Categories
Blog

Frankenstein and Compliance: Part 1 – It’s Alive: Innovation Without Governance

Ed. Note: This month, on my podcast series Popcorn and Compliance, I am taking a deep dive into the first five Frankenstein movies. Over October, I will consider Frankenstein, The Bride of Frankenstein, The Son of Frankenstein, The Ghost of Frankenstein, and Frankenstein Meets the Wolfman. The blog post is a companion to the podcast series.

The most famous moment in Frankenstein (1931) comes when Henry Frankenstein’s experiment succeeds. Electricity surges through his laboratory, the body on the table begins to move, and Frankenstein celebrates what he believes is an extraordinary scientific achievement.

“It’s alive!”

For the corporate compliance professional, however, the critical decisions occurred before Henry ever activated his equipment. He had decided to proceed without an adequate risk assessment, effective oversight, meaningful challenge, or a plan for managing the consequences if his experiment succeeded. Viewed through that lens, Frankenstein is not simply a horror movie about a scientist and the Monster he creates. It is a case study in innovation without governance.

That lesson is especially relevant as companies accelerate the adoption of AI and other emerging technologies. Businesses are appropriately focused on innovation, productivity, efficiency, growth, and competitive advantage. Yet technological capability can develop faster than the governance structures needed to manage the resulting risks. The compliance issue is not whether companies should innovate. They must. The issue is whether governance keeps pace with innovation.

The Business Case Was Clear. The Governance Case Was Not.

Henry Frankenstein has a compelling objective. He believes he can accomplish something no one has accomplished before. He assembles the equipment, obtains the materials, develops the technical capability, and builds a team capable of executing the project. In corporate terms, Henry has a strategy, resources, technical expertise, and executive sponsorship. He lacks an effective governance framework.

Before activating his creation, Henry conducts no meaningful risk assessment. He does not identify potential failure scenarios or establish control requirements. He does not define stopping criteria or determine who has authority to challenge the project. No meaningful contingency plan exists for an adverse outcome. This is precisely where compliance should enter the business process.

An effective compliance function should not first encounter a significant new technology when the business seeks approval immediately before deployment. Compliance needs to participate early enough to understand the business objective, identify the associated risks, and help determine appropriate controls.

That does not mean Compliance should own innovation or assume responsibility for the underlying business decision. Risk ownership should remain with the business. Compliance should help ensure that management understands the legal, regulatory, ethical, and control implications of the decision before significant commitments are made.

For the CCO, this raises a practical question: When does Compliance become involved in our company’s innovation process? If the answer is immediately before launch, the organization may already be too far downstream.

AI Has Made the Frankenstein Problem Immediate

Artificial intelligence makes the Frankenstein governance issue particularly relevant. Companies are deploying AI to analyze information, generate content, assist customer service, support investigations, screen candidates, evaluate transactions, enhance due diligence, identify suspicious activity, and improve decision-making. These applications can generate significant business value. They also raise governance questions that organizations must address before deployment.

Organizations need to understand what data an AI application uses, how it obtained that information, who approved the use case, and which regulatory requirements apply. They should determine how outputs are validated, where human review is required, how confidential information is protected, and what happens when a system produces an unexpected or inappropriate result.

There must also be clear accountability. Someone should own the business risk associated with the use case, and the organization should understand who has authority to suspend or terminate the application if circumstances warrant.

The NIST AI Risk Management Framework provides one useful approach through its Govern, Map, Measure, and Manage functions. ISO/IEC 42001 similarly treats AI through a management-system framework emphasizing governance, accountability, risk management, and continual improvement.

Both approaches reinforce a broader compliance principle: technology risk needs governance throughout the lifecycle. Henry Frankenstein has no lifecycle governance. His approach is essentially to build the system, activate it, and evaluate the consequences afterward. That is not an acceptable corporate control environment.

The Abnormal Brain and the Importance of Validating Inputs

One of the film’s most useful compliance scenes occurs before the Monster comes to life. Henry needs a brain for his creation. His assistant Fritz obtains one, but the intended specimen is destroyed. Rather than report what happened, Fritz substitutes another brain, identified in the film as abnormal, without telling Henry. (Abbey Normal—if you know, you know.) The project therefore proceeds after a critical input has changed without the project leader’s knowledge.

For compliance professionals, the scene provides a useful analogy for third-party risk, supply-chain controls, due diligence, and data governance. Organizations routinely rely on information others provide. A distributor provides beneficial ownership information. A vendor completes a compliance certification. An employee submits an expense report. An acquisition target makes representations during due diligence. A supplier certifies compliance with contractual obligations. An AI application relies upon data obtained from multiple sources.

The relevant control question is not simply whether the required information was received. It is whether the organization appropriately validated important information based on risk. Fritz completed his assignment in the narrowest sense. He returned with a brain. The process failed because nobody verified that he returned with the correct brain. That distinction is important for compliance program effectiveness. A completed checklist demonstrates that an activity occurred. Appropriate validation assures that the control achieved its purpose.

Dr. Waldman and Credible Challenge

Henry is not entirely without oversight. Dr. Waldman understands what Henry is attempting and recognizes the potential danger. He raises objections. Henry proceeds anyway. This takes the film from risk assessment into the effectiveness of the challenge function. Many companies can demonstrate that compliance participated in a significant decision. That does not necessarily establish that a compliance professional had meaningful influence over the outcome. A CCO can attend meetings, review proposals, identify concerns, and recommend additional controls. If commercial leadership can routinely disregard those concerns without escalation, the company may have consultation without credible challenge.

This is why the authority, stature, resources, independence, and access of the compliance function matter. The effectiveness of a corporate compliance program becomes most visible when it disagrees with an important business proposal. Boards should therefore look beyond whether your compliance function was consulted. They should understand what happens when a compliance officer disagrees with the business. They need to ask such questions as: Can the CCO escalate a significant concern? Does the CCO have appropriate access to the Audit Committee or board? Are material disagreements documented? Who has authority to accept significant compliance risk? Can commercial management override a compliance objection without further review?

If a CCO can raise a concern but nobody with decision-making authority has to address it, the organization has created the appearance of challenge without its substance. Dr. Waldman had a voice. He lacked the influence to change the decision.

Maria and the Risk of Unintended Consequences

Next we consider one of the most poignant scenes in the movie. The encounter between the Monster and young Maria provides another important business lesson. This is certainly one of the most unforgettable, and indeed tragic, scenes in all the Frankenstein movies. If you have ever seen it, you will never forget it. A small child, Maria, shows the Monster how flowers float on the lake. He imitates what he observes. When the flowers are gone, he throws Maria into the water, apparently expecting her to float as the flowers did. The consequences are tragic. The Monster recognizes a pattern without understanding its context.

That distinction has obvious relevance for artificial intelligence and automated decision-making. A system may identify patterns, generate recommendations, and produce technically consistent outputs without understanding their broader legal, ethical, or business implications. A technically accurate output can still create an inappropriate result.

This is why human oversight cannot exist merely as language in an AI policy. Companies need to determine where human judgment is required, who provides that judgment, what qualifications reviewers need, when automated recommendations can be overridden, and how significant exceptions are documented.

Management should also understand whether human review is substantive or simply procedural. An employee clicking an approval button after an automated recommendation does not necessarily constitute meaningful oversight. The relevant control question is not simply whether the technology performed as designed. It is whether the resulting decision was appropriate.

Innovation Requires Accountability

Henry eventually discovers that creating something and controlling it require different capabilities. Corporate leaders should understand the same distinction. Management establishes incentive structures, sales strategies, compensation plans, technology deployments, acquisition strategies, third-party relationships, and performance expectations. Those decisions shape employee behavior and create risk. Leadership accountability therefore does not begin only after misconduct occurs. It begins with the decisions that establish the operating environment.

For the CCO, this means integrating compliance risk into strategic business decisions. For management, it means risk ownership remains with the business. For the board, oversight should focus on whether management has reasonable systems to identify, manage, monitor, and escalate significant risks. Compliance does not own a business risk simply because the compliance function identifies it. Management remains responsible for the business decision and the risks it creates.

That principle becomes particularly important with emerging technology. The CCO should contribute expertise regarding regulatory requirements, ethical considerations, controls, monitoring, and escalation. Technology leaders should contribute technical expertise. Legal, Privacy, Information Security, HR, Internal Audit, and other functions may have roles depending on the application. Business leadership remains accountable for the decision to deploy the technology and the resulting business risk.

Practical Actions for the CCO

Frankenstein suggests a practical agenda for compliance leadership. Compliance should move upstream and identify significant business processes where its participation adds the most value before making commitments. Emerging technology, acquisitions, market entry, compensation design, significant third parties, and new products are obvious candidates.

Risk assessment should occur before deployment and should address foreseeable legal, compliance, ethical, operational, and reputational consequences. High-risk inputs supplied by employees, vendors, third parties, acquisition targets, or technology systems should receive risk-based validation.

The organization should also define what credible challenge means in practice. Escalation procedures should be clear when Compliance and business leadership disagree about significant risk.

Finally, treat approval as the beginning of governance rather than its conclusion. Test controls, monitor outcomes, analyze exceptions, and update risk assessments as the business and technology evolve. The objective is not to slow innovation. It is to make innovation governable.

The Compliance Lesson

Frankenstein is not an argument against innovation. It is an argument for governance.

