Categories
Blog

Board Week, Part 4: So You Want to Be on a Board

If you work in compliance, you already speak the language boards care about risk, resilience, integrity, and long-term value. The opportunity now is to package your experience so that directors and the searchers who advise them will view you as a business voice who specializes in compliance, rather than the other way around. Drawing on insights from women leaders who have navigated their way to board service, along with hard-won boardroom lessons, we present today a step-by-step playbook for compliance professionals who want a seat at the table.

Reframe Your Value: From “Compliance Leader” to “Board-Ready Risk Strategist”

Boards add people to fill needs, not aspirations. Translate your day job into board outcomes.

As a CCO, you use judgment under uncertainty. Some of the key tasks of every compliance officer include triaging investigations, balancing disclosure risk, and managing interactions with regulators. Boards prize seasoned judgment more than technical depth. You also have a broad, enterprise risk lens. Recast hotline trends, third-party risk, sanctions exposure, data privacy, and culture measurement as strategy inputs and value protection, not just controls.

You should already have fluency crisis preparation and management. You know incident response cycles (facts are murky, pressure is high, stakeholders differ). That calm, evidence-first approach is board gold. Finally, show that you understand the boundary: boards govern, while management operates. You can probe, synthesize, and guide without taking control of the show.

Deliverable: Write a one-page Board Bio (not a resume). Lead with judgment, strategy impact, crisis experience, and committee relevance (Audit/Risk/Gov). Keep it crisp; your first paragraph must sing.

Choose Your On-Ramps: Nonprofit, Private, Public—In That Order (Usually)

Recruiters fill a minority of board seats; most come through networks and word of mouth. For many compliance professionals, the fastest on-ramp is to mission-driven or local nonprofit boards, followed by private company boards, and then public boards.

Nonprofit boards hone the muscle memory of governance, committee work, and board dynamics. You learn agendas, pre-reads, fiduciary duties, and the cadence of challenge/support. You also practice EQ moves, such as knowing when to ask in the room versus follow up offline. Private company boards value operators who have built programs and navigated growth risk, which are perfect for compliance leaders who have matured third-party, privacy, or cyber programs at scaling companies. Finally, public company boards hire for specific committee needs, prior board experience, and public company expertise (audit, compensation, nominating/governance, cyber risk).

Action to take: Pick three nonprofits whose mission you genuinely care about. Offer to help first (advisory project, committee seat), then raise your hand for the board. Passion + preparation beats paper credentials.

Build a Targeted Narrative, Not a Generic Pitch

Your pitch should not be “I want a board seat.”; but rather Here’s the problem I’m built to solve.”

If you are a controls/assurance pro (SOX, internal audit, investigations): position for Audit or Risk committee. Emphasize financial integrity, whistleblower credibility, remediation discipline, and root cause rigor. If you are a tech-savvy, privacy-conscious, or cyber-savvy CCO, aim for Risk or Technology oversight. Stress incident playbooks, data governance, AI/ML risk, and cross-functional response. If you are facing cultural/ethical issues, look to nomination and governance needs. Areas such as board composition, CEO succession risk, incentive design that deters misconduct, and culture as control.

Homework: Then do industry homework. If you’re pursuing a career in healthcare, life sciences, fintech, or manufacturing, read 10-Ks, enforcement actions, and peer risk factors; convert your experience into sector-specific oversight value.

Network Like It’s Your Job (Because It Is)

Board seats are an art, not a posting. Your path will resemble a mosaic more than a pipeline.

Warm introductions often outshine cold resumes. Tell three people each week in positions such as GCs, CFOs, fellow CCOs, auditors, and PE operating partners exactly which needs you need to fill and in which sector. Peer groups are multipliers. Join compliance councils, audit institute chapters, NACD/director forums, and alumni boards. Offer to moderate a panel on “Board Oversight of Third-Party Risk” or “AI and Culture Risk.” Finally, be visible in solving problems. Publish a short LinkedIn series on board-relevant topics (e.g., “A director’s five questions for sanctions exposure”). Speak briefly; show judgment.

Remember: Patience wins. Boards decide on quarterly cycles, not recruiting sprints.

Get Committee-Ready—Fast

Most first-time directors enter through committees. Make yourself instantly addictive:

The Audit Committee. Develop a new approach that ties investigations, SOX controls, fraud risk assessments, and hotline patterns to financial statement risk. Show how your work protected revenue or EBITDA. The Risk Committee brings a heat map that integrates cyber, third-party, geopolitical, product safety, and culture risk. Demonstrate scenario planning and escalation criteria. The Nom/Gov Committee connects incentive structures, succession planning, ethics benchmarks, and board composition to long-term value. Finally, consider the Compensation Committee by translating root causes of misconduct into incentive design advice (pay for how results are achieved, not just that they’re completed).

Deliverable: Create a two-page Board Briefing Pack you can share confidentially when asked: a sample dashboard, escalation triggers, and a case study where your counsel changed a decision.

