Categories
Blog

Dolly Parton and the Compliance Value of a Life Well Governed

Dolly Parton died this week. Her death closed one of the most remarkable careers in American entertainment, but it did not close the institutions, ideas, and expectations she built. For corporate compliance professionals, that durability is what makes her story more than a tribute. It becomes a lesson in how values can be converted into governance. Today I want to honor Parton, what she did, and what she stood for, and perhaps hope that her life will inspire all of us to be just a little better.

Parton was one of twelve children. Parton began singing on local radio and television as a child and appeared at the Grand Ole Opry at thirteen. She wrote her first song at age 6. She moved to Nashville after high school, established herself as a songwriter, and became a national star through The Porter Wagoner Show. She then built a solo career that crossed country, pop, film, television, theater, publishing, tourism, and philanthropy. She recorded more than fifty albums, wrote roughly 3,000 songs, won ten Grammy Awards, and created works such as “Jolene,” “I Will Always Love You,” and “9 to 5” that became part of the American vocabulary. One of the most amazing facts I learned while researching this piece was that “Jolene” and “I Will Always Love You” were written on the same day. How is that for creative inspiration?

Parton did not run a corporate compliance program, and her career should not be forced into that frame. Yet she demonstrated something every CCO and Board of Directors needs to understand: culture becomes credible when stated values, hard decisions, operating systems, and visible conduct reinforce one another over time. Her public identity rested on kindness, independence, dignity, humor, and respect. She repeatedly made those commitments tangible in contracts, businesses, philanthropy, and crisis response.

Her entrepreneurship deserves equal attention. Parton moved from performer to owner, producer, publisher, and partner, most visibly through Dollywood and the enterprises built around it. The portfolio was diverse, but it was not random. Music, storytelling, family entertainment, Appalachian identity, hospitality, and community investment all reinforced a coherent promise. Compliance professionals should recognize the governance advantage of that clarity. Diversification creates new legal, operational, third-party, and reputational risks, but a stable purpose helps leaders decide which opportunities fit, which controls must travel with the business, and which deals to decline.

Independence Before Applause

Parton understood the difference between access to power and surrender to it. She left Porter Wagoner in 1974 to build an independent career, expressing gratitude for the partnership without allowing it to define her future. She later declined an opportunity for Elvis Presley to record “I Will Always Love You” when his manager demanded a share of the publishing rights—saying no cost her an extraordinary short-term opportunity. Retaining ownership preserved the long-term value of her work, especially when Whitney Houston’s recording became a worldwide success. Business Insider called it “her smartest business move.”

That decision should resonate with compliance leaders. Independence is not a paragraph in a charter. It is the authority to resist pressure when revenue, status, or a powerful executive makes acquiescence attractive. A CCO needs direct access to the board, control over investigative escalation, sufficient resources, and protection against retaliation. Chuck Watson once said, “Sometimes the best deal is the one you don’t make.” A board should test whether that independence works when it is expensive, inconvenient, and unpopular. If compliance can say no only when nothing important is at stake, it is not independent.

Purpose Made Operational

Parton’s philanthropy offers an equally powerful lesson in program effectiveness. She created the Dollywood Foundation in 1988 to improve educational outcomes in her home county. Its Buddy Program paired students and offered a financial incentive for graduation; the dropout rate for the participating classes fell from 35 percent to 6 percent. In 1995, inspired by her father’s inability to read and write, she launched the Imagination Library. What began in Sevier County became a network operating across five countries that has delivered more than 300 million free books to young children.

This was not the purpose of branding. It was purpose translated into a defined population, a repeatable delivery model, local partnerships, funding, data, and measurable results. That is the same transition the Department of Justice asks companies to make when it evaluates whether a compliance program is well designed, adequately resourced, and working in practice. A value in the code of conduct must become an owner, a control, an escalation path, testing, and remediation. Intent is the beginning of a compliance program, not proof of one.

Listen to the People Who Experience Power

Parton’s film and song “9 to 5” gave popular form to workplace realities many employees already knew: power can be abused, unfairness can become routine, and people with the least authority often carry the greatest burden. The song endured because it recognized the lived experience behind organizational charts. It made a workplace issue visible without turning the people affected into abstractions.

Compliance programs fail when they listen only upward. Hotline statistics, exit interviews, culture surveys, investigation themes, retaliation allegations, and manager-level trends must reach leaders in a form that supports action. Boards should ask whether employees believe they can speak without losing status, opportunity, or employment. They should also ask whether the organization learns from weak signals before they become red flags. A speak-up system is not effective because a telephone number exists. It is effective when people trust the process and see consistent, fair outcomes.

Trust Earned Through Response

Parton’s businesses remained closely connected to the community that formed her. Dollywood became Sevier County’s largest employer, while its stated operating culture emphasizes hospitality, authenticity, collaboration, and respect. The company supports employee development, including tuition assistance. When wildfires devastated East Tennessee, Parton helped organize direct support for affected families. During the COVID-19 pandemic, her $1 million gift established a Vanderbilt research fund that supported work connected to the Moderna vaccine.

The compliance lesson is that reputation is a lagging indicator of accumulated conduct. Trust is built before a crisis through thousands of ordinary decisions about employees, customers, communities, and counterparties. A crisis tests it through the speed, fairness, transparency, and competence of the response. A company cannot purchase credibility with a campaign after years of contrary conduct. The best crisis communication remains a well-governed response supported by facts, accountable owners, and visible follow-through.

A Board Agenda Worthy of the Lesson

Parton’s legacy was unusually broad, but its organizing logic was simple. Know what matters. Protect it when pressure arrives. Build systems that carry values beyond the founder. Listen to people whose voices are easiest to overlook. Measure whether the work changes outcomes. Repeat the conduct long enough that stakeholders can rely on it.

  • For directors, that logic produces five practical questions. What principles will the company not trade away for a transaction or quarterly target?
  • Does the CCO possess real independence, resources, information, and access?
  • Which data prove that stated values operate at the employee and third-party level?
  • Are speak-up and investigation systems producing trust, learning, and remediation?
  • When the company faces a crisis, can the board see decisions, owners, deadlines, testing, and closure rather than a record showing only that management made a presentation?

Dolly Parton understood that a carefully created image can open a door, but only character and performance can keep it open for seven decades. Compliance leaders often describe their goal as building a culture of integrity. Her career reminds us what that requires: independent judgment, operational discipline, attention to the less powerful, measurable impact, and consistency when no applause is guaranteed. That is not only a fitting business lesson from her life; it is a demanding standard for every organization that wants to be trusted.

Categories
Blog

Boeing, Caremark, and the Evidence of Good-Faith Oversight

On August 13, 2026, the Delaware Court of Chancery dismissed claims arising from the January 2024 Alaska Airlines door-plug blowout. A door plug left Boeing’s factory without four securing bolts, the FAA grounded the aircraft, and investigations identified production and quality problems. Yet corporate trauma did not establish bad-faith board oversight. The question was what the directors knew, what systems delivered that information, and how the company responded. For a Chief Compliance Officer, that distinction is the heart of the case. Boeing showed what evidence of conscientious oversight can look like. The Boeing Derivative Litigation, Consol. C.A. No. 2024-1210-MTZ (Del. Ch. Aug. 13, 2026) (the “Opinion”).

This decision continues the evolution of the Caremark Doctrine and details what Boards of Directors need to consider to meet their obligations under the Caremark Doctrine. For compliance professionals, this case should be studied for not only its substantive analysis but also for how you will need to train.

Caremark Still Asks Two Hard Questions

Caremark liability is rooted in the duty of loyalty and bad faith, not negligence or a poor outcome. Directors may face liability if they fail to implement a reporting system or if they establish one but consciously fail to monitor it, preventing themselves from learning about problems that require attention. The required state of mind is an intentional dereliction of duty or conscious disregard of known responsibilities. A flawed effort is not the same as no good-faith effort.

That standard should not become a message that directors are protected unless they do nothing. Directors must demonstrate how they tried. Fiduciaries who implement and attend to a reasonable board-level reporting system meet the baseline duty. Even for mission-critical operations, “Caremark does not demand omniscience.” The Board’s task is therefore not perfect foresight. It is disciplined attention.

The Record That Protected the Board

The most useful part of the Opinion for compliance professionals is its description of Boeing’s governance machinery. The board met at least every two months, and airplane safety was discussed at every meeting. Management provided commercial-airplane updates on safety, quality, operational performance, and production targets. A Chief Aerospace Safety Officer delivered global safety updates twice each year.