Henry Frankenstein failed not because he attempted something extraordinary. He failed because his technical ambition outpaced his ability to identify, understand, govern, and control the resulting risk.

Companies face the same challenge today. Technology will advance. Business models will change. New markets will open. Competitive pressure will accelerate decision-making. New risks will emerge. Compliance’s role is not to stand outside the laboratory and demand that the electricity be turned off.

It is to help ensure that management has assessed the risk, validated critical inputs, established appropriate controls, defined accountability, created meaningful challenge, and determined how the organization will respond if the initiative produces an unexpected result. The best time to build that governance structure is before deployment.

Our next installment moves the compliance analysis forward. In Bride of Frankenstein, Henry no longer faces an unknown risk. He has already experienced the consequences of his original experiment and understands what can go wrong. Then Dr. Pretorius persuades him to return to the laboratory.

The compliance issue is no longer whether leadership identified the risk. It is what happens when leadership knows better, but pressure, ambition, and rationalization push the organization toward the same risk again.

Check out Timothy and Fiona’s commentary on Frankenstein here.

Categories
Blog

When the CEO Has to Go: What Forced Departures Tell Boards and CCOs About Governance

CEO succession is usually discussed as a planning exercise. Boards identify potential successors, develop internal talent, periodically review the succession plan, and prepare for the orderly transition that eventually comes with retirement or another planned departure.

But succession does not always wait for the planning calendar. In an article in the Harvard Law School forum on Corporate Governance, titled Forced CEO Departures, the authors reported on a new study by The Conference Board, developed with ESGAUGE and other collaborators, that examined forced CEO departures among Russell 3000 and S&P 500 companies from 2024 through August 2026. Roughly one in seven CEO succession cases were classified as forced in both 2024 and 2025. In the Russell 3000, 49 forced departures occurred in 2024 and 55 in 2025. The S&P 500 recorded seven and 10, respectively. The forced departure numbers are interesting. The governance implications are more important.

This research on forced CEO departures reminds boards to prepare for unscheduled CEO transitions. For Chief Compliance Officers, the findings raise an equally important question: what information should the compliance function be providing to the board before a leadership problem becomes a leadership crisis?

Forced CEO departures demonstrate that succession planning, executive accountability, corporate performance, investor confidence, culture, and risk oversight cannot be separated into different governance boxes. They ultimately meet in the boardroom. For a Chief Compliance Officer (CCO), they also demonstrate why compliance must function as an organizational sensor capable of identifying patterns that individual incidents may not reveal.

Forced Succession Is a Governance Risk

The report defines a forced departure broadly enough to capture the realities of corporate governance. A departure is forced when evidence indicates that the board, activist investors, an investigation, performance concerns, misconduct, or strategic disagreement materially influenced the timing or terms of the CEO’s exit. Importantly, a departure publicly described as a resignation or retirement may still have been board-driven. That distinction matters.

Boards should not think about CEO succession solely as identifying the person who eventually replaces a successful CEO. Succession planning must also contemplate what happens when the board concludes that the current CEO can no longer lead the organization effectively.

The report’s 2024 and 2025 data make that point. Forced departures represented 14.7 percent and 14.8 percent of Russell 3000 succession cases, respectively. Among the S&P 500, the corresponding figures were 14.3 percent and 15.2 percent. Those figures should change the boardroom conversation.

The question is not simply, “Who succeeds the CEO someday?” It is also, “What happens if we need a new CEO next Monday?”

Performance Is Becoming a Governance Question

Perhaps the most significant finding concerns why CEOs were forced out. Underperformance accounted for 37 percent of Russell 3000 forced departures across the period studied. It increased from 31 percent in 2024 to 44 percent in 2025 and remained the largest category through August 2026. Underperformance, activist pressure, and termination without cause collectively accounted for 70 percent of forced departures during the full period.

For directors, that creates a difficult governance question. When does poor performance become a leadership problem? A single disappointing quarter should not automatically become a referendum on the CEO. External economic conditions, industry disruption, commodity prices, interest rates, geopolitical events, and other factors can affect performance.

Yet boards cannot allow those explanations to become permanent excuses. The report recommends establishing in advance the conditions that trigger a deeper assessment of CEO effectiveness. That assessment should extend beyond financial results to strategic milestones, competitive position, organizational capability, and how the CEO responds to setbacks. That is an important governance discipline. Agreeing on the indicators before the crisis reduces the danger of redefining success after performance deteriorates.

The CCO Has a Different Window Into CEO Effectiveness

Here the compliance function enters the discussion. The report is primarily about CEO succession and board governance. It does not assign the CCO responsibility for evaluating CEO performance. Nor should it. But compliance often sees organizational information through a different lens than Finance, Strategy, HR, or Investor Relations.

A CCO may see whether employees are becoming reluctant to speak up. Compliance may identify retaliation concerns involving senior management. Investigations may reveal recurring management override. Hotline data may show patterns concentrated around particular executives or business units. Third-party reviews may expose pressure to circumvent controls. Internal investigations may demonstrate that employees believe commercial performance is valued more highly than ethical conduct.

One event may mean little. Patterns can mean much more. This is why an effective CCO should not simply report hotline statistics to the board. The CCO should help directors understand what the information may be saying about organizational culture, controls, accountability, and risk.

The question becomes: What does the board need to know to discharge its oversight responsibilities?

That is a very different question from: What compliance information did management ask us to provide?

CEO Accountability and the Control Environment

CCOs should also pay attention to forced CEO departures. The CEO sits at the top of the organization’s control environment. The CEO’s conduct affects incentives, resources, accountability, escalation, management behavior, and whether employees believe controls are genuine requirements or obstacles to business performance.

That means directors assessing leadership should consider more than revenue growth and shareholder returns. They should understand whether management responds appropriately when controls identify problems. Some key questions a CCO might ask include:

Does the CEO support investigations even when they involve high-performing executives? Does management remediate identified weaknesses? Are compliance personnel adequately resourced and empowered? Are executives held accountable consistently? Does information reach the board without being filtered into insignificance?

These questions connect CEO oversight to compliance program effectiveness. They also reinforce why direct access between the CCO and the board or an appropriate board committee matters. The value of that relationship becomes clearest when the information the board needs is information senior management would prefer not to discuss.

Activists May Ask the Questions Boards Should Already Be Asking

The report contains another significant finding.

Among S&P 500 forced departures, activist pressure accounted for five of 10 departures in 2025. Across 2024 through August 2026, activists were associated with eight of 19 forced departures, or 42 percent. The report notes that activist campaigns frequently focus on matters already within the board’s remit, including performance, strategy, capital allocation, portfolio structure, governance, and confidence in management. Forced CEO Departures

There is a governance lesson here. A board should not need an activist investor to tell it which difficult questions to ask. Directors should periodically examine the company through an independent investor lens. Where is performance lagging? Which strategic assumptions have not proved correct? Where has capital allocation failed to produce expected results? What would a sophisticated outsider identify as the company’s vulnerabilities?

For the CCO, there is a parallel exercise. What would a regulator, whistleblower, investigative journalist, plaintiff’s lawyer, or enforcement authority see if they examined the same facts? These perspectives are not substitutes for the board’s business judgment. They are tools for challenging assumptions. Effective oversight requires directors to seek disconfirming information, not just information that supports management’s existing narrative.

Succession Planning Needs a Break-Glass Option

The report recommends that boards maintain an accelerated succession plan alongside traditional succession planning. That distinction is critical. A normal succession plan asks who might become CEO in several years. An accelerated plan asks who takes control tomorrow morning.

The board should know who can provide immediate continuity, which internal executives could become permanent successors, when an external search would be required, and how to retain key executives during the transition. The plan should also address interim authority, compensation, severance arrangements, and employee and investor communications. Compliance should be part of that contingency architecture.

Questions might include: If the departure involves misconduct or an investigation, who controls the investigation after the CEO leaves? Who has authority over document preservation? Who makes disclosure decisions? Who communicates with regulators? What happens if other senior executives are implicated? Does the CCO continue reporting through the same management structure, or should reporting temporarily move directly to the board?

The report itself does not address these questions, but they follow directly from the compliance risks created by an unexpected leadership transition. The worst time to design these protocols is during the crisis.

The Board and CCO Need an Early-Warning System

The larger lesson from the forced-departure data is not that boards should terminate CEOs more quickly. It is that boards should become better prepared to recognize and respond to deteriorating conditions.

The report found no consistent company-size profile for forced turnover. Elevated rates appeared across the revenue spectrum. The more meaningful indicators were company-specific factors, including persistent underperformance, strategic misalignment, and investor scrutiny. Forced CEO Departures

That suggests boards need an integrated early-warning system.

  • Financial performance is one signal.
  • Strategic execution is another.
  • Investor sentiment is another.
  • Compliance and culture data should be another.

The CCO can contribute by identifying trends in allegations, investigations, retaliation, control overrides, disciplinary decisions, third-party exceptions, and other indicators that may reveal stress inside the organization. The board then has the responsibility to connect the dots.

Questions for the Board and CCO

Boards should periodically ask whether they have defined the conditions that would trigger a reassessment of CEO effectiveness; whether they have a genuine emergency succession plan rather than simply a long-term succession plan; whether directors receive information about culture, investigations, controls, and retaliation without inappropriate management filtering; and whether they understand recurring concerns raised by shareholders, employees, auditors, compliance, and other stakeholders.

