Categories
Blog

THE BERKO TRIAL – PART 5: From Case Study to Control Test: A Berko Compliance Playbook for CCOs and Boards

Today we conclude our 5-part deep dive into the Asante Berko trial and guilty verdict, using the trial not simply as a case study but as a mechanism to pressure-test your compliance regime.

A compliance program is not effective because the company eventually exits a troubled transaction. It is effective when leaders can show how quickly the system identified the risk, who had authority to act, whether related conduct was contained, what the investigation established, and how the organization changed afterward.

That is the governance test presented by the Berko trial. Prosecutors built their case from emails, payment patterns, personal communications, compliance questions, recorded statements, and financial evidence. The defense attacked the missing last mile. The jury convicted Asante Berko on all three counts in just over three hours. For CCOs and boards, the final lesson is not to retry the case. It is to determine whether their own program could identify the same pattern, develop reliable facts, impose accountability, and respond at the speed enforcement policy now demands.

Start With the Three Questions That Matter

The DOJ Evaluation of Corporate Compliance Programs (ECCP) organizes program effectiveness around three questions. (1) Is the program well designed? (2) Is it applied earnestly and in good faith, with adequate resources and authority? (3) Does it work in practice? Those questions should frame the board’s review of the Berko fact pattern.

A written third-party policy answers the first question only in part. The second asks whether compliance can pause a revenue-producing transaction, obtain records, challenge senior employees, and reach the board without management filtering. The third asks for outcomes: when the warning signs appeared, did the organization find them, act on them, preserve the evidence, and fix the control weakness?

The governance failure is often not the absence of a rule. It is the gap between ownership and authority. Management owns business conduct and risk decisions. The CCO advises, challenges, monitors, and escalates. Internal audit provides independent assurance. The board oversees the system and management’s response. If every party assumes another function owns the hard decision, the control exists on paper but fails in operation.

Align Incentives, Conflicts, and Consequences

High-risk transactions require a clear view of personal incentives. Employees should disclose and pre-clear outside interests, referral compensation, client-paid benefits, expected success fees, and post-employment opportunities connected to current transactions. Offboarding should preserve relevant data, review pending payments, close access, identify continuing client contacts, and obtain certifications concerning outside interests and retained information.

Compensation deserves the same scrutiny as third-party payments. A bonus plan that rewards closing without measuring risk quality invites employees to treat compliance as a cost of delay. Risk-adjusted incentives should account for diligence completion, control compliance, escalation quality, and the durability of the business outcome. The ECCP asks whether companies use incentives for ethical conduct and apply discipline consistently across seniority, geography, and business unit. It also asks whether compensation can be deferred, reduced, canceled, or recouped when misconduct is established, subject to applicable law.

Consequence management must reach more than the direct actor. A credible process examines supervisory failure, tolerated red flags, obstruction, and failure to install or use safeguards. It applies the same decision framework to rainmakers and junior employees. The board should receive trend information showing investigation cycle times, substantiation rates, disciplinary consistency, repeat issues, and whether managers were held accountable for control failures.

Build Investigation and Speak-Up Readiness

The defense’s attack on the Berko evidence offers an investigation lesson. A source may have motives. A recording may require translation. Emails may lack a witness who can explain context. Payments may be traceable to an intermediary but not to an ultimate recipient. Those are reasons to investigate carefully, not reasons to dismiss an allegation.

Separate source credibility from objective proof. Preserve native emails, attachments, metadata, messaging records, payment instructions, approval histories, and device data. Trace funds beyond the first recipient. Document translation choices, dialect issues, investigative prompting, and competing interpretations. Interview witnesses who can explain both the transaction and the communications. Record what was established, what remained disputed, and why each conclusion was reached.

Design the process before the crisis. Define triage criteria, independence, privilege, preservation, scope approval, board escalation, investigation timing, root-cause analysis, and remediation ownership. Provide reporting channels that employees and third parties know, trust, and can use without retaliation. DOJ treats a trusted reporting mechanism and timely, properly scoped, objective, and documented investigations as hallmarks of an effective program.

Prepare the Disclosure Decision Before the Clock Starts

Voluntary disclosure should not be improvised during a board emergency. The company needs a protocol that identifies decision owners, the role of counsel, the facts required, preservation steps, the escalation path, and the method for assessing seriousness, pervasiveness, seniority, ongoing harm, and potential collateral consequences.

The March 2026 Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) makes speed commercially significant. It provides a declination path when a company voluntarily self-discloses to the appropriate DOJ component, fully cooperates, timely and appropriately remediates, and lacks disqualifying aggravating circumstances, although prosecutorial discretion and the policy’s definitions still control. The policy also contains an exception for a whistleblower who reports both internally and to DOJ. A company may remain eligible if it reports as soon as reasonably practicable, no later than 120 days after the internal report, and satisfies the other requirements.

That is not a 120-day permission slip to wait. The operating standard is speed with discipline. The company must stop continuing harm, preserve evidence, protect privilege, develop facts, and keep decision-makers informed. A tabletop exercise should test whether the organization can do all five while the disclosure window is running.

Give the Board Evidence, Not Activity Counts

Boards do not need every hotline allegation or third-party file. They need a risk-based view of whether the system works. Reporting should cover high-risk transactions proceeding with incomplete diligence, unresolved politically exposed person relationships, payment holds, management overrides, aged investigations, remediation slippage, repeat control failures, off-channel communication exceptions, and risk acceptances by senior leaders.

Metrics should show speed, quality, and outcomes. Track time from red flag to triage, triage to transaction pause, allegation to investigation plan, finding to discipline, and remediation commitment to validated closure. Measure whether the company can match high-risk payments to legitimate services, verified beneficial owners, approved accounts, and evidence of performance. Show whether control testing changed behavior, not simply whether employees completed training.

The CCO should have regular direct access to the board or responsible committee, including private sessions when appropriate. The board should understand the CCO’s authority, resources, data access, and unresolved requests. DOJ asks what information directors examined, whether compliance concerns stopped or changed transactions, and whether compliance has the stature and autonomy to function effectively.

Run a 30/60/90-Day Berko Stress Test

Days 1 to 30: Replay one recent high-risk public-sector transaction against the Berko pattern. Inventory intermediaries, beneficial owners, politically exposed person relationships, success fees, conflicts, personal-email exceptions, cash exposure, payment destinations, incomplete diligence, and overrides. Identify which facts the current systems can retrieve and which depend on manual reconstruction.

Days 31 to 60: Close the most important design gaps. Add hard stops, fee benchmarking, conflict attestations, off-channel controls, evidence-preservation rules, payment analytics, investigation protocols, and an escalation matrix giving compliance documented pause authority. Assign one accountable owner and a deadline to each remediation item.

Days 61 to 90: Test the program. Sample transactions, trace selected payments end to end, test the hotline from intake through closure, and conduct an investigation and voluntary-disclosure tabletop. Present the results to senior management and the board, including accepted risks, overdue actions, resource needs, and evidence that completed remediation operates in practice.

The board should ask, “Which Berko warning signs would we detect today?” How quickly could we freeze a payment? Who may override compliance, and what evidence is required? Can investigators collect personal-device communications lawfully and preserve multilingual evidence? Which repeated control failures have affected compensation or promotion?

The CCO should ask one final question: Would our program find this pattern because the controls work, or only because an external source eventually brings it to us?

This Berko FCPA trial blog post series began with the prosecution’s evidentiary mosaic and the defense’s missing-last-mile challenge. It ends with a practical conclusion. Compliance evidence becomes trial evidence. A defensible program must create that evidence through authority, trusted reporting, disciplined investigations, consistent accountability, measurable remediation, and active board oversight. That is how a case study becomes a control test and how a control test becomes proof that the program works.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Blog

THE BERKO TRIAL – PART 4: When Red Flags Become Evidence: Transaction Controls from the Berko Trial

Today in Part 4, I want to focus on some of the compliance lessons from the Asante Berko FCPA trial. The compliance lesson from the Berko trial is not simply that employees should not pay bribes. Every code of conduct already says that. The harder question is whether the compliance program can interrupt the operating pattern: a politically connected intermediary, milestone-linked invoices, personal email, cash discussions, incomplete diligence answers, and a commercial team under pressure to close. These were some of the questions that Goldman Sachs faced and successfully answered.