Boeing also had an Aerospace Safety Committee with directors experienced in engineering, manufacturing, aerospace, aviation, or safety. It met at least 23 times from January 2022 through July 2024. Reporting included safety risk registers, in-service safety reports, Speak Up updates, and special-attention reports. Significant safety incidents or regulatory actions were to be reported to the board or committee within 24 hours or as soon as reasonably practicable. The Audit Committee separately monitored internal controls, legal compliance, the DOJ deferred prosecution agreement, and FAA obligations.

After the door plug incident, the Aerospace Safety Committee met within a day, met again twice during the following week, and arranged an onsite factory inspection. That record did not erase the operational failure. It demonstrated an active reporting and response system.

An analysis from the law firm of Sullivan & Cromwell, whose authors’ firm represented Boeing and the defendants, makes the same point: mission-critical reporting, clear committee mandates, escalation channels, and contemporaneous records can be decisive when a court examines good faith. “Delaware Court of Chancery Reinforces Limits on Oversight Liability; Stresses Importance of Conscientious Board Oversight,” Harvard Law School Forum on Corporate Governance (the “S&C Analysis”).

Train Directors to Distinguish Red from Yellow

Plaintiffs characterized dozens of reports on manufacturing and safety risks as ignored red flags. The Court rejected that theory because it threatened to convert the “volume and depth” of reporting from a best practice into evidence of disloyalty. As the defendants put it, “If everything is a red flag, then nothing is.”

Recurring adverse information is not harmless, but the board must classify and connect it. A Caremark red flag must put directors on notice that the company is violating law or headed toward specific corporate trauma. It must also connect to the misconduct that caused the loss. General operational risks under active remediation may instead show that reporting is functioning. The Court described yellow flags involving operational risk, management responses, or matters insufficiently tied to the door-plug incident.

Board training should therefore require directors to ask three questions whenever adverse information arrives: Is this a business risk or a legal compliance risk? What is management doing about it? What facts would require escalation, independent verification, or a change in strategy?

Business Judgment Has a Boundary

The Opinion also distinguished business risk from positive law. Production schedules and the management of ordinary operational risk generally receive business-judgment deference. Directors, however, have no discretion to cause the company to violate the law knowingly.

The plaintiffs argued that Boeing’s production goals favored profits over safety. The Court found no particularized allegation that the targets themselves violated the law or that directors pursued a lawbreaking strategy. The record also showed that Boeing adjusted targets, delayed production increases, and evaluated staffing, quality, supply chain, and factory-health risks. Those actions supported an inference of good-faith business judgment, not conscious disregard.

For directors, the training point is not that every production decision is insulated. The board should understand where business discretion ends, and legal obligation begins. Compliance should identify the applicable mandates, show how they enter board reporting, and specify which thresholds require action rather than monitoring.

Books and Records Are Part of the Control Environment

The plaintiffs obtained extensive books and records describing committee responsibilities, recurring reports, risk metrics, remediation, and post-incident response. The record used to challenge the directors also demonstrated their engagement.

This is not a reason to create defensive minutes. It is a reason to create accurate, decision-useful records. Minutes should capture material questions, requested follow-up, commitments, and unresolved issues. Dashboards should show trends and control effectiveness, not merely activity. Closed items should include validation. Elevate persistent issues rather than repeatedly relabeling them. As the S&C Analysis observes, contemporaneous records can be critical because the court examines what the board received, whether it signaled obvious illegality or specific trauma, and how directors and management responded.

Five Questions For Your Board

  1. Mission-critical risk. Which legal, safety, compliance, cybersecurity, or operational risks could threaten the company’s viability, customers, or license to operate? The board should identify these risks based on the company’s industry, regulatory obligations, business model, and risk profile. Directors should understand which controls address each mission-critical risk and which executives are accountable for operating them. Compliance should periodically test whether the board’s risk priorities remain aligned with changing regulations, business operations, and emerging threats.
  2. Reporting architecture. Which committee owns each risk, what information reaches it, and through which escalation channel? Committee charters should assign clear oversight responsibility and prevent material risks from falling into gaps between the board and its committees. Directors should receive decision-useful information, including trends, control failures, remediation progress, and emerging exposure, rather than raw operational data. The reporting architecture should also define when management must escalate an issue from a committee to the full board.
  3. Red-flag discipline. What criteria distinguish ordinary variance, a yellow flag requiring remediation, and a red flag requiring Board action? Management and the board should establish objective escalation thresholds based on legal exposure, customer harm, financial impact, recurrence, control failure, and the possibility of significant corporate trauma. Yellow flags should receive documented remediation plans, accountable owners, deadlines, and continuing monitoring. Red flags should trigger prompt board attention, independent inquiry where appropriate, and documented decisions about containment, investigation, disclosure, and corrective action.
  4. Response evidence. Do minutes and dashboards show questions, decisions, owners, deadlines, testing, and closure, or only that a presentation occurred? Board records should demonstrate that directors engaged with material information, challenged management assumptions, and requested appropriate follow-up. Dashboards should track remediation through completion and include evidence that corrective actions were tested for effectiveness. Minutes should accurately capture the substance of your Board’s oversight without becoming defensive narratives or sanitized accounts of difficult discussions.
  5. Speak-up integrity. Can employees raise concerns without retaliation, and does the board receive meaningful information about allegations, investigations, trends, and corrective action? Directors should understand how reports are received, triaged, investigated, escalated, and resolved across the organization. Board reporting should address substantiation rates, recurring allegations, investigation delays, retaliation claims, root causes, and remediation effectiveness. Your Board should also evaluate whether employees trust the reporting system and whether management responds consistently regardless of the seniority or business importance of the individuals involved.

Boeing continues to provide a wealth of lessons learned for compliance professionals. The Delaware Court Opinion reminds us that the Caremark Doctrine offers neither immunity nor a checklist safe harbor. It reminds boards that the Caremark Doctrine is tested through evidence of good-faith effort. Compliance must build that effort into governance before the next crisis and ensure the record shows that directors received, understood, challenged, and followed through on critical information.

Categories
Blog

Private Company, Public Risk: Building Defensible AI Governance Before the Rules Arrive

For private companies, the central question about artificial intelligence is no longer whether the technology is in the business. It is whether anyone can explain where it is, what it does, what data it touches, and who is accountable when it fails.

That is the warning in “AI Governance for Private Companies,” by Hillary Flynn, Drew Morales, and Courtney Hugger of Wellington Management, which was recently posted in the Harvard Law School Forum on Corporate Governance. The authors report that nearly three in four companies plan to deploy agentic AI within two years, while only one in five has a mature governance model for autonomous agents. That is not merely a technology gap. It is a governance gap.

Private ownership does not make AI risk private. The consequences arrive through customers, employees, regulators, investors, lenders, insurers, and business partners. A company may not yet face a single comprehensive AI law, but it can still face a privacy complaint, contract dispute, cyber incident, customer loss, or damaged valuation. For compliance professionals, governance should precede scale.

Private Does Not Mean Exempt

Private companies are moving quickly because AI can increase productivity, improve customer service, accelerate analysis, support coding, and help a growing company scale. The article also identifies a critical lesson from Wellington’s portfolio companies: the largest barriers are often organizational, not technical. Companies making the strongest progress combine AI investment with employee training, clear governance, and defined expectations.

This is where the Chief Compliance Officer can reframe the discussion. AI governance is the discipline that allows useful experimentation without unmanaged legal and business exposure. The goal is not a thick policy on a shared drive. The goal is an operating system for accountable decisions.

The European Union AI Act is being implemented in phases through 2027, with expectations around transparency, human oversight, documentation, risk management, monitoring, and AI literacy. In the United States, NIST guidance, ISO standards, sector rules, state laws, and customer requirements are shaping expectations, even without a federal AI statute. A private company can therefore face AI governance demands through a contract or transaction long before a regulator knocks on the door.

Begin With the Business Objective

One of the article’s strongest recommendations is also one of the simplest: start with the business problem, not the AI tool. This is precisely what Carl Hahn has consistently maintained: always ask, “What is the Business Value?”Teams should define the desired outcome before selecting a model or vendor. Is it lower cost, faster response, better quality, increased revenue, fewer errors, or reduced risk?

Governance cannot evaluate an undefined promise. A measurable objective gives management a basis for deciding whether the use case works and whether its benefits justify its risks. It also creates stopping rules. Approval should identify what failure, customer impact, control breakdown, or scope change will trigger redesign, escalation, suspension, or retirement.

Compliance should insist on this discipline, particularly when an AI use case affects payments, eligibility, claims, pricing, employment, healthcare, education, financial products, or customer communications. Those are not ordinary software deployments. They are decisions and interactions with consequences for real people.