CCOs should ask different questions. Are we giving the board data or insight? Are recurring issues being presented as isolated events? Are senior executives subject to the same accountability standards as everyone else? Does the CCO have a practical route to the board when senior management itself presents the risk? If the CEO suddenly departed tomorrow because of an investigation, could Compliance continue operating without interruption?

Those can be uncomfortable questions. Yet, they are also precisely the questions effective governance requires. Forced CEO departures are not simply stories about executives losing their jobs. They stress-test the governance system around those executives.

The board’s responsibility is to ensure it can recognize when leadership circumstances have materially changed and act deliberately, not reactively. The CCO’s responsibility is different but complementary: ensure that compliance, culture, control, and investigation information that can inform that judgment reaches the board clearly and promptly.

A board should never discover during a CEO crisis that the warning signs were there all along. A better governance model identifies those signals early, understands what they mean, maintains credible succession alternatives, and establishes decision processes before they are needed. That is not planning for failure. It is planning for effective oversight.

Categories
Innovation in Compliance

Innovation in Compliance: Doni Hoti on Embedding Advertising Compliance Into Content Creation

Innovation comes in many areas, and compliance professionals need to not only be ready for it but also embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode, host Tom welcomes Doni Hoti, co-founder and CEO of Adclear.

Hoti brings a fascinating perspective on embedding compliance directly into content creation. He begins with the shift in advertising and marketing compliance from a slow, “checkpoint” back-office function to an embedded, revenue-enabling capability. Hoti explains that modern content creation involves many stakeholders and must move at near-real-time speed, while enforcement risk and the cost of losing customer trust keep rising. He describes how AI has broken traditional review models by increasing both content volume and speed expectations and how Adclear uses horizon scanning across global regulators, agentic AI, and company-specific policies to deliver more deterministic, auditable compliance guidance tied to rulebooks. Fox and Hoti then turn to third-party and affiliate challenges, regulator-ready documentation and audit trails, and business outcomes such as reduced review SLAs, scalable approvals, and revenue uplift, with marketing increasingly owning the process alongside legal and compliance.

Key highlights:

  • Compliance Disconnect
  • Trust and Shopfront
  • Embed Compliance
  • Third-Party Risks
  • AI as Solution
  • Audit Trail Proof

Resources:

Adclear

Doni Hoti on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

De-Risking AI Adoption Through Accountability and Effective Governance

A company can publish thoughtful AI principles, appoint a governance committee, and still struggle to answer a basic question: who can stop an AI system when its behavior creates unacceptable business risk? For chief compliance officers and boards, that question reaches the heart of program effectiveness. Policies establish expectations. The real test comes when someone must decide, enforce a boundary, and show what happened.

Pamela Gupta addresses that challenge in De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook. Her central argument is that trustworthy AI requires an operating model connecting ownership, controls, deployment decisions, monitoring, and evidence. The book provides a structure for translating responsible AI commitments into repeatable business practices. For compliance professionals, its value lies in explaining how governance can support adoption while keeping accountability attached to the people making consequential decisions.

Making Trust Operational

Gupta defines trustworthy AI through three practical capabilities: people can understand the behavior to expect and its limits, verify what actually occurred, and identify an accountable person when something goes wrong. This moves the discussion toward demonstrable performance.

That approach should resonate with any CCO who has examined the distance between a written procedure and actual business conduct. An AI policy may require human oversight. Whether that oversight works depends on the reviewer’s information, competence, time, and authority to intervene. A human approval step has limited value if the organization rewards automatic acceptance or discourages challenges.

The compliance application is straightforward. For each significant AI use case, identify the business purpose, potential harm, responsible owner, operating limits, and evidence needed to evaluate performance. These questions belong at the beginning of development and procurement, when the answers can still shape the system.

Eight Pillars of AI Governance

The book organizes its methodology around AI TIPS™, Gupta’s framework of eight interconnected pillars: cybersecurity, privacy, ethics and bias, transparency, explainability, regulations, audit, and accountability. Together, they address the different ways AI can create enterprise exposure.

The connections matter. Security controls may protect information against unauthorized access while leaving questions about discriminatory outcomes unresolved. Transparency can establish which data and processes a system uses, while explainability addresses whether people can understand and challenge a particular decision. Independent assurance requires evidence from across these activities.

Gupta also presents mappings to established frameworks and standards, including the NIST AI Risk Management Framework and ISO/IEC 42001. Her purpose is to connect enterprise controls and evidence across multiple governance expectations.

For a compliance team, the practical lesson is to coordinate existing expertise. Privacy, security, legal, risk, audit, and business leaders each hold part of the answer. The CCO can help connect their work through common requirements, escalation procedures, and documented decisions. Business owners must remain answerable for the systems they deploy.

Accountability Must Carry Authority

Accountability receives special treatment throughout the book. Under Gupta’s methodology, a critical accountability failure blocks deployment regardless of the aggregate governance score. A system needs a named owner with authority to accept risk and stop its operation. Consequential uses also require appropriate human override and redress mechanisms.

This is a useful challenge to governance committees that distribute responsibility so broadly that no individual can decide. Participation in a committee does not automatically establish authority over a business process.

CCOs should translate this principle into explicit decision rights. Who approves the use case? Who accepts the remaining risk? Who authorizes exceptions? Who can suspend operation? Who addresses harm to an affected customer or employee? Document and understand those answers before an incident forces the organization to discover whether its governance arrangements work.

Governance Throughout the Lifecycle

Gupta’s gated lifecycle makes these responsibilities actionable. It follows AI from concept and planning through data preparation, development, independent validation, deployment, continuing monitoring, and retirement. Decision gates establish criteria for moving forward and identify the people authorized to approve or refuse progression.

Independent validation is particularly important. The team building a system should face review capable of challenging its assumptions and testing whether performance meets the intended use. Deployment readiness also includes monitoring, incident response, rollback capability, and operational procedures.

For compliance professionals, the lesson extends beyond initial approval. A system’s exposure can change when it receives new data, serves a different population, gains additional permissions, or undergoes a material modification. Gupta calls for defined triggers that return systems to validation.

Apply the same discipline to exceptions. Record the rationale, compensating controls, approver, remediation owner, and expiration date. An exception should remain visible until it is resolved. Retirement deserves similar attention, including appropriate data disposition and preservation of evidence needed to explain earlier decisions.

Measuring Whether Controls Work

The Trust Index gives Gupta’s framework a common measurement approach. It combines control implementation, control effectiveness, residual risk exposure, and compliance status into pillar scores and an overall assessment. The methodology assigns the greatest combined emphasis to whether controls exist and whether they work.

For boards, this creates a way to discuss changes in governance performance and direct attention toward unresolved weaknesses. Gupta also distinguishes inherent risk from current risk after controls. An inherently consequential use case does not become inconsequential because its controls improve.

The compliance implication is to examine the evidence supporting the number. Directors should understand significant weaknesses, testing results, exceptions, and corrective actions. A dashboard becomes useful when it supports decisions about resources, restrictions, and remediation. The underlying assessment must remain open to challenge, especially where a favorable aggregate score could obscure a serious problem in one area.

Governing AI That Takes Action

The book’s treatment of agentic AI deserves senior executives’ attention. An AI system that can invoke tools, modify records, send communications, or initiate transactions introduces questions about delegated business authority. Evaluating the model’s outputs covers only part of that exposure.

Gupta describes an agentic control plane that governs identity, permissions, tools, memory, delegation, observation, and intervention. A central principle is that consequential boundaries must operate outside the agent’s own reasoning. Written instructions alone cannot reliably limit what credentials and connected tools permit.

Consider a compliance application: an agent assisting with third-party onboarding. Management should distinguish permission to summarize diligence materials from permission to approve a supplier, alter payment information, or release a blocked transaction. Each capability requires deliberate authorization and appropriate controls.

Internal controls professionals know this lesson. Delegated authority needs defined limits, traceable actions, and effective intervention. Automation increases the importance of those disciplines because actions can occur faster than a person can review them.

Data and Third Parties Remain Central

Gupta also emphasizes the information an AI system uses when it acts. Policies, customer records, retrieved documents, and stored memory shape its behavior. Even a system operating within its permissions can make a harmful decision when its information is outdated or inappropriate.

For compliance teams, this means governing the sources behind AI advice. An assistant answering employee questions should use approved, current policies with identifiable owners and version histories. Access restrictions should continue to apply when information enters a retrieval system.

Third-party oversight must also reach beyond the primary model provider. Gupta examines tools, connectors, and packaged agent capabilities as supply-chain dependencies. She adds a business continuity question: what happens if a critical model becomes unavailable? Organizations should identify affected processes, evaluate alternatives, and test fallback arrangements before disruption forces an improvised response.

Evidence the Board Can Use

Gupta’s evidence-by-design approach connects the entire operating model. Significant decisions and actions should generate records as work occurs: approvals, validation results, system versions, permissions, relevant context, interventions, and monitoring outcomes. Those records should support reconstruction of a consequential action.

For boards, reporting should connect this evidence to oversight. Which systems carry the greatest exposure? Which controls have failed testing? Which exceptions remain unresolved? What has management restricted, delayed, or rejected? What decisions require board attention?

The CCO’s contribution is to make this reporting actionable and consistent with operational reality. Evidence should reveal where management needs to intervene and whether previous corrective actions achieved their intended result.

A useful starting exercise is to select one consequential AI decision and trace it from initial authorization to its outcome. Ask the owner to produce the supporting evidence. Any missing link identifies a concrete improvement for the governance program to address.

