Categories
Blog

Odyssey Week: Leadership – Athena in the Boardroom: Independent Oversight and Counsel

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Zendaya was great as Athena.

Athena does not row the ship. She does not lash herself to the mast, fight the Cyclops, navigate Scylla and Charybdis, or drag Odysseus’s crew away from every bad decision they seem determined to make. She is not in the trenches every day. She does not submit expense reports, approve vendors, review discount requests, or sit through the quarterly business review where someone explains why this deal is “strategic.” But Athena changes the journey.

She sees what Odysseus cannot see. She warns. She guides. She challenges. She protects. She appears at decisive moments when courage alone is not enough, and cleverness is about to become self-harm with better branding. That is why Athena belongs in the boardroom.

For corporate compliance, Athena represents independent oversight and wise counsel: the person, function, or governance body able to say, “That may win the deal, but it may also wreck the kingdom.” A compliance function that cannot challenge leadership is not Athena. Rather, it is simply decoration to meet a legal, statutory, or contractual requirement.

The Corporate Translation

Every company says it values compliance independence. The question is what that means when the business wants something. It is easy to celebrate compliance when compliance supports the decision already made. It is easy to invite the Chief Compliance Officer (CCO) to the meeting after the deal is signed, the press release is drafted, and the train has left the station with several questionable third parties in the dining car. That is not independence. That is archaeology.

Independent oversight means compliance has the authority, access, and resources to influence decisions before risk is accepted. It means the board hears directly from compliance. It means escalation does not depend on whether a business leader feels emotionally prepared for bad news. It means compliance can challenge high performers, powerful executives, and sacred business strategies without being treated as disloyal.

Athena does not exist to admire Odysseus. She exists to help him survive himself.

Access Is Not the Same as Influence

Many compliance officers technically have access to leadership. They attend meetings. They submit reports. They provide updates. They own several slides in the board deck, usually after cybersecurity and before “other business.” But access is not the same as influence.

Real access means compliance can raise concerns in a setting where they matter. It means there are private sessions with the board or audit committee. It means compliance can speak without management filtering, softening, or translating the message into something more comfortable. It means the board asks questions that go beyond “Any major issues?” which is the governance equivalent of asking a teenager whether school was fine.

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) focuses directly on whether compliance and control functions have autonomy and resources, including sufficient stature, sufficient staffing and resources, and autonomy from management, such as direct access to the board or audit committee. That is not a technical footnote. It is a central governance point. If the compliance function only reaches the board through management, the board may be hearing the music after someone else has adjusted the volume.

Authority Must Be Real

A compliance function without authority is like Athena without wisdom: impressive in name only. Authority means compliance can stop, modify, or escalate a transaction. It means policies are not optional when revenue is large enough. It means compliance concerns are documented, tracked, and resolved. It means the business must explain why it wants to proceed despite risk, not merely pressure compliance to “be practical.”

Practical compliance is not weak compliance. Practical compliance helps the business find a lawful and ethical path forward. But there is a difference between being practical and being domesticated. A good compliance function does not say no for sport. It says no when the facts, risks, and values of the company require it. It says, “not that way.” It says, “not with that intermediary.” It says, “not without diligence.” It says, “not until we understand the data, the customer, the payment, the conflict, or the control failure.”

The ECCP specifically asks how a company has responded when compliance raised concerns and whether transactions or deals have been stopped, modified, or further scrutinized because of compliance concerns. That is the right question. The ECCP states at one point, “Have they persisted in that commitment in the face of competing interests or business objectives?” Not whether compliance attended the meeting. Whether compliance changed the outcome. The ECCP further asked, “What role has compliance played in the company’s strategic and operational decisions? How has the company responded to specific instances where compliance raised concerns? Have some transactions or deals been stopped, modified, or further scrutinized as a result of compliance concerns?”

Resources Are a Statement of Values

Companies reveal what they value through budget. A board can praise compliance all day long. Still, if the function lacks staffing, technology, data access, training budget, investigative resources, and experienced personnel, the message is clear: “We support compliance, but preferably at a discount.”

No one would ask sales to grow revenue without systems, people, and market data. No one would ask finance to close the books with three spreadsheets, two interns, and a heroic attitude. Yet compliance teams are often expected to monitor global risk with underpowered tools and just enough headcount to keep the training completion dashboard from turning red.

That is not empowerment. That is wishful thinking. The ECCP asks whether compliance personnel have sufficient staffing to audit, document, analyze, and act on compliance efforts, whether resources are comparable to other parts of the company, and whether compliance has access to relevant data for timely monitoring and testing. Regarding funding and resources, the ECCP asks, “Has there been sufficient staffing for compliance personnel to effectively audit, document, analyze, and act on the results of the compliance efforts? Has the company allocated sufficient funds for the same? Have there been times when requests for resources by compliance and control functions have been denied, and if so, on what grounds? Does the company have a mechanism to measure the commercial value of investments in compliance and risk management?”

Those questions should make boards uncomfortable in a productive way. If the business has world-class tools to capture opportunity but outdated tools to detect risk, that imbalance is itself a governance decision.

Escalation: The Road from Concern to Action

Athena’s guidance matters because it reaches Odysseus when action is still possible. That is also the purpose of escalation. A well-designed escalation process moves concerns to the right people at the right time with enough information to make a decision. A weak escalation process traps concerns in email chains, local management reviews, or “let’s monitor this” limbo until the problem becomes a reportable event, a whistleblower complaint, or a headline.

Escalation should not depend on personality. It should not depend on whether the compliance officer is unusually persistent, politically skilled, or willing to become unpopular before breakfast. It should be built into governance.

What must be escalated? To whom? Within what timeframe? With what documentation? What happens when business and compliance disagree? Who decides? How are unresolved concerns reported to senior leadership or the board? These are not theoretical questions. They are the mechanics of wise counsel. Because without escalation, Athena is whispering in a locked room.

The Board’s Role: Ask Better Questions

Boards do not need to manage the compliance program day to day. That is not their role. But boards do need to oversee whether the program is real. That means asking better questions. The board should also pay attention to the moments when compliance loses. If compliance raised concerns and the business proceeded anyway, what happened? Was the decision documented? Were compensating controls added? Was the board informed? Did the risk later materialize? You learn a great deal about culture by examining what happens when wise counsel is inconvenient.

The Compliance Takeaway

Athena does not represent bureaucracy. She represents judgment. That distinction matters. Compliance officers are sometimes caricatured as the people who slow things down, complicate decisions, or drain the romance out of heroic commercial ambition. But the best compliance functions do something far more important: they help the organization see clearly before it acts.

They bring risk into the room. They challenge assumptions. They protect the company from cleverness without discipline. They help leaders understand that winning the deal, entering the market, launching the product, or pleasing the customer is not success if the path taken damages the company’s integrity.

Independent oversight is not ceremonial access. It is authority, resources, escalation, data, board engagement, and the organizational courage to let compliance challenge power. Odysseus needed Athena because brilliance has blind spots. So does every company.

The question is whether your Athena is truly in the boardroom or merely listed on the org chart.