That is where policy becomes performance. Trial reporting described a legitimate infrastructure project surrounded by evidence that prosecutors said showed corrupt intent and concealment. The same emails, diligence questions, payment records, and escalation decisions that once lived inside a transaction later became evidence before a jury. For compliance professionals, the case is a control map. It shows where a high-risk deal can be tested, paused, corrected, or stopped before red flags mature into criminal exposure.

Begin With the Business Model

Your business justification should begin with how the deal is expected to work, not with a standard questionnaire. In the Berko transaction, commercial urgency, a major public need, concentrated government discretion, substantial projected fees, and local intermediaries all increased the risk profile. None of those facts establishes bribery. Together, however, they demand a more disciplined control environment.

The deal team should be required to explain the legitimate path to success. Which officials control each approval? Which regulatory, legislative, and contractual milestones must occur? What service does every intermediary perform? How is that service connected to value rather than access? Where could commercial pressure tempt someone to bypass the process?

This is consistent with the DOJ Evaluation of Corporate Compliance Programs (ECCP), which asks whether a company understands its business from a commercial perspective and devotes appropriate attention and resources to high-risk transactions. A generic country score is not enough. The risk assessment must reflect the transaction’s economics, approval structure, counterparties, compensation model, technology, and pressure points.

Make Third-Party Diligence Operational

Third-party diligence often fails because it is treated as an onboarding event. The questionnaire is completed, screening is run, a risk rating is assigned, and the business moves on. High-risk public-sector work requires continuous control.

Before engagement, the company should document the business rationale, beneficial ownership, politically exposed person and family links, qualifications, reputation, service scope, deliverables, compensation, payment terms, and proposed bank account. Compensation should be benchmarked against the actual work. Enhanced review should apply when fees are success-based, tied to government milestones, disproportionate to services, routed through unrelated entities or individuals, or connected to officials who control approvals.

After onboarding, controls must follow the intermediary into contracting, invoicing, payment, and monitoring. The DOJ guidance asks whether the company understands the business rationale, confirms that services were actually performed, assesses whether compensation is appropriate, tracks red flags, uses audit rights, and manages third parties throughout the relationship. The relevant question is not whether the intermediary passed diligence once. It is whether the relationship still makes sense when the invoice arrives.

Control the Channels Where Business Occurs

Personal email is not proof of bribery. The Berko facts were more specific. According to the trial reporting, sensitive payment discussions occurred through personal accounts. At the same time, routine deal work proceeded through corporate systems, and one exchange referred to the monitoring of a Goldman account. The control issue was the combination of channel separation, sensitive content, and knowledge of monitoring.

Companies need clear rules for personal email, messaging applications, approved mobile platforms, and bring-your-own-device arrangements. Those rules require technical support: approved-channel design, retention settings, monitoring consistent with law, exception approval, employee attestations, and escalation when business moves outside the system. The program should also test whether records can actually be collected and preserved across the jurisdictions where the company operates.

The ECCP asks how companies manage and preserve business communications on personal devices and messaging platforms. The DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) likewise identifies appropriate controls over personal and ephemeral communications as part of timely remediation. A policy that cannot preserve the evidence it covers is not an effective control.

Give Compliance Real Stop Authority

Escalation is not effective if compliance can ask questions but cannot pause the transaction. High-risk deals need defined hard stops. Examples include incomplete beneficial ownership, inconsistent diligence answers, refusal to identify service providers, unexplained compensation, undisclosed PEP relationships, requests for cash, payments to personal or nominee accounts, and destination changes without a credible business reason.

A hard stop does not require the company to abandon every transaction containing a red flag. It requires the risk to be resolved before money or value moves. The control framework should identify who may impose a pause, who may clear it, whether any override is permitted, what evidence supports an override, and which risk decisions require senior escalation.

Trial testimony reportedly described months of compliance questions about the Ghanaian intermediary and inconsistent or incomplete answers, followed by Goldman’s withdrawal from the contemplated financing. That sequence should not be converted into a claim that every control operated early enough or that the company was legally exonerated. The more useful lesson is that the decision trail mattered. It documented the questions, the resistance, the escalation, and the exit.

Connect Diligence, Invoices, and Money

Many programs distribute the relevant facts across separate systems. Procurement sees the contract. Compliance sees the screening. Accounts payable sees the invoice. Treasury sees the destination account. Investigations see the allegation. No one sees the complete pattern.

Payment controls should require proof of service, account-name matching, country and entity consistency, independent approval for destination changes, and tight restrictions on cash. Analytics should flag round-dollar invoices, duplicate invoice numbers, payment splitting, milestone-timed consulting fees, payments to employees or related parties, high-risk correspondent routes, and transfers followed by cash withdrawals.

The decisive step is integration. Due diligence, PEP screening, contracting, procurement, accounts payable, treasury, and case-management data should be capable of producing a transaction-level view. That view allows compliance to ask whether a payment is not only properly approved but also commercially credible.

Build an Evidence-Grade Record

The defense’s most forceful theme was the missing last mile: no downstream bank record showing money reaching a Ghanaian official, no alleged recipient on the witness stand, and no eyewitness to a bribe. The jury nevertheless convicted Berko on all three charged counts. For an internal investigation, the lesson cuts both ways. Suspicion is not proof, but weak tracing can leave the company unable to determine what happened.

Preserve native emails, attachments, metadata, messaging exports, payment records, approval histories, translations, and custodial provenance—record who made each factual determination and what evidence supported it. For multilingual material, preserve the original, use qualified translators, document dialect and ambiguity, and maintain a process for reviewing disputed language. Financial tracing should move from payer to intermediary to ultimate recipient, including related-party accounts and cash conversion.

The current FCPA enforcement guidelines emphasize individual misconduct and caution against attributing nonspecific malfeasance to corporate structures. That makes an evidence-grade corporate record especially important. It can help separate an individual’s conduct from the organization’s response while also showing whether the program was designed and implemented effectively.

Test the Controls Before the Crisis

An effective program does not promise that no misconduct will ever occur. DOJ recognizes that even a strong program may fail to prevent an offense. The question is whether the program is risk-based, detects concerns, responds promptly, and improves from experience.

Replay a recent public-sector transaction against the Berko pattern. Could the company identify every approval-controlling official and intermediary? Would milestone-linked payments trigger review? Could compliance pause the deal? Would personal email activity be detected and preserved? Could investigators trace funds beyond the first intermediary? Measure time from red flag to pause, overdue enhanced diligence, unresolved PEP issues, payment exceptions, control overrides, and closure of remediation.

The practical takeaways are clear. Commercial urgency calls for greater discipline, not reduced scrutiny. Third-party diligence must remain connected to invoices, payments, monitoring, and escalation. Off-channel communications become an intent and preservation issue when combined with sensitive content and known monitoring. A deal exit matters, but an earlier hard stop may reduce exposure and preserve more business value.

Join us tomorrow as we conclude our 5-part series by moving the transaction to the enterprise. In it, we will explore such questions as who owns these controls, who funds and tests them, how accountability is imposed, and what your Board of Directors should demand as evidence that the program works in practice.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 70 – Lessons from Let That Be Your Last Battlefield: Building Justice and Fairness into Corporate Culture

Few episodes capture the destructive power of bias, systemic injustice, and the refusal to see common humanity as vividly as Star Trek: The Original Series’ “Let That Be Your Last Battlefield.” From a compliance perspective, the episode provides an unflinching mirror: organizations that fail to ensure fairness in their systems—whether in investigations, promotions, whistleblower treatment, or discipline—risk breeding internal hostilities just as destructive as Cheron’s. Today, we unpack five key compliance lessons for embedding institutional justice and fairness into the corporate DNA.

Lesson 1: Bias—Even When Invisible to Some—Can Destroy Organizational Cohesion

Illustrated by: When Bele first encounters Lokai aboard the Enterprise, he describes him as “obviously inferior.”

Compliance Lesson. Bias often hides in plain sight for those not affected by it. In corporate settings, decision-makers may not recognize that promotion patterns, discipline rates, or resource allocations favor certain groups until a whistleblower, audit, or public scandal exposes it.