Inventory First, Then Tier the Risk

A company cannot govern what it cannot see. The foundation is an inventory of models, vendors, internal tools, embedded features, customer-facing systems, employee-built applications, and known shadow AI. It does not need to be perfect. It needs an owner, an update process, and enough information to support risk decisions.

Each use case should then be placed into a risk tier. Relevant factors include data sensitivity, degree of autonomy, importance of the business process, impact on customers or employees, regulatory exposure, ability to explain the result, and ease of reversing an error. Low-risk uses can follow a streamlined path. High-impact uses should receive enhanced testing, documented approval, human oversight, monitoring, and senior-level escalation.

Risk tiering prevents two failures. Treating every use as equally dangerous overwhelms review and encourages employees to route around it. Treating every use as ordinary technology leaves consequential applications without meaningful controls. Good governance applies greater rigor where potential harm is greater.

Put a Name Next to the Risk

Every AI system should have a business owner who remains accountable for its outcome. Accountability cannot be delegated to the model, the data science team, or the vendor. The owner should understand the intended purpose, approved users, permitted data, performance standard, escalation route, and circumstances under which the system must be paused.

Higher-risk applications should receive cross-functional review involving the business, product, engineering, legal, compliance, privacy, cybersecurity, procurement, and risk functions. This does not require a new bureaucracy. It requires a repeatable process with recorded approvals and clear responsibility.

Agentic AI raises the stakes because the risk moves from a wrong answer to a wrong action. Permissions should be limited, high-stakes actions should require human approval, and activity should be logged. Test override and shutdown mechanisms. The chatbot manipulated into agreeing to sell a vehicle for one dollar shows how weak boundaries turn a novelty into an operational event.

Treat Vendors as Part of the System

Most private companies will rely on external models, platforms, and software. That makes AI governance inseparable from third-party risk management. Traditional security questionnaires are not enough. Diligence should address how vendors use data, whether customer data trains models, how model changes are communicated, what transparency is available, how performance is tested, who bears liability, and whether data and workflows can be moved if the relationship ends.

The company should monitor model updates, service degradation, changes in terms, and features that expand access or autonomy. A tool approved for summarization should not silently become authorized to send messages, approve transactions, or alter customer records.

Monitor the System in Practice

AI governance does not end at approval. Model updates, new data, and user behavior can alter performance. Companies should monitor accuracy, reliability, bias, drift, misuse, repeated failures, and customer impact. An incident protocol should define how to pause the system, preserve evidence, escalate, remediate harm, and communicate with affected stakeholders.

This is where AI governance meets familiar compliance principles. The DOJ’s Evaluation of Corporate Compliance Programs asks whether a program works in practice. COSO emphasizes control activities, information, monitoring, and accountability. NIST’s AI Risk Management Framework helps organizations govern, map, measure, and manage AI risk. ISO/IEC 42001 offers a management-system approach. A company should select a coherent baseline and produce evidence that its controls operate.

A Practical Agenda for Boards and CCOs

Establish ownership. Name an executive accountable for AI governance and identify the board committee that will oversee material AI risk.

Build the inventory: capture sanctioned tools, embedded vendor capabilities, customer-facing uses, agentic applications, and known shadow AI.

Tier the use cases. Apply enhanced review where AI affects sensitive data, consequential decisions, critical operations, or autonomous action.

Strengthen the vendor process. Add AI-specific diligence, contractual protections, change controls, exit planning, and ongoing monitoring.

Test the failure plan. Confirm that the company can detect a harmful outcome, stop the system, preserve evidence, assign responsibility, and remediate the impact.

The author’s bottom line is the right one for compliance leaders: the winners will not necessarily be the companies that deploy AI fastest. They will be the companies that combine innovation with accountability, customer awareness, and disciplined execution. For a private company, defensible AI governance is not preparation for some distant regulatory future. It is how management protects value today.

Categories
Blog

From Policy to Proof: Six Compliance Priorities for the Next 90 Days

Editor’s note: I am a columnist for Compliance Week.

Compliance Week recently released its Practitioner’s Briefing, which “is crafted as a high-level recap of Compliance Week’s 2026 National Conference (CW 26), held in Washington, D.C., in May. Whether you were there or wished to be, this briefing will bring you up to speed. The briefing captures the six themes that pervaded three days of panel discussion and the networking conversations between them, with practical actions you can implement in the next ninety days.”

The compliance profession is entering the proof era. Policies still matter, but regulators, boards, and employees are asking a harder question: Can the organization demonstrate that its controls operate in practice? That is the central lesson from the Practitioner’s Briefing. Across six themes, the briefing describes a function under pressure from rapid AI adoption, faster whistleblower timelines, redistributed enforcement, expanding third-party exposure, and sharper board expectations.

Today I want to explore the themes and initiatives from the Practitioner’s Briefing. This is not about six disconnected initiatives covered at CW 26. It is an operating model that connects governance, data, accountability, and escalation around existing risks. You can use the next 90 days to produce evidence that the program knows where its risks sit, who owns the controls, how failures surface, and what happens next.

AI Governance: Accountability Must Follow Adoption

AI makes the policy-to-proof gap visible. The Practitioner’s Briefing reports that 83 percent of compliance functions have AI in production, while only 25 percent of leaders are confident in the governance controls. That is not primarily a policy problem. It is an ownership and control-design problem.

Start with your AI inventory. A defensible AI register should identify the tool, approved use case, business owner, data involved, vendor, model, access rights, validation method, human reviewer, retention rule, incident path, and kill-switch authority. Tool approval by IT cannot substitute for use-case approval by Legal, Compliance, Privacy, Security, and the accountable business leader. One platform may be acceptable for drafting training content and unacceptable for evaluating employees or third parties.

The NIST AI Risk Management Framework and ISO/IEC 42001 can help organize this work, but a framework is not the control. The control is the approval record, test result, exception log, monitoring evidence, and documented decision. Compliance should also assume that prompts, summaries, transcripts, and agent logs are discoverable business records. Retention and legal hold procedures must catch those artifacts before the first dispute or investigation forces the question.

AI in Compliance Operations: Redesign the Work

The Practitioner’s Briefing draws a useful line between AI enablement and AI theater. Strong programs redesign a workflow around AI. Weak programs bolt AI onto a slow process and call it transformation. Due diligence, regulatory tracking, training development, and self-service policy guidance are sensible starting points because the work can be scoped, tested, and measured.

Each deployment needs acceptance criteria. Validate performance against known outcomes, constrain source material where accuracy matters, monitor drift, require human review for high-risk decisions, and define escalation when the system is uncertain. Measure return on investment first in hours returned to higher-value work. Faster output that creates more review, remediation, or false confidence is not efficiency. It is control debt.

Speak-Up and Investigations: Trust Is the Control

The Practitioner’s Briefing reports that eight in ten US employees witnessed misconduct during the prior year, yet fewer than three-quarters reported it. That gap is not solved by adding another intake channel. It is solved by showing employees that reporting is safe, fair, and consequential.

One of the Practitioner’s Briefing’s most practical recommendations is to audit the career outcomes of the last 20 employees who raised concerns. Review performance ratings, promotions, transfers, compensation, leave, and departures. Patterns in those records may reveal retaliation or career stagnation that hotline statistics will never show. Pair that review with defined post-report monitoring and documented check-ins with reporters.

Speed is now part of program effectiveness. The briefing highlights a 120-day DOJ window to investigate qualifying internal reports and decide whether voluntary self-disclosure is appropriate. CCOs should calendar that period, establish rapid triage, identify decision rights, preserve evidence immediately, and maintain a standing disclosure team. The goal is not a rushed conclusion. The goal is to prevent delay, unclear ownership, or inadequate resources from deciding for the company.

Enforcement Has Shifted, Not Disappeared

Lower federal case counts are not a safe harbor. The Practitioner’s Briefing describes enforcement as redistributed across state Attorneys General, self-regulatory organizations, the False Claims Act, and future matters still inside applicable limitation periods. A quieter headline environment can encourage exactly the wrong management response: reduced staffing, deferred remediation, and lower investment in controls.

The business discipline is straightforward. Monitor the full enforcement ecosystem, not one federal docket. Maintain the strictest applicable standard as the practical global baseline. Preserve the ability to investigate, cooperate, remediate, and disclose. Most importantly, do not confuse a change in enforcement cadence with a change in underlying legal or ethical risk. Today’s control gap may simply be tomorrow’s case.

Third-Party Risk: Manage the Entire Lifecycle

Third-party risk management is no longer a narrow anti-bribery process. The Practitioner’s Briefing places sanctions, forced labor, transnational crime, material support exposure, supply-chain integrity, and embedded AI inside the modern TPRM remit. That expansion requires a move from onboarding diligence to lifecycle control.