Join us Tomorrow

Athena teaches that independent oversight is not ceremonial access but real authority, resources, escalation, data, board engagement, and the courage to let compliance challenge power. But that lesson only matters if the organization is willing to apply it to its most celebrated leaders, not merely its easiest targets. That brings us to Odysseus: the brilliant, strategic, results-driven leader every board wants and the very leader who can become the company’s most dangerous compliance risk when success becomes a shield. If Athena is the voice saying, “That may win the deal, but it may also wreck the kingdom,” Odysseus is the leader who wins the deal and forces the organization to ask whether anyone had the authority, courage, and independence to challenge how he did it. I hope you will join us tomorrow.

Categories
From the Editor's Desk

From the Editor’s Desk: Aaron Nicodemus on the August and September in Compliance Week

In this episode of ‘From the Editor’s Desk,’ Tom Fox visits with Compliance Week editor-in-chief Aaron Nicodemus to discuss highlights from Compliance Week in August, take a look at what is coming down the pike in September in Compliance Week, and discuss the upcoming Third Party Risk Management and Supply Chain Summit in Chicago.

Tom and Aaron review key August coverage and upcoming priorities. They discuss new columnist Ben Mason’s “The Hidden Cost of Compliance Leadership,” outlining five recurring burdens for compliance leaders: independence that is often only theoretical, job risk from doing the role properly (including survey findings that nearly 70% of compliance officers have experienced retaliation), inability to voice doubts internally, the invisibility of effective prevention work, and weak leadership support—creating isolation and prompting ideas for safe forums such as the vetted CW app and event roundtables. Nicodemus highlights his Mayo Clinic whistleblower story alleging AI use may endanger patient privacy and outpace internal guardrails. He also describes a National Conference “Practitioner’s Briefing” distilling six Chatham House themes, previews a September 1MDB case study on enablers, plans AI-governance essays for National Compliance Officers Day, and promotes the Oct. 28–29 Chicago TPRM Summit.

Resources:

Aaron Nicodemus on LinkedIn

Compliance Week

Third Party Risk Management and Supply Chain Summit

Categories
Blog

Dolly Parton and the Compliance Value of a Life Well Governed

Dolly Parton died this week. Her death closed one of the most remarkable careers in American entertainment, but it did not close the institutions, ideas, and expectations she built. For corporate compliance professionals, that durability is what makes her story more than a tribute. It becomes a lesson in how values can be converted into governance. Today I want to honor Parton, what she did, and what she stood for, and perhaps hope that her life will inspire all of us to be just a little better.

Parton was one of twelve children. Parton began singing on local radio and television as a child and appeared at the Grand Ole Opry at thirteen. She wrote her first song at age 6. She moved to Nashville after high school, established herself as a songwriter, and became a national star through The Porter Wagoner Show. She then built a solo career that crossed country, pop, film, television, theater, publishing, tourism, and philanthropy. She recorded more than fifty albums, wrote roughly 3,000 songs, won ten Grammy Awards, and created works such as “Jolene,” “I Will Always Love You,” and “9 to 5” that became part of the American vocabulary. One of the most amazing facts I learned while researching this piece was that “Jolene” and “I Will Always Love You” were written on the same day. How is that for creative inspiration?

Parton did not run a corporate compliance program, and her career should not be forced into that frame. Yet she demonstrated something every CCO and Board of Directors needs to understand: culture becomes credible when stated values, hard decisions, operating systems, and visible conduct reinforce one another over time. Her public identity rested on kindness, independence, dignity, humor, and respect. She repeatedly made those commitments tangible in contracts, businesses, philanthropy, and crisis response.

Her entrepreneurship deserves equal attention. Parton moved from performer to owner, producer, publisher, and partner, most visibly through Dollywood and the enterprises built around it. The portfolio was diverse, but it was not random. Music, storytelling, family entertainment, Appalachian identity, hospitality, and community investment all reinforced a coherent promise. Compliance professionals should recognize the governance advantage of that clarity. Diversification creates new legal, operational, third-party, and reputational risks, but a stable purpose helps leaders decide which opportunities fit, which controls must travel with the business, and which deals to decline.

Independence Before Applause

Parton understood the difference between access to power and surrender to it. She left Porter Wagoner in 1974 to build an independent career, expressing gratitude for the partnership without allowing it to define her future. She later declined an opportunity for Elvis Presley to record “I Will Always Love You” when his manager demanded a share of the publishing rights—saying no cost her an extraordinary short-term opportunity. Retaining ownership preserved the long-term value of her work, especially when Whitney Houston’s recording became a worldwide success. Business Insider called it “her smartest business move.”

That decision should resonate with compliance leaders. Independence is not a paragraph in a charter. It is the authority to resist pressure when revenue, status, or a powerful executive makes acquiescence attractive. A CCO needs direct access to the board, control over investigative escalation, sufficient resources, and protection against retaliation. Chuck Watson once said, “Sometimes the best deal is the one you don’t make.” A board should test whether that independence works when it is expensive, inconvenient, and unpopular. If compliance can say no only when nothing important is at stake, it is not independent.

Purpose Made Operational

Parton’s philanthropy offers an equally powerful lesson in program effectiveness. She created the Dollywood Foundation in 1988 to improve educational outcomes in her home county. Its Buddy Program paired students and offered a financial incentive for graduation; the dropout rate for the participating classes fell from 35 percent to 6 percent. In 1995, inspired by her father’s inability to read and write, she launched the Imagination Library. What began in Sevier County became a network operating across five countries that has delivered more than 300 million free books to young children.

This was not the purpose of branding. It was purpose translated into a defined population, a repeatable delivery model, local partnerships, funding, data, and measurable results. That is the same transition the Department of Justice asks companies to make when it evaluates whether a compliance program is well designed, adequately resourced, and working in practice. A value in the code of conduct must become an owner, a control, an escalation path, testing, and remediation. Intent is the beginning of a compliance program, not proof of one.

Listen to the People Who Experience Power

Parton’s film and song “9 to 5” gave popular form to workplace realities many employees already knew: power can be abused, unfairness can become routine, and people with the least authority often carry the greatest burden. The song endured because it recognized the lived experience behind organizational charts. It made a workplace issue visible without turning the people affected into abstractions.

Compliance programs fail when they listen only upward. Hotline statistics, exit interviews, culture surveys, investigation themes, retaliation allegations, and manager-level trends must reach leaders in a form that supports action. Boards should ask whether employees believe they can speak without losing status, opportunity, or employment. They should also ask whether the organization learns from weak signals before they become red flags. A speak-up system is not effective because a telephone number exists. It is effective when people trust the process and see consistent, fair outcomes.

Trust Earned Through Response

Parton’s businesses remained closely connected to the community that formed her. Dollywood became Sevier County’s largest employer, while its stated operating culture emphasizes hospitality, authenticity, collaboration, and respect. The company supports employee development, including tuition assistance. When wildfires devastated East Tennessee, Parton helped organize direct support for affected families. During the COVID-19 pandemic, her $1 million gift established a Vanderbilt research fund that supported work connected to the Moderna vaccine.

The compliance lesson is that reputation is a lagging indicator of accumulated conduct. Trust is built before a crisis through thousands of ordinary decisions about employees, customers, communities, and counterparties. A crisis tests it through the speed, fairness, transparency, and competence of the response. A company cannot purchase credibility with a campaign after years of contrary conduct. The best crisis communication remains a well-governed response supported by facts, accountable owners, and visible follow-through.