Lesson 2: Enforcement Must Be Fair, Consistent, and Transparent

Illustrated by: Bele claims the right to arrest Lokai for crimes committed on Cheron. Lokai, in turn, accuses Bele of genocide. Neither offers verifiable evidence; instead, both rely on their moral certainty.

Compliance Lesson. Internal enforcement that rests on vague accusations or uneven application destroys trust in compliance systems.

Lesson 3: Leaders Must Refuse to Be Drawn into Partisan Vendettas

Illustrated by: Kirk insists on the Enterprise’s code of conduct and rules of evidence.

Compliance Lessons. Senior leaders are often pressured, subtly or overtly, to “pick a side” in internal disputes.

Lesson 4: Systemic Injustice Can Persist Until It Consumes the Organization

Illustrated by: When Bele and Lokai finally return to Cheron, they find their planet in ruins, destroyed by centuries of hatred. Yet, even faced with the extinction of their people, they continue their pursuit, consumed by the need to destroy the other.

Compliance Lesson. Corporate cultures that allow systemic injustice, favoritism in promotions, discriminatory pay structures, and retaliation against whistleblowers risk not only reputational harm but also the destruction of the organization’s ability to function cohesively. Over time, injustice becomes normalized, making reform nearly impossible without significant disruption.

Lesson 5: Without a Shared Framework for Fairness, Conflict Has No Resolution

Illustrated by: Spock, ever the voice of logic, tries to point out that the two aliens are more alike than different. To them, justice is entirely defined by the defeat of the other.

Compliance Lesson. In corporations, the absence of a clear, visible framework for fairness, along with policies, expectations, and trusted reporting channels, leads to conflicts that devolve into zero-sum games.

Final ComplianceLog Reflections

Let That Be Your Last Battlefield ends on a tragic note: the two survivors beam down to a dead world, still locked in mutual hatred. It’s a cautionary tale for corporate life. Without institutional justice and fairness, even the most advanced organizations can collapse into destructive internal conflict.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Timothy is an AI-generated voice

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 67 – The Human Element in Compliance: CCO Takeaways from ‘The Empath’

Today we set a course for one of Star Trek: The Original Series’ most underrated yet profound episodes: “The Empath.” As compliance professionals, we know that the heart of any effective compliance program is its leadership. The Hallmarks of an Effective Compliance Program, from the FCPA Resource Guide, 2nd edition, require that the CCO possess the “appropriate expertise” to do the job. But what does that mean, and how does a leader’s expertise transcend mere technical skill to encompass the human, ethical, and cultural challenges inherent to the compliance function?

As we explore five critical lessons for compliance officers from “The Empath,” you will observe that true expertise for a CCO is not simply about credentials or technical know-how; rather, it is about the deeper qualities that empower a leader to guide organizations through pain, ambiguity, and risk.

Lesson 1: Beyond the Resume: The CCO as Empathic Leader

Illustrated by: Gem learns not through technical means, but by direct connection and deep feeling.

Compliance Lesson. Expertise is more than certifications, legal degrees, or audit experience. The most effective CCOs bring an “empathic intelligence” to their work, a capacity to understand the pressures, fears, and motivations of employees at all levels.

Lesson 2: Courage Under Pressure: The CCO Must Withstand the Ultimate Test

Illustrated by: The episode asks, who dares to stand up, even when it hurts?

Compliance Lesson. CCO expertise is proven under fire. This means the ability to stand firm when pressured by powerful business leaders, to deliver hard truths to the Board, and to make unpopular recommendations in the face of potential personal or professional blowback.

Lesson 3: Interdisciplinary Skillset: Bridging Science and Compassion

Illustrated by: The Enterprise officers combine analytical thinking with compassion, helping Gem grow by demonstrating both logic and heart.

Compliance Lesson. A truly effective CCO integrates hard skills with the “soft skills” of persuasion, relationship-building, and cultural sensitivity.

Lesson 4: The Power of Sacrifice: Prioritizing the Mission Over Personal Gain

Illustrated by: McCoy’s selflessness teaches Gem that true empathy means accepting risk for the sake of others’ well-being.

Compliance Lesson. The CCO role demands a willingness to prioritize the organization’s long-term health, even when it may come at the cost of short-term popularity or personal advancement.

Lesson 5: Teaching and Transforming: The CCO as Culture Carrier

Illustrated by: By the episode’s conclusion, Gem is transformed by the example set by the Enterprise crew. She learns to act, not just to feel, demonstrating that real change comes from both internalizing values and taking decisive action.

Compliance Lesson. A CCO’s expertise is measured not only in what they know but also in how effectively they teach, mentor, and shape the organization’s culture—the enterprise.

Final ComplianceLog Reflections

The Empath” reminds us that leadership in compliance, like leadership in the Enterprise, requires more than technical skill. It requires empathy, courage, interdisciplinary knowledge, sacrifice, and the ability to teach and inspire. The DOJ’s Hallmarks of an Effective Compliance Program make it clear: a CCO must have the appropriate expertise to do the job, and that expertise is as much about the heart as the head.

In evaluating, supporting, or stepping into the CCO role, remember Gem’s journey. The greatest expertise lies not only in knowing the rules but also in living them and in helping others do the same, especially when the path is hard. Empathic leadership is not a luxury; it is a requirement for building compliance programs that endure.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

Categories
Blog

Empathy, Expertise, and the CCO: Five Lessons from Star Trek’s “The Empath”

Today, we set a course for one of Star Trek: The Original Series’ most underrated yet profound episodes: “The Empath.” As compliance professionals, we know that the heart of any effective compliance program is its leadership. The Hallmarks of an Effective Compliance Program, from the FCPA Resource Guide, 2nd edition, Justice, require that the Chief Compliance Officer (CCO) possess the “appropriate expertise” to do the job. But what does that mean, and how does a leader’s expertise transcend mere technical skill to encompass the human, ethical, and cultural challenges inherent to the compliance function?

Let’s use “The Empath” as our guide. This visually striking and emotionally powerful episode puts Captain Kirk, Dr. McCoy, and Mr. Spock in the hands of alien scientists who subject them and a mysterious, silent woman named Gem to a series of moral and physical trials. At its core, the episode explores the transformative power of empathy, self-sacrifice, and moral courage.

As we explore five critical lessons for compliance officers from “The Empath,” you will observe that true expertise for a CCO is not simply about credentials or technical know-how; rather, it is about the deeper qualities that empower a leader to guide organizations through pain, ambiguity, and risk.

Lesson 1: Beyond the Resume: The CCO as Empathic Leader

Illustrated by: Gem, the titular empath, can sense and even absorb the pain of others, experiencing their suffering as if it were her own. She learns not through technical means, but by direct connection and deep feeling.

Compliance Lesson. Expertise is more than certifications, legal degrees, or audit experience. The most effective CCOs bring an “empathic intelligence” to their work, a capacity to understand the pressures, fears, and motivations of employees at all levels. Just as Gem could not help without first connecting to others’ pain, a CCO must be attuned to the human element behind every compliance risk. This empathy allows the CCO to anticipate issues before they become crises, to speak credibly to leadership about real risks, and to create a culture where people feel safe reporting concerns.

What should you do now? When evaluating CCO expertise, look beyond the resume. Ask: Does this person have the emotional intelligence to sense the cultural currents within the organization? Can they “walk the decks” and listen with intention? Empathy is not optional; it is essential.

Lesson 2: Courage Under Pressure: The CCO Must Withstand the Ultimate Test

Illustrated by: In “The Empath,” Kirk, Spock, and McCoy are subjected to torturous experiments designed to test their moral fiber. Dr. McCoy, in particular, volunteers to endure pain so others may be spared. The episode asks, Who dares to stand up, even when it hurts?

Compliance Lesson. CCO expertise is proven under fire. In practice, this means the ability to stand firm when pressured by powerful business leaders, to deliver hard truths to the Board, and to make unpopular recommendations in the face of potential personal or professional blowback. The DOJ’s 10 Hallmarks require CCOs who can operate with autonomy and independence, not simply as figureheads or “window dressing.” True expertise reveals itself when the stakes are high, and the right answer is the hard one.