Monitor material relationships from selection through offboarding, with risk-based refreshes, event-driven alerts, beneficial ownership checks, adverse media review, and clear remediation ownership. For AI-enabled vendors, procurement should require disclosure of material fourth- and fifth-party dependencies. Contract terms should address model provenance, data lineage, audit rights, incident notice, control changes, and the ability to explain consequential decisions.

List screening alone is increasingly thin protection. High-risk supply chains may require route mapping, chokepoint analysis, and source-verified information reviewed in context by humans. AI can compress the initial diligence cycle, but it does not replace judgment on coercion, shell companies, access payments, or other facts that demand legal and operational analysis.

Board Reporting and Culture: Lead With the Problem

Directors want a compliance report that begins with bad news, explains the risk, and shows the response. That is the board-reporting message in the Practitioner’s Briefing. Activity counts belong in the appendix. The main discussion should address control failures, investigation aging, retaliation indicators, overdue high-risk diligence, AI exceptions, remediation status, and emerging exposure compared with peers.

This approach also supports a Caremark-style oversight record. The board needs credible information systems, timely escalation of red flags, and evidence that management and directors responded. A between-meetings protocol with the audit or risk committee chair is therefore a control, not a courtesy.

Culture is equally operational. The briefing reports that direct managers and immediate colleagues exert the strongest influence on 80 percent of employees, while only 58 percent of organizations evaluate how results were achieved. Compliance should train managers to receive concerns, audit incentives as rigorously as financial controls, and make conduct part of performance and promotion decisions. The real code of conduct is what the organization rewards, tolerates, and corrects.

A 90-Day Agenda for CCOs

  1. Build the evidence map. Select the highest-risk obligations in AI, investigations, and third-party management. For each one, identify the owner, control, evidence, escalation path, and board metric.
  2. Test AI governance. Reconcile the official AI inventory with procurement records, browser access, expense data, and employee attestations. Review several approved use cases from request through monitoring.
  3. Stress-test investigations. Tabletop a significant internal report against the 120-day decision window. Confirm preservation, privilege, staffing, disclosure authority, and board communication.
  4. Rebuild TPRM around lifecycle risk. Segment critical third parties, define continuous-monitoring triggers, review AI dependencies, and assign remediation deadlines with accountable owners.
  5. Change the board report. Put the three most significant problems first. Add peer comparison, trend data, remediation aging, and decisions required from the board or management.

The Compliance Lesson

The Practitioner’s Briefing is not fundamentally a technology story or an enforcement story. It is a program-effectiveness story. The effective compliance function can identify risk, assign accountability, test controls, learn from failures, and show its work. Policies establish expectations. Evidence establishes credibility. In the next 90 days, that distinction should drive the agenda of every CCO, executive team, and board committee responsible for corporate integrity.

Categories
Blog

From the Tower of Babel to the Boardroom: Part 4 – AI, Truth, and Corporate Trust

Employees trust that leadership will tell them the truth. Investors trust that disclosures are accurate. Customers trust that representations are reliable. Boards trust that management reporting is complete. Compliance officers trust that records, interviews, hotline reports, emails, chats, invoices, certifications, and audit findings reflect reality.

Artificial intelligence now challenges that foundation. AI can generate text, audio, images, video, records, summaries, identities, and narratives at speed and scale. It can help a compliance function become more effective. It can also make falsehood more convincing, fraud more sophisticated, and manipulation harder to detect.

In the first three posts in this series, we used Magnifica Humanitas to move from governance principle to compliance program design and then to internal controls for shadow AI. In this fourth post, we turn to one of the most important themes in the Encyclical Letter: truth. Pope Leo XIV says the digital transformation requires us to rediscover truth as a common good, protect the dignity of work, and safeguard freedom against dependence and commercialization (Magnifica Humanitas, ¶131). For boards and compliance leaders, that is a powerful governance lesson. Without truth, there is no trust. Without trust, there is no culture. Without culture, no compliance program can be effective.

Truth as a Common Good

Magnifica Humanitas warns that digital platforms and AI systems are transforming public and institutional communication. The Encyclical identifies a core risk: AI can construct distorted narratives, blur the boundary between truth and falsehood, mix facts with opinions, and manipulate content, images, and video (Magnifica Humanitas, ¶132). It also reminds us that truthful information requires verification, cross-checking of sources, responsible argument, and shared practices of trust (Magnifica Humanitas, ¶132).

For the compliance professional, this is not abstract philosophy. It is an operational reality. A corporation is built on records and representations. A company’s compliance program depends on accurate policies, reliable data, trustworthy reporting, credible investigations, authentic communications, and truthful escalation to leadership and the board. If AI weakens the company’s ability to know what is real, AI becomes a compliance risk.

The issue is not only misinformation in public discourse. It is misinformation inside the enterprise. AI-generated falsehood can appear in emails, invoices, employee complaints, due diligence materials, contracts, investigation files, synthetic images, training materials, board reports, and financial documentation. Truth is no longer only an ethical value. It is a control objective.

From Encyclical Principle to Corporate Trust Requirement

The corporate translation is direct. If truth is a common good, information integrity is a governance requirement. If AI can distort narratives and manipulate content, companies need verification controls. If truthful information depends on cross-checking and responsible argument, compliance cannot treat AI outputs as self-authenticating. If communication creates culture, as Magnifica Humanitas teaches, then AI-generated communications must be governed because they shape how employees, customers, investors, and directors understand the company (Magnifica Humanitas, ¶135).

The Encyclical also calls for an ecology of communication grounded in transparency, personal data protection, rigorous verification, and the proper use of digital tools (Magnifica Humanitas, ¶137). In corporate terms, that means controls over high-risk communications, rules for AI-generated content, validation of AI-assisted summaries, protection of the integrity of investigations, and reporting systems that enable the board to trust what it receives.

Synthetic Reality and Corporate Risk

We are entering the age of synthetic reality. Companies must assume that audio may be cloned, video may be fabricated, documents may be AI-generated, and digital identities may be false. This does not mean every communication is suspect. It means the company must build verification protocols for high-risk decisions.

The Arup deepfake fraud demonstrates the corporate risk. The Guardian reported that in 2024, public reporting stated that engineering firm Arup was victimized in a deepfake scam involving its Hong Kong office, where fraudsters reportedly used AI-generated video impersonations in a call that led to the transfer of approximately $25 million. That incident should be understood as more than a cyber story. It is a governance story, a finance controls story, a human factors story, and a compliance story.

A traditional approval process may fail when a trusted executive appears to be present on a video call. A fraud-prevention control may fail when an employee believes their identity has already been verified. A payment control may fail when urgency, authority, secrecy, and synthetic trust converge. The compliance lesson is clear: in an AI-enabled environment, trust must be verified when the risk is high.

AI and the Integrity of Corporate Information

Boards and CCOs should treat the integrity of corporate information as part of AI governance. This includes information created by AI, information summarized by AI, and information used to make AI-supported decisions.

Consider internal investigations. AI can help summarize documents, cluster communications, identify patterns, and organize timelines. But Magnifica Humanitas reminds us that AI lacks moral conscience, does not understand what it produces, and does not bear responsibility for its consequences (Magnifica Humanitas, ¶99). A compliance investigator cannot delegate credibility findings to a machine. AI can support the investigation record. It cannot become the investigation record.

Consider hotline reporting. AI may help triage allegations, identify themes, translate complaints, and route issues. But if the system misclassifies a serious allegation as low risk, strips away nuance, or fails to identify indicators of retaliation, the company may miss a critical signal. Consider board reporting. A polished AI-generated report may look authoritative while masking weak data, incomplete controls, or unsupported conclusions. In compliance, elegance is not evidence.

The DOJ ECCP and Trustworthy AI

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) now asks how companies identify and manage emerging technology risks, including AI. It asks how companies govern AI in commercial operations and in their compliance programs; whether controls monitor trustworthiness and reliability; whether AI is limited to intended uses; what human decision-making baseline is used; how accountability is enforced; and how employees are trained.

This is where the Encyclical’s moral mandate and the DOJ’s compliance test meet. Magnifica Humanitas says responsibility must be clearly defined at every stage and that accountability requires identifying who must account for decisions, justify them, monitor them, challenge them, and remedy harm (Magnifica Humanitas, ¶105). The ECCP asks whether a company has converted that accountability into governance, controls, training, monitoring, and evidence. For CCOs, the question is not whether AI can help compliance. It can. The question is whether compliance can explain how AI-supported information is validated, reviewed, escalated, corrected, and documented.