A Board Agenda Worthy of the Lesson

Parton’s legacy was unusually broad, but its organizing logic was simple. Know what matters. Protect it when pressure arrives. Build systems that carry values beyond the founder. Listen to people whose voices are easiest to overlook. Measure whether the work changes outcomes. Repeat the conduct long enough that stakeholders can rely on it.

  • For directors, that logic produces five practical questions. What principles will the company not trade away for a transaction or quarterly target?
  • Does the CCO possess real independence, resources, information, and access?
  • Which data prove that stated values operate at the employee and third-party level?
  • Are speak-up and investigation systems producing trust, learning, and remediation?
  • When the company faces a crisis, can the board see decisions, owners, deadlines, testing, and closure rather than a record showing only that management made a presentation?

Dolly Parton understood that a carefully created image can open a door, but only character and performance can keep it open for seven decades. Compliance leaders often describe their goal as building a culture of integrity. Her career reminds us what that requires: independent judgment, operational discipline, attention to the less powerful, measurable impact, and consistency when no applause is guaranteed. That is not only a fitting business lesson from her life; it is a demanding standard for every organization that wants to be trusted.

Categories
Blog

From Gatekeeper to Navigator: Dr. Hemma Lomax on the Decision Intelligence Gap

Compliance failures are usually narrated backward. Once the outcome is known, every warning appears obvious, every missed escalation looks negligent, and every decision seems to point toward the result. The board asks who knew what and when. The investigation searches for the broken control. Management wants the person or moment that explains the failure.

Dr. Hemma Lomax has done it again, leading the discussion in the compliance community. Her most recent book, The Decision Intelligence Gap, asks compliance professionals to look earlier. What happened before the decision became visible? Which assumptions hardened into facts? When did reversal become more expensive? Who noticed something that never gained enough purchase to change the direction? The book’s central insight is that the distance between intention and execution is not space. It is an operating environment shaped by incentives, defaults, authority, silence, pressure, and the accumulated residue of earlier decisions.

That makes this an important book for CCOs, boards, in-house counsel, audit, risk, and business leaders. It is not a conventional compliance manual. It does not provide a new risk taxonomy or a checklist for program design. It offers something more foundational: a way to examine how organizational choices form while there is still time to influence them.

A Book About the Decisions Before the Decision

Lomax defines the Decision Intelligence Gap in two related ways. It is the distance between the responsibility people carry for decisions and the visibility they have into how those decisions form. It is also the space between intention and execution, where choice remains alive. The book develops that idea across five parts: how choice narrows, how decision architecture changes what remains possible, how leaders can redesign the environment, how organizations should respond when things go wrong, and how learning can scale.

The governing image is the trolley problem viewed upstream. Compliance professionals know the familiar last-minute choice between two unacceptable outcomes. Lomax is more interested in what happened before anyone reached the lever. Who laid the track? When did the brakes become unavailable? Which earlier choices reduced the available paths? This move from moral drama to decision architecture is the book’s most valuable contribution.

Several concepts give that architecture practical shape. The silent hijack occurs when a concern is heard but never alters the decision. The threshold paradox describes the point at which an option remains technically open but becomes materially more costly to exercise. Designed desperation arises when the system makes the wrong choice easier, safer, or more serviceable than the right one. Defaults then carry yesterday’s decisions forward until repetition begins to look like legitimacy. None of these concepts removes individual agency. They show why accountability must examine both the actor and the conditions the organization created.

Why Compliance Leaders Should Read It

The book challenges the compliance function’s instinct to become the gatekeeper for every uncertain choice. Lomax does not argue against approvals, bright lines, or specialist authority. Some risks require them. Her sharper point is that a program can become excellent at routing questions to experts while failing to build decision capacity in the business. The CCO answers the immediate question, but the next employee facing similar terrain remains dependent on the same escalation.

Lomax proposes a navigation layer instead. Expertise should travel without automatically taking ownership of the decision. Employees need to understand the objective, the boundary being protected, the conditions that change the answer, the discretion that remains local, and the threshold for seeking another perspective. This is a powerful description of compliance as a business discipline. It moves the function from permission provider to designer of better choices while preserving hard stops where the risk requires them.

Her discussion of speak-up culture is equally strong. The important question is not only whether employees are permitted to report. It is what speaking has come to require and what happens when the room responds. A concern may be incomplete, inconvenient, or wrong. If the first response demands a finished case, the organization may force one employee to do the collective work of noticing, investigating, proving, and solving before the signal deserves attention. Lomax’s idea of being safe to learn goes beyond psychological safety. It asks whether people can contribute uncertainty, revise a position, or discover they were wrong without losing the standing to participate next time.

This insight should reshape investigations. A bad outcome does not prove poor reasoning, and a good outcome does not validate the process that produced it. Lomax’s account of outcome bias provides a disciplined basis for distinguishing accepted risk, ordinary mistake, flawed reasoning, reckless conduct, concealment, and misconduct. The compliance lesson is straightforward: reconstruct the information state at the time of the decision before hindsight rewrites what was knowable. Accountability then becomes more precise, more credible, and more useful to the next decision.

Lomax’s architecture also sharpens the familiar effectiveness question. A policy may be well designed on paper yet fail because the decision environment rewards delay, makes escalation costly, or teaches employees that exceptions are easier to approve than to revisit. Monitoring should therefore test not only control completion but also control use: who bypasses, who escalates, which questions recur, where decisions stall, and whether learning from one matter changes the next. This is where the book connects most directly to modern compliance evaluation.

The Most Useful Tool: HQDM

The book’s most immediately deployable framework is High-Quality Decision Making, or HQDM. It records five elements in proportion to the significance of the choice: the objective and what the organization is actually optimizing for; the thresholds that materially change the answer; the options genuinely available at the time; the rationale connecting facts, assumptions, uncertainty, and choice; and the learning plan, including what to monitor and what would trigger reconsideration.

For compliance professionals, HQDM offers a practical bridge between governance and evidence. It can improve a third-party exception, an AI use-case approval, an investigation disclosure decision, a market-entry choice, or a board risk-acceptance decision. It also creates a contemporaneous reasoning trace that can later help separate a defensible decision from one that merely benefited from luck. Lomax wisely cautions against turning inspectability into surveillance. The record should preserve decision-useful reasoning, not every tentative thought.

The framework also fits the board’s oversight role. A board cannot manage every operating decision. Still, it can ask whether management has identified the objective, made critical assumptions visible, established escalation thresholds, considered viable alternatives, and defined the conditions for returning to the decision. That is a better oversight record than a slide showing that the policy was approved and the training was completed.

Where the Book Requires Compliance Translation

The Decision Intelligence Gap is intentionally a thinking book, not an implementation guide. Its metaphors are memorable, its research base is broad, and its questions are often excellent. Yet compliance teams will still need to convert those ideas into governance mechanisms, owners, data, testing, and metrics. The book explains why a navigation layer matters, but it does not provide a detailed operating model for building one across a global enterprise.

The same issue appears with decision traces. The concept is sound, but the compliance application requires careful design. Records can create discovery, privilege, privacy, retention, and employee-relations consequences. A proportionate trace needs risk tiers, approved fields, access controls, retention rules, legal-hold integration, and guidance on what not to record. Otherwise, a tool intended to make reasoning visible may produce defensive writing or concealment.