Do the Diligence: Culture, Time, and Risk

Do not treat an offer like a trophy; do your homework for the Company and the position. Ensure you are a cultural fit. Talk to multiple directors and at least two executives. Ask how the board challenges management, how dissent is handled, and how pre-reads and follow-ups actually work. If they are reticent to connect you, that is a red flag. Make sure you understand the time reality. Beyond quarterly meetings, count committee meetings, prep, and off-cycle crises. Nonprofit boards can be especially “needy”; set eyes-open expectations. And last but certainly not least, tie down the D&O and indemnification. Always ask to see the policy and indemnity language, including limits, carve-outs, and advancement of expenses. For public or PE-backed companies, confirm coverage by entity and by capacity.

Make Your Board Bio and Outreach Ready This Month

Create a one-page Board Bio. It should contain an Opening (3–4 lines) that demonstrates your judgment, sector context, and committee fit (e.g., “Audit/Risk-ready executive who led global compliance and crisis response across 30 countries; proven board advisor on cyber, sanctions, and culture risk”). It should contain 3-5 selected impact bullets tying actions you have taken to outcomes (“Reduced investigation cycle time 40% and increased substantiation quality; informed board decision to exit a high-risk distributor, avoiding potential enforcement exposure”). Add your board interests in selected industries, committee preferences, and geography. Of course, add your contact information.

Action: Take this and create an outreach list with 15 names, including those from legal, finance, audit, PE ops partners, CEOs you’ve advised, and nonprofit leaders. Ask for needs-first conversations, not a seat at the table.

Final Word: You’re More Board-Ready Than You Think

Boards do not need passengers; they need steady judgment, crisis fluency, and a practical grasp of how controls become strategy. That’s your wheelhouse. Do the homework, shape a needs-first narrative, and start where you can make an impact now. The seat will often come from a conversation you did not know would matter.

And when it does, remember the rule that separates great directors from the rest: noses in, fingers out, with a steady hand on the compass of integrity.

30-60-90 Action Plan

Next 30 days

  • Draft board bio + two-page briefing pack.
  • Reconnect with five execs who’ve seen your judgment under pressure; ask for introductions to their board contacts.
  • Identify and approach one nonprofit and one private company where your risk expertise is directly relevant.

Days 31–60

  • Speak on one panel/webinar: “Board Oversight of Third-Party & Sanctions Risk” or “What Directors Need to Know About AI and Culture.”
  • Conduct three informational interviews with current directors and refine your narrative based on their feedback.

Days 61–90

  • Commit to a nonprofit board or board committee role.
  • Join a director education program (NACD or equivalent) and complete a module on Audit/Risk oversight.
  • Publish a three-post LinkedIn series: “A Director’s Playbook for Crisis Escalation,” “Five Board Questions for AI Risk,” “Culture as a Control.”
Categories
Compliance Tip of the Day

Compliance Tip of the Day – The CCO Role in Preparing the Board for the Next Crisis

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

We continue our 5-part series, considering several questions about compliance officers working with or on the Board. Today, we consider the role of a CCO in preparing a Board for the next crisis.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which was recently released by LexisNexis. It is available here.

Categories
Blog

Board Week, Part 3: The CCO’s Role in Preparing a Board for the Next Crisis

Crisis is no longer a rare event. From ransomware attacks and regulatory shocks to activist investors and CEO departures, boards today operate in an environment defined by volatility and disruption. PwC’s recent memorandum, “Being Prepared for the Next Crisis,” highlights the importance of boards adopting a proactive approach to resilience and oversight. However, while directors bear the primary responsibility for governance, a Chief Compliance Officer (CCO) plays a distinct role: ensuring that the board is informed, equipped, and prepared to respond effectively.

The CCO is often the organization’s “early warning system,” translating risks from the operating level into insights for the board. In a crisis, this role becomes magnified. The CCO must help the board anticipate threats, stress-test plans, and avoid the common pitfalls that derail effective responses. Today, we will explore how CCOs can adapt the PwC framework into a playbook to guide the board through the crisis preparedness lifecycle.

1. Before the Crisis: Embedding Compliance into Resilience Planning

The best crisis plans are living documents that are constantly updated, tested, and integrated across all functions. For CCOs, the challenge is to ensure compliance and ethics considerations are built into those plans from the start.

The CCO’s Role:

  • Cross-functional integration. Ensure that the compliance function sits at the crisis planning table alongside risk, legal, and operations. Issues such as bribery, data privacy breaches, or third-party misconduct can escalate into crises if left unaddressed.
  • Scenario planning. Push for tabletop exercises that include compliance scenarios—not just cyber breaches. A dawn raid by regulators, whistleblower allegations, or sanctions violations should all be tested with the board. Most boards are fixated on cyber exercises (81%) while under-testing activist campaigns, fraud investigations, and geopolitical risks. The CCO can broaden that scope.
  • Defining escalation triggers. Collaborate with management and the board to define when compliance issues rise to the level of a board crisis. For example, a government subpoena, a major third-party red flag, or media exposure of misconduct should be predefined as triggers for immediate notification to the board.

By embedding compliance into resilience planning, the CCO ensures that ethical and regulatory risks are not afterthoughts but central to the crisis playbook.

