Categories
Blog

Setting the Right Ambition for Your Compliance Strategic Plan

A compliance strategic plan should explain how the function will build the capabilities the business needs to manage its risks. That requires choices about priorities, resources, authority, and execution. A plan can fall short by asking the organization for too little. It can also promise more than the company is prepared to support.

Consider a CCO preparing a three-year plan while the company expands through acquisitions and new distribution channels. The proposed compliance plan calls for refreshed policies, additional training, and a new monitoring platform. Each initiative may be useful. But does the plan address the integration gaps and third-party decisions that expansion will create? And has anyone committed the people, data, and funding needed to deliver it?

Rebecca Knight explores the calibration of strategic ambition in “Is Your Strategic Plan Too Ambitious? Or Not Ambitious Enough? In the Harvard Business Review. Her article draws on insights from Columbia Business School’s Sheena Iyengar and MIT Sloan School of Management’s Donald Sull. Their discussion provides a useful foundation for examining the compliance function’s strategy. The compliance applications below build on that discussion.

Define the Problem Before Setting the Target

Knight begins with Iyengar’s advice to identify the problem a strategy must solve before debating the ambition of its targets. For CCOs, this discipline matters because familiar deliverables can substitute for a clear diagnosis. Take a goal to increase training hours. What problem requires that increase? Employees may misunderstand an approval requirement. They may understand it perfectly but lack a workable way to obtain approval before a commercial deadline. Those conditions require different responses.

The strategic plan should connect each major initiative to an identified weakness or emerging business need. If acquisitions repeatedly leave the company with incomplete third-party records, define the intended capability: an integration process that establishes ownership, identifies missing information, and escalates unresolved risks within a specified period. This gives management a concrete outcome to fund and the board a meaningful basis for oversight.

Develop Alternatives Before Committing Resources

Knight reports Iyengar’s recommendation to consider several distinct approaches so leaders can see their trade-offs. A CCO can apply this by requiring alternatives for the plan’s largest investments. Suppose the objective is better third-party monitoring. One option might strengthen existing reviews and accountability. Another might integrate procurement and payment data. A broader approach might redesign the third-party lifecycle, including who can engage an intermediary and what evidence permits renewal.

Compare the options against the actual problem, implementation demands, and expected improvement. A technology purchase may be appropriate, but its value depends on the process and information supporting it. This exercise also exposes insufficient ambition. If every option preserves the same fragmented ownership that created the problem, the CCO has reason to question whether the proposed change goes far enough. A major redesign also needs stronger justification than an attractive vision of a fully integrated program.

Make Resource Commitments Explicit

Sull’s resource argument, as Knight presents it, is that substantial strategic change can require moving money and talent away from existing commitments. That has direct implications for compliance planning. CCOs often describe new responsibilities without specifying which existing activities will change. A team already handling investigations, advice, training, and monitoring cannot absorb unlimited transformation work simply because the strategic plan assigns it a deadline.

For each major initiative, identify the required budget, expertise, business participation, and implementation time. Explain what can be simplified or discontinued and what must remain protected. Required controls and essential response capacity need explicit provision during the transition.

Dependencies deserve the same attention as the compliance budget. If success requires information technology support, procurement process changes, or finance data, obtain named owners and documented commitments. Where a critical commitment is missing, describe the resulting limitation in the proposal presented to leadership. Your board should be able to see the relationship between the approved ambition and the resources management has committed.

Build Capability Around the Business Strategy

Knight’s discussion of staffing emphasizes the expertise needed to execute a bold plan. Applied to compliance, the question extends beyond headcount to the capabilities the company’s direction requires. Acquisition-led growth may require stronger integration management. Expansion through distributors may require regional knowledge and commercial experience. A monitoring initiative may require data analysis, systems access, and people who understand how transactions occur.

Map the company’s major strategic moves to their compliance implications, then identify the skills and authority needed to respond. This helps the CCO explain why the function needs particular capabilities and when those capabilities must be available. Business alignment also requires independence of judgment. The plan should enable informed decisions about growth while preserving the CCO’s ability to challenge unsupported assumptions, escalate concerns, and identify conditions that should be met before proceeding. Management owns the commercial strategy; compliance must be equipped to assess and address its implications.

Use Pilots With Clear Decision Rules

Knight describes experimentation as a way to pursue ambitious goals while learning through smaller steps. A compliance plan can use that approach to improve processes and build new capabilities. For example, a proposed monitoring method could begin in one business unit. Before launch, define the information required, the existing controls that remain in place, the people responsible for reviewing results, and the conditions for expansion or revision.

The pilot should answer a specific question. Does the method identify relevant exceptions? Can the business resolve them? Are the results dependable enough to support decisions? A successful software demonstration alone does not answer those questions. Set a review date and a decision owner. Without those commitments, a pilot can continue indefinitely, consuming resources while providing little clarity about whether the broader strategic objective is achievable.

Measure Progress Toward a Working Capability

Knight connects a longer strategic horizon with measurable interim progress. This is particularly useful for compliance improvements that require changes across functions and systems. A multi-year goal to improve acquisition integration could include quarterly milestones for establishing ownership, validating acquired third-party records, addressing priority exceptions, and testing whether the revised process works on a subsequent acquisition.

Select measures that reveal both implementation and performance. Completing a procedure establishes that something was produced. Evidence that business teams use it, resolve exceptions, and escalate overdue actions helps show whether the capability is functioning.

Establish a baseline before claiming improvement. Faster review times need context about review quality. Fewer exceptions need context about detection coverage. Report limitations alongside results so management and directors can distinguish progress from incomplete information. The strategic plan should also specify when it will revisit assumptions. A major acquisition, a new business model, or a material change in available resources may require revised priorities and sequencing.

Give the Board Decisions It Can Assess

Board oversight becomes more useful when the CCO presents the choices behind the plan. Directors need to understand the priority problems, the proposed response, the resource commitments, and the consequences of delay.

A practical strategy discussion should explain what the function expects to accomplish, what depends on other executives, and what remains outside the funded scope. Where alternatives exist, show their implications for timing and capability. This gives the board a basis to challenge both overpromises and underinvestment. It also establishes what management should report back as the plan proceeds.

Action Steps for the CCO

Use the next planning review to test whether ambition and execution are aligned:

  1. Define the priority problems. State the business risk or capability gap behind each major initiative and the evidence supporting its priority.
  2. Compare credible alternatives. Examine different ways to achieve the intended outcome, including their costs, dependencies, and implementation demands.
  3. Secure resource commitments. Identify accountable business partners, required expertise, funding, and the activities that must change to make room for execution.
  4. Set milestones and decision points. Establish baselines, measures, pilot criteria, and dates for reassessing assumptions.
  5. Present the choices to the board. Explain the funded scope, unresolved dependencies, and consequences of deferring priority capabilities.

A sound compliance strategy makes a demanding but supportable commitment to improving how the company manages risk. The CCO’s responsibility is to make that commitment specific enough to execute, measure, and oversee.

Categories
Blog

When Employees Rationalize Misconduct: What CCOs Need to Change

A sales manager needs one more transaction to meet the quarterly target. The customer has not completed the required approvals, but the manager believes the paperwork will arrive tomorrow. Booking the sale today will protect the team’s bonus and keep the regional president satisfied. The manager tells herself that the transaction is real, the delay is administrative, and nobody will be harmed.

This hypothetical illustrates a problem every chief compliance officer should consider. An employee can understand a rule and still construct a convincing reason to disregard it. The compliance challenge includes recognizing the reasoning that makes a violation feel acceptable before the employee acts.

Todd Haugh examined that challenge in The Trouble With Corporate Compliance Programs, published in the Fall 2017 issue of MIT Sloan Management Review. Drawing on behavioral ethics and criminology, Haugh argued that compliance programs need to address how employees make ethical decisions and rationalize misconduct. His analysis laid the foundation for this discussion; the operational recommendations I adapted from his article apply that perspective to the CCO’s work.

