless of legal precedent.

II. Strengthening Compliance Programs in Light of Caremark

1. Building a Proactive Compliance Framework.

Given the heightened expectations of board oversight, companies must establish rigorous compliance frameworks that extend beyond minimum regulatory requirements. A robust compliance strategy should include:

Board-Level Training. Directors must be educated on their Caremark duties and understand their personal liability risks. Compliance officers should facilitate ongoing training on emerging regulatory risks and enforcement trends.

Risk-Based Monitoring. Compliance should not be a one-size-fits-all approach. Companies must identify mission-critical areas and allocate resources accordingly.

Whistleblower and Incident Reporting Systems. Companies must ensure that directors receive timely, credible information on compliance failures. This means strengthening internal reporting mechanisms and providing whistleblower protections are in place.

2. Data-Driven Compliance Monitoring.

The Caremark Doctrine has also emphasized the importance of data-driven oversight. Boards cannot exercise proper oversight without access to meaningful compliance data. Companies must:

  • Leverage analytics to detect anomalies in high-risk areas, such as supply chain transactions, financial reporting, and regulatory disclosures.
  • Implement dashboards that provide directors with real-time compliance insights.
  • Internal audits should be conducted to assess compliance program effectiveness and identify gaps before they escalate into enforcement actions.

III. The Compliance-Board Partnership: Closing the Oversight Gap 

1. Integrating Compliance into Corporate Strategy

One of the most significant lessons from Caremark is that compliance must be embedded into overall business strategy. Boards and executives should move beyond viewing compliance as a reactive function and instead treat it as a key driver of business sustainability. Compliance teams should work closely with legal and operational leadership to ensure that:

  • Compliance is integrated into strategic decision-making, particularly in areas with heightened regulatory risk.
  • Board members actively engage in compliance discussions rather than relying solely on quarterly reports.
  • Directors have direct access to compliance officers and internal audit teams to stay informed about emerging risks.

IV. Mitigating Personal and Corporate Risk

For boards, compliance failures are not just a corporate risk but a personal liability risk. Directors and executives should take steps to protect both the company and themselves by:

  • Ensuring robust documentation of compliance efforts. Regulators and courts expect clear evidence of proactive compliance oversight.
  • Regularly reviewing and updating governance policies. Compliance obligations evolve with regulatory shifts, and boards must stay ahead of these changes.
  • Engaging external compliance experts when necessary. Outside counsel or compliance specialists can provide critical insights, particularly in highly regulated industries.

V. The Future of Caremark: Compliance in an Evolving Legal Landscape 

The Caremark standard will continue to evolve as courts and regulators refine expectations for board oversight. Companies should prepare for:

Stronger enforcement actions against directors for compliance failures in mission-critical areas. This trend is relevant to the healthcare, finance, and technology industries, where regulatory expectations are intensifying.

More aggressive shareholder litigation. Investors increasingly use Caremark claims to hold directors accountable for compliance missteps, particularly in ESG-related areas.

Greater emphasis on cybersecurity and data governance. As regulators focus on data privacy and cybersecurity breaches, boards must ensure they are actively monitoring these risks.

VI. Turning Compliance into a Strategic Asset

For business executives, Caremark should not be viewed solely as a legal doctrine but as a strategic framework for strengthening corporate oversight and resilience. Companies that proactively embrace compliance as a board-level priority will reduce regulatory risk and enhance investor confidence, corporate reputation, and long-term business sustainability.

The key takeaway? Compliance is no longer optional. It is a fundamental component of responsible corporate governance, and boards that fail to adapt face increasing legal, financial, and reputational consequences. Compliance professionals must take the lead in bridging the oversight gap, ensuring that directors are equipped to meet their evolving fiduciary responsibilities in a complex regulatory landscape.

Categories
Blog

A Road Trip on the Crypto Regulatory Landscape: A Guide for Compliance and the Board of Directors

Securities and Exchange Commission (SEC) Commissioner Hester Peirce recently announced a ‘crypto road trip’ for the SEC and crypto industry. This trip includes a newly announced Crypto Task Force at the SEC, and she said it will “be more enjoyable and less risky than the crypto road trip the Commission has taken the industry on for the last decade.” She said, “On that last trip, the Commission refused to use regulatory tools at its disposal and incessantly slammed on the enforcement brakes as it lurched along a meandering route with a destination not discernible to anyone.”

Much like past road trips, the journey of crypto regulation has been unpredictable and challenging. In previous years, the SEC has navigated the crypto industry hesitantly, relying heavily on enforcement rather than clear regulatory guidance. However, with the introduction of the SEC’s Crypto Task Force, there is now an opportunity to develop a more structured, transparent, and effective regulatory framework.

Imagine you are a Chief Compliance Officer and get a call from the head of the Board of Directors’ Compliance Committee. They ask you what the company should do to prepare for this new ‘road trip.’ This blog post will provide an overview of the key regulatory challenges, risks, and strategic considerations that a Board of Directors should know as they oversee their organizations’ engagement with the evolving crypto landscape.

Where Did the Journey Start?

Since 2013, the first bitcoin exchange-traded product application was filed, and the SEC has approached crypto with a mix of enforcement actions, limited no-action letters, and ambiguous guidance. This has left many market participants uncertain about compliance requirements and legal risks. Key regulatory concerns include:

  • Legal Uncertainty: Ambiguities in applying securities laws, particularly through the Howey test, have created confusion regarding classifying crypto assets.
  • Enforcement-Driven Approach: Many regulatory decisions have been reactive, leading to litigation, stalled rulemaking, and business operational uncertainty.
  • Market Integrity and Fraud Prevention: The SEC remains committed to protecting investors by cracking down on fraudsters while balancing innovation.
  • Jurisdictional Overlap: The interplay between various regulatory agencies, such as the SEC, CFTC, and global regulators, adds complexity to compliance efforts.