What should you do now? Your CCO must be someone who will put the organization’s integrity first, even at personal cost. The “ultimate test” for a CCO is not a certification but the ability to hold the line when ethical principles are threatened.

Lesson 3: Interdisciplinary Skillset: Bridging Science and Compassion

Illustrated by: The Vians, the alien scientists, are coldly rational, treating their subjects as experimental variables. In contrast, the Enterprise officers combine analytical thinking with compassion, helping Gem grow by demonstrating both logic and heart.

Compliance Lesson. A CCO’s expertise must bridge multiple disciplines. Today’s compliance challenges touch on law, accounting, behavioral science, technology, communications, and global business. But technical expertise is only half the equation. A truly effective CCO integrates hard skills with the “soft skills” of persuasion, relationship-building, and cultural sensitivity. Like Kirk and Spock, who blend analysis and empathy to navigate the Vians’ trials, a CCO must translate regulatory requirements into messages that resonate and motivate across the organization.

What should you do now? Evaluate CCO candidates for both their cross-disciplinary knowledge and their ability to synthesize and communicate complex concepts persuasively. Expertise means connecting dots and connecting with people.

Lesson 4: The Power of Sacrifice: Prioritizing the Mission Over Personal Gain

Illustrated by: McCoy’s willingness to sacrifice himself for Kirk and Spock is a turning point—both for Gem and the Vians. His selflessness teaches Gem that true empathy means accepting risk for the sake of others’ well-being.

Compliance Lesson. The CCO role demands a willingness to prioritize the organization’s long-term health, even when it may come at the cost of short-term popularity or personal advancement. This can mean blowing the whistle on powerful stakeholders, accepting the possibility of career setbacks, or simply shouldering the emotional burden of being the “corporate conscience.” The DOJ expects companies to empower CCOs with the independence to act—because true expertise includes the courage to make sacrifices for the greater good.

What should you do now? Ask not only whether your CCO is capable, but whether they are willing to accept the risks of leadership. Expertise means prioritizing the mission even when the cost is high.

Lesson 5: Teaching and Transforming: The CCO as Culture Carrier

Illustrated by: By the episode’s conclusion, Gem is transformed by the example set by the Enterprise crew. She learns to act, not just to feel, demonstrating that real change comes from both internalizing values and taking decisive action.

Compliance Lesson. A CCO’s expertise is measured not only in what they know but also in how effectively they teach, mentor, and shape the organization’s culture. Just as Gem evolved through the guidance of Kirk and McCoy, so too must a CCO help others grow, empowering managers, employees, and even Board members to become stewards of compliance. Expertise is contagious: a strong CCO leaves a legacy of ethical leadership throughout the enterprise.

What should you do now?

Does your CCO inspire others to act with integrity? Are they a “culture carrier,” modeling the behaviors and values they wish to see at every level? True expertise is reflected in the transformation of others.

Final ComplianceLog Reflections

The Empath” reminds us that leadership in compliance, like leadership in the enterprise, requires more than technical skill. It requires empathy, courage, interdisciplinary knowledge, sacrifice, and the ability to teach and inspire. The DOJ’s Hallmarks of an Effective Compliance Program make it clear: a CCO must have the appropriate expertise to do the job, and that expertise is as much about the heart as the head.

In evaluating, supporting, or stepping into the CCO role, remember Gem’s journey. The greatest expertise lies not only in knowing the rules but in living them and in helping others do the same, especially when the path is hard. Empathic leadership is not a luxury; it is a requirement for building compliance programs that endure.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Connected Compliance: Part 5 – From Signals to Trust: Why Compliance Must Operate as One System

We conclude our series on various components of connected compliance by pulling them all together in an integrated whole. An effective compliance program is often described through its components: policies, training, risk assessment, reporting channels, investigations, discipline, and monitoring. That description is accurate, but incomplete. It tells us what the program contains. It does not tell us how the program works.

The deeper lesson from this series is that compliance effectiveness lives in the connections. Communication, risk sensing, investigations, and whistleblower programs are not separate workstreams that happen to sit under the same organizational chart. They are parts of one information-and-accountability system. Each part produces information that another part must receive, interpret, and convert into action.

That is the integrated argument. Compliance is truly connected because risk moves through an organization as a signal before it becomes an event. An employee question, customer request, control exception, supplier problem, unusual payment, new technology use, or hotline report may be the first indication that the company’s risk profile has changed. The program succeeds when it can move that information through a disciplined cycle: listen, assess, assign, investigate, remediate, communicate, and learn.

The program fails when the signal dies at a handoff.

The Seams Are Where Compliance Breaks

Most companies do not lack compliance activity. They lack reliable movement between activities. Training may be completed, but recurring questions never reach the risk assessment. A hotline may capture an allegation, but intake and investigation teams may use different priorities. An investigation may identify a control weakness, but the remediation owner may not be named. A new policy may be issued, but compliance may never test whether employees understand the change. Each function can report progress while the overall system remains ineffective.

This is why silos create more than inefficiency. They create control risk. A program can look mature by function and still fail as a system because no one owns the transfer of information, the decision deadline, or the feedback loop. Compliance professionals should therefore examine the seams: Who receives the signal? Who decides what it means? Who owns the response? What evidence confirms completion? Who tests whether the response worked? How does the lesson return to employees, managers, controls, and the risk assessment? Those are not administrative questions. They are the architecture of effectiveness.

Compliance Is an Information System

Communication is the first connection because it moves information in both directions. It tells employees what the organization expects, but it also tells compliance what employees are experiencing. Questions, requests for advice, training discussions, manager escalations, surveys, and workplace observations are all risk data. Communication becomes a control when it does more than broadcast. It creates a dependable exchange.

That information must then enter a dynamic risk process. Risk assessment is not merely a periodic exercise that ranks known categories. It is the organization’s method for deciding which signals require monitoring, immediate containment, deeper review, new controls, or additional resources. The quality of that decision depends on access to operational information across functions.

The Department of Justice (DOJ) makes this connection explicit in its 2024 Evaluation of Corporate Compliance Programs (ECCP). The ECCP asks whether periodic risk review is limited to a point-in-time snapshot or is based on “continuous access to operational data and information across functions.” It also asks whether the results lead to updates in policies, procedures, and controls. The enforcement lesson is straightforward: information must move, and it must change the program.

Compliance Is Also an Accountability System

Information alone does not create effectiveness. The organization must make decisions and assign responsibility. When a risk signal becomes an allegation, the investigation process establishes reliable facts. A credible investigation determines scope, protects evidence, preserves independence, treats witnesses fairly, reaches a supported conclusion, and identifies root causes. Its value is not limited to deciding whether one person violated a policy. It should reveal what the organization must change.

This is the point where accountability often weakens. A case may close when a report is issued, even though the control failure remains. Discipline may address the individual without addressing incentives, supervision, access rights, third-party oversight, or prior warnings. Recommendations may be accepted without an owner, deadline, testing plan, or escalation route.

A connected program treats investigation closure as the beginning of remediation. Findings should feed risk assessment, control design, training, management reporting, and resource allocation. Remediation should then be tested, and the result should be documented. If the company cannot show how a material finding changed the program, it has created a record of the past, not a control for the future.

Trust Is Both an Input and an Outcome

The whistleblower program completes the system because it determines whether critical information enters at all. A hotline provides access, but employees decide whether the reporting system is credible. Their decision is shaped by manager behavior, confidentiality practices, investigation quality, anti-retaliation protection, communication during the process, and what they observe after a concern is raised.

Trust is therefore not a soft cultural benefit sitting outside internal control. It is an operating condition for detection. Employees who believe that reporting is unsafe or futile will withhold information. The company then loses the opportunity to address misconduct early, protect people, preserve evidence, and reduce loss. Trust is also an outcome of the company’s response. A respectful intake, timely triage, fair investigation, consistent accountability, active anti-retaliation monitoring, and appropriate closure communication strengthen the next employee’s willingness to speak. A mishandled matter does the opposite. Every case affects the future supply of risk information.

The ECCP captures this end-to-end logic. It calls for an “efficient and trusted mechanism” for anonymous or confidential reporting, asks whether reporting and investigation information is analyzed for patterns and compliance weaknesses, and asks whether the company tests hotline effectiveness by tracking a report from start to finish. That is a systems test. It examines the full journey, not the existence of a vendor platform.