Examine the Decision Behind the Violation

Compliance professionals devote substantial attention to policies, training, approvals, and investigations. Each has a role. Yet a completed training course tells us relatively little about how an employee will respond when a supervisor demands a result that appears impossible to achieve within the rules.

Haugh’s central contribution was treating rationalization as something that can precede misconduct and help enable it. (The same is true in the Fraud Triangle.) Drawing on criminological research, including Donald Cressey’s work, Haugh explained how people can make a breach of trust seem consistent with their view of themselves as good people.

For the CCO, this changes the inquiry. Alongside asking whether an employee knew the rule, ask what made bypassing it appear reasonable. Was the employee protecting a colleague? Responding to a threat of dismissal? Following a practice that managers had repeatedly accepted? Those questions can reveal weaknesses in supervision, incentives, escalation, and accountability. They also help explain why repeating the policy may leave the conditions behind a violation intact.

Recognize the Language of Rationalization

Haugh identified eight common rationalizations: denying responsibility, denying injury, denying the victim, condemning the condemners, appealing to higher loyalties, using a ledger metaphor, claiming entitlement, and claiming relative acceptability or normality.

Several relate directly to daily compliance work. An employee who says a supervisor left no choice may be denying responsibility. Someone who minimizes the consequences of an inaccurate record may be denying injury. A manager who defends a questionable payment as necessary to protect the business may be appealing to higher loyalties. An executive who invokes years of excellent performance to excuse a violation may be treating past contributions as credits against present misconduct.

The practical value of these categories lies in the questions they generate. When someone defends a practice as common across the industry, the CCO should explore how the company evaluates that practice and who has approved it. When loyalty to the business becomes the explanation, ask which business interest the conduct actually serves and what risks it creates.

Such statements warrant inquiry. They do not, by themselves, establish misconduct. A useful discussion must leave room for employees to describe pressure, uncertainty, and disagreement candidly.

Put Business Pressure Within the Compliance Review

Haugh discussed Wells Fargo’s sales practices as an example of how organizational pressure can overwhelm formal ethics messaging. In Haugh’s view, aggressive sales expectations helped create an environment in which employees could rationalize improper behavior despite instructions against it. The broader lesson for CCOs is to examine the operating conditions surrounding a control. A policy requiring approval has limited practical support if management consistently rewards employees who bypass the process to deliver faster results.

Consider a third-party onboarding process. The written procedure requires due diligence before engagement. The business promises the intermediary an immediate start date, procurement receives the request late, and the responsible employee is evaluated on speed. Compliance then encounters an urgent request for an exception.

The proposed response should reach beyond that individual exception. Who committed the company before review? Why did the planning process omit the approval period? Does management treat compliance review as part of the transaction schedule? Repeated urgency deserves examination as a management practice. The CCO should bring those findings to the business owner with a concrete correction, an accountable executive, and a timetable.

Practice the Conversation Employees Need to Have

Haugh recommended discussion and storytelling to help employees recognize rationalizations. This approach gives compliance training a useful operational purpose: rehearsing the conversation that must occur when commercial pressure and an ethical obligation collide. Use a scenario drawn from your organization’s actual work, with identifying details removed where necessary. Ask participants to explain the pressure, identify the affected parties, describe the proposed justification, and decide how they would respond. Then require a practical answer. Whom would the employee contact? Can the transaction pause? Who can authorize an alternative? What should the employee say to a manager who insists on proceeding?

Managers should participate because their response determines whether the proposed solution is credible. If the training encourages escalation but the supervisor treats questions as disloyalty, the employee receives conflicting instructions. The CCO can use these sessions to identify unclear responsibilities and impractical procedures. Training becomes a source of information about how work gets done, as well as an opportunity to explain expectations.

Connect Incentives and Accountability

Haugh also emphasized incentives and organizational culture. For compliance practitioners, the application is direct: examine the behaviors that receive recognition, promotion, and protection. A company may praise integrity while celebrating a commercial result without asking how it was achieved. A high performer may receive repeated exceptions unavailable to others. Employees can reasonably interpret those decisions as evidence of management’s priorities.

The CCO should work with human resources and business leadership to incorporate performance metrics into evaluations. Relevant evidence might include how a manager responds to concerns, handles approval requirements, and corrects recurring control failures. Recognition also has a role. With appropriate confidentiality, leadership can acknowledge a team that raised a concern early or found an acceptable way to complete a difficult transaction. The explanation should make it clear that the conduct is worth repeating.

Accountability must extend to supervisors whose instructions or tolerated practices contributed to a problem. Otherwise, remediation may remove an employee while preserving the management behavior that shaped the decision.

Give the Board Evidence About Behavior

Board reporting should help directors understand whether the program influences business decisions. Training completion and policy certifications provide useful coverage information. They need context from the company’s operating experience. A CCO might report recurring reasons for approval exceptions, examples of management responses to escalation, or repeated control failures concentrated within a business unit. Such information can help directors question whether performance expectations and compliance obligations are aligned.

Interpretation matters. More reported concerns could reflect greater trust in the reporting process. Fewer exceptions could reflect better planning or a failure to record deviations. Explain the evidence, its limitations, and the follow-up needed before presenting a conclusion about effectiveness.

Action Steps for the CCO

Haugh’s article challenged compliance leaders to take employee decision-making seriously. Turn that insight into a focused review:

  1. Review a sample of closed matters. Identify the justifications employees offered, the pressures they described, and management’s role. Look for recurring conditions across cases.
  2. Examine one business process. Select a process with frequent exceptions or urgent approvals. Determine where planning, incentives, or unclear authority encourage employees to bypass requirements.
  3. Run a manager-led scenario discussion. Practice recognizing rationalizations and responding to pressure. Record procedural gaps that prevent employees from taking the expected action.
  4. Assign corrective actions to business owners. Address the underlying workflow or management practice, with deadlines and evidence of completion.
  5. Report what changed. Show senior management and the board how the intervention affected decisions, exceptions, or recurring issues. Distinguish observed improvement from conclusions that still require evidence.

The CCO’s task is to make ethical conduct workable under the conditions employees actually face. That requires understanding the justifications for misconduct and changing the business practices that give those justifications force.

Categories
Blog

Odyssey Week: Leadership – Athena in the Boardroom: Independent Oversight and Counsel

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Zendaya was great as Athena.

Athena does not row the ship. She does not lash herself to the mast, fight the Cyclops, navigate Scylla and Charybdis, or drag Odysseus’s crew away from every bad decision they seem determined to make. She is not in the trenches every day. She does not submit expense reports, approve vendors, review discount requests, or sit through the quarterly business review where someone explains why this deal is “strategic.” But Athena changes the journey.

She sees what Odysseus cannot see. She warns. She guides. She challenges. She protects. She appears at decisive moments when courage alone is not enough, and cleverness is about to become self-harm with better branding. That is why Athena belongs in the boardroom.

For corporate compliance, Athena represents independent oversight and wise counsel: the person, function, or governance body able to say, “That may win the deal, but it may also wreck the kingdom.” A compliance function that cannot challenge leadership is not Athena. Rather, it is simply decoration to meet a legal, statutory, or contractual requirement.

The Corporate Translation

Every company says it values compliance independence. The question is what that means when the business wants something. It is easy to celebrate compliance when compliance supports the decision already made. It is easy to invite the Chief Compliance Officer (CCO) to the meeting after the deal is signed, the press release is drafted, and the train has left the station with several questionable third parties in the dining car. That is not independence. That is archaeology.

Independent oversight means compliance has the authority, access, and resources to influence decisions before risk is accepted. It means the board hears directly from compliance. It means escalation does not depend on whether a business leader feels emotionally prepared for bad news. It means compliance can challenge high performers, powerful executives, and sacred business strategies without being treated as disloyal.