2. During the Crisis: Supporting the Board’s Oversight and Communications

Once a crisis hits, speed and clarity are critical. Work to avoid pitfalls such as “leaping before looking,” minimizing the problem, or losing credibility with stakeholders. Here, the CCO becomes the board’s translator and truth-teller.

The CCO’s Role:

  • Facts over speculation. Ensure that communications to the board are grounded in verified information. If facts are incomplete, emphasize transparency about what is known and what remains to be investigated.
  • Maintaining authenticity. Compliance leaders are custodians of corporate values. During crisis communications, the CCO should challenge management if the messaging strays from the organization’s ethical commitments. As PwC notes, stakeholder trust depends on alignment with company values.
  • Stakeholder inclusivity. Understand the importance of addressing all stakeholders, not just the loudest. The CCO should ensure employees are included in the communication strategy. In many crises, employees are both victims and messengers. If left uninformed, they can become sources of rumor or disengagement.

The CCO also helps the board resist the temptation to downplay severity. Regulators and investors are unforgiving of minimization. Credibility, once lost, is difficult to recover.

3. After the Crisis: Driving Root Cause Analysis and Continuous Improvement

The PwC framework underscores the importance of post-event reviews, root cause analysis, and continuous improvement. For CCOs, this is where compliance expertise shines.

The CCO’s Role:

  • Independent assessment. If misconduct or governance failures triggered the crisis, the CCO should advocate for independent investigations to determine the cause. This not only ensures credibility but also demonstrates the board’s seriousness in remediating gaps.
  • Root cause focus. Compliance officers are trained to ask “how and why.” A surface-level review, examining what happened and the actions taken, overlooks the deeper cultural or control weaknesses that enabled the crisis to occur. Without addressing these, organizations remain vulnerable.
  • Policy and training updates. Post-crisis reviews should feed directly into compliance programs. If a whistleblower report was ignored, revise reporting protocols. If a sanctions violation occurred, strengthen third-party screening.
  • Board education. Provide directors with debriefs on regulatory trends that emerged during the crisis. For example, if a DOJ enforcement action shaped the company’s response, explain the broader implications for future oversight.

By institutionalizing lessons learned, the CCO helps the board convert a painful episode into a competitive advantage.

4. The CCO as the Board’s Crisis Sherpa

PwC notes that boards must balance guiding management while not being overwhelmed themselves. In practice, this requires a trusted advisor who can translate complexity, cut through the noise, and flag issues that rise to governance levels. That advisor is often the CCO.

The CCO’s Role:

  • Regular briefings. Establish quarterly “crisis readiness” updates for the board, led by compliance. These sessions review recent regulatory developments, whistleblower trends, and geopolitical risks.
  • Committee alignment. Work closely with the audit or risk committee to ensure that crisis oversight responsibilities are clearly defined and understood. In some cases, a compliance liaison may be designated to report directly to the board during a crisis.
  • Tone from the top. Model ethical courage in board communications. If executives resist disclosure or push spin, the CCO must be willing to articulate the risks of opacity. The board relies on the unvarnished truth, even when it is uncomfortable to hear.

The CCO, in essence, becomes the board’s crisis sherpa: guiding directors through treacherous terrain with foresight, facts, and fidelity to values.

5. A CCO’s Checklist for Board Crisis Preparedness

To translate this into action, here’s a compliance-focused checklist adapted from PwC’s recommendations:

  1. Ensure crisis plans are compliance-inclusive. Integrate regulatory, ethical, and third-party risks into enterprise crisis planning.
  2. Broaden board exercises. Advocate for tabletop simulations that extend beyond cyber—encompassing fraud, sanctions, whistleblower events, and activist campaigns.
  3. Define escalation triggers. Codify the process for escalating compliance issues to the board.
  4. Champion transparent communication. Push for fact-based, values-aligned messaging during crises.
  5. Include employees. Make internal communications as robust as external messaging.
  6. Drive post-crisis reviews. Lead root cause analysis and ensure findings inform compliance program updates.
  7. Educate directors. Keep the board informed about current regulatory expectations and cultural red flags.

Preparing the Board for the Crisis That Hasn’t Happened Yet

As PwC observes, a crisis is no longer hypothetical; it is cyclical. Boards that prepare systematically will emerge stronger. But preparation is not solely the task of directors or management. The Chief Compliance Officer must bridge the gap by embedding compliance into resilience plans, guiding directors during responses, and ensuring that lessons are institutionalized after the fact.

The next crisis will come. We don’t know whether it will be a cyber, regulatory, or reputational issue. But we do know this: the boards that succeed will have a compliance leader at their side, someone who combines regulatory expertise with cultural insight, and who can guide directors through the storm with clarity and integrity.

That is the CCO’s role. And it may be the most important contribution compliance makes to long-term corporate resilience.

Categories
Compliance Tip of the Day

Compliance Tip of the Day – A CCO Playbook to Master Board Communications

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with bite-sized, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

We continue our five-part series, considering several questions about compliance officers working with or on the Board. Today, we consider how CCOs use a playbook to master Board communications.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which was recently released by LexisNexis. It is available here.