Think in Loops, Not Lines

Compliance professionals should stop viewing the program as a sequence that ends when a task is completed. Training does not end with completion. Risk assessment does not end with a heat map. An investigation does not end with a finding. A report does not end when the case is closed.

Each activity must create an output for the next decision and a feedback path to the earlier controls. Communication produces risk intelligence. Risk assessment prioritizes that intelligence. Reporting channels supply allegations and weak signals. Investigations convert allegations into facts and root causes. Remediation changes controls and accountability. Communication then explains the change, and monitoring tests whether it worked. The experience shapes culture and determines whether employees will use the system again.

This loop also changes the role of the compliance professional. The CCO does not need to own every business risk or perform every task. The CCO must help design and steward the system that connects them. That means establishing decision rights, information-sharing protocols, escalation thresholds, common taxonomies, remediation ownership, testing standards, and reporting that shows whether the loop is moving.

The practical objective is not centralization. It is coordinated accountability. Legal, human resources, internal audit, finance, security, procurement, technology, and business leaders may own different decisions. Compliance should ensure that the handoffs are explicit and that no material issue disappears between functions.

Measure the Health of the Cycle

Traditional metrics often count isolated activity: training completions, policy attestations, number of reports, cases closed, or risk assessments performed. Those measures remain useful, but they do not show whether the system is connected. A stronger dashboard measures movement and learning. How long does it take to move a material signal to a decision? What percentage of remediation actions has a named owner, deadline, evidence requirement, and testing plan? How often do investigation findings change the risk assessment? Which recurring employee questions lead to policy or training changes? Are reporter updates timely? Are retaliation concerns monitored after closure? Do repeat issues decline after remediation?

These measures test whether compliance converts information into action and action into improved performance. They also expose stalled handoffs. A long delay between investigation closure and remediation, for example, is not simply a case-management issue. It is a weakness in the connected program.

From Culture to Credibility

The best compliance programs do not eliminate uncertainty, misconduct, or failure. They create a reliable way to identify change, surface concerns, establish facts, make accountable decisions, and learn. That reliability is what turns stated values into operating culture.

Compliance is truly connected because culture affects reporting, reporting affects risk visibility, risk assessment affects resource allocation, investigations affect accountability, remediation affects controls, and communication affects whether employees trust the system enough to use it again. No element can be fully effective on its own.

The final question for compliance professionals is therefore not whether every component exists. It is whether the components exchange information, preserve accountability, and improve one another. When they do, compliance becomes more than a collection of requirements. It becomes a business system that turns signals into decisions, decisions into controls, and controls into credibility.

Bonus Questions for Compliance Professionals

  1. Where are material compliance signals most likely to stall or disappear in the current program?
  2. Who owns the transfer from employee concern to risk decision, and from investigation finding to tested remediation?
  3. Can the organization trace a recent issue from first signal through final control improvement?
  4. Which functions use different taxonomies, priorities, or case thresholds in ways that weaken handoffs?
  5. What evidence shows that reporting and investigation data changed risk assessment, resources, policies, or controls?
  6. Do current metrics reveal system delays and repeat weaknesses, or only completed activity?
  7. How does the organization communicate lessons without compromising confidentiality?
  8. What recent employee experience strengthened or weakened trust in the compliance system?
Categories
Blog

Connected Compliance: Part 4 – From Hotline to Trust

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust them enough to speak. In Blog Post 1, we considered communication as a compliance control. Blog Post 2 showed how operational signals create a dynamic risk radar. In Blog Post 3, we explained why every investigation is a test of governance and culture. This final installment examines the front door to the entire system: the reporting program.

A company can buy a hotline in an afternoon. It cannot buy employee trust. That distinction is the starting point for an effective whistleblower program. The platform, policy, telephone number, and case-management system are necessary infrastructure. They are not the program. The real program is the experience an employee anticipates before reporting and receives after doing so.

The answers do not come primarily from policy language. They come from what employees see happen to colleagues who raise concerns. A mishandled report can teach an entire workplace that silence is safer.

The First Report Is the Real Program Test

One of the easiest ways to discourage reporting is to do a poor job after a report arrives. An ignored allegation, confidentiality breach, unexplained delay, dismissive intake, or retaliation can do more damage than an outdated hotline poster.

This is why the reporting program and investigation process cannot be separated. Intake creates an expectation of action. Investigation determines whether that expectation is met. Follow-up determines what the reporter tells others about the experience. The process should begin with prompt acknowledgment. Whenever possible, a trained person should thank the reporter, gather clarifying information, explain next steps, and set realistic expectations. An automated receipt confirms that the technology worked. Personal contact demonstrates that the organization is listening.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places confidential reporting within its evaluation of whether a compliance program is well designed. The 2024 Evaluation of Corporate Compliance Programs (ECCP) calls for an “efficient and trusted mechanism” for anonymous or confidential reports. The two words that matter most are efficient and trusted.

Efficiency requires accessible channels, proper routing, risk-based triage, qualified investigators, timely handling, documentation, and accountable remediation. Trust requires employees to believe that the company will take concerns seriously, limit information sharing, prevent retaliation, and respond consistently regardless of rank or commercial importance.

The DOJ asks whether employees know about the reporting mechanism, feel comfortable using it, and are willing to report misconduct. It also asks a difficult question: “Conversely, does the company use practices that tend to chill such reporting?” That directs compliance professionals beyond the hotline itself. Confidentiality agreements, manager behavior, performance systems, investigation delays, incentive structures, employment actions, and prior reporter experiences can all affect willingness to speak. The DOJ further asks whether the company tests hotline effectiveness by tracking a report from intake through disposition. This makes end-to-end testing a governance exercise, not a vendor-management task.

Design Channels Around the Workforce

A reporting system designed for headquarters may fail the people most likely to observe operational risk. Field employees, shift workers, remote personnel, contractors, and employees with limited computer access need channels that fit how they work. The answer is a meaningful choice. A mature program may include a telephone hotline, web portal, mobile access, email, QR codes, and in-person reporting to compliance, human resources, legal, internal audit, security, or management. Channels should be available in appropriate languages and accessible to employees with disabilities.

Placement matters. A QR code on an identification badge, break-room poster, or work-issued device may be more useful than a buried intranet link. A telephone line remains essential for employees who prefer to speak or lack reliable digital access. Many employees will first approach someone they trust. Compliance should analyze channel use by location, function, shift, language, and workforce type. A channel with no reports is not necessarily evidence that the location has no concerns. It may be evidence that the channel is unknown, inaccessible, or distrusted.

Make Speaking Up a Leadership Behavior

Tone at the top remains essential, but the employee’s immediate supervisor often controls the reporting climate. A chief executive may celebrate integrity while a frontline manager rolls their eyes, interrupts the employee, demands names, or warns that a report will hurt the team. The manager’s reaction becomes the company’s culture in that moment.

Managers need specific training. They should listen without investigating on the spot, avoid promises they cannot keep, preserve information, escalate promptly, and reinforce anti-retaliation expectations. A concern does not have to arrive through the hotline to require action. Leadership modeling should be visible. When leaders invite dissent, respond calmly to bad news, thank employees who identify risk, and communicate anonymized lessons, they show that speaking up protects the business. Regular field presence builds relationships, reveals access barriers, and provides context unavailable from a dashboard.

Tell the Truth About Confidentiality

Employees often use anonymity and confidentiality interchangeably, but they are different. An anonymous reporter does not disclose identity. Confidentiality means identity and related information are limited to people with a legitimate need to know. The company should never promise absolute secrecy when the facts make it impossible. In a small team, subject matter, timing, or witnesses may reveal who raised the concern. Overpromising creates a second breach of trust.

The better approach is candor. Explain that information will be restricted as far as reasonably possible, that some disclosure may be necessary to investigate fairly or meet legal obligations, and that retaliation is prohibited. Use role-based access, careful case notes, secure records, disciplined interview planning, and clear need-to-know rules. Confidentiality is not a slogan. It is an information-control process.