Athena does not exist to admire Odysseus. She exists to help him survive himself.

Access Is Not the Same as Influence

Many compliance officers technically have access to leadership. They attend meetings. They submit reports. They provide updates. They own several slides in the board deck, usually after cybersecurity and before “other business.” But access is not the same as influence.

Real access means compliance can raise concerns in a setting where they matter. It means there are private sessions with the board or audit committee. It means compliance can speak without management filtering, softening, or translating the message into something more comfortable. It means the board asks questions that go beyond “Any major issues?” which is the governance equivalent of asking a teenager whether school was fine.

The DOJ’s 2024 Evaluation of Corporate Compliance Programs (ECCP) focuses directly on whether compliance and control functions have autonomy and resources, including sufficient stature, sufficient staffing and resources, and autonomy from management, such as direct access to the board or audit committee. That is not a technical footnote. It is a central governance point. If the compliance function only reaches the board through management, the board may be hearing the music after someone else has adjusted the volume.

Authority Must Be Real

A compliance function without authority is like Athena without wisdom: impressive in name only. Authority means compliance can stop, modify, or escalate a transaction. It means policies are not optional when revenue is large enough. It means compliance concerns are documented, tracked, and resolved. It means the business must explain why it wants to proceed despite risk, not merely pressure compliance to “be practical.”

Practical compliance is not weak compliance. Practical compliance helps the business find a lawful and ethical path forward. But there is a difference between being practical and being domesticated. A good compliance function does not say no for sport. It says no when the facts, risks, and values of the company require it. It says, “not that way.” It says, “not with that intermediary.” It says, “not without diligence.” It says, “not until we understand the data, the customer, the payment, the conflict, or the control failure.”

The ECCP specifically asks how a company has responded when compliance raised concerns and whether transactions or deals have been stopped, modified, or further scrutinized because of compliance concerns. That is the right question. The ECCP states at one point, “Have they persisted in that commitment in the face of competing interests or business objectives?” Not whether compliance attended the meeting. Whether compliance changed the outcome. The ECCP further asked, “What role has compliance played in the company’s strategic and operational decisions? How has the company responded to specific instances where compliance raised concerns? Have some transactions or deals been stopped, modified, or further scrutinized as a result of compliance concerns?”

Resources Are a Statement of Values

Companies reveal what they value through budget. A board can praise compliance all day long. Still, if the function lacks staffing, technology, data access, training budget, investigative resources, and experienced personnel, the message is clear: “We support compliance, but preferably at a discount.”

No one would ask sales to grow revenue without systems, people, and market data. No one would ask finance to close the books with three spreadsheets, two interns, and a heroic attitude. Yet compliance teams are often expected to monitor global risk with underpowered tools and just enough headcount to keep the training completion dashboard from turning red.

That is not empowerment. That is wishful thinking. The ECCP asks whether compliance personnel have sufficient staffing to audit, document, analyze, and act on compliance efforts, whether resources are comparable to other parts of the company, and whether compliance has access to relevant data for timely monitoring and testing. Regarding funding and resources, the ECCP asks, “Has there been sufficient staffing for compliance personnel to effectively audit, document, analyze, and act on the results of the compliance efforts? Has the company allocated sufficient funds for the same? Have there been times when requests for resources by compliance and control functions have been denied, and if so, on what grounds? Does the company have a mechanism to measure the commercial value of investments in compliance and risk management?”

Those questions should make boards uncomfortable in a productive way. If the business has world-class tools to capture opportunity but outdated tools to detect risk, that imbalance is itself a governance decision.

Escalation: The Road from Concern to Action

Athena’s guidance matters because it reaches Odysseus when action is still possible. That is also the purpose of escalation. A well-designed escalation process moves concerns to the right people at the right time with enough information to make a decision. A weak escalation process traps concerns in email chains, local management reviews, or “let’s monitor this” limbo until the problem becomes a reportable event, a whistleblower complaint, or a headline.

Escalation should not depend on personality. It should not depend on whether the compliance officer is unusually persistent, politically skilled, or willing to become unpopular before breakfast. It should be built into governance.

What must be escalated? To whom? Within what timeframe? With what documentation? What happens when business and compliance disagree? Who decides? How are unresolved concerns reported to senior leadership or the board? These are not theoretical questions. They are the mechanics of wise counsel. Because without escalation, Athena is whispering in a locked room.

The Board’s Role: Ask Better Questions

Boards do not need to manage the compliance program day to day. That is not their role. But boards do need to oversee whether the program is real. That means asking better questions. The board should also pay attention to the moments when compliance loses. If compliance raised concerns and the business proceeded anyway, what happened? Was the decision documented? Were compensating controls added? Was the board informed? Did the risk later materialize? You learn a great deal about culture by examining what happens when wise counsel is inconvenient.

The Compliance Takeaway

Athena does not represent bureaucracy. She represents judgment. That distinction matters. Compliance officers are sometimes caricatured as the people who slow things down, complicate decisions, or drain the romance out of heroic commercial ambition. But the best compliance functions do something far more important: they help the organization see clearly before it acts.

They bring risk into the room. They challenge assumptions. They protect the company from cleverness without discipline. They help leaders understand that winning the deal, entering the market, launching the product, or pleasing the customer is not success if the path taken damages the company’s integrity.

Independent oversight is not ceremonial access. It is authority, resources, escalation, data, board engagement, and the organizational courage to let compliance challenge power. Odysseus needed Athena because brilliance has blind spots. So does every company.

The question is whether your Athena is truly in the boardroom or merely listed on the org chart.

Join us Tomorrow

Athena teaches that independent oversight is not ceremonial access but real authority, resources, escalation, data, board engagement, and the courage to let compliance challenge power. But that lesson only matters if the organization is willing to apply it to its most celebrated leaders, not merely its easiest targets. That brings us to Odysseus: the brilliant, strategic, results-driven leader every board wants and the very leader who can become the company’s most dangerous compliance risk when success becomes a shield. If Athena is the voice saying, “That may win the deal, but it may also wreck the kingdom,” Odysseus is the leader who wins the deal and forces the organization to ask whether anyone had the authority, courage, and independence to challenge how he did it. I hope you will join us tomorrow.

Categories
From the Editor's Desk

From the Editor’s Desk: Aaron Nicodemus on the August and September in Compliance Week

In this episode of ‘From the Editor’s Desk,’ Tom Fox visits with Compliance Week editor-in-chief Aaron Nicodemus to discuss highlights from Compliance Week in August, take a look at what is coming down the pike in September in Compliance Week, and discuss the upcoming Third Party Risk Management and Supply Chain Summit in Chicago.

Tom and Aaron review key August coverage and upcoming priorities. They discuss new columnist Ben Mason’s “The Hidden Cost of Compliance Leadership,” outlining five recurring burdens for compliance leaders: independence that is often only theoretical, job risk from doing the role properly (including survey findings that nearly 70% of compliance officers have experienced retaliation), inability to voice doubts internally, the invisibility of effective prevention work, and weak leadership support—creating isolation and prompting ideas for safe forums such as the vetted CW app and event roundtables. Nicodemus highlights his Mayo Clinic whistleblower story alleging AI use may endanger patient privacy and outpace internal guardrails. He also describes a National Conference “Practitioner’s Briefing” distilling six Chatham House themes, previews a September 1MDB case study on enablers, plans AI-governance essays for National Compliance Officers Day, and promotes the Oct. 28–29 Chicago TPRM Summit.

Resources:

Aaron Nicodemus on LinkedIn

Compliance Week

Third Party Risk Management and Supply Chain Summit

Categories
Blog

Dolly Parton and the Compliance Value of a Life Well Governed

Dolly Parton died this week. Her death closed one of the most remarkable careers in American entertainment, but it did not close the institutions, ideas, and expectations she built. For corporate compliance professionals, that durability is what makes her story more than a tribute. It becomes a lesson in how values can be converted into governance. Today I want to honor Parton, what she did, and what she stood for, and perhaps hope that her life will inspire all of us to be just a little better.