Categories
Blog

Board Week, Part 2: Mastering Boardroom Communication: A Chief Compliance Officer’s Playbook

Boardroom communication is not just a matter of style; it is a skill much needed for every Chief Compliance Officer (CCO). In today’s environment of heightened regulatory scrutiny, geopolitical disruption, and rapid technological change, a CCO sits squarely at the intersection of risk, ethics, and strategy. How a CCO communicates with the board can shape director confidence, influence resource allocation, and ultimately determine whether compliance is viewed as a strategic partner or a cost center.

A recent Harvard Law School Forum on Corporate Governance article outlined five essentials for executives engaging with their boards. For CCOs, these essentials carry even more weight. Compliance is often the messenger of uncomfortable truths: misconduct uncovered, regulatory inquiries, or cultural red flags that leadership may prefer to avoid. Delivering these messages effectively requires preparation, precision, and presence. In this blog post, we will explore how CCOs can adapt these five essentials to elevate their boardroom communication.

1. Invest in Relationships: Building Trust Before the Crisis

For CCOs, credibility with the board is currency. Relationships cannot be built during a crisis; they must be established well in advance of one arriving. Intentional relationship-building with directors pays dividends. CCOs should regularly meet with audit and compliance committee chairs outside of formal sessions. These pre-meeting touchpoints allow you to test messaging, gauge concerns, and set expectations. They also build the trust needed when delivering difficult news, such as a whistleblower report implicating senior leadership or an FCPA investigation.

Equally important, CCOs must present a united front with fellow executives. Fragmented messaging from the CCO versus the CFO or General Counsel undermines board confidence. Directors want assurance that compliance is embedded across all functions, not confined to silos. Demonstrating cross-functional collaboration signals maturity and readiness. You can provide directors with candid “heads-up” updates on emerging risks. If the Department of Justice signals a shift in compliance program evaluation (as it did with the 2024 ECCP Update), brief your directors in advance. Early transparency fosters credibility.

2. Know Your Audience: Translating Compliance into Board Priorities

Directors are a distinct audience; they are seasoned leaders with broad but varied expertise. The article emphasizes the importance of tailoring messages to individuals’ backgrounds and perspectives. For CCOs, this means translating compliance risks into business-relevant language. For example, when discussing data privacy, it is best to avoid using technical jargon. Instead, connect privacy risks to reputational harm, customer trust, and market access. When discussing sanctions enforcement, frame it in terms of geopolitical instability and supply chain resilience.

CCOs must also bridge perspective gaps between management and the board. Senior executives often want boards to add expertise in emerging areas, such as AI, but directors are slower to prioritize it. The CCO’s role is to highlight how these gaps translate into real risk exposure. If the board does not see the value of AI oversight on its agenda, provide evidence, such as regulator speeches, enforcement trends, and peer actions. Do your homework: know which directors come from legal, financial, or technology backgrounds. A director with former regulatory experience will expect different details than one with private equity experience. Anticipating these perspectives ensures that your compliance story resonates.

3. Prepare What You Will Share: Making Compliance Digestible

The board’s time is scarce. As the article notes, directors want strategy, not operations. That makes the pre-read and presentation materials critical tools for the CCO. Your pre-read should strike a balance: concise enough to be digestible, but substantive enough to demonstrate rigor. A best practice is a one-to-two-page executive summary highlighting:

  • Key compliance risks and emerging issues.
  • Required board actions (e.g., policy approval, risk appetite setting).
  • High-level metrics (e.g., hotline trends, third-party due diligence outcomes).

Supporting dashboards or appendices can provide depth for directors who want to dive in. Use visuals such as heat maps, trend charts, and red/yellow/green risk indicators to cut through dense text. During the meeting, avoid repeating the pre-read. Instead, highlight the “so what”: why a risk matters now, how it aligns with strategy, and what action is needed. For example: “We are seeing a 40% increase in third-party red flags in Latin America. This aligns with the DOJ’s recent statements on third-party risk. We recommend enhanced monitoring of intermediaries before the next audit committee meeting.”

End with a clear ask: whether you need endorsement, resources, or merely board awareness. Ambiguity is the enemy of effective compliance communication.

4. Manage the Meeting: Maximizing Scarce Minutes

Most CCOs are allocated just 15–20 minutes on a crowded board agenda. This means every minute counts. Enter with a game plan: two or three key messages, delivered crisply. Speak for no more than half the time; reserve the rest for questions and answers. Board members’ questions are where trust is built and oversight is demonstrated.

If the meeting drifts into operational details, such as the specifics of a particular investigation, steer the conversation back to the strategic view: patterns, controls, and lessons learned. Capture follow-up items and commit to deliver them post-meeting. This demonstrates respect for the board’s time while ensuring no issue is left unresolved. Align with the corporate secretary to understand time allocations and broader agenda flow. If your presentation follows the CFO’s, anticipate financial framing; if it precedes the General Counsel’s, coordinate on legal versus compliance perspectives. Seamless alignment avoids director confusion and reinforces management cohesion.