Practical Steps for CCOs and Boards

Gupta recommends starting with an honest readiness assessment and a manageable set of high-impact use cases, then expanding proven governance practices. Apply that approach through five actions:

  1. Inventory consequential AI systems, their owners, permissions, and dependencies.
  2. Establish authority for approval, exceptions, escalation, and suspension.
  3. Test controls against actual business risks and affected populations.
  4. Capture decision evidence during ordinary operations.
  5. Give the board visibility into unresolved exposure and remediation.

The business lesson from De-Risking AI Adoption is that effective governance makes responsible adoption repeatable. For CCOs and boards, the immediate task is to make accountability observable in how AI is approved, operated, challenged, and improved.

Categories
Blog

Andrew McBride Does it Again: His New Guide on Buying Compliance Technology

Compliance technology has become the operational backbone of the modern ethics and compliance program. When technology works, it can make compliance faster, more consistent, measurable, and embedded in business operations. When it doesn’t, the consequences show up everywhere: spreadsheets, manual workarounds, disconnected data, frustrated employees, and compliance professionals spending time administering technology rather than managing risk.

That makes buying compliance technology more than an IT procurement exercise. It is a compliance program effectiveness issue. One commentator on this aspect of AI for compliance is Andrew McBride, founder of the consulting firm Integrity Bridge LLC. McBride recently released Recommended Practice for Buying & Selling Compliance Technology, based on surveys of compliance technology buyers and vendors. Its findings illuminate a fundamental imbalance in the marketplace. I can safely say this paper is the standard for compliance professionals evaluating and purchasing AI-based technology.

CCOs buy compliance technology infrequently. Vendors sell it every day. That imbalance matters. Compliance teams can be oversold on functionality. Vendors can become trapped in opaque procurement exercises. Business requirements can become disconnected from technical requirements. AI capabilities can be accepted without sufficient governance. Contracts can focus extensively on getting into a system while ignoring how the company will eventually get out. For the CCO, the lesson is straightforward. If you want to run compliance like a business, you must learn to buy compliance technology like a business. This is where McBride comes in.

Start With Strategy, Not Software

As a CCO, start with a documented compliance technology strategy aligned with business operations. McBride sees three operational layers for that strategy.

Compliance-owned technology includes platforms compliance directly manages, such as Codes of Conduct, training, whistleblower systems, investigation case management, and workflows for gifts, entertainment, and conflicts.

Compliance-shared technology includes systems operated across functions, such as third-party due diligence, transaction monitoring, and communications monitoring.

Enterprise dependency technology includes compliance systems that may not be owned but depend on ERP, CRM, HRIS, procurement, and financial platforms.

This third category is particularly important. A CCO may believe the company has a third-party risk problem when the real issue is poor vendor master data. Transaction monitoring may generate noise because underlying financial data is inconsistent. Technology strategy therefore begins with understanding the compliance program’s architecture.

Know What Compliance Really Costs

Here, McBride frames the question as, ‘What is the total cost of ownership? ‘How many screening tools are independently licensed by Compliance, Procurement, Finance, Credit, and Legal? How many employees maintain spreadsheets? How many hours are spent chasing approvals or reconciling systems? How much compliance talent is consumed by administration rather than risk management? Those costs matter because an inexpensive system can become extraordinarily expensive once you include the human infrastructure required to run it.

This leads to the recurring question: buy, build, or assemble? Internal IT may propose building custom tools. Sometimes that works, but the calculation must include maintenance, upgrades, staffing, cybersecurity, documentation, and key-person risk. Another option is configuring technology the company already owns. That may reduce licensing costs, but “we already own it” does not mean “it is free.” Configuration, integration, testing, administration, and support still cost money.

Commercial software offers established products and vendor-supported roadmaps, but buying software does not eliminate implementation challenges. Apply the same economic discipline to all three options. Don’t compare the sticker price of commercial software with an internal solution whose real costs have never been calculated.

AI Changes the Conversation

AI is moving into transaction analysis, investigation scoping, interview preparation, monitoring, and other compliance workflows. The opportunity is substantial. So is the governance challenge. The Integrity Bridge research presents an interesting picture. AI use appears widespread, but governance and confidence have not necessarily kept pace. Only about one in four compliance teams surveyed had established a formal governance framework. Fewer than half could articulate how AI demonstrably improved compliance outcomes. Only 41 percent of compliance leaders trusted AI-driven outputs for operational decisions.

At the same time, 84 percent reported efficiency gains, while fewer than half reported actual cost savings. That distinction between efficiency and effectiveness is critical. Doing something faster does not necessarily mean doing it better. The CCO should not simply ask, “Does this product use AI?” The better question is, “What compliance outcome does the AI improve, and how can we demonstrate it?”

AI Governance Starts Under the Hood

“AI-powered” is not a meaningful technical specification. McBride advises that compliance should understand what happens under the hood. Once again, he is spot on. Ask questions such as, “Which model is being used?” What information goes into it? What comes back? Is customer information retained? Can corporate data be used for training? Does a third-party model provider receive the information?

These are compliance governance questions because the data may include investigations, employee information, third-party records, or financial information. The contract should address how that information is handled and establish appropriate restrictions on the use of corporate data and queries.

Next, a series of questions about where the AI can fail. Here McBride suggests: How does the system prevent cross-tenant data leakage? How does it identify unsupported statements, hallucinations, or fabricated citations? What happens when malicious instructions are hidden inside uploaded documents? Most importantly, does the system recognize when it lacks sufficient confidence and escalate the matter to a human?

One of the most important characteristics of compliance AI may not be its ability to answer questions. It may be its ability to recognize when it should not answer them.

Keep Humans in the Control Environment

Agentic AI raises the stakes because technology moves from providing information to taking action. But this requires clear authority boundaries. What systems can the agent access? What records can it change? What decisions can it make? Which actions require approval?

Certain compliance decisions should remain subject to documented human authorization. Closing an investigation, changing third-party screening rules, or approving high-risk onboarding are obvious examples. This is where AI governance becomes internal controls. The organization should demonstrate not merely that humans are theoretically “in the loop,” but where human intervention occurs, who has authority, what approval evidence is retained, and what happens when the AI crosses a defined threshold.

CCOs must also understand AI economics. Traditional platforms may be priced by employees, users, or third parties. AI functionality can introduce consumption pricing tied to tokens, documents, searches, or API calls. Model realistic usage and negotiate appropriate spending caps, alerts, overage controls, and consumption rates.

Turn the RFP Into a Governance Exercise

A good RFP does more than collect vendor responses. It forces the organization to define what it actually needs. McBride highlights vendor frustration with “phantom RFPs,” where an incumbent has effectively been selected, or the process is used primarily to gain renewal leverage. A credible RFP must instead be transparent, disciplined, and operationally grounded.

Start with Procurement. Understand source-to-pay requirements, spending thresholds, cybersecurity reviews, privacy requirements, and contracting procedures before bringing vendors deep into the process. Then give vendors meaningful operational information: employee populations, transaction volumes, existing systems, data maturity, integrations, geographic requirements, and workflow constraints.

Most importantly, force precision into vendor answers. Require vendors to classify functionality as:

  1. Available out of the box.
  2. Available through configuration.
  3. Available through a named third-party integration.
  4. On the roadmap with a committed date.
  5. Not supported.

That discipline can dramatically improve an evaluation and create a record of what was actually promised.

Stop Buying Features. Test Controls.

Feature checklists have limits.

McBride suggests that a better test is a scenario. Suppose a critical third party is added to a sanctions list overnight. Ask the vendor to show exactly what happens. Ask questions such as, “How is the alert generated?” Who receives it? How is it prioritized? Who can override it? How is the matter escalated? What evidence is captured? What appears in the audit trail?

Now you are not evaluating a feature. You are evaluating a control. The same principle applies to sandboxes. A generic vendor sandbox tells you relatively little. Require a guided environment configured around your workflows using synthetic or anonymized data. Make users perform the work. That is where implementation problems begin to reveal themselves.

Look Under the Hood Before You Buy

A beautiful interface can be seductive, but buying compliance technology based primarily on user experience is like buying a house because you like the countertops without checking the plumbing. However, before you make a final selection, conduct due diligence around security controls, hosting, uptime, integrations, implementation resources, and data portability.

Review relevant SOC 2 Type II controls. Speak with peer customers. Consider asking to speak with a customer that recently left the platform. Just as importantly, interview the people who will actually implement the product. The team delivering the sales demonstration may not be the team handling implementation. Know who shows up after the contract is signed.

Begin the Relationship by Planning the Exit

Perhaps the most overlooked element of compliance technology contracting is the exit. Companies spend enormous time determining how information will enter a system and surprisingly little determining how they will get it back. A CSV containing basic fields may not recreate an investigation file or preserve the history of a third-party approval. It may not capture attachments, comments, timestamps, escalations, approvals, or audit trails.

Before signing, define export requirements. Ask questions such as: What formats will be provided? What metadata will be preserved? What happens to attachments? Will the audit trail survive? How long will migration assistance remain available? What will extraction cost? When will the vendor delete remaining copies? Understand how you will leave a compliance technology provider before deciding to join it.