Parton was one of twelve children. Parton began singing on local radio and television as a child and appeared at the Grand Ole Opry at thirteen. She wrote her first song at age 6. She moved to Nashville after high school, established herself as a songwriter, and became a national star through The Porter Wagoner Show. She then built a solo career that crossed country, pop, film, television, theater, publishing, tourism, and philanthropy. She recorded more than fifty albums, wrote roughly 3,000 songs, won ten Grammy Awards, and created works such as “Jolene,” “I Will Always Love You,” and “9 to 5” that became part of the American vocabulary. One of the most amazing facts I learned while researching this piece was that “Jolene” and “I Will Always Love You” were written on the same day. How is that for creative inspiration?

Parton did not run a corporate compliance program, and her career should not be forced into that frame. Yet she demonstrated something every CCO and Board of Directors needs to understand: culture becomes credible when stated values, hard decisions, operating systems, and visible conduct reinforce one another over time. Her public identity rested on kindness, independence, dignity, humor, and respect. She repeatedly made those commitments tangible in contracts, businesses, philanthropy, and crisis response.

Her entrepreneurship deserves equal attention. Parton moved from performer to owner, producer, publisher, and partner, most visibly through Dollywood and the enterprises built around it. The portfolio was diverse, but it was not random. Music, storytelling, family entertainment, Appalachian identity, hospitality, and community investment all reinforced a coherent promise. Compliance professionals should recognize the governance advantage of that clarity. Diversification creates new legal, operational, third-party, and reputational risks, but a stable purpose helps leaders decide which opportunities fit, which controls must travel with the business, and which deals to decline.

Independence Before Applause

Parton understood the difference between access to power and surrender to it. She left Porter Wagoner in 1974 to build an independent career, expressing gratitude for the partnership without allowing it to define her future. She later declined an opportunity for Elvis Presley to record “I Will Always Love You” when his manager demanded a share of the publishing rights—saying no cost her an extraordinary short-term opportunity. Retaining ownership preserved the long-term value of her work, especially when Whitney Houston’s recording became a worldwide success. Business Insider called it “her smartest business move.”

That decision should resonate with compliance leaders. Independence is not a paragraph in a charter. It is the authority to resist pressure when revenue, status, or a powerful executive makes acquiescence attractive. A CCO needs direct access to the board, control over investigative escalation, sufficient resources, and protection against retaliation. Chuck Watson once said, “Sometimes the best deal is the one you don’t make.” A board should test whether that independence works when it is expensive, inconvenient, and unpopular. If compliance can say no only when nothing important is at stake, it is not independent.

Purpose Made Operational

Parton’s philanthropy offers an equally powerful lesson in program effectiveness. She created the Dollywood Foundation in 1988 to improve educational outcomes in her home county. Its Buddy Program paired students and offered a financial incentive for graduation; the dropout rate for the participating classes fell from 35 percent to 6 percent. In 1995, inspired by her father’s inability to read and write, she launched the Imagination Library. What began in Sevier County became a network operating across five countries that has delivered more than 300 million free books to young children.

This was not the purpose of branding. It was purpose translated into a defined population, a repeatable delivery model, local partnerships, funding, data, and measurable results. That is the same transition the Department of Justice asks companies to make when it evaluates whether a compliance program is well designed, adequately resourced, and working in practice. A value in the code of conduct must become an owner, a control, an escalation path, testing, and remediation. Intent is the beginning of a compliance program, not proof of one.

Listen to the People Who Experience Power

Parton’s film and song “9 to 5” gave popular form to workplace realities many employees already knew: power can be abused, unfairness can become routine, and people with the least authority often carry the greatest burden. The song endured because it recognized the lived experience behind organizational charts. It made a workplace issue visible without turning the people affected into abstractions.

Compliance programs fail when they listen only upward. Hotline statistics, exit interviews, culture surveys, investigation themes, retaliation allegations, and manager-level trends must reach leaders in a form that supports action. Boards should ask whether employees believe they can speak without losing status, opportunity, or employment. They should also ask whether the organization learns from weak signals before they become red flags. A speak-up system is not effective because a telephone number exists. It is effective when people trust the process and see consistent, fair outcomes.

Trust Earned Through Response

Parton’s businesses remained closely connected to the community that formed her. Dollywood became Sevier County’s largest employer, while its stated operating culture emphasizes hospitality, authenticity, collaboration, and respect. The company supports employee development, including tuition assistance. When wildfires devastated East Tennessee, Parton helped organize direct support for affected families. During the COVID-19 pandemic, her $1 million gift established a Vanderbilt research fund that supported work connected to the Moderna vaccine.

The compliance lesson is that reputation is a lagging indicator of accumulated conduct. Trust is built before a crisis through thousands of ordinary decisions about employees, customers, communities, and counterparties. A crisis tests it through the speed, fairness, transparency, and competence of the response. A company cannot purchase credibility with a campaign after years of contrary conduct. The best crisis communication remains a well-governed response supported by facts, accountable owners, and visible follow-through.

A Board Agenda Worthy of the Lesson

Parton’s legacy was unusually broad, but its organizing logic was simple. Know what matters. Protect it when pressure arrives. Build systems that carry values beyond the founder. Listen to people whose voices are easiest to overlook. Measure whether the work changes outcomes. Repeat the conduct long enough that stakeholders can rely on it.

  • For directors, that logic produces five practical questions. What principles will the company not trade away for a transaction or quarterly target?
  • Does the CCO possess real independence, resources, information, and access?
  • Which data prove that stated values operate at the employee and third-party level?
  • Are speak-up and investigation systems producing trust, learning, and remediation?
  • When the company faces a crisis, can the board see decisions, owners, deadlines, testing, and closure rather than a record showing only that management made a presentation?

Dolly Parton understood that a carefully created image can open a door, but only character and performance can keep it open for seven decades. Compliance leaders often describe their goal as building a culture of integrity. Her career reminds us what that requires: independent judgment, operational discipline, attention to the less powerful, measurable impact, and consistency when no applause is guaranteed. That is not only a fitting business lesson from her life; it is a demanding standard for every organization that wants to be trusted.

Categories
Blog

From Gatekeeper to Navigator: Dr. Hemma Lomax on the Decision Intelligence Gap

Compliance failures are usually narrated backward. Once the outcome is known, every warning appears obvious, every missed escalation looks negligent, and every decision seems to point toward the result. The board asks who knew what and when. The investigation searches for the broken control. Management wants the person or moment that explains the failure.

Dr. Hemma Lomax has done it again, leading the discussion in the compliance community. Her most recent book, The Decision Intelligence Gap, asks compliance professionals to look earlier. What happened before the decision became visible? Which assumptions hardened into facts? When did reversal become more expensive? Who noticed something that never gained enough purchase to change the direction? The book’s central insight is that the distance between intention and execution is not space. It is an operating environment shaped by incentives, defaults, authority, silence, pressure, and the accumulated residue of earlier decisions.

That makes this an important book for CCOs, boards, in-house counsel, audit, risk, and business leaders. It is not a conventional compliance manual. It does not provide a new risk taxonomy or a checklist for program design. It offers something more foundational: a way to examine how organizational choices form while there is still time to influence them.

A Book About the Decisions Before the Decision

Lomax defines the Decision Intelligence Gap in two related ways. It is the distance between the responsibility people carry for decisions and the visibility they have into how those decisions form. It is also the space between intention and execution, where choice remains alive. The book develops that idea across five parts: how choice narrows, how decision architecture changes what remains possible, how leaders can redesign the environment, how organizations should respond when things go wrong, and how learning can scale.