Above all, project confidence. If you appear tentative when discussing risks, directors may question the maturity of your program. Credibility is as much about presence as it is about content.

5. Continue the Conversation: Compliance as a Constant Dialogue

Boardroom communication does not end when the gavel falls. You should reach out to board members to cultivate ongoing engagement. For CCOs, this is mission-critical. Complex topics, such as sanctions, cybersecurity, or ESG reporting, cannot be fully explored in a single board session. Utilize committee meetings or off-cycle workshops for in-depth discussions and analysis. For example, a compliance officer might host a session with the audit committee on DOJ expectations for root cause analysis, tying it to the company’s investigation protocols.

Follow up after meetings with concise updates. If a regulator issues new guidance relevant to a recent board discussion, send a one-page summary highlighting its implications. Demonstrating responsiveness keeps compliance at the forefront and positions you as a trusted advisor. Finally, monitor evolving board concerns. Directors’ focus shifts with the environment—activist campaigns, regulatory changes, or high-profile enforcement actions. Staying attuned allows you to tailor communications to what keeps your directors up at night.

The CCO and the 3 ‘T’s”

Boardroom communication is not about dazzling directors with slides or overwhelming them with data. For the Chief Compliance Officer, it is about trust, translation, and truth. (1) Trust, because relationships established before crises determine how your messages are received in a storm. (2) Translation, because directors need compliance framed in terms of strategy, value, and risk, not technical minutiae. (3) Truth, because your role is to surface uncomfortable realities. This means discussing topics such as cultural weaknesses, compliance failures, and regulatory gaps that others may prefer to avoid.

Board time is limited and precious. For CCOs, mastering the art of concise, transparent, and strategic communication is not optional. It is the difference between compliance being perceived as a watchdog or as a partner in building resilient, ethical, and sustainable business practices.

The boardroom is your stage. Prepare, practice, and perform with clarity. The future of your compliance program and your credibility as its leader may depend on it.

Categories
Daily Compliance News

Daily Compliance News: September 15, 2025, The AI CCO Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, including compliance, ethics, risk management, leadership, or general interest, relevant to the compliance professional.

Top stories include:

  • First AI CCO. (BBC)
  • CFTC probes Google, Amazon over advertising. (Reuters)
  • Can Zoom make your meetings better? (NYT)
  • DOJ is looking at Uber for Disabilities violations. (WSJ)
Categories
Compliance Tip of the Day

Compliance Tip of the Day – Why Compliance Professionals Should Not Overlook Board Oversight

Welcome to “Compliance Tip of the Day,” the podcast that brings you daily insights and practical advice on navigating the ever-evolving landscape of compliance and regulatory requirements. Whether you’re a seasoned compliance professional or just starting your journey, our goal is to provide you with concise, actionable tips to help you stay ahead in your compliance efforts. Join us as we explore the latest industry trends, share best practices, and demystify complex compliance issues to keep your organization on the right side of the law. Tune in daily for your dose of compliance wisdom, and let’s make compliance a little less daunting, one tip at a time.

In this 5-part series, we will consider several questions about compliance officers working with or on the Board. Today, we begin with a look at why compliance officers need to embrace Board Oversight.

For more on this topic, check out The Compliance Handbook, a Guide to Operationalizing your Compliance Program, 6th edition, which was recently released by LexisNexis. It is available here.

Categories
Blog

Culture, Controls, and Consequences: Why Compliance Should Address Abuse Before It Escalates

When we discuss “fraud, waste, and abuse” in the corporate compliance world, fraud often takes center stage. Fraud is the deliberate deception of knowingly submitting false information for personal or corporate gain. Waste is easier to define: the careless or inefficient use of resources. But abuse? Abuse sits in that murky middle ground. It may not rise to the level of criminal fraud. Still, it represents conduct that undermines the ethical framework of the organization and erodes trust in systems designed to manage risk.

In many ways, abuse is the most insidious of the three. It thrives in the shadows, often justified by employees as “harmless” or “making up for what the company owes me.” Yet left unchecked, abuse not only costs organizations real money but also paves the way for outright fraud. One of the clearest examples of abuse today lies in employee expense reimbursement, a process now under siege by the rise of AI-generated fake receipts.

Today, we continue our week-long exploration of the role of a Chief Compliance Officer (CC) and corporate compliance function in fighting fraud, waste, and abuse. Today, we explore what abuse means, how expense reimbursement schemes illustrate the problem, why weak controls allow abuse to metastasize into fraud, and what compliance professionals can do to address it. We use a real-world example of AI creating fraudulent expense reimbursements to demonstrate how the task has become more difficult and why a corporate compliance function must be even more vigilant.

Defining Abuse in the Compliance Framework

Abuse is often defined as the use of authority, processes, or resources in a manner that is inconsistent with accepted business practices, resulting in unnecessary costs or unfair advantages. Unlike fraud, abuse does not always involve intent to deceive. Instead, it often reflects opportunistic behavior, such as stretching policies to personal advantage, exploiting loopholes, or rationalizing misconduct.