The CCO’s Technology Mandate

Compliance technology doesn’t succeed or fail when Legal finishes negotiating the contract. The outcome is largely determined earlier. Did Compliance understand the business problem? Did it know the true cost of the existing process? Did it understand its data? Did it challenge AI claims? Did it test failure modes and workflows? Did it involve Procurement, IT, Privacy, Security, Legal, and the business at the right points? Did it negotiate for implementation, operation, and exit?

Those questions turn technology procurement into compliance governance. Compliance professionals spend their careers asking businesses to operate with transparency, accountability, documentation, fairness, and integrity. Compliance should bring those same principles into the technology marketplace.

Define what you need. Understand what it costs. Test what the vendor claims. Document what was promised. Build controls around AI. Measure whether the technology improves the program. Make sure you can get your data back when the relationship ends. That is what it means to run compliance like a business.

Practical Takeaways

For the CCO, the mandate is clear: build the strategy before selecting the technology; calculate the Total Cost of Ownership rather than the license cost; treat AI as a governance and internal controls issue; test workflows rather than watch demonstrations; diligence the implementation team; and negotiate data portability and exit before signing.

For boards and senior management, the oversight question is equally straightforward: What compliance risk is this technology addressing, how will management measure whether it improves program effectiveness, and what controls govern its use?

The answer tells you much more than whether Compliance has purchased the latest technology. It tells you whether the organization is building a technology architecture that can support an effective compliance program.

If you do not follow Andrew McBride on LinkedIn, you should. He is leading the discussion on the practical aspects of putting the right AI tool in place for you and your organization. His organization will be displaying at this week’s SCCE CEI, so drop by the Integrity Bridge and find out why I think he is the go-to guy in this area.

Categories
FCPA Compliance Report

FCPA Compliance Report: From Prosecutor to White Collar Lawyer to CCO and Back: Mike Koenig

In this episode, Tom Fox welcomes Mike Koenig to talk about his career and his recent move back to private practice after a 5-year stint at JBS. Mike is one of the few folks to move from private practice to an in-house CCO role, then back to private practice.

Mike began by reviewing his career, from 25 years in private practice and a 2003 DOJ Fraud Section stint prosecuting corporate fraud to becoming chief compliance officer at JBS in August 2021 amid DOJ and SEC settlement agreements requiring an effective compliance program. He describes learning to operate within business-driven priorities by building relationships, learning the business and culture, “educating not dictating,” and securing C-suite, board, and audit committee buy-in, including CEO-driven training completion. He explains that he uses trusted outside experts and focuses on the specific problem to solve rather than “boiling the ocean.” After JBS completed the settlements and listed on the NYSE in June 2025, he returned to private practice at Friedman Kaplan to advise on investigations and compliance, emphasizing concise, solution-oriented counsel. He warns against de-prioritizing compliance despite reduced enforcement, urges risk assessments (tariffs, export controls, and human rights), and recommends using DOJ compliance guidance to review programs.

Key highlights:

  • Career Journey Recap
  • Joining JBS In-House
  • Building Compliance Fast
  • Relationships Not Dictates
  • Leadership Buy-In
  • FCPA Pause or a Wake-Up Call
  • Compliance Through 2030

Resources:

Mike Koenig on LinkedIn

Mike Koenig at Friedman Kaplan

Friedman Kaplan

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

Da Vinci Week: Part 5 – Leonardo’s Notebooks and the Defensible Compliance Program

In the first four posts in the Leonardo Compliance Framework, we used Leonardo’s work to explore the compliance disciplines of Refine, Investigate, Innovate, and Monitor.  For our final blog post, the lesson comes not from a single Leonardo masterpiece but from the extraordinary collection of notebooks he created throughout his life. Leonardo recorded observations about anatomy, engineering, mechanics, water, optics, mathematics, architecture, flight, weapons, and the natural world. He drew machines, recorded experiments, posed questions, explored ideas, and returned repeatedly to subjects that interested him.

The compliance lesson goes beyond good note-taking. Leonardo externalized knowledge. He created a record of observations, ideas, questions, and reasoning that otherwise would have existed only in his mind. Modern corporations face a similar challenge. A CCO may understand why a particular control exists. An investigator may remember why an inquiry was expanded. A regional compliance officer may know why a distributor received enhanced scrutiny. An audit committee may understand why management accepted a particular residual risk. An AI governance committee may know why it approved a particular use case with specific limitations.

Then people leave, responsibilities change, businesses are reorganized, and memories fade. The policy remains, but the reasoning disappears. That is why documentation should be viewed as a component of compliance governance rather than simply an administrative obligation.

If It Is Not Documented, the Organization May Not Know It

Compliance professionals know the maxim that if something is not documented, it did not happen. That formulation can be overly simplistic, but it points toward a genuine problem. Organizations often know more than their systems preserve.

Consider a high-risk distributor approved five years ago. The compliance file may contain due diligence reports, certifications, contractual provisions, and an approval. Yet the people involved may have known far more. They may have discussed a government relationship, considered terminating the proposed engagement, obtained additional information, imposed enhanced controls, and ultimately concluded that the residual risk was manageable.

If the file contains only the final approval, a future reviewer may know what the company decided without understanding why. That distinction matters. Good compliance documentation should preserve significant reasoning, not simply outcomes.

This does not mean every routine decision requires a lengthy memorandum. Documentation should remain proportional to risk. A routine low-risk approval may require little explanation. A significant exception involving elevated corruption risk, a senior executive, a sensitive investigation, or a consequential AI application may warrant considerably more.

Risk-based documentation is part of a defensible compliance program.

Documentation Creates Institutional Memory

One of the most significant vulnerabilities in many compliance programs is the concentration of institutional knowledge in particular individuals. Every organization has employees who know why things work the way they do.

A longtime compliance officer remembers why a control was implemented after an investigation. An internal audit executive understands why a particular business unit receives enhanced testing. A finance employee knows why payments to a particular category of third parties require additional approval. An investigator remembers a series of cases that revealed a recurring management problem.

That knowledge has value. A new CCO should be able to understand why major components of the program exist. A new audit committee chair should understand significant unresolved compliance risks. A new investigator should be able to identify relevant historical matters. A new control owner should understand what problem the control was designed to address. Institutional memory should belong to the institution.

Documentation Supports Accountability

Clear documentation also helps answer one of the most important questions in corporate governance: who decided?

Organizations make thousands of decisions involving compliance risk. Most are routine. Some are consequential.

When a significant risk is accepted, the company should be able to identify the person or governance body with authority to accept it.

This is particularly important for exceptions.

If a high-risk third party is approved despite significant red flags, who approved the relationship? If an investigation involving a senior executive is narrowed, who authorized the scope change? If a remediation deadline is extended, who approved the extension and what interim controls are operating? If an AI system is permitted to influence consequential decisions, who approved the use case and under what conditions?

These are governance questions.

Documentation creates a decision trail.

That trail allows management, internal audit, the board, and, when necessary, regulators or enforcement authorities to understand how the organization exercised judgment.

A defensible compliance program does not require perfect decisions. Business decisions involve uncertainty.

It should, however, be able to demonstrate that significant decisions were made through an appropriate process by people with the authority and information necessary to make them.

Remediation Requires Evidence

The Michelangelo series emphasized the difference between closing a project and solving the underlying problem. Leonardo’s notebooks add another dimension: the organization should preserve evidence of what it changed and why.

Suppose an investigation identifies weak approval controls over distributor discounts. Management agrees to remediate the issue by modifying system permissions and requiring additional review.

The compliance record should identify the deficiency, remediation owner, planned corrective action, expected completion date, and evidence required for closure. When management reports that remediation is complete, the record should support that conclusion.

Was the system actually modified? Were users informed? Did testing confirm that the revised control operates as intended? Were similar vulnerabilities evaluated elsewhere? This creates a defensible chain from problem to solution.

Finding → Root Cause → Remediation → Ownership → Validation → Closure

That chain matters to the CCO because it shows compliance findings lead to management action. Internal Audit values it because it supports assurance. It is valuable to the board because it provides evidence that identified risks are being addressed. Documentation converts remediation from a promise into an accountable process.

AI Makes Documentation More Important

Artificial intelligence may make the documentation principle more important than ever in the modern compliance program. AI governance involves decisions that may be difficult to reconstruct after the fact if they are not documented when made.

A company evaluating a significant AI use case should preserve enough information to understand the system’s intended purpose, business owner, risk classification, relevant data, identified risks, testing, required controls, human oversight, approval conditions, and monitoring expectations.

The record should also reflect material changes.

An AI application approved as a low-risk productivity tool may later gain access to sensitive internal data. A vendor may change the underlying model. A system may become integrated into a consequential business process. An application initially used to recommend actions may eventually be authorized to take them. The governance record should evolve with the system.

This matters because AI can complicate traditional assumptions about decision-making. When a human employee makes a decision, organizations generally know who made it. When an AI system influences or takes an action, accountability can become less obvious.

Documentation should prevent that ambiguity from becoming an accountability gap. The company should be able to reconstruct what the system was authorized to do, who approved that authority, what controls applied, and who was responsible for monitoring its operation.

NIST AI RMF and ISO/IEC 42001 both reinforce the broader value of structured governance, risk management, documentation, monitoring, and continuous improvement. For the CCO, the important point is not simply alignment with a framework. It is the ability to demonstrate how the organization governed the technology in practice.

Documentation Should Feed Organizational Learning

Documentation becomes most valuable when the organization uses it. Investigation records can reveal recurring root causes. Exception records can identify controls employees routinely struggle to follow. Third-party approval records can reveal recurring risk patterns. Remediation documentation can show which corrective actions are effective. AI governance records can identify use cases generating repeated incidents or overrides.

The organization can analyze these records to improve the compliance program. This closes the loop between all five Leonardo principles.

  • Documentation captures what monitoring reveals.
  • Monitoring identifies issues requiring investigation.
  • Investigations generate lessons that drive refinement.
  • Refinement can support responsible innovation.
  • Innovation creates new risks that require monitoring and documentation.

The framework is therefore not linear. It is a learning cycle. That is perhaps the most important Leonardo lesson for the modern CCO.

Completing the Leonardo Compliance Framework

With Leonardo’s notebooks, we complete our five-part framework:

Refine-> Investigate-> Innovate-> Monitor-> Document

Together, these principles describe compliance as an organizational learning system. Effective programs learn from experience, investigate failures to understand root causes, support innovation within appropriate governance, monitor whether controls continue to work, and preserve what the organization learns so that knowledge informs future decisions.

The Mona Lisa taught us to Refine. Compliance programs should improve because organizations learn from experience, changing risks, investigations, employee feedback, and data. Leonardo’s anatomical studies taught us to Investigate. Misconduct should be examined beneath the surface so the organization understands root causes, control failures, incentives, management behavior, and systemic vulnerabilities. His flying machines taught us to Innovate. Compliance should help the company capture the value of emerging technology while maintaining risk-based governance, meaningful human oversight, and clear accountability. The Last Supper taught us to Monitor. Controls can deteriorate as the environment changes, making testing, analytics, ownership, remediation, and continuing oversight essential to program effectiveness. Leonardo’s notebooks teach us to Document.

That provides the essential contrast with Michelangelo. His framework of Challenge, Execute, Defend, Build, and Govern taught a CCO how to construct and operate an effective compliance program. Leonardo teaches a CCO how to keep that program learning and adapting. The modern compliance function needs both disciplines because strong controls can become obsolete if the organization fails to recognize changes in its business, technology, and risk environment.

That combination matters even more in 2026. AI is accelerating business change, geopolitical developments can rapidly alter risk, third-party ecosystems continue to expand, and boards need evidence that compliance systems work in practice. The CCO cannot administer yesterday’s compliance program while the business builds tomorrow’s operating model.

Leonardo’s notebooks leave us with a simple compliance mandate: learn from what the organization does, preserve what it learns, and use that knowledge to make the organization better.

Categories
Blog

Da Vinci Week: Part 2 – Leonardo’s Anatomical Studies and Getting Beneath the Surface

In the first post in our Leonardo Compliance Framework, the Mona Lisa introduced Refine: the discipline of continuous improvement. An effective compliance program should learn from investigations, monitoring, risk assessments, employee feedback, control failures, and business changes. The program should evolve because the organization knows more today than it knew yesterday. That brings us to the second principle: investigate.

Leonardo was not satisfied with observing the human body from the outside. His anatomical studies examined muscles, bones, organs, movement, and the relationships among different parts of the body because he wanted to understand how the entire system worked. That provides a useful model for the modern Chief Compliance Officer because an effective corporate investigation should accomplish more than determine whether an employee violated a policy. It should help the organization understand why the conduct occurred, which controls failed, what incentives influenced behavior, whether management contributed to the problem, whether similar conditions exist elsewhere, and what should change as a result.

The compliance lesson from Leonardo is to look beneath the visible misconduct and understand the system that produced it.

An Investigation Is More Than a Search for Misconduct

Consider a familiar scenario. An investigation establishes that a sales employee used a consultant to make an improper payment to secure business. The company confirms the misconduct, terminates the employee and consultant, documents the findings, and closes the matter.

That process may answer the immediate legal and disciplinary questions, but it does not necessarily answer the larger compliance question. The company should also understand why it hired the consultant, how it approved the relationship, what due diligence it performed, whether it identified red flags, how it compensated the consultant, and how the resulting invoices and payments moved through the organization. Management should consider whether commercial incentives contributed to the conduct, whether supervisors encountered warning signs, and whether similar consultants are being used elsewhere.

If the company concludes only that one employee violated the anti-corruption policy, it may remove the individual while leaving intact the conditions that allowed the misconduct to occur. The investigation has then addressed the actor without addressing the vulnerability. That is why investigations should be viewed as a source of organizational intelligence.

Root Cause Should Drive Remediation

Root-cause analysis is where Leonardo’s anatomical method becomes particularly relevant. The objective is to move from the visible event to the systems underneath it. The Evaluation of Corporate Compliance Program (ECCP) states, “Finally, a hallmark of a compliance program that is working effectively in practice is the extent to which a company can conduct a thoughtful root.” It asks: What is the company’s root cause analysis of the misconduct at issue? Were any systemic issues identified? Who in the company was involved in making the analysis?

Root-cause analysis helps the company distinguish symptoms from causes, and that distinction should determine remediation. A response directed only at the visible misconduct may create the appearance of action without materially reducing the underlying risk.

This is also why significant investigations should test assumptions about the compliance program. If an intermediary engages in misconduct despite passing third-party due diligence, the company should examine whether the process missed information it reasonably could have identified. If an employee disguises improper payments, Compliance and Finance should understand how the relevant financial controls were circumvented. If retaliation occurs after an employee raises a concern, the organization should determine whether its anti-retaliation controls function in practice.

A well-designed compliance program can still experience misconduct. No reasonable system eliminates all risk. Effectiveness is measured by how the organization detects misconduct, responds, learns from failures, and strengthens the program when it identifies weaknesses.

Follow the Decision Trail

Investigators naturally follow evidence by reviewing documents, interviewing witnesses, analyzing transactions, and reconstructing events. Compliance investigations should also follow the decision trail because misconduct frequently passes through business processes designed to create accountability.

The investigation should identify who selected and approved a problematic third party, who authorized exceptions or unusual compensation, who approved payments, who received warnings, and who decided whether concerns warranted escalation. This becomes especially important when misconduct involves senior personnel, high performers, or commercially significant relationships.

The purpose is not to assign blame indiscriminately across every function connected to an incident. It is to understand where accountability actually resided and whether the people responsible for operating or supervising controls fulfilled those responsibilities.

A decision trail can reveal that misconduct was not simply the act of one individual. Other employees may have facilitated the conduct, ignored warning signs, approved questionable transactions, or failed to escalate information. Conversely, the evidence may demonstrate that established controls operated appropriately and that the individual deliberately circumvented them.

Organizational Justice Requires Consistency

Investigations also play a central role in corporate culture. Employees watch how organizations respond to allegations, particularly when cases involve senior executives or high-performing employees. They notice whether powerful people receive different treatment and whether employees who raise concerns suffer professional consequences. This makes consistency an important component of organizational justice, which the ECCP identifies as a part of every compliance program.

Consistency does not require identical outcomes. Facts, intent, responsibilities, prior conduct, cooperation, supervisory duties, and other legitimate considerations can justify different consequences. What matters is that the organization uses a credible process and applies its standards without creating privileged classes of employees.

Investigation governance is therefore important. The company should establish clear decision rights concerning whether allegations require investigation, who determines scope, who approves closure, how disciplinary decisions are made, when conflicts of interest require independent handling, and when matters involving senior executives should be escalated to the Audit Committee or board. These governance arrangements should be in place before a sensitive case arises.

Accountability should also extend beyond the individual who directly engaged in misconduct. Management behavior matters. A supervisor who ignored repeated warning signs, encouraged excessive risk-taking, approved unjustified exceptions, or created incentives that contributed to misconduct may raise separate accountability issues.

If employees see junior personnel disciplined while supervisors face no consequences for meaningful oversight failures, the company may signal that accountability flows only downward. Credible organizational justice requires a more consistent approach.

Investigation Data Is Enterprise Risk Intelligence

Individual investigations explain specific events. Aggregated investigation data can reveal enterprise-wide patterns, making it an important compliance asset. A CCO must understand which allegations recur, whether particular business units or managers appear repeatedly, where investigations are delayed, what root causes occur most often, whether similar control failures appear across jurisdictions, and whether employees who raise concerns subsequently experience unusual turnover or other adverse outcomes.

Those patterns can identify emerging risks that individual case files may not reveal. The data must be interpreted carefully. A business unit with a high number of hotline reports may have significant cultural problems, or it may have a healthy speak-up environment in which employees trust the reporting system. A location with few reports may have an excellent culture, or employees may fear retaliation.

Investigation data works best when combined with other information, including hotline trends, employee surveys, HR data, audit findings, transaction monitoring, exit interviews, and business knowledge. The objective is not simply to count cases but to use investigative information to understand the organization more effectively. This is the Leonardo approach in practice: observation combined with inquiry.

AI Changes the Investigation Function

Artificial intelligence is also changing corporate investigations. AI tools may assist with document review, chronology development, translation, pattern identification, data analysis, and summarization. Used appropriately, these capabilities may allow investigation teams to analyze larger volumes of information and identify relationships more efficiently.

They also create significant governance issues because investigations frequently involve some of the company’s most sensitive information. Before using AI, the organization should understand what data it will provide to the system, whether the material includes privileged, confidential, personal, or commercially sensitive information, where the data will be processed and retained, and what contractual and technical protections apply. Once again, the ECCP puts this onus on your compliance function.