The governing image is the trolley problem viewed upstream. Compliance professionals know the familiar last-minute choice between two unacceptable outcomes. Lomax is more interested in what happened before anyone reached the lever. Who laid the track? When did the brakes become unavailable? Which earlier choices reduced the available paths? This move from moral drama to decision architecture is the book’s most valuable contribution.

Several concepts give that architecture practical shape. The silent hijack occurs when a concern is heard but never alters the decision. The threshold paradox describes the point at which an option remains technically open but becomes materially more costly to exercise. Designed desperation arises when the system makes the wrong choice easier, safer, or more serviceable than the right one. Defaults then carry yesterday’s decisions forward until repetition begins to look like legitimacy. None of these concepts removes individual agency. They show why accountability must examine both the actor and the conditions the organization created.

Why Compliance Leaders Should Read It

The book challenges the compliance function’s instinct to become the gatekeeper for every uncertain choice. Lomax does not argue against approvals, bright lines, or specialist authority. Some risks require them. Her sharper point is that a program can become excellent at routing questions to experts while failing to build decision capacity in the business. The CCO answers the immediate question, but the next employee facing similar terrain remains dependent on the same escalation.

Lomax proposes a navigation layer instead. Expertise should travel without automatically taking ownership of the decision. Employees need to understand the objective, the boundary being protected, the conditions that change the answer, the discretion that remains local, and the threshold for seeking another perspective. This is a powerful description of compliance as a business discipline. It moves the function from permission provider to designer of better choices while preserving hard stops where the risk requires them.

Her discussion of speak-up culture is equally strong. The important question is not only whether employees are permitted to report. It is what speaking has come to require and what happens when the room responds. A concern may be incomplete, inconvenient, or wrong. If the first response demands a finished case, the organization may force one employee to do the collective work of noticing, investigating, proving, and solving before the signal deserves attention. Lomax’s idea of being safe to learn goes beyond psychological safety. It asks whether people can contribute uncertainty, revise a position, or discover they were wrong without losing the standing to participate next time.

This insight should reshape investigations. A bad outcome does not prove poor reasoning, and a good outcome does not validate the process that produced it. Lomax’s account of outcome bias provides a disciplined basis for distinguishing accepted risk, ordinary mistake, flawed reasoning, reckless conduct, concealment, and misconduct. The compliance lesson is straightforward: reconstruct the information state at the time of the decision before hindsight rewrites what was knowable. Accountability then becomes more precise, more credible, and more useful to the next decision.

Lomax’s architecture also sharpens the familiar effectiveness question. A policy may be well designed on paper yet fail because the decision environment rewards delay, makes escalation costly, or teaches employees that exceptions are easier to approve than to revisit. Monitoring should therefore test not only control completion but also control use: who bypasses, who escalates, which questions recur, where decisions stall, and whether learning from one matter changes the next. This is where the book connects most directly to modern compliance evaluation.

The Most Useful Tool: HQDM

The book’s most immediately deployable framework is High-Quality Decision Making, or HQDM. It records five elements in proportion to the significance of the choice: the objective and what the organization is actually optimizing for; the thresholds that materially change the answer; the options genuinely available at the time; the rationale connecting facts, assumptions, uncertainty, and choice; and the learning plan, including what to monitor and what would trigger reconsideration.

For compliance professionals, HQDM offers a practical bridge between governance and evidence. It can improve a third-party exception, an AI use-case approval, an investigation disclosure decision, a market-entry choice, or a board risk-acceptance decision. It also creates a contemporaneous reasoning trace that can later help separate a defensible decision from one that merely benefited from luck. Lomax wisely cautions against turning inspectability into surveillance. The record should preserve decision-useful reasoning, not every tentative thought.

The framework also fits the board’s oversight role. A board cannot manage every operating decision. Still, it can ask whether management has identified the objective, made critical assumptions visible, established escalation thresholds, considered viable alternatives, and defined the conditions for returning to the decision. That is a better oversight record than a slide showing that the policy was approved and the training was completed.

Where the Book Requires Compliance Translation

The Decision Intelligence Gap is intentionally a thinking book, not an implementation guide. Its metaphors are memorable, its research base is broad, and its questions are often excellent. Yet compliance teams will still need to convert those ideas into governance mechanisms, owners, data, testing, and metrics. The book explains why a navigation layer matters, but it does not provide a detailed operating model for building one across a global enterprise.

The same issue appears with decision traces. The concept is sound, but the compliance application requires careful design. Records can create discovery, privilege, privacy, retention, and employee-relations consequences. A proportionate trace needs risk tiers, approved fields, access controls, retention rules, legal-hold integration, and guidance on what not to record. Otherwise, a tool intended to make reasoning visible may produce defensive writing or concealment.

AI adds another layer. Lomax correctly warns that putting a human in the loop is meaningless if the human merely approves the system’s preferred answer. A true navigation layer should expose sources, assumptions, uncertainty, alternatives, and override routes. Compliance leaders will need to add the control architecture: data governance, access management, validation, bias testing, monitoring, audit logs, incident response, and clear human accountability. NIST AI RMF and ISO/IEC 42001 can help operationalize that part of the vision.

The Verdict

This is a thoughtful, humane, and unusually relevant book for the compliance profession. Its strength lies in refusing the easy choice between individual blame and system excuse. People retain agency, but they exercise it inside conditions that can make signals harder to share, boundaries harder to hold, and reversals harder to justify. Effective compliance must examine both.

CCOs should read The Decision Intelligence Gap not as a substitute for the DOJ’s Evaluation of Corporate Compliance Programs, COSO, investigations protocols, or AI governance frameworks, but as a connective operating philosophy. It explains why policies can be clear while decisions remain poor and why speak-up programs can be available. At the same time, silence persists, and why lessons learned can be documented while organizational capability barely grows. It is especially valuable for compliance leaders ready to move from owning answers to building an organization that decides, learns, and adapts with integrity.

Questions for CCOs and Boards

Decision visibility. Which high-risk choices are becoming expensive to reverse before they reach formal approval?

Speak-up response. What does the organization do with an unfinished concern, and what does that response teach the next employee?

Accountability. Can investigations distinguish a bad outcome from poor reasoning and a mistake from misconduct without losing either fairness or rigor?

Learning loop. Where do investigation findings, exceptions, overrides, and near misses change the conditions of the next decision?

Navigation. Is compliance increasing the business’s capacity to recognize thresholds and exercise sound judgment, or merely increasing the number of questions routed to Compliance?

Categories
Blog

Private Company, Public Risk: Building Defensible AI Governance Before the Rules Arrive

For private companies, the central question about artificial intelligence is no longer whether the technology is in the business. It is whether anyone can explain where it is, what it does, what data it touches, and who is accountable when it fails.

That is the warning in “AI Governance for Private Companies,” by Hillary Flynn, Drew Morales, and Courtney Hugger of Wellington Management, which was recently posted in the Harvard Law School Forum on Corporate Governance. The authors report that nearly three in four companies plan to deploy agentic AI within two years, while only one in five has a mature governance model for autonomous agents. That is not merely a technology gap. It is a governance gap.

Private ownership does not make AI risk private. The consequences arrive through customers, employees, regulators, investors, lenders, insurers, and business partners. A company may not yet face a single comprehensive AI law, but it can still face a privacy complaint, contract dispute, cyber incident, customer loss, or damaged valuation. For compliance professionals, governance should precede scale.

Private Does Not Mean Exempt

Private companies are moving quickly because AI can increase productivity, improve customer service, accelerate analysis, support coding, and help a growing company scale. The article also identifies a critical lesson from Wellington’s portfolio companies: the largest barriers are often organizational, not technical. Companies making the strongest progress combine AI investment with employee training, clear governance, and defined expectations.

This is where the Chief Compliance Officer can reframe the discussion. AI governance is the discipline that allows useful experimentation without unmanaged legal and business exposure. The goal is not a thick policy on a shared drive. The goal is an operating system for accountable decisions.