Communicate Without Compromising the Investigation

Silence during a long investigation can feel like indifference. Reporters do not need access to witness statements or confidential personnel decisions, but they do need evidence that the matter remains active. Set a communication cadence based on case risk and expected duration. Provide updates even when the update is that the review continues. Explain delays where appropriate, remind the reporter how to provide additional information, and repeat the anti-retaliation contact route.

At closure, confirm that the concern was reviewed and addressed as appropriate. Thank the reporter and reinforce anti-retaliation protection. The company may be unable to disclose findings or discipline, but it can close the human loop.

Treat Anti-Retaliation as an Active Control

An anti-retaliation policy is necessary, but it is not self-executing. Retaliation can be direct, such as termination, demotion, or loss of pay. It can also be subtle: exclusion from meetings, undesirable shifts, lost development opportunities, hostile supervision, damaged reputation, or social isolation. The company should assess retaliation risk throughout the matter. Compliance and human resources should preserve a baseline of the reporter’s role and treatment, monitor employment actions, schedule check-ins, and provide an escalation route outside the normal chain. Monitoring should continue after closure.

Protection does not mean immunity from legitimate performance management. It means employment decisions affecting a reporter receive appropriate review, are supported by contemporaneous evidence, and are not influenced by protected activity. When retaliation occurs, discipline should be prompt and visible enough, within confidentiality limits, to reinforce the rule.

Do Not Discredit the Difficult Messenger

Serial reporters and incomplete reports create operational challenges, but frequency, frustration, or poor drafting does not determine whether an allegation is true. Each concern should be assessed on its merits. A sparse report may still contain breadcrumbs. Investigators can review organizational charts, personnel changes, transactions, prior complaints, and control data before concluding that the matter cannot proceed. Multiple reports may reveal an unresolved environmental problem or weak earlier investigations.

Motivation can be relevant to credibility, but it should not replace evidence. Labeling someone a troublemaker is often an easy way to miss a difficult fact and an effective way to chill the next reporter.

Measure Trust, Not Just Volume

Hotline volume alone is a weak measure. A low number may reflect a healthy culture, a small risk population, inaccessible channels, fear, or lack of awareness. A rising number may reflect deteriorating conduct or growing confidence in the program. A useful dashboard combines volume with context: awareness and comfort survey results, reports by workforce segment, intake-to-acknowledgment time, triage time, case aging by risk, substantiation patterns, repeat allegations, reporter-update timeliness, retaliation concerns, remediation completion, and employee feedback after closure.

Compliance should test the entire system. Submit a controlled report, trace routing and access, review acknowledgments, confirm escalation rules, examine investigation handoffs, and verify closure and retention. Analyze whether reporting data changes risk assessment, controls, training, and resources. The objective is evidence that the program learns.

Closing the Connected Compliance Program

This four-part blog post series began with communication because employees cannot use a system they do not understand. It moved to dynamic risk assessment because organizations must recognize changing signals. It then examined investigations because allegations require independent facts, accountability, and remediation. Today we discussed whistleblower programs because none of those capabilities matter if people do not trust the company enough to speak. Join us tomorrow in our concluding Part 5 for a deeper discussion of how compliance truly is connected.

The connected compliance program is a loop. Communication builds awareness. Reporting supplies risk intelligence. Investigation converts allegations into reliable findings. Remediation improves controls. Feedback strengthens culture and makes future reporting more likely.

For the compliance professional, the final test is not whether the hotline exists. It is whether an employee facing a difficult choice believes that raising a concern will protect the organization, lead to a credible response, and not cost that employee a career. That is how a reporting channel becomes a trusted control and how culture becomes credibility.

Bonus Questions for Compliance Professionals

  1. Can every workforce segment access a reporting channel during the way and hours in which it actually works?
  2. Do employees know the available channels, understand external reporting rights, and say they feel comfortable using them?
  3. What happens during the first 24 hours after a report arrives, and who is accountable for acknowledgment, triage, and protection?
  4. Are managers trained to recognize and escalate concerns received outside formal reporting channels?
  5. Can the company show how reporter identity and case information are restricted to people with a legitimate need to know?
  6. How does the organization monitor direct and subtle retaliation during and after an investigation?
  7. Does the company communicate appropriately with reporters when an investigation is delayed and when it closes?
  8. Are serial, anonymous, and incomplete reports assessed on evidence and context rather than labels or assumptions?
  9. What reporting data has changed the risk assessment, controls, training, discipline, or resource allocation during the past year?
  10. Has the company recently tested one report from submission through routing, investigation, remediation, feedback, and retention?
Categories
Blog

Connected Compliance: Part 3 – Why Every Investigation Is a Culture Opportunity for Your Organization

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. In Blog 1, we examined communication as a compliance control. In Blog Post 2, we showed how those communications and other operational signals create a dynamic risk radar. Today in Blog Post 3, we ask what happens when a signal becomes an allegation as an introduction to how and why every investigation can be an opportunity to both pressure-test and build out your culture.

A hotline report, audit exception, control override, manager escalation, or unusual transaction may begin as just another compliance signal; once the company decides it requires investigation, the stakes change. The organization must establish what happened, protect people and evidence, make defensible decisions, and strengthen the program.

That makes an investigation more than a fact-finding exercise. It is a visible test of governance. Employees watch who is interviewed, how leaders behave, whether the process appears fair, whether high performers receive special treatment, and whether the company acts when misconduct is substantiated. Details should remain confidential, but the organization cannot erase the cultural impact. Every investigation sends a message.

Credibility Is Built Before the First Interview

The strongest investigations begin with disciplined triage. Before scheduling interviews or collecting data, the company should first identify the immediate risks that require action. Is anyone’s health or safety at risk? Could misconduct be continuing? Is evidence vulnerable? Does the allegation implicate financial reporting, government contracting, sanctions, corruption, product integrity, cybersecurity, privacy, or another obligation requiring prompt escalation?

Containment is not a conclusion. Suspending access, preserving records, pausing a payment, separating employees, or protecting a reporter may be necessary while the facts remain unresolved. The decision should be proportionate, documented, and revisited as evidence develops.

Triage should identify the functions that need to participate without turning the matter into a committee project. One person should own the process, one decision-maker should approve material scope changes, and communication lines should be defined at the outset.

What the DOJ Is Really Asking

The Department of Justice (DOJ) places investigations squarely inside its test of program effectiveness. The 2024 Evaluation of Corporate Compliance Programs (ECCP) asks, “How does the company ensure that investigations are properly scoped?” It then asks what steps the company takes to ensure investigations are “independent, objective, appropriately conducted, and properly documented,” as well as how the company determines who should conduct an investigation.

Those words provide a practical quality standard. Proper scope means the investigation addresses the allegation and reasonably connected issues without drifting into an unlimited inquiry. Independence means the investigator is free from conflicts and improper business pressure. Objectivity requires a search for facts that may confirm or disprove the allegation. Appropriate conduct includes lawful evidence collection, fair treatment of witnesses, and proportionate methods. Proper documentation allows the company to explain what it did, why it did it, and how it reached its conclusions.

DOJ also asks whether the company applies timing metrics, monitors outcomes, and ensures accountability for findings and recommendations. Later, the ECCP describes a working program as having an “appropriately funded mechanism for the timely and thorough investigations” of allegations or suspicions of misconduct. The point is not speed at any cost. It is disciplined responsiveness supported by adequate resources.

Scope the Question, Not the Desired Answer

A written investigation plan should define the allegation, relevant policy or legal issues, time period, business units, people, data sources, immediate risks, and proposed work. It should identify the standard used to reach findings and the expected form of the report. It should also record what remains outside scope.

The plan must be flexible. Evidence may reveal additional conduct, another geography, a control failure, or management involvement. The investigator should document the new information, assess its materiality, identify any additional resources or conflicts, and obtain appropriate approval for expansion.

This discipline prevents a scope narrowed to contain the issue and investigation drift that delays a conclusion. A credible process follows the evidence while preserving a clear line of sight to the original allegation.

Choose the Investigator for the Risk

Not every matter requires outside counsel, and not every matter should remain inside the company. The choice should turn on credibility and capability, not habit. Internal investigators may understand the business and manage routine matters efficiently. External counsel or specialists may be appropriate when allegations involve senior leadership, significant legal exposure, government reporting, material financial impact, technical evidence, cross-border restrictions, litigation, or concerns about internal independence.