The Crypto Task Force’s Objectives

The newly established Crypto Task Force is focused on developing a framework that:

  1. Defines the Security Status of Crypto Assets – Clarifying when digital assets fall under securities regulations.
  2. Creates a More Predictable Regulatory Environment – Establishing structured compliance requirements to guide businesses.
  3. Facilitates Responsible Market Innovation – Allowing for industry growth while protecting investors from fraud and abuse.
  4. Enhances Inter-Agency and Global Coordination – Ensuring crypto regulation is consistent across jurisdictions.
  5. Supports Transparent and Efficient Markets – Addressing market manipulation, custody solutions, and exchange-traded products.

Key Considerations for Boards

Corporate boards must take a proactive approach to navigating this changing landscape. Some critical areas of focus include:

  • Regulatory Compliance Readiness: Ensuring the organization has the necessary policies and procedures to comply with evolving crypto regulations.
  • Risk Management Strategies: Identifying crypto investments and transactions’ legal, financial, and reputational risks.
  • Engagement with Regulators: Encouraging dialogue with regulatory bodies to stay ahead of compliance expectations and contribute to policy discussions.
  • Governance and Oversight: Establishing clear accountability for crypto-related initiatives within the organization.
  • Investor and Stakeholder Communications: Being transparent with investors about how regulatory developments may impact business strategy.

Preparing for the Road Ahead

As regulatory clarity emerges, organizations should take the following steps:

  1. Monitor Regulatory Developments – Stay informed about SEC, CFTC, and international regulatory body updates.
  2. Develop a Compliance Framework – Implement internal controls that align with anticipated regulatory requirements.
  3. Assess Crypto Engagement Strategies – Determine how the organization should engage with crypto markets while balancing innovation and compliance.
  4. Educate Leadership and Stakeholders – Ensure board members, executives, and investors understand the regulatory landscape.
  5. Stay Agile – Be prepared to adjust business models as new rules and enforcement priorities take shape.

What about Compliance?

For good measure, you should add your thoughts about the role of compliance in this road trip for the new crypto regulatory paradigm. With greater regulatory scrutiny and the increasing use of technology in compliance, companies have an opportunity to bring structure and clarity to their compliance programs. But like any journey, knowing the destination is crucial, and so is staying aware of the risks and opportunities along the way.

Setting the GPS: The Role of a Strong Compliance Program

An effective compliance program is like a well-planned road trip; it ensures the organization stays on the right path while avoiding unnecessary detours. A well-designed compliance framework should focus on:

  1. Clear Regulatory Understanding – Organizations must stay informed about evolving laws and regulations that impact their industry. Regular monitoring and interpretation of compliance requirements are critical.
  2. Proactive Risk Management It is key to identify and mitigate risks before they become major issues. Companies should implement risk assessments and compliance audits to maintain regulatory integrity.
  3. Robust Internal Controls – Just as road safety measures protect travelers, strong internal controls help businesses prevent fraud, misconduct, and regulatory violations.
  4. Employee Training and Awareness – Employees are the front line of compliance. Regular training ensures they understand policies and procedures and recognize compliance risks.
  5. Collaboration with Regulators and Industry Groups – Engaging with regulatory bodies and participating in industry discussions can help shape best practices and ensure a more transparent regulatory environment.

Pit Stops and Road Hazards: Compliance Challenges

For corporate leaders and compliance professionals, regulatory changes present opportunities and challenges. Some key takeaways include:

  • Different Compliance Requirements – Companies should expect increasing oversight and enforcement, requiring them to enhance their compliance efforts.
  • No Blanket Approval from the SEC – Just because an organization adheres to compliance regulations does not mean it is immune to scrutiny. Continuous improvement and adaptation are necessary.
  • A Shift Toward Proactive Compliance – Businesses should focus on building compliance into their operations from the start rather than waiting for enforcement actions.
  • Industry Engagement is Essential – Businesses that engage with regulators and industry peers can better anticipate regulatory trends and shape policy.

The SEC’s approach to crypto regulation is shifting from reactive enforcement to proactive rulemaking. While uncertainty remains, establishing the Crypto Task Force is a step toward greater clarity. Board members must stay informed and strategically align their organizations to navigate regulatory challenges while capitalizing on crypto innovation opportunities.

The road ahead requires vigilance, adaptability, and strong governance. Businesses can thrive in the evolving crypto regulatory environment by taking a proactive stance.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Compliance Expertise on Board

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Just as ever corporate Board of Directors should have a Compliance Committee and a compliance expert on the Board.

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

Check out the entire 3-book series, The Compliance Kids, on Amazon.com.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Board Compliance Committee

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Every corporate Board of Directors should have a Compliance Committee.

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

Check out the full 3-book series, The Compliance Kids, on Amazon.com.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – Compliance Obligation for Boards

Welcome to “Compliance Tip of the Day,” the podcast where we bring you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, we aim to provide bite-sized, actionable tips to help you stay on top of your compliance game. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

Today, we begin considering Board obligations around compliance.

For more information on the Ethico Toolkit for Middle Managers, available at no charge, click here.

Check out the full 3-book series, The Compliance Kids, on Amazon.com.