The European Union AI Act is being implemented in phases through 2027, with expectations around transparency, human oversight, documentation, risk management, monitoring, and AI literacy. In the United States, NIST guidance, ISO standards, sector rules, state laws, and customer requirements are shaping expectations, even without a federal AI statute. A private company can therefore face AI governance demands through a contract or transaction long before a regulator knocks on the door.

Begin With the Business Objective

One of the article’s strongest recommendations is also one of the simplest: start with the business problem, not the AI tool. This is precisely what Carl Hahn has consistently maintained: always ask, “What is the Business Value?”Teams should define the desired outcome before selecting a model or vendor. Is it lower cost, faster response, better quality, increased revenue, fewer errors, or reduced risk?

Governance cannot evaluate an undefined promise. A measurable objective gives management a basis for deciding whether the use case works and whether its benefits justify its risks. It also creates stopping rules. Approval should identify what failure, customer impact, control breakdown, or scope change will trigger redesign, escalation, suspension, or retirement.

Compliance should insist on this discipline, particularly when an AI use case affects payments, eligibility, claims, pricing, employment, healthcare, education, financial products, or customer communications. Those are not ordinary software deployments. They are decisions and interactions with consequences for real people.

Inventory First, Then Tier the Risk

A company cannot govern what it cannot see. The foundation is an inventory of models, vendors, internal tools, embedded features, customer-facing systems, employee-built applications, and known shadow AI. It does not need to be perfect. It needs an owner, an update process, and enough information to support risk decisions.

Each use case should then be placed into a risk tier. Relevant factors include data sensitivity, degree of autonomy, importance of the business process, impact on customers or employees, regulatory exposure, ability to explain the result, and ease of reversing an error. Low-risk uses can follow a streamlined path. High-impact uses should receive enhanced testing, documented approval, human oversight, monitoring, and senior-level escalation.

Risk tiering prevents two failures. Treating every use as equally dangerous overwhelms review and encourages employees to route around it. Treating every use as ordinary technology leaves consequential applications without meaningful controls. Good governance applies greater rigor where potential harm is greater.

Put a Name Next to the Risk

Every AI system should have a business owner who remains accountable for its outcome. Accountability cannot be delegated to the model, the data science team, or the vendor. The owner should understand the intended purpose, approved users, permitted data, performance standard, escalation route, and circumstances under which the system must be paused.

Higher-risk applications should receive cross-functional review involving the business, product, engineering, legal, compliance, privacy, cybersecurity, procurement, and risk functions. This does not require a new bureaucracy. It requires a repeatable process with recorded approvals and clear responsibility.

Agentic AI raises the stakes because the risk moves from a wrong answer to a wrong action. Permissions should be limited, high-stakes actions should require human approval, and activity should be logged. Test override and shutdown mechanisms. The chatbot manipulated into agreeing to sell a vehicle for one dollar shows how weak boundaries turn a novelty into an operational event.

Treat Vendors as Part of the System

Most private companies will rely on external models, platforms, and software. That makes AI governance inseparable from third-party risk management. Traditional security questionnaires are not enough. Diligence should address how vendors use data, whether customer data trains models, how model changes are communicated, what transparency is available, how performance is tested, who bears liability, and whether data and workflows can be moved if the relationship ends.

The company should monitor model updates, service degradation, changes in terms, and features that expand access or autonomy. A tool approved for summarization should not silently become authorized to send messages, approve transactions, or alter customer records.

Monitor the System in Practice

AI governance does not end at approval. Model updates, new data, and user behavior can alter performance. Companies should monitor accuracy, reliability, bias, drift, misuse, repeated failures, and customer impact. An incident protocol should define how to pause the system, preserve evidence, escalate, remediate harm, and communicate with affected stakeholders.

This is where AI governance meets familiar compliance principles. The DOJ’s Evaluation of Corporate Compliance Programs asks whether a program works in practice. COSO emphasizes control activities, information, monitoring, and accountability. NIST’s AI Risk Management Framework helps organizations govern, map, measure, and manage AI risk. ISO/IEC 42001 offers a management-system approach. A company should select a coherent baseline and produce evidence that its controls operate.

A Practical Agenda for Boards and CCOs

Establish ownership. Name an executive accountable for AI governance and identify the board committee that will oversee material AI risk.

Build the inventory: capture sanctioned tools, embedded vendor capabilities, customer-facing uses, agentic applications, and known shadow AI.

Tier the use cases. Apply enhanced review where AI affects sensitive data, consequential decisions, critical operations, or autonomous action.

Strengthen the vendor process. Add AI-specific diligence, contractual protections, change controls, exit planning, and ongoing monitoring.

Test the failure plan. Confirm that the company can detect a harmful outcome, stop the system, preserve evidence, assign responsibility, and remediate the impact.

The author’s bottom line is the right one for compliance leaders: the winners will not necessarily be the companies that deploy AI fastest. They will be the companies that combine innovation with accountability, customer awareness, and disciplined execution. For a private company, defensible AI governance is not preparation for some distant regulatory future. It is how management protects value today.

Categories
Blog

THE BERKO TRIAL – PART 5: From Case Study to Control Test: A Berko Compliance Playbook for CCOs and Boards

Today we conclude our 5-part deep dive into the Asante Berko trial and guilty verdict, using the trial not simply as a case study but as a mechanism to pressure-test your compliance regime.

A compliance program is not effective because the company eventually exits a troubled transaction. It is effective when leaders can show how quickly the system identified the risk, who had authority to act, whether related conduct was contained, what the investigation established, and how the organization changed afterward.

That is the governance test presented by the Berko trial. Prosecutors built their case from emails, payment patterns, personal communications, compliance questions, recorded statements, and financial evidence. The defense attacked the missing last mile. The jury convicted Asante Berko on all three counts in just over three hours. For CCOs and boards, the final lesson is not to retry the case. It is to determine whether their own program could identify the same pattern, develop reliable facts, impose accountability, and respond at the speed enforcement policy now demands.

Start With the Three Questions That Matter

The DOJ Evaluation of Corporate Compliance Programs (ECCP) organizes program effectiveness around three questions. (1) Is the program well designed? (2) Is it applied earnestly and in good faith, with adequate resources and authority? (3) Does it work in practice? Those questions should frame the board’s review of the Berko fact pattern.

A written third-party policy answers the first question only in part. The second asks whether compliance can pause a revenue-producing transaction, obtain records, challenge senior employees, and reach the board without management filtering. The third asks for outcomes: when the warning signs appeared, did the organization find them, act on them, preserve the evidence, and fix the control weakness?

The governance failure is often not the absence of a rule. It is the gap between ownership and authority. Management owns business conduct and risk decisions. The CCO advises, challenges, monitors, and escalates. Internal audit provides independent assurance. The board oversees the system and management’s response. If every party assumes another function owns the hard decision, the control exists on paper but fails in operation.

Align Incentives, Conflicts, and Consequences

High-risk transactions require a clear view of personal incentives. Employees should disclose and pre-clear outside interests, referral compensation, client-paid benefits, expected success fees, and post-employment opportunities connected to current transactions. Offboarding should preserve relevant data, review pending payments, close access, identify continuing client contacts, and obtain certifications concerning outside interests and retained information.

Compensation deserves the same scrutiny as third-party payments. A bonus plan that rewards closing without measuring risk quality invites employees to treat compliance as a cost of delay. Risk-adjusted incentives should account for diligence completion, control compliance, escalation quality, and the durability of the business outcome. The ECCP asks whether companies use incentives for ethical conduct and apply discipline consistently across seniority, geography, and business unit. It also asks whether compensation can be deferred, reduced, canceled, or recouped when misconduct is established, subject to applicable law.