The company should establish decision criteria before a crisis. Who determines whether compliance, legal, human resources, internal audit, security, or outside counsel will lead? What conflicts require recusal? When does the audit committee or another independent authority oversee the matter? Which technical experts may be needed, and how will their work be directed? An outside law firm’s letterhead does not create independence. It comes from clear authority, freedom from interference, sufficient resources, access to evidence, and an escalation route when investigators encounter resistance.

Protect the Privilege with Precision

The attorney-client privilege can protect confidential communications seeking or providing legal advice, but an investigation is not privileged simply because a lawyer attends. Privilege rules are jurisdiction-specific, and careless circulation, unclear roles, or unnecessary third-party involvement can create risk.

At the beginning, counsel should define the legal purpose, identify the client and team, establish communication and documentation protocols, and explain confidentiality expectations. Team members should know which communications seek legal advice, where documents will be stored, and who may receive them. Over-labeling every document as privileged does not create stronger protection. It can undermine discipline and complicate later disclosure decisions. The better approach is to use privilege deliberately, involve counsel where legal advice is genuinely required, and preserve a reliable factual record that supports the company’s decisions.

Treat Witnesses as People, Not Evidence Containers

Witness interviews often determine whether employees experience the investigation as fair. The investigator should explain the purpose of the interview, the investigator’s role, expectations for truthful cooperation, applicable confidentiality limits, and the company’s prohibition against retaliation. The interviewer should not promise complete secrecy, prejudge the allegation, coach testimony, or imply that raising concerns created the problem.

Respect improves evidence quality. Employees are more likely to provide complete information when questions are neutral, and the interviewer listens before challenging inconsistencies. Cultural, language, disability, and power dynamics may affect participation and should be addressed thoughtfully.

Anti-retaliation protection requires more than an opening statement. Compliance and human resources should identify foreseeable risks of retaliation, monitor employment actions and workplace behavior, provide a safe escalation channel, and respond quickly to concerns. Retaliation may be subtle: exclusion, schedule changes, lost opportunities, hostile supervision, or reputational harm. A technically sound investigation can still damage culture if the reporter or witnesses pay a price for participating.

Preserve Evidence and Measure the Right Clock

Evidence management must begin early. Relevant emails, collaboration messages, mobile communications, transaction records, system logs, personnel documents, and physical evidence all require preservation. Collection should follow applicable law, privacy requirements, company policy, and forensic protocols. The team should document sources, custodians, dates, gaps, and chain of custody where necessary. Always remember the first question the DOJ will ask after you self-disclose is, “Do you have the documents tied down?

Timeliness should be measured, but the metric must support quality. Useful measures include time from intake to triage, time to investigator assignment, aging by risk category, days awaiting business action, time from finding to remediation, and overdue reporter updates. A single average completion target can create pressure to close simple matters quickly or rush complex ones. Status reviews should ask what is delaying the matter, whether scope remains appropriate, whether interim protections still work, and whether new risks require escalation. The objective is a process that explains delay, removes bottlenecks, and prioritizes higher-consequence matters.

Move Beyond the Bad Actor

An investigation that identifies who violated a policy but not why the system allowed it has completed only half the work. DOJ asks whether investigations identify “root causes, system vulnerabilities, and accountability lapses,” including those involving supervisors and senior executives.

Root-cause analysis should examine incentives, performance pressure, control design, access rights, training, supervision, third-party oversight, data availability, prior warnings, and the consistency of discipline. Did the policy prohibit the conduct but the workflow reward it? Did a manager ignore a red flag? Did an exception process become the normal process? Did earlier reports reveal the same weakness?

The answer should drive remediation, including discipline, control redesign, policy revision, monitoring, training, leadership changes, third-party action, disclosure, or resource reallocation. Each action needs an owner, deadline, evidence, and testing. Otherwise, the investigation becomes a historical record rather than a compliance control.

Close the Case and the Cultural Loop

A reasoned closure record should state the allegation, scope, steps taken, evidence considered, credibility analysis, findings, and approved response. Discipline should be consistent across ranks and levels of commercial importance, with deviations documented. Investigation data should then feed the risk assessment, training plan, control testing, and management reporting.

The reporting party also matters. Without disclosing confidential personnel information, the company can acknowledge that the review is complete, thank the person for speaking up, restate anti-retaliation protections, and provide a contact for further concerns. Silence after intake encourages employees to conclude that nothing happened.

This is the connection across the series. Communication brings information into the program. Dynamic risk assessment helps the company recognize its significance. Investigation converts allegations into facts, accountability, and learning. Therefore, join us for Part 4 tomorrow, as we will demonstrate the front door to that process: how an effective whistleblower program gives employees safe, accessible ways to report and confidence that speaking up will lead to credible follow-through.

Bonus Questions for Compliance Professionals

  1. Who has authority to triage an allegation and order immediate containment or preservation measures?
  2. What written criteria determine who should lead an investigation and when independent oversight or outside counsel is required?
  3. Can the company show that recent investigations were properly scoped, independent, objective, timely, and documented?
  4. Which stages of the investigation create the greatest delays, and are those delays risk-based or simply unmanaged?
  5. How does the organization monitor subtle retaliation against reporters and witnesses?
  6. Do investigation reports identify control failures, incentives, supervisory accountability, and root causes in addition to individual misconduct?
  7. What evidence shows that completed investigations changed controls, training, discipline, resources, or risk assessment?
  8. How does the company communicate appropriate closure to reporters without compromising confidentiality?
Categories
Innovation in Compliance

Innovation in Compliance: Compliance Evangelists Fighting Modern Slavery Together with Matt Friedman

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom Fox visits with Matt Friedman, who provides a 2026 update to the fight against the international scourge of human trafficking and modern slavery and discusses his latest book, Awakening the Advocate.

Friedman is a leading voice in the fight against human trafficking and modern slavery, known for founding and leading the Mekong Club and for more than 35 years of advocacy, policy work, and corporate engagement. He views modern slavery as a vast, still underaddressed crisis, where tens of millions remain trapped while the number of survivors helped and criminals convicted remains far too small to match the scale of the problem. Friedman believes the biggest barrier is not compassion but awareness and that educating employees inside companies can “wake up” lawyers, bankers, marketers, and other professionals who already have the instincts to help. From his perspective, ESG and compliance efforts can protect the business while also driving meaningful anti-slavery action, making corporate compliance a practical engine for both risk reduction and social change.

Key highlights:

  • Compliance Evangelists Fighting Modern Slavery Together
  • Leadership Briefings and Procurement Risk Assessments
  • Board-Level Awareness Protects Reputation and Brand Value
  • AI sifting data to uncover scam-center patterns
  • Modern Slavery Risks Make ESG’s Future Uncertain

Resources:

Matt Friedman on LinkedIn

The Mekong Club

Awakening the Advocate on Amazon.com

Innovation in Compliance was recently honored as the Number 4 podcast in Risk Management by 1,000,000 Podcasts.

Categories
Blog

Connected Compliance: Part 2 – From Risk Register to Risk Radar

An effective compliance program is not a collection of disconnected policies, training modules, hotline reports, and investigation files. It is an operating system. Culture determines whether employees will use it. Risk assessment tells the organization where it must adapt. Investigations test whether the system responds credibly. Whistleblower programs reveal whether employees trust it enough to speak. Blog 1 examined communication as the control that connects those elements. In this Part 2, we examine what compliance must do with the intelligence that communication produces.

The traditional risk assessment was built for a world that moved more slowly. Compliance gathered a group of leaders, reviewed enforcement trends, scored familiar risks, produced a heat map, and returned to the exercise the following year. That process still has value, but it is no longer enough.

Today, a new market restriction, customer demand, artificial intelligence deployment, supply-chain disruption, sanctions measure, or data rule can alter the company’s risk profile before the annual plan is approved. The central question is therefore not whether the organization has a risk register. It is whether compliance has a risk radar that can detect change, decide what matters, assign ownership, and translate the signal into action.