NIST, COSO, and the Control Language of Trust

NIST provides a practical vocabulary for this discussion. The NIST AI Risk Management Framework identifies trustworthy AI characteristics, including validity and reliability; safety, security, and resilience; accountability and transparency; explainability and interpretability; privacy enhancement; and fairness, with harmful bias managed. For this post, reliability and transparency matter most. Reliability asks whether an output can be trusted for the intended purpose. Transparency asks whether the company can understand, explain, and govern the system.

COSO also matters here. COSO’s internal control framework is designed to help organizations achieve operations, reporting, and compliance objectives, and COSO’s GenAI guidance translates that internal-control discipline into AI governance. In the AI context, companies need controls over the creation, use, review, approval, and communication of AI-generated or AI-assisted information. This is where CCOs, internal audit, finance, legal, and IT must work together. The company should identify where authenticity matters most and design controls accordingly.

Practical Controls for AI, Truth, and Trust

A practical compliance program should include controls for AI-enabled truth risk.

First, companies should adopt verification protocols for high-risk communications. Payment instructions, executive requests, wire transfers, confidential transactions, changes to vendor banking information, M&A activity, crisis communications, and sensitive employment decisions should require independent verification outside the original communication channel.

Second, companies should require labeling or disclosure where AI-generated content is used in official corporate communications and authenticity matters. Third, companies should protect investigations from unverified AI outputs. AI-generated summaries should be treated as work aids, not evidence. Investigators should validate source documents, preserve original records, and document human review.

Fourth, companies should train employees on synthetic fraud. Magnifica Humanitas warns that AI-enabled manipulation of images and videos can make exploitation and deception more insidious (Magnifica Humanitas, ¶141). Employees should learn the red flags: urgency, secrecy, unusual payment instructions, refusal to use normal channels, unexpected video calls, requests to bypass controls, and pressure from apparent senior leaders.

Fifth, companies should create an incident response process for AI-enabled deception. A deepfake attempt, a synthetic invoice, a cloned executive voice, a fake employee profile, or an AI-generated document should be reportable, investigated, tracked, and remediated.

Board Oversight and Corporate Trust

For boards, AI and truth raise a serious oversight issue. Directors rely on management reporting to fulfill their duties. If AI affects the integrity of that reporting, boards need to understand the control environment.

The Caremark lesson is not that directors must become forensic AI experts. Directors must make a good-faith effort to ensure that reasonable information and reporting systems are in place for central compliance risks. In Marchand v. Barnhill (Bluebell Ice Cream), the Delaware Supreme Court emphasized the importance of board-level monitoring and reporting systems for mission-critical compliance risks.

Magnifica Humanitas gives this oversight obligation a deeper accountability mandate. It says AI governance requires defined responsibility, justification of decisions, monitoring, challenge, and remediation (Magnifica Humanitas, ¶105). The board’s obligation is not technical mastery. It is a reporting and monitoring system that shows management can authenticate what matters, identify AI-enabled truth risks, escalate concerns, and remediate failures.

5 Lessons for the CCO
  1. Treat truth as a compliance control. Accurate records, authentic communications, validated reports, and reliable investigation files are essential to the effectiveness of compliance programs. Truth must be designed into the control environment.
  2. Build verification into high-risk processes. Payment approvals, executive instructions, vendor bank changes, crisis communications, and sensitive decisions should require independent verification.
  3. Govern AI-assisted evidence. AI can support investigations and reporting, but human review, source validation, preservation of original records, and documentation must remain mandatory.
  4. Train employees to challenge synthetic reality. Deepfakes, cloned voices, fake identities, and AI-generated documents should be part of fraud, cyber, finance, and compliance training.
  5. Report information integrity risk to the board. Boards need evidence that management has identified AI-enabled truth risks and designed controls to prevent, detect, respond to, and remediate them.
Conclusion: Corporate Trust Must Be Protected

Magnifica Humanitas reminds us that truth is a common good. That is a moral principle, but it is also a compliance principle. A company cannot govern itself if it cannot trust its information. A board cannot oversee what management cannot verify. A CCO cannot certify program effectiveness if the underlying records, reports, and communications are unreliable.

Compliance professionals should embrace AI. It can improve risk detection, strengthen monitoring, support investigations, and expand analytical capacity. But AI also requires vigilance, responsibility, transparency, governance, and human primacy. In the age of synthetic reality, compliance must help the company protect truth as part of the control environment.

In the next and final post in this five-part series, we will broaden the lens again. We will examine the Human Supply Chain of AI: Workforce Transformation, Third-Party Risk, and Modern Slavery. That post will tie together the human impact of AI, the dignity of work, vendor risk, data governance, and the compliance responsibility to look beyond the visible interface to the people, suppliers, and systems that make AI possible.

Categories
Blog

Compliance Week 2026: AI Governance Highlights

The 21st Annual Compliance Week Conference made one point unmistakably clear: AI is no longer a technology issue sitting outside the compliance function. It is now a governance, risk, controls, culture, and accountability issue. Across the conference, AI appeared in nearly every discussion, from practical tools for compliance teams to regulatory uncertainty, shadow AI, third-party risk, and board oversight. The central message for compliance professionals was clear: AI must be governed with the same discipline, documentation, monitoring, and continuous improvement as any other enterprise risk.

That should not surprise any Chief Compliance Officer. The DOJ’s Evaluation of Corporate Compliance Programs (2024 ECCP) has long asked whether a compliance program is well-designed, adequately resourced, empowered to function effectively, and working in practice. Those same questions now apply to AI. The issue is not whether an organization is using AI. It almost certainly is. The issue is whether the company knows where AI is being used, who approved it, the risks it creates, the controls that apply, and whether those controls are being monitored.

AI Is Now a Compliance Governance Issue

The first major theme from Compliance Week 2026 was governance. AI may be exciting, efficient, and creative, but without governance, it can quickly become a source of unmanaged enterprise risk. That governance challenge begins with oversight. Who owns AI risk? Who approves AI use cases? Who determines whether a tool is appropriate for use with company data? Who has the authority to stop an AI project that is not meeting its stated purpose? These are not theoretical questions. They are the basic operating questions of an effective compliance program.

A company should not treat AI as a series of disconnected experiments. It should treat AI as part of the enterprise control environment. That means clear governance structures, documented approvals, defined risk owners, escalation protocols, monitoring, testing, and board reporting. The board does not need to become a group of AI engineers. But directors do need to understand whether management has created a defensible AI governance framework. They should ask how AI risks are identified, how high-risk use cases are reviewed, how third-party AI vendors are assessed, and how the company detects unauthorized AI use.

Shadow AI Is the Risk Hiding in Plain Sight

One of the strongest compliance lessons from the conference was the danger of shadow AI. Employees are already using AI tools, often because they are efficient, accessible, and easy to deploy. The problem is that ease of use can defeat governance. If employees are using ChatGPT, Claude, Gemini, Copilot, or other tools without authorization, training, or data restrictions, the company has a control gap. Confidential business information, financial data, personal information, customer information, or regulated data can move into systems the company does not control. That creates legal, privacy, cybersecurity, contractual, and reputational risk.

The answer is not simply to prohibit AI. That approach is unlikely to work. The better answer is to identify the tools being used, classify them by risk, authorize appropriate use cases, train employees, monitor usage, and make clear what data can and cannot be entered into an AI system. A strong AI governance program should include an AI use register. It should identify approved tools, owners, business purposes, data categories, risk ratings, controls, monitoring obligations, and renewal or reassessment dates. Without that inventory, a company cannot credibly claim to govern AI risk.

The Compliance Risk Management Model Already Works

One of the most important insights from the conference was that compliance professionals already have the right risk management framework. AI risk does not require abandoning the compliance discipline. It requires applying it.

The framework is familiar. Identify the risk. Develop a risk management strategy. Train employees. Implement the strategy. Monitor performance. Use data to improve your strategy continuously. That is the compliance operating model. It is also the right model for AI governance.

The 2024 ECCP emphasized risk-based compliance, data access, continuous improvement, and the effectiveness of controls in practice. Those expectations fit naturally into AI governance. A company should ask whether its AI controls are designed around actual risks, whether compliance has access to AI-related data, whether employees understand acceptable use, and whether the company can prove that its controls operate effectively. The lesson is straightforward. Do not build AI governance as a technology policy alone. Build it as a compliance program.

AI Risk Has Three Core Dimensions

The conference also highlighted the need to separate AI risk into practical categories. For compliance officers, three risk areas deserve immediate attention.