Consequence management must reach more than the direct actor. A credible process examines supervisory failure, tolerated red flags, obstruction, and failure to install or use safeguards. It applies the same decision framework to rainmakers and junior employees. The board should receive trend information showing investigation cycle times, substantiation rates, disciplinary consistency, repeat issues, and whether managers were held accountable for control failures.

Build Investigation and Speak-Up Readiness

The defense’s attack on the Berko evidence offers an investigation lesson. A source may have motives. A recording may require translation. Emails may lack a witness who can explain context. Payments may be traceable to an intermediary but not to an ultimate recipient. Those are reasons to investigate carefully, not reasons to dismiss an allegation.

Separate source credibility from objective proof. Preserve native emails, attachments, metadata, messaging records, payment instructions, approval histories, and device data. Trace funds beyond the first recipient. Document translation choices, dialect issues, investigative prompting, and competing interpretations. Interview witnesses who can explain both the transaction and the communications. Record what was established, what remained disputed, and why each conclusion was reached.

Design the process before the crisis. Define triage criteria, independence, privilege, preservation, scope approval, board escalation, investigation timing, root-cause analysis, and remediation ownership. Provide reporting channels that employees and third parties know, trust, and can use without retaliation. DOJ treats a trusted reporting mechanism and timely, properly scoped, objective, and documented investigations as hallmarks of an effective program.

Prepare the Disclosure Decision Before the Clock Starts

Voluntary disclosure should not be improvised during a board emergency. The company needs a protocol that identifies decision owners, the role of counsel, the facts required, preservation steps, the escalation path, and the method for assessing seriousness, pervasiveness, seniority, ongoing harm, and potential collateral consequences.

The March 2026 Department-wide Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) makes speed commercially significant. It provides a declination path when a company voluntarily self-discloses to the appropriate DOJ component, fully cooperates, timely and appropriately remediates, and lacks disqualifying aggravating circumstances, although prosecutorial discretion and the policy’s definitions still control. The policy also contains an exception for a whistleblower who reports both internally and to DOJ. A company may remain eligible if it reports as soon as reasonably practicable, no later than 120 days after the internal report, and satisfies the other requirements.

That is not a 120-day permission slip to wait. The operating standard is speed with discipline. The company must stop continuing harm, preserve evidence, protect privilege, develop facts, and keep decision-makers informed. A tabletop exercise should test whether the organization can do all five while the disclosure window is running.

Give the Board Evidence, Not Activity Counts

Boards do not need every hotline allegation or third-party file. They need a risk-based view of whether the system works. Reporting should cover high-risk transactions proceeding with incomplete diligence, unresolved politically exposed person relationships, payment holds, management overrides, aged investigations, remediation slippage, repeat control failures, off-channel communication exceptions, and risk acceptances by senior leaders.

Metrics should show speed, quality, and outcomes. Track time from red flag to triage, triage to transaction pause, allegation to investigation plan, finding to discipline, and remediation commitment to validated closure. Measure whether the company can match high-risk payments to legitimate services, verified beneficial owners, approved accounts, and evidence of performance. Show whether control testing changed behavior, not simply whether employees completed training.

The CCO should have regular direct access to the board or responsible committee, including private sessions when appropriate. The board should understand the CCO’s authority, resources, data access, and unresolved requests. DOJ asks what information directors examined, whether compliance concerns stopped or changed transactions, and whether compliance has the stature and autonomy to function effectively.

Run a 30/60/90-Day Berko Stress Test

Days 1 to 30: Replay one recent high-risk public-sector transaction against the Berko pattern. Inventory intermediaries, beneficial owners, politically exposed person relationships, success fees, conflicts, personal-email exceptions, cash exposure, payment destinations, incomplete diligence, and overrides. Identify which facts the current systems can retrieve and which depend on manual reconstruction.

Days 31 to 60: Close the most important design gaps. Add hard stops, fee benchmarking, conflict attestations, off-channel controls, evidence-preservation rules, payment analytics, investigation protocols, and an escalation matrix giving compliance documented pause authority. Assign one accountable owner and a deadline to each remediation item.

Days 61 to 90: Test the program. Sample transactions, trace selected payments end to end, test the hotline from intake through closure, and conduct an investigation and voluntary-disclosure tabletop. Present the results to senior management and the board, including accepted risks, overdue actions, resource needs, and evidence that completed remediation operates in practice.

The board should ask, “Which Berko warning signs would we detect today?” How quickly could we freeze a payment? Who may override compliance, and what evidence is required? Can investigators collect personal-device communications lawfully and preserve multilingual evidence? Which repeated control failures have affected compensation or promotion?

The CCO should ask one final question: Would our program find this pattern because the controls work, or only because an external source eventually brings it to us?

This Berko FCPA trial blog post series began with the prosecution’s evidentiary mosaic and the defense’s missing-last-mile challenge. It ends with a practical conclusion. Compliance evidence becomes trial evidence. A defensible program must create that evidence through authority, trusted reporting, disciplined investigations, consistent accountability, measurable remediation, and active board oversight. That is how a case study becomes a control test and how a control test becomes proof that the program works.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026. Supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Blog

THE BERKO TRIAL – PART 4: When Red Flags Become Evidence: Transaction Controls from the Berko Trial

Today in Part 4, I want to focus on some of the compliance lessons from the Asante Berko FCPA trial. The compliance lesson from the Berko trial is not simply that employees should not pay bribes. Every code of conduct already says that. The harder question is whether the compliance program can interrupt the operating pattern: a politically connected intermediary, milestone-linked invoices, personal email, cash discussions, incomplete diligence answers, and a commercial team under pressure to close. These were some of the questions that Goldman Sachs faced and successfully answered.

That is where policy becomes performance. Trial reporting described a legitimate infrastructure project surrounded by evidence that prosecutors said showed corrupt intent and concealment. The same emails, diligence questions, payment records, and escalation decisions that once lived inside a transaction later became evidence before a jury. For compliance professionals, the case is a control map. It shows where a high-risk deal can be tested, paused, corrected, or stopped before red flags mature into criminal exposure.

Begin With the Business Model

Your business justification should begin with how the deal is expected to work, not with a standard questionnaire. In the Berko transaction, commercial urgency, a major public need, concentrated government discretion, substantial projected fees, and local intermediaries all increased the risk profile. None of those facts establishes bribery. Together, however, they demand a more disciplined control environment.

The deal team should be required to explain the legitimate path to success. Which officials control each approval? Which regulatory, legislative, and contractual milestones must occur? What service does every intermediary perform? How is that service connected to value rather than access? Where could commercial pressure tempt someone to bypass the process?

This is consistent with the DOJ Evaluation of Corporate Compliance Programs (ECCP), which asks whether a company understands its business from a commercial perspective and devotes appropriate attention and resources to high-risk transactions. A generic country score is not enough. The risk assessment must reflect the transaction’s economics, approval structure, counterparties, compensation model, technology, and pressure points.

Make Third-Party Diligence Operational

Third-party diligence often fails because it is treated as an onboarding event. The questionnaire is completed, screening is run, a risk rating is assigned, and the business moves on. High-risk public-sector work requires continuous control.

Before engagement, the company should document the business rationale, beneficial ownership, politically exposed person and family links, qualifications, reputation, service scope, deliverables, compensation, payment terms, and proposed bank account. Compensation should be benchmarked against the actual work. Enhanced review should apply when fees are success-based, tied to government milestones, disproportionate to services, routed through unrelated entities or individuals, or connected to officials who control approvals.

After onboarding, controls must follow the intermediary into contracting, invoicing, payment, and monitoring. The DOJ guidance asks whether the company understands the business rationale, confirms that services were actually performed, assesses whether compensation is appropriate, tracks red flags, uses audit rights, and manages third parties throughout the relationship. The relevant question is not whether the intermediary passed diligence once. It is whether the relationship still makes sense when the invoice arrives.