Every Compliance Risk Has a Political Dimension

Compliance obligations do not develop in a vacuum. They reflect choices made by governments about national security, trade, technology, labor, privacy, corruption, competition, and corporate accountability. For a multinational company, those choices may conflict, overlap, or change with little notice. Particularly in this political age, the single most-used byword is volatility.

That makes geopolitical awareness a compliance capability. It does not require the CCO to become a foreign-policy analyst. It requires the compliance function to understand how political priorities can become legal obligations, enforcement pressure, customer expectations, or operational constraints. Export controls can reshape product access. Sanctions can alter payment and counterparty risk. Forced-labor requirements can reach deep into a supply chain. AI rules can change how a business collects data, develops products, and makes decisions.

The practical lesson is that legal change is often the last stage in a longer policy development process. Compliance should monitor the earlier signals: legislative proposals, agency speeches, enforcement patterns, trade measures, customer questions, supplier difficulties, and operational workarounds. These indicators do not all demand a program change, but they should enter a disciplined triage process.

What the DOJ Is Really Asking

The Department of Justice has made dynamic risk assessment part of the effectiveness inquiry. The 2024 Evaluation of Corporate Compliance Programs (ECCP) directs prosecutors to consider “emerging risks as internal and external circumstances impacting the company’s risk profile evolve.” This risk profile can change due to factors outside a company’s control or its own business decisions. Moreover, the ECCP language moves risk assessment beyond a scheduled document and into continuous management.

DOJ then asks: “Is the company’s approach to risk management proactive or reactive?” The distinction is critical. A reactive program updates controls after a failure, enforcement action, or audit finding. A proactive program uses operational information across functions to identify change before misconduct occurs. The ECCP also asks whether periodic review is merely a point-in-time exercise or draws on continuing access to operational data, and whether the results lead to updates in policies, procedures, and controls.

The enforcement question is not whether the company predicted every development. No program can. The question is whether the company had a reasonable process for identifying material changes, directing resources to higher-risk areas, documenting its decisions, and revising the program over time.

Build the Risk Radar From Multiple Signals

A dynamic risk process begins with a wider field of vision. Regulatory alerts and outside counsel updates are useful, but they show only part of the environment. Some of the earliest warnings come from inside the business. Sales may see unusual customer demands in a new market. Procurement may find suppliers unable to provide origin information. Finance may identify payment routes that no longer fit the expected transaction. Information security may discover employees using unapproved AI tools. Human resources may raise concerns about retaliation or pressure related to performance targets. Audit may identify recurring exceptions. Hotline reports and investigations may reveal a pattern that a heat map missed.

Compliance should bring these signals together through a repeatable cadence. A quarterly cross-functional review can examine changes in the business model, geography, products, third parties, technology, enforcement, and employee concerns. High-velocity risks may require monthly or event-driven review. The objective is not to create another committee. It is to establish a reliable place where weak signals are compared, challenged, and assigned.

Or simply look at the changes wrought by the Trump Administration in 2026 alone. Venezuela is now open for business. How about the Democratic Republic of Congo? See here and here. Of course there is Iran, but you have to ask what week it is and are we doing business with Iran or are we at war with Iran.

Give One Person the Clock

Emerging risks often fall between organizational boxes. Legal understands the rule. Compliance sees the control issue. Operations owns the process. Procurement controls the supplier relationship. Technology owns the system. To use a well-worn maxim, if everyone is in charge, no one is in charge. In the corporate world, when everyone is generally responsible, no one is specifically accountable. This is both why and where compliance needs to step up its game.

Every material risk needs a named owner with the authority to convene the necessary functions, set deadlines, escalate disagreements, and report on the disposition. That person does not perform every task. The owner keeps the clock, maintains the decision record, and ensures that the issue does not disappear between meetings.

Governance should also define escalation triggers. A credible framework identifies which developments require immediate executive attention, which can be handled through a working group, and which should remain under observation. Without thresholds, organizations either under-escalate material risk or flood leadership with undeveloped issues.

Use a Two-Speed Assessment

Not every signal requires an enterprise-wide risk assessment. Compliance needs two speeds. The first is rapid triage. A small group of subject-matter experts identifies the potential legal obligation, affected operations, time horizon, severity, available data, current controls, and immediate containment needs. This is where AI can play a key role in compliance, essentially superforecasting risks to enable quick, efficient risk management strategies when volatility hits. Additionally, such an approach may lead to a decision to monitor, take interim action, or launch a deeper review.

The second is formal assessment. Complex or high-impact risks may require structured interviews, data analysis, control testing, external counsel, forensic support, or scenario planning. The deeper process should be proportionate to the exposure, not triggered simply because the issue is new. This two-speed model protects agility without sacrificing rigor. It also creates evidence that the company made a reasoned decision. A short written triage record can show what information was considered, who participated, why the company chose its response, and when the issue will be reviewed again.

Convert Assessment Into Real Controls

The most common failure is not the inability to identify risk. It is the failure to convert assessment into a viable risk management strategy and then to implement, monitor, and improve your business operations. A new questionnaire, certification, or policy may create documentation, but documentation alone does not mitigate the underlying exposure.

Consider third-party risk. A supplier questionnaire can identify missing information, but the control lies in what happens next: enhanced diligence, contractual protection, source verification, payment restrictions, audit rights, monitoring, remediation, or a decision not to proceed. The same principle applies to AI. An AI-use policy matters, but effective governance also requires an inventory of use cases, approval gates, data controls, human oversight, testing, monitoring, and accountability.

Each response should identify the control objective, owner, implementation date, evidence, and testing method. Compliance should also ask what existing control can be adapted before building a separate program. Strong governance, escalation, training, data access, and investigation processes are reusable infrastructure across risk domains.

Resource allocation is part of that conversion. If a changing risk profile calls for deeper third-party monitoring, faster export review, or additional AI oversight, the organization must decide what people, technology, and budget will support the response. Compliance cannot claim to be risk-based when yesterday’s priorities continue to dictate today’s resources. The allocation decision, including any accepted constraint, should be visible and documented.

Treat Change Management as a Control

A technically correct response can still fail if employees do not understand it or the business cannot implement it. New requirements frequently collide with established incentives, systems, customer commitments, and local practice. Change management should therefore be part of the control design. Explain why the risk changed. Identify which decisions and workflows are affected. Train the employees and gatekeepers who must act differently. Provide a practical escalation route. Test understanding. Gather feedback. Then revise the process when implementation exposes friction or unintended consequences. For a full discussion of change management as a compliance control, listen to the podcast Ronnie Feldman and I did with Caveni Wong on this episode of Creativity and Compliance.

This is where blog post 1’s communication discipline comes into play. Compliance cannot adapt to risk through broadcast messages alone. It needs a two-way channel that tells employees what changed and tells compliance whether the response works in practice.

Measure Adaptation, Not Activity

The number of risk meetings or completed assessments says little about effectiveness. Better measures test whether the organization moves from signal to decision and from decision to control. Useful indicators include the time required to triage a material development, percentage of actions with named owners and deadlines, overdue remediation, control implementation and testing results, repeat exceptions, unresolved ownership disputes, and lessons incorporated from investigations.

Compliance should also examine whether resources shifted when risk shifted. A program that identifies a higher risk but leaves staffing, monitoring, and controls unchanged has produced analysis without management. The result should be a closed loop: detect, assess, assign, mitigate, test, and learn. That loop turns risk assessment from an annual artifact into a management process.

That transition is where program credibility is tested. Join us tomorrow as we consider how organizations scope investigations, preserve independence, establish consistency, document decisions, and convert findings into remediation. A dynamic risk process helps the company see the signal. A credible investigation determines what happened and what the organization must do next.

Bonus Questions for Compliance Professionals

  1. Which internal and external signals can change the company’s risk profile between formal assessments?
  2. Who has specific ownership for emerging risks that cross legal, compliance, operations, procurement, finance, and technology?
  3. What criteria determine whether an issue is monitored, triaged, escalated, or formally assessed?
  4. Can the company show how a recent risk assessment changed a policy, control, resource allocation, or business decision?
  5. Do substantive mitigation and ongoing monitoring support questionnaires and certifications?
  6. How quickly can the organization move from a weak signal to a documented decision?
  7. What recent investigation finding should change the current risk assessment?