AI adds another layer. Lomax correctly warns that putting a human in the loop is meaningless if the human merely approves the system’s preferred answer. A true navigation layer should expose sources, assumptions, uncertainty, alternatives, and override routes. Compliance leaders will need to add the control architecture: data governance, access management, validation, bias testing, monitoring, audit logs, incident response, and clear human accountability. NIST AI RMF and ISO/IEC 42001 can help operationalize that part of the vision.

The Verdict

This is a thoughtful, humane, and unusually relevant book for the compliance profession. Its strength lies in refusing the easy choice between individual blame and system excuse. People retain agency, but they exercise it inside conditions that can make signals harder to share, boundaries harder to hold, and reversals harder to justify. Effective compliance must examine both.

CCOs should read The Decision Intelligence Gap not as a substitute for the DOJ’s Evaluation of Corporate Compliance Programs, COSO, investigations protocols, or AI governance frameworks, but as a connective operating philosophy. It explains why policies can be clear while decisions remain poor and why speak-up programs can be available. At the same time, silence persists, and why lessons learned can be documented while organizational capability barely grows. It is especially valuable for compliance leaders ready to move from owning answers to building an organization that decides, learns, and adapts with integrity.

Questions for CCOs and Boards

Decision visibility. Which high-risk choices are becoming expensive to reverse before they reach formal approval?

Speak-up response. What does the organization do with an unfinished concern, and what does that response teach the next employee?

Accountability. Can investigations distinguish a bad outcome from poor reasoning and a mistake from misconduct without losing either fairness or rigor?

Learning loop. Where do investigation findings, exceptions, overrides, and near misses change the conditions of the next decision?

Navigation. Is compliance increasing the business’s capacity to recognize thresholds and exercise sound judgment, or merely increasing the number of questions routed to Compliance?

Categories
Blog

Private Company, Public Risk: Building Defensible AI Governance Before the Rules Arrive

For private companies, the central question about artificial intelligence is no longer whether the technology is in the business. It is whether anyone can explain where it is, what it does, what data it touches, and who is accountable when it fails.

That is the warning in “AI Governance for Private Companies,” by Hillary Flynn, Drew Morales, and Courtney Hugger of Wellington Management, which was recently posted in the Harvard Law School Forum on Corporate Governance. The authors report that nearly three in four companies plan to deploy agentic AI within two years, while only one in five has a mature governance model for autonomous agents. That is not merely a technology gap. It is a governance gap.

Private ownership does not make AI risk private. The consequences arrive through customers, employees, regulators, investors, lenders, insurers, and business partners. A company may not yet face a single comprehensive AI law, but it can still face a privacy complaint, contract dispute, cyber incident, customer loss, or damaged valuation. For compliance professionals, governance should precede scale.

Private Does Not Mean Exempt

Private companies are moving quickly because AI can increase productivity, improve customer service, accelerate analysis, support coding, and help a growing company scale. The article also identifies a critical lesson from Wellington’s portfolio companies: the largest barriers are often organizational, not technical. Companies making the strongest progress combine AI investment with employee training, clear governance, and defined expectations.

This is where the Chief Compliance Officer can reframe the discussion. AI governance is the discipline that allows useful experimentation without unmanaged legal and business exposure. The goal is not a thick policy on a shared drive. The goal is an operating system for accountable decisions.

The European Union AI Act is being implemented in phases through 2027, with expectations around transparency, human oversight, documentation, risk management, monitoring, and AI literacy. In the United States, NIST guidance, ISO standards, sector rules, state laws, and customer requirements are shaping expectations, even without a federal AI statute. A private company can therefore face AI governance demands through a contract or transaction long before a regulator knocks on the door.

Begin With the Business Objective

One of the article’s strongest recommendations is also one of the simplest: start with the business problem, not the AI tool. This is precisely what Carl Hahn has consistently maintained: always ask, “What is the Business Value?”Teams should define the desired outcome before selecting a model or vendor. Is it lower cost, faster response, better quality, increased revenue, fewer errors, or reduced risk?

Governance cannot evaluate an undefined promise. A measurable objective gives management a basis for deciding whether the use case works and whether its benefits justify its risks. It also creates stopping rules. Approval should identify what failure, customer impact, control breakdown, or scope change will trigger redesign, escalation, suspension, or retirement.

Compliance should insist on this discipline, particularly when an AI use case affects payments, eligibility, claims, pricing, employment, healthcare, education, financial products, or customer communications. Those are not ordinary software deployments. They are decisions and interactions with consequences for real people.

Inventory First, Then Tier the Risk

A company cannot govern what it cannot see. The foundation is an inventory of models, vendors, internal tools, embedded features, customer-facing systems, employee-built applications, and known shadow AI. It does not need to be perfect. It needs an owner, an update process, and enough information to support risk decisions.

Each use case should then be placed into a risk tier. Relevant factors include data sensitivity, degree of autonomy, importance of the business process, impact on customers or employees, regulatory exposure, ability to explain the result, and ease of reversing an error. Low-risk uses can follow a streamlined path. High-impact uses should receive enhanced testing, documented approval, human oversight, monitoring, and senior-level escalation.

Risk tiering prevents two failures. Treating every use as equally dangerous overwhelms review and encourages employees to route around it. Treating every use as ordinary technology leaves consequential applications without meaningful controls. Good governance applies greater rigor where potential harm is greater.

Put a Name Next to the Risk

Every AI system should have a business owner who remains accountable for its outcome. Accountability cannot be delegated to the model, the data science team, or the vendor. The owner should understand the intended purpose, approved users, permitted data, performance standard, escalation route, and circumstances under which the system must be paused.

Higher-risk applications should receive cross-functional review involving the business, product, engineering, legal, compliance, privacy, cybersecurity, procurement, and risk functions. This does not require a new bureaucracy. It requires a repeatable process with recorded approvals and clear responsibility.

Agentic AI raises the stakes because the risk moves from a wrong answer to a wrong action. Permissions should be limited, high-stakes actions should require human approval, and activity should be logged. Test override and shutdown mechanisms. The chatbot manipulated into agreeing to sell a vehicle for one dollar shows how weak boundaries turn a novelty into an operational event.

Treat Vendors as Part of the System

Most private companies will rely on external models, platforms, and software. That makes AI governance inseparable from third-party risk management. Traditional security questionnaires are not enough. Diligence should address how vendors use data, whether customer data trains models, how model changes are communicated, what transparency is available, how performance is tested, who bears liability, and whether data and workflows can be moved if the relationship ends.

The company should monitor model updates, service degradation, changes in terms, and features that expand access or autonomy. A tool approved for summarization should not silently become authorized to send messages, approve transactions, or alter customer records.

Monitor the System in Practice

AI governance does not end at approval. Model updates, new data, and user behavior can alter performance. Companies should monitor accuracy, reliability, bias, drift, misuse, repeated failures, and customer impact. An incident protocol should define how to pause the system, preserve evidence, escalate, remediate harm, and communicate with affected stakeholders.

This is where AI governance meets familiar compliance principles. The DOJ’s Evaluation of Corporate Compliance Programs asks whether a program works in practice. COSO emphasizes control activities, information, monitoring, and accountability. NIST’s AI Risk Management Framework helps organizations govern, map, measure, and manage AI risk. ISO/IEC 42001 offers a management-system approach. A company should select a coherent baseline and produce evidence that its controls operate.