In the context of compliance, abuse is the “gateway drug” to fraud. An employee who casually exploits the expense system, rounding up mileage, submitting duplicate claims, or fabricating receipts for lost expenses, may start with small infractions. But over time, the lack of consequences emboldens greater misconduct.

One only needs to look back at the sordid story of GSK in China to recall that employee expense reimbursement can lead to catastrophic consequences for an organization.

Expense Reimbursement Abuse: The AI-Receipt Problem

As the New York Times (NYT) recently reported, employees are increasingly turning to generative AI tools to create realistic fake receipts. This is abuse in action. It often begins innocently enough: an employee loses a legitimate receipt and turns to an AI chatbot to recreate it. They may even rationalize the act as necessary to be reimbursed for actual money spent.

But the abuse does not stop there. Once the employee realizes the system can be gamed and that compliance or finance fails to detect the fraud, they repeat the behavior. In one case, an employee submitted AI-generated receipts for hotels and airfare in Bangkok, despite never traveling there.

The ACFE in its most recent Report to the Nations confirms the scale of the issue:

  • 13% of occupational fraud cases involve inflated or invented expenses.
  • Median loss per case: $50,000.
  • 30% of fraudulent receipts detected by one major auditing tool are now AI-generated.

What makes this a prime example of abuse is not just the false documentation. It is the culture of permissiveness that allows employees to cross the line between mistake, abuse, and eventually fraud.

How Lack of Controls Fuels Greater Fraud

The absence of strong internal controls around expense reimbursement is fertile ground for abuse. Companies that rely on manual review or outdated systems may not be equipped to detect sophisticated fakes. AI has supercharged this risk. Where once an employee might need Photoshop skills to doctor a receipt, now anyone with a chatbot can generate a convincing fake in seconds.

Weak controls create three distinct risks for compliance:

1. Normalization of Misconduct

Employees who “get away” with small abuses normalize this behavior, eroding ethical culture. “Everyone does it” becomes the rallying cry.

2. Escalation to Fraud

Abuse begets fraud. What begins as recreating a lost taxi receipt morphs into fabricating entire trips, complete with hotels, meals, and airfare never taken.

3. Regulatory and Legal Exposure

Inflated or fabricated expense claims, especially involving government contracts or international operations, can trigger False Claims Act liability, FCPA scrutiny, or other regulatory action.

Ultimately, compliance officers should view expense reimbursement abuse as more than an administrative nuisance. It is a leading indicator of deeper cultural weakness and a flashing red light for greater fraud risk.

Building a Compliance Response

How should compliance professionals address abuse in expense reimbursement systems? Three principles stand out:

  • Leverage Data and Technology: Just as employees use AI to fabricate receipts, compliance teams must deploy AI to detect them. Expense auditing platforms now compare metadata, font spacing, and behavioral patterns to identify suspicious submissions.
  • Strengthen Policy and Training: Clear guidance is essential. Employees should know that even “recreating” a lost receipt is prohibited, and repeated violations will trigger disciplinary action. Training should emphasize that abuse is not a victimless act; it drains resources and undermines trust.
  • Promote a Speak-Up Culture: Abuse thrives in silence. Anonymous hotlines, visible accountability, and consistent follow-through on reports send the message that integrity matters.

Five Key Takeaways for Compliance Professionals

1. Abuse Is the Gateway to Fraud

Abuse often sits in the gray space between negligence and intentional misconduct. An employee may rationalize using a fake receipt as a harmless way to recover legitimate expenses, but once this behavior is accepted, it erodes the organization’s integrity. Abuse teaches employees that rules can be bent without consequence. Over time, this rationalization escalates, leading to outright fraud. Compliance professionals must recognize abuse not as minor misconduct but as the earliest sign of a deeper cultural problem. Treating abuse seriously, through policy, training, and accountability, prevents small acts of dishonesty from snowballing into systemic fraud that damages the enterprise.

2. Expense Reimbursement Abuse Is Rising

Expense abuse has always been a problem, but the introduction of generative AI has made it easier and more scalable. Employees no longer need technical expertise in Photoshop to fabricate documents. Today, they can generate convincing receipts in seconds, often indistinguishable to the human eye. Cases of employees submitting AI-generated receipts for trips never taken highlight just how quickly this abuse can escalate. For compliance teams, this shift means that traditional manual review is no longer enough. Organizations must anticipate that abuse in expense systems is increasing both in volume and sophistication, and they must respond accordingly.

3. Weak Controls Enable Misconduct

Compliance professionals recognize that robust internal controls are the foundation of effective fraud prevention. When expense systems lack proper oversight, they create opportunities for abuse to thrive. Employees quickly learn where controls are lax, whether through inconsistent auditing, inadequate documentation requirements, or poor segregation of duties. Without strong controls, small abuses go unchecked, and employees feel emboldened to escalate their misconduct. Worse still, regulators may interpret weak controls as evidence of willful blindness or negligence, thereby exposing companies to additional liability. Compliance officers must ensure expense reimbursement processes are fortified with modern controls that prevent, detect, and remediate abuse at every level.