First, internal risk. This includes employee use of AI, shadow AI, unauthorized tools, misuse of confidential information, lack of training, and gaps in approval processes.

Second, external risk. This involves AI systems that affect customers, patients, consumers, investors, or other external stakeholders. These tools may raise issues involving fairness, privacy, transparency, discrimination, consumer protection, and regulatory obligations.

Third, third-party risk. Vendors, consultants, service providers, and sales agents may introduce AI into the company’s operations. A third-party vendor using AI in screening, analytics, customer service, data processing, or decision support can pose a risk to the company, even when the company did not build the tool.

This is where compliance must bring discipline. Third-party AI risk should be part of due diligence, contracting, audit rights, monitoring, and renewal. Companies should ask vendors what AI tools they use, what data those tools process, whether subcontractors are involved, how outputs are validated, and whether the company has audit rights over AI-related controls.

ROI Must Begin With the Business Purpose

AI projects should begin with a simple question: what problem are we trying to solve? Too many AI initiatives begin with pressure to “use AI” rather than a clear business case. That is not governance. That is technology enthusiasm without control or discipline. A compliance-minded AI review should ask whether the proposed tool has a defined use case, measurable business value, appropriate controls, and a clear owner. It should also ask whether the project is drifting from its original purpose. Mission creep is a real AI risk. A tool approved for one purpose can quickly be used for another. That creates new risks and may invalidate the original approval.

The more regulated the use case, the more important this analysis becomes. AI used in healthcare, employment, finance, consumer decisions, investigations, sanctions screening, or third-party risk management demands heightened scrutiny. ROI may not always appear as a direct financial return. Sometimes the business value is avoiding regulatory exposure, improving consistency, strengthening documentation, or reducing unmanaged risk.

Training Is No Longer Optional

AI training must move beyond general awareness. Employees need practical, role-based instruction. They need to know which tools are approved. They need to know what data is prohibited. They need to understand when human review is required. They need to know how to report AI concerns, errors, bias, hallucinations, or misuse. They also need to understand that AI output is not a substitute for professional judgment.

For compliance teams, training should include investigators, auditors, third-party managers, procurement, legal, finance, HR, IT, and business leaders. The message should be clear: AI can support the work, but it does not remove accountability.

Build AI In, Do Not Bolt It On

One of the most practical insights from the conference was that AI should be built into business processes, not bolted on afterward. That distinction matters. Bolted-on AI becomes a tool without governance. Built-in AI becomes part of the control environment.

For example, in third-party risk management, AI can help analyze due diligence responses, identify red flags, monitor adverse media, track contract obligations, and support ongoing risk scoring. But it must be embedded into a process with human oversight, escalation protocols, audit trails, and testing. The same applies to investigations, hotline analytics, policy management, training, and monitoring. AI should strengthen compliance processes, not bypass them.

The CCO Must Have a Seat at the AI Table

The compliance function should not wait to be invited into AI governance. It should claim its role. The CCO brings the language of risk, controls, accountability, documentation, monitoring, and culture. Those are precisely the disciplines AI governance requires. Compliance should help design AI approval workflows, risk assessments, training, third-party reviews, monitoring plans, and board reporting.

This does not mean compliance owns every AI decision. It means compliance must be part of the governance architecture. AI governance should be cross-functional, with legal, compliance, IT, privacy, cybersecurity, internal audit, procurement, HR, and the business working together. But compliance must ensure that the program is not simply innovative. It must be defensible.

Practical Takeaways for Compliance Professionals

  1. Create an AI inventory. Know what tools are being used, by whom, for what purpose, and with what data.
  2. Establish an AI governance committee. Include compliance, legal, IT, privacy, cybersecurity, internal audit, procurement, and business leadership.
  3. Build a risk-based approval process. High-risk AI use cases should require enhanced review, documentation, testing, and escalation.
  4. Address shadow AI directly. Do not assume employees are waiting for policy guidance. Identify actual use and bring it into governance.
  5. Train by role and risk. General AI awareness is not enough. Employees need practical rules for approved tools, prohibited data, human review, and reporting.
  6. Extend third-party risk management to AI. Vendor diligence, contracts, audit rights, monitoring, and renewal reviews should include AI-specific questions.
  7. Monitor and improve. AI governance is not a one-time policy exercise. It requires testing, metrics, incident review, and continuous improvement.

Board Questions

  1. Do we have an inventory of AI tools currently used across the enterprise?
  2. Who approves AI use cases, and how are high-risk uses escalated?
  3. How do we detect and manage shadow AI?
  4. What data is prohibited from being entered into AI tools?
  5. How are third-party AI vendors reviewed, contracted, monitored, and audited?
  6. What AI metrics does management provide to the board?
  7. Who has the authority to pause or terminate an AI project that creates unacceptable risk?

CCO Questions

  1. Is compliance involved before AI tools are deployed?
  2. Do our policies distinguish between approved, restricted, and prohibited uses of AI?
  3. Can we prove employees have been trained on AI risks?
  4. Do we have a documented AI risk assessment process?
  5. Are AI controls tested by internal audit or another independent function?
  6. Are AI incidents, errors, and misuse captured through speak-up and escalation systems?
  7. Can we show regulators that our AI governance works in practice?

Conclusion

Compliance Week 2026 confirmed that AI has crossed the threshold from emerging technology to core compliance risk. The companies that succeed will not be those that chase every new tool. They will be the companies that govern AI with discipline. For the modern CCO, this is the moment to step forward. AI governance belongs squarely within the compliance conversation because it involves risk, accountability, culture, controls, third parties, monitoring, and board oversight. Those are the foundations of effective compliance.

AI may change the tools. It does not change the obligation. Governance still matters. Controls still matter. Culture still matters. Accountability still matters. And compliance must help lead the way.

Categories
Blog

The Warner Bros. Bidding War: Part 3 – The CCO Playbook for Transactions Under Pressure

The Warner Bros. Bidding War: Part 3 – The CCO Playbook for Transactions Under Pressure

The Warner Bros. (WBD) bidding war is not simply a Board story. It is a compliance operating model test. When a superior proposal emerges, the Chief Compliance Officer (CCO) must move from program design to execution discipline. Today, we conclude our short review of the Warner Bros./Netflix/Paramount dance and sale by considering lessons for the compliance professional.

In Part 1, we focused on the deal mechanics that led Warner Bros. Discovery to move from an agreed transaction with Netflix to a superior proposal from Paramount Skydance. In Part 2, the focus shifted to Board governance and fiduciary duty. This final post, Post 3, answers the operational question. What must the Chief Compliance Officer do when the process accelerates and governance must be proven in real time?

The answer is grounded in the DOJ’s Evaluation of Corporate Compliance Programs (ECCP). The core question remains constant. Is the program working in practice? A live transaction provides the answer.

Move Compliance Into the Transaction Control Room

Too many compliance functions treat M&A as a legal and financial activity. That approach fails when the transaction becomes contested. Once a superior proposal is identified, the compliance function must:

  • Participate in transaction governance meetings
  • Map control risks across disclosure, communications, and decision-making
  • Establish escalation pathways for new information

This is consistent with the expectations embedded in the DOJ’s Corporate Enforcement Policy, which rewards companies that demonstrate real-time awareness, escalation, and action. A compliance function that is not present during the decision-making process cannot later demonstrate that controls were effective.

Build and Execute an Evidence Protocol

The most significant compliance failure point in transactions is not misconduct. It is the absence of a reliable evidentiary record. In the WBD process, multiple streams of information were created simultaneously:

  • Board materials
  • Banker communications
  • Draft proposals and revisions
  • Internal analyses and emails

The CCO must ensure that the company has an evidence-based protocol that includes:

  • Centralized collection of transaction-related materials
  • Defined custodians for document integrity
  • Time-stamped records of key decisions and communications

Under the DOJ’s framework, this directly ties to the question of whether the company can demonstrate effectiveness through data and documentation. If the company cannot reconstruct its decision-making process, it cannot defend it.

Treat Disclosure Controls as a Real-Time Compliance System

Post 2 emphasized that disclosure is a governance issue. For the CCO, it is a control system. The compliance function should validate that:

  • The disclosure committee is activated and functioning continuously
  • There is a clear trigger matrix for Form 8-K filings and proxy updates
  • All external communications are coordinated and controlled

This is not theoretical. In a contested transaction, the volume and speed of information create a risk of selective disclosure, inconsistent messaging, or delayed filings. The CCO must ensure that disclosure controls meet the same standard as financial controls. They must be tested, documented, and operational.

Control Third-Party and Advisor Risk

Transactions introduce intense third-party engagement. Investment banks, legal advisors, consultants, and communications firms all operate at speed. In the WBD scenario, third-party actions included:

  • Structuring revised proposals
  • Communicating deal terms
  • Interacting with market participants

The CCO must ensure:

  • Clear protocols for third-party communications
  • Defined boundaries on who can speak on behalf of the company
  • Documentation of all material third-party interactions

This aligns with long-standing expectations under the Foreign Corrupt Practices Act (FCPA) and the broader third-party risk principles embedded in compliance programs. Even in a domestic transaction, third-party risk remains a control issue.

Align Governance With Internal Controls Frameworks

The events described in Parts 1 and 2 map directly onto internal control frameworks such as the COSO Internal Controls Framework. For the CCO, this means:

  • Control Environment: Tone at the top regarding disciplined decision-making
  • Risk Assessment: Identification of disclosure, litigation, and regulatory risks
  • Control Activities: Implementation of approval processes and documentation protocols
  • Information and Communication: Real-time disclosure and coordination
  • Monitoring: Ongoing review of transaction-related controls

This mapping is not academic. It is how the company demonstrates that governance is structured, repeatable, and effective.

Prepare for Day Two Risk

The transaction does not end with signing or closing. It creates a new risk profile. The CCO must plan for:

  • Integration of compliance programs across entities
  • Review of legacy decisions made during the transaction process
  • Preservation of records for litigation or regulatory review

This is where the DOJ’s focus on continuous improvement becomes critical. The company must show that it learns from the transaction and strengthens its program.

Connecting the Lessons Across the Series

Part 1 showed that deal terms, including termination fees and superior proposal mechanics, can change outcomes. Part 2 demonstrated that the Board must govern those changes through documented, disciplined processes. In Part 3, we demonstrated the connections between the two. The compliance function is the mechanism that allows the company to prove that governance worked. Without compliance execution, governance is an assertion. With compliance execution, governance becomes evidence.

Practical Action Steps for CCOs

  1. Embed compliance into the transaction governance structure at the outset of any deal.
  2. Implement an evidence protocol that captures all material transaction activity in real time.
  3. Test disclosure controls under accelerated conditions, including mock 8-K scenarios.
  4. Define and enforce third-party communication protocols.
  5. Map transaction governance to COSO and DOJ ECCP requirements before a contested situation arises.

Questions for the CCO

  1. If a regulator requested the full decision record tomorrow, could the company produce it?
  2. Are disclosure controls capable of operating continuously under transaction pressure?
  3. Is there a single source of truth for transaction-related documentation?
  4. Are third-party interactions fully documented and controlled?
  5. Has the compliance program been stress-tested in a high-speed governance scenario?

Final Thoughts

The Warner Bros. Discovery bidding war is not unique. What is unique is how clearly it illustrates the modern role of the Chief Compliance Officer. Compliance is no longer limited to preventing misconduct. It is responsible for enabling the company to act, decide, and disclose with integrity under pressure and then prove it. That is the standard set by the DOJ. That is the expectation of Boards. And that is the future of the compliance profession.

 

Categories
Blog

The Warner Bros. Bidding War: Part 1 – What Happened and Why Compliance Professionals Should Care

A fast-moving corporate auction shows how deal terms, fiduciary duties, disclosure controls, regulatory risk, and evidence discipline can determine the outcome of a major transaction. Over the rest of this week, I will be exploring the Warner Bros./Netflix/Paramount bidding war, which

The Deal That Changed Direction

The Warner Bros./Netflix/Paramount bidding war is one of those corporate stories that looks like Hollywood drama on the surface but is really a governance story underneath. At first, Warner Bros. (WBD) had an agreed transaction with Netflix. That deal carried a $2.8 billion company termination fee payable by WBD under specified circumstances, including termination to enter into a superior proposal. The proxy materials also disclosed a $5.8 billion regulatory termination fee payable by Netflix if the deal failed for certain regulatory reasons. (SEC)

Then Paramount Skydance (Paramount) came back with a revised proposal. It raised the bid to $31 per WBD share in cash, added a ticking fee, offered a $7 billion regulatory termination fee, and agreed to fund the $2.8 billion termination fee owed to Netflix. (SEC) Reuters reported that WBD said the revised Paramount proposal could be considered superior, which set the process in motion. (Reuters)

By February 27, 2026, WBD terminated the Netflix agreement and entered into a merger agreement with Paramount Skydance. WBD later disclosed that Paramount Skydance paid the $2.8 billion Netflix termination fee on WBD’s behalf. (SEC)

That is the transaction story. The compliance story is deeper.

This Was Not Merely a Higher Price

In M&A, price matters. But price is rarely the only issue. Boards also look at certainty of closing, regulatory risk, financing, timing, shareholder value, legal exposure, and execution risk. Paramount did not merely increase the cash price. It addressed several deal objections at once. It offered to cover the Netflix break fee. It added a ticking fee if closing was delayed. It increased regulatory risk protection. It positioned its offer as cleaner, faster, and more certain than the existing transaction. (SEC)

That matters because boards do not evaluate superior proposals in a vacuum. They evaluate the entire package. The better governance question is not simply, “Which offer is higher? ”It is, “Which offer delivers the best risk-adjusted value to shareholders, and can the Board prove how it reached that conclusion? ”

The Termination Fee Became a Governance Issue

The $2.8 billion termination fee is an important part of the story. In ordinary conversation, that number sounds like a barrier. In this transaction, it became part of the competitive bidding structure. Paramount agreed to fund the termination fee, which changed the economics for WBD shareholders. WBD’s own annual report language later stated that, after the Board determined it had received a Company Superior Proposal and Netflix waived its right to propose revisions, WBD terminated the Netflix agreement and Paramount paid Netflix the $2.8 billion fee on WBD’s behalf. (SEC)

For compliance and governance professionals, this is the control point: when a large termination fee can be assumed, reimbursed, funded, or otherwise neutralized by a rival bidder, the company needs clear documentation showing who approved that structure, how it was analyzed, how it was disclosed, and how conflicts were managed.

Disclosure Was Not a Back-Office Exercise

In a contested transaction, disclosure is part of the control environment. The company must update shareholders, respond to rival communications, track proxy statements, preserve drafts, document board deliberations, and avoid selective disclosure. The Netflix proxy materials laid out the termination fee structure and the circumstances under which the fee could become payable. (SEC) Paramount’s revised proposal was also publicly communicated through SEC filings, including the increased $31-per-share cash price and the regulatory termination fee. (SEC)

This is where compliance should pay attention. A transaction can move faster than the company’s document discipline. Emails, banker calls, board materials, draft press releases, proxy supplements, and negotiation notes can become evidence. If the company doesn’t have a real-time evidence protocol, the record will build itself, which isn’t ideal.

Why Compliance Professionals Should Care

Some believe this is a board-and-banker story. That is too narrow. It is also a compliance story because compliance is about governance, controls, documentation, accountability, escalation, and evidence. A high-stakes transaction tests whether the company’s control environment holds up under the highest pressure. It tests whether the Board receives complete information. It tests whether management understands escalation obligations. It tests whether legal, finance, communications, investor relations, and compliance can coordinate without losing the record.

This is exactly the kind of moment when the DOJ’s Evaluation of Corporate Compliance Programs is relevant, even outside an enforcement action. The central question is familiar: is the program well-designed, adequately resourced, empowered to function, and working in practice? In M&A, that means the compliance function should understand how deal governance intersects with disclosure controls, third-party risk, regulatory commitments, document preservation, and post-closing integration.

The Larger Lesson

The WBD bidding war shows that corporate governance is not theoretical. It is operational. A superior proposal clause is not just legal drafting. A termination fee is not just a financial number. A proxy supplement is not just a filing. Each is a control point. The companies that manage these moments well do three things. They make decisions through disciplined processes. They document the basis for those decisions in real time. They align governance, legal, finance, disclosure, and compliance before the crisis point arrives.

Practical Takeaways for Compliance Professionals

  1. Major transactions require evidence discipline from day one.
  2. Disclosure controls must be ready before a rival bidder appears.
  3. Termination fees and regulatory commitments should be treated as governance issues, not simply deal terms.
  4. Board minutes and waiver records must tell the fiduciary story.
  5. Compliance should have a seat at the broader transaction control table, especially when regulatory, third-party, data access, communications, and post-closing integration risks are implicated.

That is the lesson for every CCO. You may not be running the auction, but your program should help the company prove that it made decisions with integrity, evidence, and accountability.