A Practical Agenda for Boards and CCOs

Establish ownership. Name an executive accountable for AI governance and identify the board committee that will oversee material AI risk.

Build the inventory: capture sanctioned tools, embedded vendor capabilities, customer-facing uses, agentic applications, and known shadow AI.

Tier the use cases. Apply enhanced review where AI affects sensitive data, consequential decisions, critical operations, or autonomous action.

Strengthen the vendor process. Add AI-specific diligence, contractual protections, change controls, exit planning, and ongoing monitoring.

Test the failure plan. Confirm that the company can detect a harmful outcome, stop the system, preserve evidence, assign responsibility, and remediate the impact.

The author’s bottom line is the right one for compliance leaders: the winners will not necessarily be the companies that deploy AI fastest. They will be the companies that combine innovation with accountability, customer awareness, and disciplined execution. For a private company, defensible AI governance is not preparation for some distant regulatory future. It is how management protects value today.

Categories
Blog

THE BERKO TRIAL – PART 5: From Case Study to Control Test: A Berko Compliance Playbook for CCOs and Boards

Today we conclude our 5-part deep dive into the Asante Berko trial and guilty verdict, using the trial not simply as a case study but as a mechanism to pressure-test your compliance regime.

A compliance program is not effective because the company eventually exits a troubled transaction. It is effective when leaders can show how quickly the system identified the risk, who had authority to act, whether related conduct was contained, what the investigation established, and how the organization changed afterward.

That is the governance test presented by the Berko trial. Prosecutors built their case from emails, payment patterns, personal communications, compliance questions, recorded statements, and financial evidence. The defense attacked the missing last mile. The jury convicted Asante Berko on all three counts in just over three hours. For CCOs and boards, the final lesson is not to retry the case. It is to determine whether their own program could identify the same pattern, develop reliable facts, impose accountability, and respond at the speed enforcement policy now demands.

Start With the Three Questions That Matter

The DOJ Evaluation of Corporate Compliance Programs (ECCP) organizes program effectiveness around three questions. (1) Is the program well designed? (2) Is it applied earnestly and in good faith, with adequate resources and authority? (3) Does it work in practice? Those questions should frame the board’s review of the Berko fact pattern.

A written third-party policy answers the first question only in part. The second asks whether compliance can pause a revenue-producing transaction, obtain records, challenge senior employees, and reach the board without management filtering. The third asks for outcomes: when the warning signs appeared, did the organization find them, act on them, preserve the evidence, and fix the control weakness?

The governance failure is often not the absence of a rule. It is the gap between ownership and authority. Management owns business conduct and risk decisions. The CCO advises, challenges, monitors, and escalates. Internal audit provides independent assurance. The board oversees the system and management’s response. If every party assumes another function owns the hard decision, the control exists on paper but fails in operation.

Align Incentives, Conflicts, and Consequences

High-risk transactions require a clear view of personal incentives. Employees should disclose and pre-clear outside interests, referral compensation, client-paid benefits, expected success fees, and post-employment opportunities connected to current transactions. Offboarding should preserve relevant data, review pending payments, close access, identify continuing client contacts, and obtain certifications concerning outside interests and retained information.

Compensation deserves the same scrutiny as third-party payments. A bonus plan that rewards closing without measuring risk quality invites employees to treat compliance as a cost of delay. Risk-adjusted incentives should account for diligence completion, control compliance, escalation quality, and the durability of the business outcome. The ECCP asks whether companies use incentives for ethical conduct and apply discipline consistently across seniority, geography, and business unit. It also asks whether compensation can be deferred, reduced, canceled, or recouped when misconduct is established, subject to applicable law.

Consequence management must reach more than the direct actor. A credible process examines supervisory failure, tolerated red flags, obstruction, and failure to install or use safeguards. It applies the same decision framework to rainmakers and junior employees. The board should receive trend information showing investigation cycle times, substantiation rates, disciplinary consistency, repeat issues, and whether managers were held accountable for control failures.

Build Investigation and Speak-Up Readiness

The defense’s attack on the Berko evidence offers an investigation lesson. A source may have motives. A recording may require translation. Emails may lack a witness who can explain context. Payments may be traceable to an intermediary but not to an ultimate recipient. Those are reasons to investigate carefully, not reasons to dismiss an allegation.

Separate source credibility from objective proof. Preserve native emails, attachments, metadata, messaging records, payment instructions, approval histories, and device data. Trace funds beyond the first recipient. Document translation choices, dialect issues, investigative prompting, and competing interpretations. Interview witnesses who can explain both the transaction and the communications. Record what was established, what remained disputed, and why each conclusion was reached.

Design the process before the crisis. Define triage criteria, independence, privilege, preservation, scope approval, board escalation, investigation timing, root-cause analysis, and remediation ownership. Provide reporting channels that employees and third parties know, trust, and can use without retaliation. DOJ treats a trusted reporting mechanism and timely, properly scoped, objective, and documented investigations as hallmarks of an effective program.

Prepare the Disclosure Decision Before the Clock Starts

Voluntary disclosure should not be improvised during a board emergency. The company needs a protocol that identifies decision owners, the role of counsel, the facts required, preservation steps, the escalation path, and the method for assessing seriousness, pervasiveness, seniority, ongoing harm, and potential collateral consequences.

The March 2026 Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) makes speed commercially significant. It provides a declination path when a company voluntarily self-discloses to the appropriate DOJ component, fully cooperates, timely and appropriately remediates, and lacks disqualifying aggravating circumstances, although prosecutorial discretion and the policy’s definitions still control. The policy also contains an exception for a whistleblower who reports both internally and to DOJ. A company may remain eligible if it reports as soon as reasonably practicable, no later than 120 days after the internal report, and satisfies the other requirements.

That is not a 120-day permission slip to wait. The operating standard is speed with discipline. The company must stop continuing harm, preserve evidence, protect privilege, develop facts, and keep decision-makers informed. A tabletop exercise should test whether the organization can do all five while the disclosure window is running.

Give the Board Evidence, Not Activity Counts

Boards do not need every hotline allegation or third-party file. They need a risk-based view of whether the system works. Reporting should cover high-risk transactions proceeding with incomplete diligence, unresolved politically exposed person relationships, payment holds, management overrides, aged investigations, remediation slippage, repeat control failures, off-channel communication exceptions, and risk acceptances by senior leaders.

Metrics should show speed, quality, and outcomes. Track time from red flag to triage, triage to transaction pause, allegation to investigation plan, finding to discipline, and remediation commitment to validated closure. Measure whether the company can match high-risk payments to legitimate services, verified beneficial owners, approved accounts, and evidence of performance. Show whether control testing changed behavior, not simply whether employees completed training.

The CCO should have regular direct access to the board or responsible committee, including private sessions when appropriate. The board should understand the CCO’s authority, resources, data access, and unresolved requests. DOJ asks what information directors examined, whether compliance concerns stopped or changed transactions, and whether compliance has the stature and autonomy to function effectively.

Run a 30/60/90-Day Berko Stress Test

Days 1 to 30: Replay one recent high-risk public-sector transaction against the Berko pattern. Inventory intermediaries, beneficial owners, politically exposed person relationships, success fees, conflicts, personal-email exceptions, cash exposure, payment destinations, incomplete diligence, and overrides. Identify which facts the current systems can retrieve and which depend on manual reconstruction.