4. Technology Must Match the Threat

The same tools employees use to commit expense abuse can be harnessed by compliance to stop it. AI-generated receipts may look convincing, but advanced auditing tools can detect subtle inconsistencies in formatting, metadata, and behavioral patterns. Expense management platforms now deploy machine learning to flag unusual submissions, such as repeating server names or meals in fabricated restaurant receipts. Compliance professionals must advocate for investment in these technologies to stay ahead of evolving threats. Without matching technology to the risk, organizations remain vulnerable. Ultimately, AI must be part of the compliance toolbox to counteract the AI-enabled abuse already occurring.

5. Culture Is the Ultimate Control

No amount of technology or policy will succeed without a culture that values accountability. Abuse thrives in environments where misconduct is ignored, rationalized, or dismissed as “just the cost of doing business.” By contrast, cultures where leadership models ethical behavior, encourages reporting, and rewards integrity create natural barriers to abuse. Compliance must work hand in hand with leadership to embed accountability into daily operations. When employees see that even small abuses are addressed, they understand the seriousness of compliance expectations. A healthy culture sends the clearest message: abuse will not be tolerated, and integrity is non-negotiable.

Abuse Is Fraud’s Precursor

Fraud, waste, and abuse are often discussed as a package, but compliance professionals must pay special attention to abuse. It is the gray zone where rationalizations take root, where misconduct begins small, and where organizational culture is tested. Expense reimbursement systems offer a cautionary tale: without proper controls and accountability, abuse can quickly evolve into systemic fraud.

Compliance officers who ignore abuse risk far more than inflated receipts. They risk cultivating an environment that fosters fraud. The lesson is clear: treat abuse as seriously as fraud, because in practice, one leads inexorably to the other.

Categories
Blog

Agentic AI, Data Discipline, and Cross-Functional Governance: Compliance Insights for the Modern Era

As compliance professionals, we often inherit the boundaries that IT, Legal, and Security established long before we arrived. But what happens when those lines are out of date? I recently had a far-ranging conversation with cybersecurity author and educator Robert Meyers, who has spent more than three decades transitioning from “plain IT” to a world where cybersecurity and privacy have become distinct, high-impact disciplines. He explains why the old map no longer matches the terrain. Meyers’ vantage point spans early dial-up remote access fiascos, modern breach response, philosophical differences between U.S. and EU privacy regimes, and the tidal shift that agentic AI is bringing to accountability and data governance.

This blog post distills that conversation for a corporate compliance audience, focusing on practical, board-relevant governance and the day-to-day tactics that make privacy and security work together before, during, and after incidents.

From “IT Does Everything” to “Risk, Roles, and Accountability”

Meyers started in an era when “cybersecurity” did not exist. There was just “IT,” and everyone did everything. That lack of specialization produced preventable harm;  misconfigured remote access where a “guest” credential quietly had admin rights, cavalier attitudes toward email and user surveillance (Remember when “I read your email” bumper stickers were a thing.), and a culture that treated privacy as a corporate secrecy issue rather than a people-protection mandate. The lesson for compliance? Risk thrives in ambiguity. When roles and ownership are unclear and authority is not defined, controls are merely a facade.

Meyer contrasts the U.S. and EU not as a legal vs. legal comparison, but as a philosophical split. In Europe, privacy is government-centric and procedurally channeled through regulators; in the U.S., it is more individual-centric and notification-driven. California’s rules can even exceed the practical strictness of the GDPR in certain respects. For compliance leaders, that means your privacy posture must be designed around intent (IE., who is protected), governance (IE., who decides), and operational execution (IE., who does the work) and not just a citation list.

Data Has a Life Cycle—Treat It That Way

One of Meyers’ most pointed critiques is that organizations hoard data without a purpose or end-of-life discipline. If you keep 30 years of email, do not be surprised when eDiscovery asks for all 30. The habit of “keep it all, we might need it” is the enemy of proportional risk. Compliance should drive a business-backed data minimization program with explicit retention schedules tied to legal, operational, and risk rationales and then audit for enforcement. If the business cannot articulate why it needs a dataset today and in the future, that data is a liability, not an asset.

Fix the Operating Model: Privacy Is Not a Side Gig for Security

Meyers has observed the exact misalignment play out repeatedly: privacy responsibility is often assigned to Legal or Compliance, but Cybersecurity typically handles the work and associated expectations. CISOs are asked to “own” controls for which they lack budgetary authority or policy ownership. Legal “owns” privacy on paper, but it is not integrated into cyber operations. Meyer is clear that the cure is governance, not heroics: establish a cross-functional steering committee (including Legal, Security, Compliance, IT Ops, and the business) with clear charters, shared KPIs, and defined decision rights. Diversity matters here; mix senior leaders with younger employees and varied backgrounds to avoid blind spots. The first agenda item of that committee should be ruthless purpose-alignment: “Why do we have this data? Do we still need it?”