Categories
Daily Compliance News

Daily Compliance News: April 29, 2026, The Trial of the Century Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • PR exec tried to get rid of documents. (FT)
  • Why did First Brands hire BDO? (FT)
  • Altman v. Musk. Trial of the Century. (FT)
  • Should your Board appoint a Bot? (FT)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Data Governance, Privacy, and Model Integrity: The Control Foundation of AI Governance

Artificial intelligence may look like a technology story on the surface, but beneath that surface lies a governance reality every board and Chief Compliance Officer must confront. AI systems are only as sound as the data that feeds them, the controls that govern them, and the integrity of the outputs they generate. When data governance is weak, privacy obligations are poorly managed, or model integrity is assumed rather than tested, AI risk can move quickly from a technical flaw to enterprise exposure.

In the prior blog posts in this series, I examined the foundational questions of AI governance: board oversight and accountability, and the danger of strategy outrunning governance. Today, I want to turn to a third issue that sits at the core of every credible AI governance program: data governance, privacy, and model integrity.

This is where the AI conversation often moves from excitement to discipline. Companies may be eager to deploy tools, automate functions, and improve decision-making. But none of that matters if the underlying data is flawed, sensitive information is mishandled, or the model produces outputs that are unreliable, biased, or impossible to explain in context—the more powerful the technology, the more important the governance framework beneath it.

For boards and CCOs, this is not simply a technical control matter. It is a governance matter because failures in data integrity, privacy management, and model performance can have legal, regulatory, reputational, financial, and cultural consequences simultaneously.

AI Governance Begins with the Data

There is an old saying in technology: garbage in, garbage out. In the AI era, that phrase remains true, but it is no longer sufficient. In corporate governance terms, the problem is not merely bad data. It is unknown, unauthorized, untraceable, biased, stale, overexposed, or used in ways the organization never properly approved. That is why data governance is the control foundation of AI governance.

Every AI use case depends on inputs. Those inputs may include structured internal data, public information, personal data, third-party data, proprietary records, historical documents, transactional records, prompts, or user interactions. If management does not understand where that data comes from, who has rights over it, whether it is accurate, how it is classified, and whether it is appropriate for the intended purpose, then the company is not governing AI. It is merely using it.

For compliance professionals, this point should feel familiar. Data governance is not new. What is new is the speed and scale at which AI can amplify data weaknesses. A spreadsheet error may affect one report. A flawed AI input may affect thousands of interactions, recommendations, or decisions before anyone notices.

Why Boards Should Care About Data Lineage

Boards do not need to become technical experts in model training or data architecture. But they do need to ask whether management understands the provenance and reliability of the information flowing into critical AI systems.

At a governance level, this is a question of data lineage. Can the company trace the source of the data, how it was curated, whether it was changed, and whether it was approved for the intended use? If a customer, regulator, employee, or auditor asks why the system reached a particular result, can management explain not only the output, but the data conditions that shaped it?

A board that does not ask these questions risks receiving polished dashboards and impressive demonstrations while missing the underlying weaknesses. AI systems can sound authoritative even when they are wrong. That is part of what makes governance here so essential. Confidence is not the same as integrity.

This is also where the Department of Justice’s Evaluation of Corporate Compliance Programs (ECCP) offers a helpful mindset. The ECCP pushes companies to think in terms of operational reality. Do policies work in practice? Are controls tested? Is the company learning from what goes wrong? The same discipline applies here. A company should not assume its data environment is fit for AI simply because it has data available. It should test, verify, document, and challenge that assumption.

Privacy Is Not an Adjacent Issue

Too many organizations still treat privacy as adjacent to AI governance rather than central to it. That is a mistake. AI systems often rely on data sets that include personal information, employee information, customer records, usage patterns, communications, or behavior-based inputs. Even when a company believes it has de-identified or anonymized data, there may still be re-identification risks, overcollection concerns, retention issues, or use limitations tied to law, contract, or internal policy.

For the board and the CCO, privacy should not be discussed as a compliance side note. It should be part of the approval and governance architecture from the outset. Before an AI use case is deployed, management should understand what personal data is involved, whether its use is permitted, what notices or disclosures apply, what access restrictions are required, how the data will be retained, and whether any vendor relationships create additional privacy exposure.

This is particularly important in generative AI environments, where employees may paste confidential, proprietary, or personal information into tools without fully appreciating the consequences. A privacy incident in the AI context may not begin with malicious intent. It may begin with convenience. That is why governance must focus not only on policy, but on system design, training, and usage constraints.

The CCO has a critical role here because privacy governance often intersects with policy management, employee conduct, training, investigations, and disciplinary response. If privacy is left solely to specialists without integration into the broader governance process, the organization risks building fragmented controls that do not hold together under pressure.

Model Integrity Is a Governance Question

Model integrity sounds like a technical term, but it is really a governance concept. It asks whether the system is performing in a manner consistent with its intended purpose, risk classification, and control expectations.

That means asking hard questions. Is the model accurate enough for the use case? Has it been validated before deployment? Are there known limitations? Does it perform differently across populations or scenarios? Can outputs be reviewed in a meaningful way by human decision-makers? Are there conditions under which the model should not be used? These are not engineering questions alone. They are governance questions because they determine whether management is relying on the system responsibly.

This is where NIST’s AI Risk Management Framework is especially valuable. NIST emphasizes that organizations should map, measure, and manage AI risks, including those related to validity, reliability, safety, security, resilience, explainability, and fairness. It is not enough to say that a tool works most of the time. The organization must understand where it may fail, how failure will be detected, and what safeguards are in place when it does.

ISO/IEC 42001 reinforces the same discipline through the lens of management systems. It requires structured attention to risk identification, control design, monitoring, documentation, and continual improvement. In other words, it treats model integrity not as a technical aspiration, but as an organizational responsibility. For boards, the takeaway is direct: if management cannot explain how model integrity is validated and maintained, then the board does not yet have assurance that AI is being governed effectively.

Third Parties Increase the Stakes

One of the more dangerous assumptions in AI governance is that outsourcing technology also outsources risk. It does not. Many organizations will deploy AI through third-party vendors, embedded tools, software platforms, or external service providers. That may be practical, even necessary. But it also means the company may be relying on data practices, training methods, model assumptions, or privacy safeguards it did not design and cannot fully see.

That is why data governance, privacy, and model integrity must extend to third-party risk management. Procurement cannot focus solely on functionality and price. Legal cannot focus solely on contract form. Compliance, privacy, security, and risk all need to understand what the vendor is doing, what data is being used, what rights the company has to inspect or question performance, and what happens when the vendor changes the model or its underlying terms.

This is not simply good vendor management. It is a governance necessity. A company remains accountable for business decisions made using third-party AI tools, especially when those tools affect customers, employees, compliance obligations, or regulated activities.

Documentation Is What Makes Governance Real

As with every major governance issue, documentation is what turns theory into evidence. If a company is serious about data governance, privacy, and model integrity, it should have records that show it. Those records may include data inventories, data classification standards, model validation summaries, privacy assessments, vendor due diligence files, testing results, approved use cases, control requirements, escalation logs, and remediation actions. Without this documentation, governance becomes anecdotal. With it, governance becomes reviewable, auditable, and improvable.

This is another place where the ECCP mindset is so useful. Prosecutors and regulators tend to ask the same core question in different ways: how do you know your program works? In the AI context, the answer cannot be “our vendor told us so” or “the business says the tool is helpful.” It must be grounded in evidence, testing, and management discipline.

What Boards and CCOs Should Be Pressing For

Boards should expect management to present AI use cases with enough clarity to answer four questions. What data is being used? What privacy implications attach to that use? How has model integrity been tested? What controls will remain in place after deployment?

CCOs should press equally hard from the management side. Is there a documented data governance process for AI? Are privacy reviews built into the intake and approval process? Are models validated according to risk? Are third-party tools subject to diligence and contract controls? Are incidents and anomalies logged and investigated? Are employees trained not to expose confidential or personal information through improper use? These are not burdensome questions. They are the practical questions that separate governed AI from hopeful AI.

Governance Requires Trustworthy Inputs and Defensible Outputs

In the end, AI governance depends on a simple but demanding truth: the organization must be able to trust what goes into the system and defend what comes out of it.

If the data is poorly governed, privacy rights are handled casually, or model integrity is assumed rather than demonstrated, then no amount of strategic enthusiasm will make the program safe. Boards will not have real oversight. CCOs will not have a defensible control environment. The company will merely have a faster way to create risk.

That is why data governance, privacy, and model integrity are not support issues in AI governance. They are central issues. They determine whether the enterprise is using AI with discipline or simply hoping for the best.

In the next article in this series, I will turn to the fourth governance challenge: ongoing monitoring, where many organizations discover that approving an AI use case is far easier than governing it after it goes live.