Days 31 to 60: Close the most important design gaps. Add hard stops, fee benchmarking, conflict attestations, off-channel controls, evidence-preservation rules, payment analytics, investigation protocols, and an escalation matrix giving compliance documented pause authority. Assign one accountable owner and a deadline to each remediation item.

Days 61 to 90: Test the program. Sample transactions, trace selected payments end to end, test the hotline from intake through closure, and conduct an investigation and voluntary-disclosure tabletop. Present the results to senior management and the board, including accepted risks, overdue actions, resource needs, and evidence that completed remediation operates in practice.

The board should ask, “Which Berko warning signs would we detect today?” How quickly could we freeze a payment? Who may override compliance, and what evidence is required? Can investigators collect personal-device communications lawfully and preserve multilingual evidence? Which repeated control failures have affected compensation or promotion?

The CCO should ask one final question: Would our program find this pattern because the controls work, or only because an external source eventually brings it to us?

This Berko FCPA trial blog post series began with the prosecution’s evidentiary mosaic and the defense’s missing-last-mile challenge. It ends with a practical conclusion. Compliance evidence becomes trial evidence. A defensible program must create that evidence through authority, trusted reporting, disciplined investigations, consistent accountability, measurable remediation, and active board oversight. That is how a case study becomes a control test and how a control test becomes proof that the program works.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Blog

THE BERKO TRIAL – PART 4: When Red Flags Become Evidence: Transaction Controls from the Berko Trial

Today in Part 4, I want to focus on some of the compliance lessons from the Asante Berko FCPA trial. The compliance lesson from the Berko trial is not simply that employees should not pay bribes. Every code of conduct already says that. The harder question is whether the compliance program can interrupt the operating pattern: a politically connected intermediary, milestone-linked invoices, personal email, cash discussions, incomplete diligence answers, and a commercial team under pressure to close. These were some of the questions that Goldman Sachs faced and successfully answered.

That is where policy becomes performance. Trial reporting described a legitimate infrastructure project surrounded by evidence that prosecutors said showed corrupt intent and concealment. The same emails, diligence questions, payment records, and escalation decisions that once lived inside a transaction later became evidence before a jury. For compliance professionals, the case is a control map. It shows where a high-risk deal can be tested, paused, corrected, or stopped before red flags mature into criminal exposure.

Begin With the Business Model

Your business justification should begin with how the deal is expected to work, not with a standard questionnaire. In the Berko transaction, commercial urgency, a major public need, concentrated government discretion, substantial projected fees, and local intermediaries all increased the risk profile. None of those facts establishes bribery. Together, however, they demand a more disciplined control environment.

The deal team should be required to explain the legitimate path to success. Which officials control each approval? Which regulatory, legislative, and contractual milestones must occur? What service does every intermediary perform? How is that service connected to value rather than access? Where could commercial pressure tempt someone to bypass the process?

This is consistent with the DOJ Evaluation of Corporate Compliance Programs (ECCP), which asks whether a company understands its business from a commercial perspective and devotes appropriate attention and resources to high-risk transactions. A generic country score is not enough. The risk assessment must reflect the transaction’s economics, approval structure, counterparties, compensation model, technology, and pressure points.

Make Third-Party Diligence Operational

Third-party diligence often fails because it is treated as an onboarding event. The questionnaire is completed, screening is run, a risk rating is assigned, and the business moves on. High-risk public-sector work requires continuous control.

Before engagement, the company should document the business rationale, beneficial ownership, politically exposed person and family links, qualifications, reputation, service scope, deliverables, compensation, payment terms, and proposed bank account. Compensation should be benchmarked against the actual work. Enhanced review should apply when fees are success-based, tied to government milestones, disproportionate to services, routed through unrelated entities or individuals, or connected to officials who control approvals.

After onboarding, controls must follow the intermediary into contracting, invoicing, payment, and monitoring. The DOJ guidance asks whether the company understands the business rationale, confirms that services were actually performed, assesses whether compensation is appropriate, tracks red flags, uses audit rights, and manages third parties throughout the relationship. The relevant question is not whether the intermediary passed diligence once. It is whether the relationship still makes sense when the invoice arrives.

Control the Channels Where Business Occurs

Personal email is not proof of bribery. The Berko facts were more specific. According to the trial reporting, sensitive payment discussions occurred through personal accounts. At the same time, routine deal work proceeded through corporate systems, and one exchange referred to the monitoring of a Goldman account. The control issue was the combination of channel separation, sensitive content, and knowledge of monitoring.

Companies need clear rules for personal email, messaging applications, approved mobile platforms, and bring-your-own-device arrangements. Those rules require technical support: approved-channel design, retention settings, monitoring consistent with law, exception approval, employee attestations, and escalation when business moves outside the system. The program should also test whether records can actually be collected and preserved across the jurisdictions where the company operates.

The ECCP asks how companies manage and preserve business communications on personal devices and messaging platforms. The DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) likewise identifies appropriate controls over personal and ephemeral communications as part of timely remediation. A policy that cannot preserve the evidence it covers is not an effective control.

Give Compliance Real Stop Authority

Escalation is not effective if compliance can ask questions but cannot pause the transaction. High-risk deals need defined hard stops. Examples include incomplete beneficial ownership, inconsistent diligence answers, refusal to identify service providers, unexplained compensation, undisclosed PEP relationships, requests for cash, payments to personal or nominee accounts, and destination changes without a credible business reason.

A hard stop does not require the company to abandon every transaction containing a red flag. It requires the risk to be resolved before money or value moves. The control framework should identify who may impose a pause, who may clear it, whether any override is permitted, what evidence supports an override, and which risk decisions require senior escalation.

Trial testimony reportedly described months of compliance questions about the Ghanaian intermediary and inconsistent or incomplete answers, followed by Goldman’s withdrawal from the contemplated financing. That sequence should not be converted into a claim that every control operated early enough or that the company was legally exonerated. The more useful lesson is that the decision trail mattered. It documented the questions, the resistance, the escalation, and the exit.

Connect Diligence, Invoices, and Money

Many programs distribute the relevant facts across separate systems. Procurement sees the contract. Compliance sees the screening. Accounts payable sees the invoice. Treasury sees the destination account. Investigations see the allegation. No one sees the complete pattern.

Payment controls should require proof of service, account-name matching, country and entity consistency, independent approval for destination changes, and tight restrictions on cash. Analytics should flag round-dollar invoices, duplicate invoice numbers, payment splitting, milestone-timed consulting fees, payments to employees or related parties, high-risk correspondent routes, and transfers followed by cash withdrawals.

The decisive step is integration. Due diligence, PEP screening, contracting, procurement, accounts payable, treasury, and case-management data should be capable of producing a transaction-level view. That view allows compliance to ask whether a payment is not only properly approved but also commercially credible.

Build an Evidence-Grade Record

The defense’s most forceful theme was the missing last mile: no downstream bank record showing money reaching a Ghanaian official, no alleged recipient on the witness stand, and no eyewitness to a bribe. The jury nevertheless convicted Berko on all three charged counts. For an internal investigation, the lesson cuts both ways. Suspicion is not proof, but weak tracing can leave the company unable to determine what happened.