Put Risks on One Page—and Make It Everyone’s Page

While cybersecurity tooling is often automated and technical, Meyers recommends one deceptively simple instrument to unite the disciplines: a shared risk register. GRC teams already live in this world. You should bring Security into it and treat security events, control weaknesses, and privacy exposures as entries that share owners, mitigations, and review cadences. If the CISO, Chief Compliance Officer, and General Counsel are not reading, updating, and arguing over the same risk register, you do not have a single source of truth or a shared sense of urgency.

Breach Reality: Precision Beats Blanket Notification

“Assume breach” is not fatalism; it is a sign of professional maturity. Meyers highlights the emergence of data security posture management (DSPM) solutions that not only identify exposures but also determine who actually owns the data that was accessed. That allows for targeted notifications — “these 15 people, not 500,000 customers” — and saves both real money and reputation. For the compliance function, the key point is proportionality; your incident playbook should pair legal thresholds with data lineage and ownership maps, ensuring a fast, accurate, and respectful response to individuals.

Agentic AI: Accountability Without a Face

Agentic AI changes the rules. Agents act without asking, talk to other agents, and traverse systems and data at machine speed. They also obscure accountability because the human “operator” may interact with one agent while three others are making consequential decisions out of view. This breaks the legacy consent and audit paradigms, demanding new guardrails: identity and authorization that can follow agents, granular logging of agent-to-agent interactions, and data lineage that respects privacy scopes. From a compliance lens, agentic AI requires you to rewrite playbooks on consent, purpose limitation, and lawful processing, before deployment, not after the first mishap.

Storytelling: The Culture Carrier for Security and Privacy

Meyers’ long connection to San Diego Comic-Con may seem far removed from cybersecurity. Yet when you see a cybersecurity team finally “get it” when you swap a nameless attacker for “Lex Luthor” in a tabletop. That is not playing to pop culture; rather, it is cultural engineering. Humans adopt guardrails that they emotionally understand. If your privacy training or AI oversight policy can be told as a story, with villains, flawed heroes, and a clear “why,”  you improve retention, reduce resistance, and create connective tissue across silos. Compliance is, at its core, applied storytelling backed by controls.

Robert Meyers traces the evolution from undifferentiated IT to today’s specialized privacy and cybersecurity disciplines, emphasizing how poor role clarity and indiscriminate data retention have caused preventable harm for decades. He frames the U.S.–EU divide as a philosophical one, between individual-centric versus regulator-centric approaches, while urging companies to stop treating privacy as a side project for Security when Legal nominally “owns” it. The solution involves a cross-functional steering committee, a shared risk register, and purpose-driven data lifecycle governance.

Meyers underscores “assume breach” realism and highlights new DSPM tooling that enables precise, owner-level breach notification instead of blanket, costly responses. Looking ahead, agentic AI creates accountability gaps as autonomous agents act and collaborate out of human view, demanding fresh guardrails for identity, consent, lineage, and logging. Finally, Meyers champions storytelling (yes, even Comic-Con-style narratives) to make security and privacy relatable, and advocates for cross-training, with privacy professionals learning security and vice versa, so organizations can speak a single operational language from the boardroom to the SOC.

Categories
Great Women in Compliance

Great Women in Compliance – Catching Up with the OG GWIC with Mary Shirley

Welcome to the Great Women in Compliance podcast with Hemma Lomax and Lisa Fine, sponsored by Corporate Compliance Insight and a part of the Compliance Podcast Network.  My guest today isn’t really a guest; she’s so much more.  She is an architect of GWIC, my first partner in compliance, and my first compliance friend, who remains a dear friend to this day.  She coined the phrase “Send the Elevator Back Down,” taught me about tall poppy syndrome, and I am still using her cheat codes.  Of course, it’s Mary Shirley!

Mary, can you update everyone on all the cool things that have been happening since you became, as we call it, #GWICemerita?

As a global compliance leader who has lived in several countries and now three very different states in the US, what do you see as the principles of a “culture of integrity” that apply to any business, regardless of geography or industry?

  • While there have been changes in US laws, particularly the FCPA, and newer laws in the EU and the UK, among others, are you seeing any shifts in how to define – or communicate – a culture of integrity?
  • You have compiled a list of questions for job seekers to ask about the terms of compliance programs and a culture of integrity. What do you think is the most revealing one and why?
    • Mine is “Can I talk to my predecessor?”

I look forward to seeing you very soon at SCCE CEI.  You and Matt Kelly are presenting “AI Governance for N00bs: A Beginner’s Guide for the Non-Tech Compliance Practitioner” on Sunday to kick off the event.

  • What do you see as the biggest opportunities for compliance professionals to use AI and machine learning?
  • What challenges do you see for integrating AI and machine learning into their compliance program, and how should we approach it?
  • What about the algorithmic bias?
  • It seems like ethics and compliance are being welcomed as “partners” at the AI governance table. What do you think is the most significant reason for this shift, and what can a compliance professional do to ensure they maintain that strategic seat at the table?

When you think about the first 200 episodes, do you have a specific non-substantive, non-podcast memory that sticks out to you?  Besides the origin story – which I still tell!