Reliability is equally important. Investigators need a process to validate AI-assisted analysis and identify inaccurate or unsupported outputs. AI use should not obscure how a significant investigative conclusion was reached or prevent the company from explaining the evidence supporting its decision.

Human accountability should remain clear. AI can assist investigators, but it should not replace professional judgment concerning scope, credibility, findings, discipline, or remediation. The broader governance principles reflected in the NIST AI Risk Management Framework and ISO/IEC 42001 can help organizations think about risk management, human oversight, documentation, and monitoring. Still, the fundamental investigation requirements remain confidentiality, accuracy, fairness, privilege, and defensibility.

Connect Investigations to Remediation and Lessons Learned

Companies sometimes separate investigations and remediation too sharply. Legitimate reasons exist to maintain appropriate independence between fact-finding and certain management decisions, but the compliance program still needs a clear mechanism to convert investigative findings into corrective action.

For significant matters, management should understand what failed, why it failed, whether the weakness could exist elsewhere, what corrective action is required, who owns that action, and how the company will determine whether remediation worked. This turns an investigation from a historical examination into a forward-looking compliance tool. Without that connection, an organization can become highly proficient at investigating the same problem repeatedly without becoming better at preventing it.

Lessons learned should also travel beyond the specific business unit or jurisdiction involved. If an investigation in one market identifies improper distributor discounts caused partly by weak approval controls, the company should consider whether comparable controls exist elsewhere. If employees use personal messaging applications to circumvent company systems, management should assess whether the practice extends beyond the employees involved in the investigation. If an AI incident reveals that employees can deploy unapproved tools without effective technical restrictions, the organization should consider the broader governance implications.

This does not require distributing confidential investigative details throughout the company. It means converting case-specific findings into enterprise risk intelligence. Depending on the issue, the lesson may lead to changes in controls, risk assessments, monitoring, training, policies, management communications, or incentive structures. That is how Investigate feeds Refine.

What the Board Should Understand About Investigations

Boards and Audit Committees should resist evaluating the investigation function primarily through case counts. Knowing how many matters were opened and closed provides useful operational information, but it offers limited insight into program effectiveness.

Directors should understand what the company is learning from investigations. Significant themes, recurring root causes, internal control weaknesses, unusual patterns across business units, retaliation concerns, and the status and effectiveness of remediation all provide more meaningful information about compliance risk.

The board should also understand whether investigative resources match the company’s risk profile. Significant cases should not remain unresolved because the organization lacks appropriate staffing, cross-border expertise, data capabilities, employment-law support, or access to information. Matters involving senior personnel should be handled through processes designed to preserve independence and avoid conflicts.

The board does not need to manage individual investigations. Its role is to understand whether the investigation system provides reliable information about significant compliance risks and whether management responds appropriately to what that system reveals.

Getting Beneath the Surface

Leonardo’s anatomical studies give compliance professionals a useful model for investigations because the visible event may be only the first indication of a larger systemic issue. An improper payment may reveal a third-party weakness that exposes deficiencies in due diligence, technology, ownership, incentives, or management oversight.

The investigator’s task is to understand those connections without allowing every matter to become an unlimited enterprise-wide inquiry. Scope should remain proportionate to the seriousness, complexity, and potential reach of the issue. The objective is disciplined curiosity: understanding whether the evidence points to an isolated act or a broader weakness in the compliance system.

For the CCO, the practical lesson is that investigations should do more than establish whether a rule was violated. Significant matters should help the organization understand the controls, incentives, management decisions, and business conditions that contributed to the conduct. Root-cause analysis should drive remediation, investigation findings should test assumptions about program effectiveness, aggregated case data should inform enterprise risk assessment, and lessons learned should improve controls beyond the immediate matter.

That is Investigate, the second principle of the Leonardo Compliance Framework. Finding misconduct matters, but the greater compliance value comes from understanding the system that produced it and using that knowledge to reduce the likelihood of recurrence.

From Investigation to Innovation

Investigation helps the compliance professional understand how existing systems work and why they sometimes fail. Leonardo, however, was equally interested in systems that did not yet exist, which takes us to the third principle in the Leonardo Compliance Framework: Innovate.

In Blog Post Three, Leonardo’s Flying Machines and AI Governance, we will use Leonardo’s studies of flight to examine responsible innovation in 2026. Artificial intelligence and increasingly agentic technologies are moving from generating information to taking action within business processes, raising new questions about risk classification, human accountability, third-party AI, data governance, testing, monitoring, NIST AI RMF, and ISO/IEC 42001.

Leonardo’s willingness to imagine flight provides the innovation lesson. For the modern CCO, the corresponding governance task is ensuring the enterprise understands the risks, controls, and accountability needed before giving new technology meaningful authority inside the business.

Categories
Blog

When an Effective CCO Is Labeled Difficult

A business leader calls a Chief Compliance Officer (CCO) difficult after a proposed distributor fails to provide basic ownership information. The transaction is important to the quarter. The CCO has asked for the missing information, explained the concern, and identified what is needed to proceed. In the performance discussion that follows, the focus shifts to whether the CCO understands the business.

This hypothetical presents a governance question. Did the CCO handle the matter poorly, or did an appropriate challenge expose a business practice management would prefer to leave alone? The answer requires evidence about the decision, the CCO’s conduct, and the operating environment. A label provides none of that.

Luis Velasquez examines this diagnostic problem in Why Effective Leaders Get Branded as Problems, published in Harvard Business Review. He identifies four sources of leadership friction: genuine skill deficits, historical reputation, overextension of a leadership strength, and organizational barriers. His framework provides a useful starting point for evaluating CCO effectiveness while protecting the independence necessary to perform the role. The compliance applications below build on his analysis.

Diagnose the Conflict Before Evaluating a CCO

Velasquez describes an evaluation trap in which organizations treat visible behavior as the explanation for friction while giving insufficient attention to context. Once a leader acquires a negative reputation, subsequent assessments can reinforce it without testing whether the original diagnosis was sound.

For compliance, this creates a particular risk. A CCO’s responsibilities include raising concerns that may complicate a transaction, challenge an executive, or require management to change an established practice. Friction can arise while the function is doing its job. It can also arise when compliance communicates poorly, applies inconsistent standards, or takes too long to decide. An effective evaluation must examine both possibilities.

Start with the event behind the criticism. What decision was required? What information was available? What did the compliance request say, when, and why? What alternatives did a CCO identify? Which actions by the business affected the outcome? These questions create a basis for assessing performance without assuming the conclusion.

Address Genuine Skill Gaps Directly

Velasquez’s first category recognizes that leaders sometimes lack a necessary capability. Applied to CCOs, relevant gaps may include unclear communication, weak prioritization, insufficient business knowledge, or ineffective delegation. Consider a CCO who repeatedly sends lengthy technical explanations without identifying the decision management must make. Executives may reasonably struggle to act on the advice. Similarly, a compliance team that treats every request as equally urgent can consume resources while delaying matters that warrant immediate attention.

Those are legitimate performance concerns when supported by recent examples and a clear account of their consequences. Agree on the improvement required, provide support, and assess the result. Independence does not excuse disrespectful conduct, poor execution, or unsupported recommendations. It gives a CCO room to exercise judgment while remaining accountable for the work’s quality and delivery. A sound review evaluates whether a CCO explains concerns clearly and helps the business identify acceptable ways forward where they exist.

Replace Old Reputation With Current Evidence

Velasquez’s second category concerns historical reputation. A leader may change while the organization still relies on an outdated account of how that person operates. A CCO who joined during a serious control failure may initially have imposed tight review requirements. Years later, colleagues may still describe the function as inflexible even after it has introduced clearer thresholds, delegated decisions, and improved turnaround times.

The evaluation process should test whether the criticism reflects current experience. Ask for specific recent interactions, the applicable requirements, and the outcome. Compare those accounts with evidence of how the process now works. Older incidents may remain relevant, but explain their continued significance rather than assume it.

A CCO can contribute by demonstrating improvement through current service measures, examples of resolved issues, and feedback from people who use the process. The objective is an accurate assessment. Favorable anecdotes alone are no more sufficient than a repeated negative label.

Recognize When a Strength Needs a Different Application

Velasquez distinguishes a missing skill from a strength used too broadly. That distinction matters for a compliance leader whose career has rewarded detailed review and personal control of important decisions. Those habits may help stabilize a troubled program. As the business grows, the same approach can create bottlenecks if routine matters still require a CCO’s personal involvement. The leader needs to develop the team and establish clear decision authority while retaining appropriate escalation for significant concerns.

The response should specify where judgment can be delegated, what standards apply, and how quality will be checked. This preserves the value of careful review while changing how it is delivered. A CCO should be willing to examine this possibility candidly. A complaint about delay may reveal poor business planning, an overly centralized compliance process, or both. Correcting one cause does not remove the need to address the other.

Examine Whether the Organization Undermines the Role

Velasquez’s fourth category addresses organizational barriers involving culture, resources, incentives, and decision rights. This is where the implications for compliance independence become particularly significant.

A company may require review before engaging a third party while rewarding executives who commit to start dates before review begins. It may expect timely investigations while restricting access to relevant records. It may ask a CCO to escalate serious concerns and then criticize the escalation as a failure to collaborate.

In each case, evaluate the contradiction alongside a CCO’s response. Coaching the leader to communicate more effectively may help, but it cannot supply missing authority or correct an incentive that rewards bypassing controls. A CCO should document the constraint, its practical consequences, and the proposed correction. Management should identify who will resolve it and by when. Repeated, material barriers belong in discussions with the responsible board committee, particularly when they prevent the function from carrying out agreed responsibilities.

Make Board Support Concrete

Board support for a CCO should be visible in the governance process. Directors need access to an account of significant compliance concerns that explains the facts, management’s response, and any unresolved differences. The responsible committee should also understand the basis for material criticism of a CCO’s performance. Where criticism arises from an executive whose conduct or decisions compliance has challenged, that context warrants examination. It does not automatically invalidate the criticism or establish retaliation.

An appropriately independent review should consider the substance of the concern, how it was raised, and the evidence behind any proposed personnel action. Human resources, legal, and the relevant board leadership should have clear roles consistent with the company’s governance arrangements. Regular private discussions between a CCO and ELT leadership (or the appropriate board committee) can help surface barriers before a performance dispute becomes entrenched. Directors should ask whether compliance has the access, resources, and authority needed to deliver what management expects.

Evaluate Effectiveness With Measures That Fit the Role

An evaluation based heavily on executive satisfaction can discourage necessary challenge. A review based solely on activity counts provides an equally incomplete picture. Assess the quality and timeliness of advice, the prioritization of risk, the development of the team, and the follow-through on significant issues. Consider whether recommendations are supported and whether remediation addresses the underlying problem. Business feedback remains useful when it is specific and examined in context.

The central discipline is to evaluate the work and its consequences. Agreement with management is not a reliable measure of effectiveness; disagreement alone does not demonstrate courage or sound judgment.

Action Steps for the CCO

Use Velasquez’s framework to improve how performance concerns are examined:

  1. Ask for specific evidence. Identify recent events, decisions, and consequences behind broad criticisms. Respond to substantiated concerns directly.
  2. Test all four explanations. Examine skill gaps, outdated reputation, overused strengths, and organizational constraints. Recognize that more than one may contribute.
  3. Agree on meaningful performance measures. Include advice quality, timeliness, prioritization, team capability, and remediation follow-through alongside contextualized business feedback.
  4. Document barriers to effective execution. Record missing resources, restricted access, conflicting incentives, or unclear authority, with proposed corrections and accountable owners.
  5. Establish a credible board review process. Clarify escalation and evaluation arrangements so significant concerns about a CCO and constraints on the role receive informed consideration.

Effective compliance leadership requires both sound judgment and the ability to make that judgment understood. Organizations strengthen accountability when they evaluate those capabilities fairly and address the conditions that prevent a CCO from using them.

Categories
Blog

Does Your Board Have the Expertise and Independence to Oversee Compliance

A board can have impressive credentials and still lack the experience needed to challenge management on the company’s most significant compliance risks. Directors may understand finance, strategy, and operations in broad terms while struggling to recognize how misconduct could arise within a particular business model. Effective oversight requires relevant knowledge and the willingness to use it when the answers become uncomfortable.

For the chief compliance officer, that makes board capability a practical program issue. The quality of oversight influences the questions management must answer, the resources compliance receives, and what happens when a concern conflicts with a commercial priority. Today we examine board composition in the article Measuring Board Fit — Evidence from Elliott’s Campaign at Norwegian Cruise Line, from the Harvard Law School Forum on Corporate Governance. Their analysis uses AI to compare directors’ professional backgrounds with company strategy and with one another. It offers a starting point for a broader compliance question: Does this board have the expertise and independent judgment to oversee the risks this company actually faces?

Look Beyond the Skills Matrix

DesJardine and Mertens argue that conventional skills matrices can conceal meaningful differences in experience. Two directors may receive the same designation for operations or risk management while bringing very different capabilities to the boardroom.

The compliance application is straightforward. A risk management designation should prompt further inquiry into the nature, relevance, and recency of that experience. Has the director overseen a business using intermediaries in difficult markets? Has the director managed the integration of acquired companies? Examined an investigation involving senior leadership? Challenged a compensation structure that encouraged questionable conduct? No director needs to possess every capability. The board and its committees do need an informed basis for questioning management across the company’s priority risks.

The CCO can help define that basis. Translate the risk assessment into the experience and understanding needed for oversight. Where third-party conduct creates substantial exposure, explain the commercial relationships, payment practices, and escalation decisions directors need to understand. This gives the nominating and governance committee a more useful description than a generic request for compliance expertise.

Read the Norwegian Findings Carefully

The authors apply their method to Norwegian Cruise Line Holdings before and after Elliott Investment Management’s campaign, comparing its board with those of three cruise industry peers. They report that the company’s board-to-company similarity score increased from 0.382 to 0.396 following the changes. Average director-to-board similarity declined from 0.729 to 0.701, which they interpret as more distinct professional perspectives.

Those results describe changes in the authors’ measures of professional alignment and overlap. They do not establish that the reconstituted board became more effective at compliance oversight, that individual directors exercised greater independence, or that misconduct risk declined. That distinction matters for CCOs. An assessment can identify questions about composition without answering how directors perform. A board with relevant backgrounds still needs reliable information, sufficient time, and the resolve to follow an issue through. The practical response is to combine an examination of credentials with evidence of the board’s oversight process.

Examine Independence Through the Oversight Process

The authors acknowledge that their method cannot assess integrity, interpersonal skills, or willingness to challenge a chief executive. Those limitations point directly to the independent judgment compliance oversight requires. Consider a hypothetical board discussion about a distributor generating substantial revenue while repeatedly failing to provide requested ownership information. Management recommends extending the relationship during further review. A director with relevant experience may recognize how significant the missing information is. The next question is whether the board presses management to explain the proposed safeguards, decision authority, and consequences of continued delay.

The CCO should help create the conditions for that discussion. Present the facts, uncertainties, available options, and recommendation clearly. Identify who owns the decision and what would trigger escalation. Provide access to the underlying analysis where needed.

Direct access to the responsible committee and opportunities for discussion without management present can support candid oversight. Follow-up is equally important. An unresolved concern should return with updated evidence and a clear account of management’s actions. A difficult question has value when the governance process ensures it receives an adequate answer.

Make Expertise Usable Through Better Information

Even an experienced director can struggle with reports that emphasize activity while obscuring unresolved risk. Assess board capability and reporting quality together. A presentation may show that due diligence reviews are complete without explaining the exceptions approved. Investigation statistics may omit repeated issues within one business unit. Remediation updates may describe actions as finished without showing whether the revised controls work.

A CCO should organize reporting around decisions and consequences. Explain the issue, the evidence, management’s response, and what remains unresolved. When a commercial objective conflicts with a compliance recommendation, make that tension clear. Directors can then apply their experience to a concrete problem. Does the proposed response address the cause? Is the responsible executive accountable for delivery? What evidence will show that the correction is working? These questions help convert professional knowledge into oversight of program effectiveness.

Preserve Perspectives That Challenge Assumptions

The authors examine both alignment with company strategy and similarity among directors. That combination highlights a tension: a board needs relevant experience while retaining perspectives that question the organization’s assumptions. For compliance, industry familiarity can help a director spot questionable practices. It can also leave accepted business conventions insufficiently examined. Experience from another sector may expose weaknesses in customer treatment, escalation, or control ownership that insiders have normalized.

A CCO should therefore avoid equating a closely matched background with superior judgment. Ask what the board needs to understand and where a different perspective could improve its questions. Director education can help close specific knowledge gaps. Sessions built around the company’s actual processes, anonymized matters, and emerging business changes can give directors a better foundation for challenge. Persistent gaps may also warrant discussion of committee expertise or board recruitment, with those decisions remaining with the appropriate governance bodies.

Use AI Assessment as a Diagnostic Input

DesJardine and Mertens use contextualized word embeddings, a technique that turns text into numerical representations, to compare professional and company profiles. The approach can surface similarities that broad categories miss. For a board considering such analysis, the CCO and governance team should ask what information supports each profile and what the resulting score actually measures. Public biographies and media coverage provide an incomplete record of a director’s contributions. The volume and character of available material may differ substantially between candidates.

Company disclosures also describe the organization through a particular lens. Similarity to that description does not necessarily establish the expertise needed to address an overlooked risk or challenge an unsuccessful strategy. Use the output to inform interviews, reference discussions, and committee deliberations. Ask how sensitive the result is to source selection and whether the underlying evidence supports the interpretation. Record significant limitations. A numerical score should help the board investigate a capability question; appointment and evaluation decisions require accountable human judgment.

Action Steps for the CCO

Bring a practical assessment of oversight capability to the next discussion with the committee chair:

  1. Map priority risks to oversight knowledge. Identify what directors need to understand about the company’s business practices, controls, and escalation decisions.
  2. Provide evidence of capability gaps. Work with the corporate secretary and general counsel to inform education and composition discussions, using specific examples rather than broad labels.
  3. Strengthen the conditions for independent challenge. Establish clear access, candid reporting, and follow-up arrangements for unresolved concerns, including matters involving senior management.
  4. Test the usefulness of board reporting. Ensure directors can see material exceptions, recurring issues, remediation evidence, and decisions requiring their attention.
  5. Apply scrutiny to AI assessments. Examine source quality, missing information, and the limits of similarity measures before incorporating results into governance decisions.

Effective compliance oversight depends on directors who understand the company’s risks and are prepared to question how management addresses them. The CCO can strengthen that oversight by making capability needs explicit and ensuring the board receives the evidence needed to exercise its judgment.