Preserve native emails, attachments, metadata, messaging exports, payment records, approval histories, translations, and custodial provenance—record who made each factual determination and what evidence supported it. For multilingual material, preserve the original, use qualified translators, document dialect and ambiguity, and maintain a process for reviewing disputed language. Financial tracing should move from payer to intermediary to ultimate recipient, including related-party accounts and cash conversion.

The current FCPA enforcement guidelines emphasize individual misconduct and caution against attributing nonspecific malfeasance to corporate structures. That makes an evidence-grade corporate record especially important. It can help separate an individual’s conduct from the organization’s response while also showing whether the program was designed and implemented effectively.

Test the Controls Before the Crisis

An effective program does not promise that no misconduct will ever occur. DOJ recognizes that even a strong program may fail to prevent an offense. The question is whether the program is risk-based, detects concerns, responds promptly, and improves from experience.

Replay a recent public-sector transaction against the Berko pattern. Could the company identify every approval-controlling official and intermediary? Would milestone-linked payments trigger review? Could compliance pause the deal? Would personal email activity be detected and preserved? Could investigators trace funds beyond the first intermediary? Measure time from red flag to pause, overdue enhanced diligence, unresolved PEP issues, payment exceptions, control overrides, and closure of remediation.

The practical takeaways are clear. Commercial urgency calls for greater discipline, not reduced scrutiny. Third-party diligence must remain connected to invoices, payments, monitoring, and escalation. Off-channel communications become an intent and preservation issue when combined with sensitive content and known monitoring. A deal exit matters, but an earlier hard stop may reduce exposure and preserve more business value.

Join us tomorrow as we conclude our 5-part series by moving the transaction to the enterprise. In it, we will explore such questions as who owns these controls, who funds and tests them, how accountability is imposed, and what your Board of Directors should demand as evidence that the program works in practice.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 70 – Lessons from Let That Be Your Last Battlefield: Building Justice and Fairness into Corporate Culture

Few episodes capture the destructive power of bias, systemic injustice, and the refusal to see common humanity as vividly as Star Trek: The Original Series’ “Let That Be Your Last Battlefield.” From a compliance perspective, the episode provides an unflinching mirror: organizations that fail to ensure fairness in their systems—whether in investigations, promotions, whistleblower treatment, or discipline—risk breeding internal hostilities just as destructive as Cheron’s. Today, we unpack five key compliance lessons for embedding institutional justice and fairness into the corporate DNA.

Lesson 1: Bias—Even When Invisible to Some—Can Destroy Organizational Cohesion

Illustrated by: When Bele first encounters Lokai aboard the Enterprise, he describes him as “obviously inferior.”

Compliance Lesson. Bias often hides in plain sight for those not affected by it. In corporate settings, decision-makers may not recognize that promotion patterns, discipline rates, or resource allocations favor certain groups until a whistleblower, audit, or public scandal exposes it.

Lesson 2: Enforcement Must Be Fair, Consistent, and Transparent

Illustrated by: Bele claims the right to arrest Lokai for crimes committed on Cheron. Lokai, in turn, accuses Bele of genocide. Neither offers verifiable evidence; instead, both rely on their moral certainty.

Compliance Lesson. Internal enforcement that rests on vague accusations or uneven application destroys trust in compliance systems.

Lesson 3: Leaders Must Refuse to Be Drawn into Partisan Vendettas

Illustrated by: Kirk insists on the Enterprise’s code of conduct and rules of evidence.

Compliance Lessons. Senior leaders are often pressured, subtly or overtly, to “pick a side” in internal disputes.

Lesson 4: Systemic Injustice Can Persist Until It Consumes the Organization

Illustrated by: When Bele and Lokai finally return to Cheron, they find their planet in ruins, destroyed by centuries of hatred. Yet, even faced with the extinction of their people, they continue their pursuit, consumed by the need to destroy the other.

Compliance Lesson. Corporate cultures that allow systemic injustice, favoritism in promotions, discriminatory pay structures, and retaliation against whistleblowers risk not only reputational harm but also the destruction of the organization’s ability to function cohesively. Over time, injustice becomes normalized, making reform nearly impossible without significant disruption.

Lesson 5: Without a Shared Framework for Fairness, Conflict Has No Resolution

Illustrated by: Spock, ever the voice of logic, tries to point out that the two aliens are more alike than different. To them, justice is entirely defined by the defeat of the other.

Compliance Lesson. In corporations, the absence of a clear, visible framework for fairness, along with policies, expectations, and trusted reporting channels, leads to conflicts that devolve into zero-sum games.

Final ComplianceLog Reflections

Let That Be Your Last Battlefield ends on a tragic note: the two survivors beam down to a dead world, still locked in mutual hatred. It’s a cautionary tale for corporate life. Without institutional justice and fairness, even the most advanced organizations can collapse into destructive internal conflict.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Timothy is an AI-generated voice

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 67 – The Human Element in Compliance: CCO Takeaways from ‘The Empath’

Today we set a course for one of Star Trek: The Original Series’ most underrated yet profound episodes: “The Empath.” As compliance professionals, we know that the heart of any effective compliance program is its leadership. The Hallmarks of an Effective Compliance Program, from the FCPA Resource Guide, 2nd edition, require that the CCO possess the “appropriate expertise” to do the job. But what does that mean, and how does a leader’s expertise transcend mere technical skill to encompass the human, ethical, and cultural challenges inherent to the compliance function?

As we explore five critical lessons for compliance officers from “The Empath,” you will observe that true expertise for a CCO is not simply about credentials or technical know-how; rather, it is about the deeper qualities that empower a leader to guide organizations through pain, ambiguity, and risk.

Lesson 1: Beyond the Resume: The CCO as Empathic Leader

Illustrated by: Gem learns not through technical means, but by direct connection and deep feeling.

Compliance Lesson. Expertise is more than certifications, legal degrees, or audit experience. The most effective CCOs bring an “empathic intelligence” to their work, a capacity to understand the pressures, fears, and motivations of employees at all levels.

Lesson 2: Courage Under Pressure: The CCO Must Withstand the Ultimate Test

Illustrated by: The episode asks, who dares to stand up, even when it hurts?

Compliance Lesson. CCO expertise is proven under fire. This means the ability to stand firm when pressured by powerful business leaders, to deliver hard truths to the Board, and to make unpopular recommendations in the face of potential personal or professional blowback.

Lesson 3: Interdisciplinary Skillset: Bridging Science and Compassion

Illustrated by: The Enterprise officers combine analytical thinking with compassion, helping Gem grow by demonstrating both logic and heart.

Compliance Lesson. A truly effective CCO integrates hard skills with the “soft skills” of persuasion, relationship-building, and cultural sensitivity.

Lesson 4: The Power of Sacrifice: Prioritizing the Mission Over Personal Gain

Illustrated by: McCoy’s selflessness teaches Gem that true empathy means accepting risk for the sake of others’ well-being.

Compliance Lesson. The CCO role demands a willingness to prioritize the organization’s long-term health, even when it may come at the cost of short-term popularity or personal advancement.

Lesson 5: Teaching and Transforming: The CCO as Culture Carrier

Illustrated by: By the episode’s conclusion, Gem is transformed by the example set by the Enterprise crew. She learns to act, not just to feel, demonstrating that real change comes from both internalizing values and taking decisive action.