Control the Channels Where Business Occurs

Personal email is not proof of bribery. The Berko facts were more specific. According to the trial reporting, sensitive payment discussions occurred through personal accounts. At the same time, routine deal work proceeded through corporate systems, and one exchange referred to the monitoring of a Goldman account. The control issue was the combination of channel separation, sensitive content, and knowledge of monitoring.

Companies need clear rules for personal email, messaging applications, approved mobile platforms, and bring-your-own-device arrangements. Those rules require technical support: approved-channel design, retention settings, monitoring consistent with law, exception approval, employee attestations, and escalation when business moves outside the system. The program should also test whether records can actually be collected and preserved across the jurisdictions where the company operates.

The ECCP asks how companies manage and preserve business communications on personal devices and messaging platforms. The DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) likewise identifies appropriate controls over personal and ephemeral communications as part of timely remediation. A policy that cannot preserve the evidence it covers is not an effective control.

Give Compliance Real Stop Authority

Escalation is not effective if compliance can ask questions but cannot pause the transaction. High-risk deals need defined hard stops. Examples include incomplete beneficial ownership, inconsistent diligence answers, refusal to identify service providers, unexplained compensation, undisclosed PEP relationships, requests for cash, payments to personal or nominee accounts, and destination changes without a credible business reason.

A hard stop does not require the company to abandon every transaction containing a red flag. It requires the risk to be resolved before money or value moves. The control framework should identify who may impose a pause, who may clear it, whether any override is permitted, what evidence supports an override, and which risk decisions require senior escalation.

Trial testimony reportedly described months of compliance questions about the Ghanaian intermediary and inconsistent or incomplete answers, followed by Goldman’s withdrawal from the contemplated financing. That sequence should not be converted into a claim that every control operated early enough or that the company was legally exonerated. The more useful lesson is that the decision trail mattered. It documented the questions, the resistance, the escalation, and the exit.

Connect Diligence, Invoices, and Money

Many programs distribute the relevant facts across separate systems. Procurement sees the contract. Compliance sees the screening. Accounts payable sees the invoice. Treasury sees the destination account. Investigations see the allegation. No one sees the complete pattern.

Payment controls should require proof of service, account-name matching, country and entity consistency, independent approval for destination changes, and tight restrictions on cash. Analytics should flag round-dollar invoices, duplicate invoice numbers, payment splitting, milestone-timed consulting fees, payments to employees or related parties, high-risk correspondent routes, and transfers followed by cash withdrawals.

The decisive step is integration. Due diligence, PEP screening, contracting, procurement, accounts payable, treasury, and case-management data should be capable of producing a transaction-level view. That view allows compliance to ask whether a payment is not only properly approved but also commercially credible.

Build an Evidence-Grade Record

The defense’s most forceful theme was the missing last mile: no downstream bank record showing money reaching a Ghanaian official, no alleged recipient on the witness stand, and no eyewitness to a bribe. The jury nevertheless convicted Berko on all three charged counts. For an internal investigation, the lesson cuts both ways. Suspicion is not proof, but weak tracing can leave the company unable to determine what happened.

Preserve native emails, attachments, metadata, messaging exports, payment records, approval histories, translations, and custodial provenance—record who made each factual determination and what evidence supported it. For multilingual material, preserve the original, use qualified translators, document dialect and ambiguity, and maintain a process for reviewing disputed language. Financial tracing should move from payer to intermediary to ultimate recipient, including related-party accounts and cash conversion.

The current FCPA enforcement guidelines emphasize individual misconduct and caution against attributing nonspecific malfeasance to corporate structures. That makes an evidence-grade corporate record especially important. It can help separate an individual’s conduct from the organization’s response while also showing whether the program was designed and implemented effectively.

Test the Controls Before the Crisis

An effective program does not promise that no misconduct will ever occur. DOJ recognizes that even a strong program may fail to prevent an offense. The question is whether the program is risk-based, detects concerns, responds promptly, and improves from experience.

Replay a recent public-sector transaction against the Berko pattern. Could the company identify every approval-controlling official and intermediary? Would milestone-linked payments trigger review? Could compliance pause the deal? Would personal email activity be detected and preserved? Could investigators trace funds beyond the first intermediary? Measure time from red flag to pause, overdue enhanced diligence, unresolved PEP issues, payment exceptions, control overrides, and closure of remediation.

The practical takeaways are clear. Commercial urgency calls for greater discipline, not reduced scrutiny. Third-party diligence must remain connected to invoices, payments, monitoring, and escalation. Off-channel communications become an intent and preservation issue when combined with sensitive content and known monitoring. A deal exit matters, but an earlier hard stop may reduce exposure and preserve more business value.

Join us tomorrow as we conclude our 5-part series by moving the transaction to the enterprise. In it, we will explore such questions as who owns these controls, who funds and tests them, how accountability is imposed, and what your Board of Directors should demand as evidence that the program works in practice.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 70 – Lessons from Let That Be Your Last Battlefield: Building Justice and Fairness into Corporate Culture

Few episodes capture the destructive power of bias, systemic injustice, and the refusal to see common humanity as vividly as Star Trek: The Original Series’ “Let That Be Your Last Battlefield.” From a compliance perspective, the episode provides an unflinching mirror: organizations that fail to ensure fairness in their systems—whether in investigations, promotions, whistleblower treatment, or discipline—risk breeding internal hostilities just as destructive as Cheron’s. Today, we unpack five key compliance lessons for embedding institutional justice and fairness into the corporate DNA.

Lesson 1: Bias—Even When Invisible to Some—Can Destroy Organizational Cohesion

Illustrated by: When Bele first encounters Lokai aboard the Enterprise, he describes him as “obviously inferior.”

Compliance Lesson. Bias often hides in plain sight for those not affected by it. In corporate settings, decision-makers may not recognize that promotion patterns, discipline rates, or resource allocations favor certain groups until a whistleblower, audit, or public scandal exposes it.

Lesson 2: Enforcement Must Be Fair, Consistent, and Transparent

Illustrated by: Bele claims the right to arrest Lokai for crimes committed on Cheron. Lokai, in turn, accuses Bele of genocide. Neither offers verifiable evidence; instead, both rely on their moral certainty.

Compliance Lesson. Internal enforcement that rests on vague accusations or uneven application destroys trust in compliance systems.

Lesson 3: Leaders Must Refuse to Be Drawn into Partisan Vendettas

Illustrated by: Kirk insists on the Enterprise’s code of conduct and rules of evidence.

Compliance Lessons. Senior leaders are often pressured, subtly or overtly, to “pick a side” in internal disputes.

Lesson 4: Systemic Injustice Can Persist Until It Consumes the Organization

Illustrated by: When Bele and Lokai finally return to Cheron, they find their planet in ruins, destroyed by centuries of hatred. Yet, even faced with the extinction of their people, they continue their pursuit, consumed by the need to destroy the other.

Compliance Lesson. Corporate cultures that allow systemic injustice, favoritism in promotions, discriminatory pay structures, and retaliation against whistleblowers risk not only reputational harm but also the destruction of the organization’s ability to function cohesively. Over time, injustice becomes normalized, making reform nearly impossible without significant disruption.

Lesson 5: Without a Shared Framework for Fairness, Conflict Has No Resolution

Illustrated by: Spock, ever the voice of logic, tries to point out that the two aliens are more alike than different. To them, justice is entirely defined by the defeat of the other.

Compliance Lesson. In corporations, the absence of a clear, visible framework for fairness, along with policies, expectations, and trusted reporting channels, leads to conflicts that devolve into zero-sum games.

Final ComplianceLog Reflections

Let That Be Your Last Battlefield ends on a tragic note: the two survivors beam down to a dead world, still locked in mutual hatred. It’s a cautionary tale for corporate life. Without institutional justice and fairness, even the most advanced organizations can collapse into destructive internal conflict.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Timothy is an AI-generated voice