Compliance Lesson. A CCO’s expertise is measured not only in what they know but also in how effectively they teach, mentor, and shape the organization’s culture—the enterprise.

Final ComplianceLog Reflections

The Empath” reminds us that leadership in compliance, like leadership in the Enterprise, requires more than technical skill. It requires empathy, courage, interdisciplinary knowledge, sacrifice, and the ability to teach and inspire. The DOJ’s Hallmarks of an Effective Compliance Program make it clear: a CCO must have the appropriate expertise to do the job, and that expertise is as much about the heart as the head.

In evaluating, supporting, or stepping into the CCO role, remember Gem’s journey. The greatest expertise lies not only in knowing the rules but also in living them and in helping others do the same, especially when the path is hard. Empathic leadership is not a luxury; it is a requirement for building compliance programs that endure.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

Categories
Blog

Empathy, Expertise, and the CCO: Five Lessons from Star Trek’s “The Empath”

Today, we set a course for one of Star Trek: The Original Series’ most underrated yet profound episodes: “The Empath.” As compliance professionals, we know that the heart of any effective compliance program is its leadership. The Hallmarks of an Effective Compliance Program, from the FCPA Resource Guide, 2nd edition, Justice, require that the Chief Compliance Officer (CCO) possess the “appropriate expertise” to do the job. But what does that mean, and how does a leader’s expertise transcend mere technical skill to encompass the human, ethical, and cultural challenges inherent to the compliance function?

Let’s use “The Empath” as our guide. This visually striking and emotionally powerful episode puts Captain Kirk, Dr. McCoy, and Mr. Spock in the hands of alien scientists who subject them and a mysterious, silent woman named Gem to a series of moral and physical trials. At its core, the episode explores the transformative power of empathy, self-sacrifice, and moral courage.

As we explore five critical lessons for compliance officers from “The Empath,” you will observe that true expertise for a CCO is not simply about credentials or technical know-how; rather, it is about the deeper qualities that empower a leader to guide organizations through pain, ambiguity, and risk.

Lesson 1: Beyond the Resume: The CCO as Empathic Leader

Illustrated by: Gem, the titular empath, can sense and even absorb the pain of others, experiencing their suffering as if it were her own. She learns not through technical means, but by direct connection and deep feeling.

Compliance Lesson. Expertise is more than certifications, legal degrees, or audit experience. The most effective CCOs bring an “empathic intelligence” to their work, a capacity to understand the pressures, fears, and motivations of employees at all levels. Just as Gem could not help without first connecting to others’ pain, a CCO must be attuned to the human element behind every compliance risk. This empathy allows the CCO to anticipate issues before they become crises, to speak credibly to leadership about real risks, and to create a culture where people feel safe reporting concerns.

What should you do now? When evaluating CCO expertise, look beyond the resume. Ask: Does this person have the emotional intelligence to sense the cultural currents within the organization? Can they “walk the decks” and listen with intention? Empathy is not optional; it is essential.

Lesson 2: Courage Under Pressure: The CCO Must Withstand the Ultimate Test

Illustrated by: In “The Empath,” Kirk, Spock, and McCoy are subjected to torturous experiments designed to test their moral fiber. Dr. McCoy, in particular, volunteers to endure pain so others may be spared. The episode asks, Who dares to stand up, even when it hurts?

Compliance Lesson. CCO expertise is proven under fire. In practice, this means the ability to stand firm when pressured by powerful business leaders, to deliver hard truths to the Board, and to make unpopular recommendations in the face of potential personal or professional blowback. The DOJ’s 10 Hallmarks require CCOs who can operate with autonomy and independence, not simply as figureheads or “window dressing.” True expertise reveals itself when the stakes are high, and the right answer is the hard one.

What should you do now? Your CCO must be someone who will put the organization’s integrity first, even at personal cost. The “ultimate test” for a CCO is not a certification but the ability to hold the line when ethical principles are threatened.

Lesson 3: Interdisciplinary Skillset: Bridging Science and Compassion

Illustrated by: The Vians, the alien scientists, are coldly rational, treating their subjects as experimental variables. In contrast, the Enterprise officers combine analytical thinking with compassion, helping Gem grow by demonstrating both logic and heart.

Compliance Lesson. A CCO’s expertise must bridge multiple disciplines. Today’s compliance challenges touch on law, accounting, behavioral science, technology, communications, and global business. But technical expertise is only half the equation. A truly effective CCO integrates hard skills with the “soft skills” of persuasion, relationship-building, and cultural sensitivity. Like Kirk and Spock, who blend analysis and empathy to navigate the Vians’ trials, a CCO must translate regulatory requirements into messages that resonate and motivate across the organization.

What should you do now? Evaluate CCO candidates for both their cross-disciplinary knowledge and their ability to synthesize and communicate complex concepts persuasively. Expertise means connecting dots and connecting with people.

Lesson 4: The Power of Sacrifice: Prioritizing the Mission Over Personal Gain

Illustrated by: McCoy’s willingness to sacrifice himself for Kirk and Spock is a turning point—both for Gem and the Vians. His selflessness teaches Gem that true empathy means accepting risk for the sake of others’ well-being.

Compliance Lesson. The CCO role demands a willingness to prioritize the organization’s long-term health, even when it may come at the cost of short-term popularity or personal advancement. This can mean blowing the whistle on powerful stakeholders, accepting the possibility of career setbacks, or simply shouldering the emotional burden of being the “corporate conscience.” The DOJ expects companies to empower CCOs with the independence to act—because true expertise includes the courage to make sacrifices for the greater good.

What should you do now? Ask not only whether your CCO is capable, but whether they are willing to accept the risks of leadership. Expertise means prioritizing the mission even when the cost is high.

Lesson 5: Teaching and Transforming: The CCO as Culture Carrier

Illustrated by: By the episode’s conclusion, Gem is transformed by the example set by the Enterprise crew. She learns to act, not just to feel, demonstrating that real change comes from both internalizing values and taking decisive action.

Compliance Lesson. A CCO’s expertise is measured not only in what they know but also in how effectively they teach, mentor, and shape the organization’s culture. Just as Gem evolved through the guidance of Kirk and McCoy, so too must a CCO help others grow, empowering managers, employees, and even Board members to become stewards of compliance. Expertise is contagious: a strong CCO leaves a legacy of ethical leadership throughout the enterprise.

What should you do now?

Does your CCO inspire others to act with integrity? Are they a “culture carrier,” modeling the behaviors and values they wish to see at every level? True expertise is reflected in the transformation of others.

Final ComplianceLog Reflections

The Empath” reminds us that leadership in compliance, like leadership in the enterprise, requires more than technical skill. It requires empathy, courage, interdisciplinary knowledge, sacrifice, and the ability to teach and inspire. The DOJ’s Hallmarks of an Effective Compliance Program make it clear: a CCO must have the appropriate expertise to do the job, and that expertise is as much about the heart as the head.

In evaluating, supporting, or stepping into the CCO role, remember Gem’s journey. The greatest expertise lies not only in knowing the rules but in living them and in helping others do the same, especially when the path is hard. Empathic leadership is not a luxury; it is a requirement for building compliance programs that endure.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha