Categories
AI Today in 5

AI Today in 5: September 4, 2026 the Cutting False Positives Edition

Welcome to AI Today in 5, the newest edition to the Compliance Podcast Network. Each day, I will bring to you 5 stories about AI stories to start your day. Sit back, enjoy a cup of morning coffee and listen in to the AI Today In 5. All, from the Compliance Podcast Network. Each day we consider four stories from the business world, compliance, ethics, risk management, leadership or general interest about AI.

  1. Using Agentic AI to cut false positives in AML.(FinTechGlobal)
  2. The compliance gap in AI notetakers. (InvestmentNews)
  3. 3 paths forward for AI in healthcare. (HealthcareFinance)
  4. AI adoption gaps in finance. (FFNews)
  5. Looking for AI proof assets. (WSJ)

For more information on the use of AI in Compliance programs, my new book, Upping Your Game. You can purchase a copy of the book on Amazon.com. To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out my latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com

Categories
Blog

The NBA/Clippers Investigation: Part 1- A Compliance Failure in Five Acts

Over the next five blog posts, we will consider how commercial pressure, weak controls, and leadership decisions turned a salary-cap rule into an enterprise-wide governance failure. Today in Part 1 we summarize those compliance failures.

The most dangerous compliance failure is not ignorance of the rules. It is knowing the rules, receiving targeted training, having a history of prior violations, and then creating a process that appears compliant while delivering a prohibited result. That is the central compliance lesson from the investigation into the LA Clippers and Kawhi Leonard.

The independent investigators’ report, prepared by the law firm Wachtell, Lipton, Rosen & Katz, concluded that the Clippers violated the NBA’s salary-cap circumvention rules through a pattern of transactions involving Leonard, his representatives, team executives, and four companies doing business with the organization. This is a sports story, but it is also much more. It is a case study in executive accountability, third-party risk, conflicts of interest, internal controls, reporting failures, organizational culture, and board oversight.

The Investigation

The matter began after the September 2025 podcast Pablo Torre Finds Out reported allegations involving a four-year endorsement agreement between Leonard and Aspiration Partners, a sustainability services company that later entered bankruptcy. Torre won a Pulitzer Prize for his podcast reporting. Thereafter the NBA retained Wachtell Lipton to investigate. The inquiry eventually expanded beyond Aspiration to include endorsement agreements involving Boingo Wireless, Daktronics, and Lockton Insurance.

Investigators conducted 73 interviews of 60 people and reviewed more than 200,000 pages of documents. They interviewed Clippers owner Steve Ballmer, President of Business Operations Gillian Zucker, President of Basketball Operations Lawrence Frank, Leonard, and Leonard’s uncle and then-business manager, Dennis Robertson (Uncle Dennis). Third-party cooperation varied. Aspiration’s bankruptcy trustee and Daktronics provided substantial assistance, while other parties reportedly limited or refused cooperation.

The resulting 36-page report is a summary, not a complete presentation of the evidence. Nevertheless, the investigators concluded that the record was sufficient to establish multiple violations. The misconduct unfolded in five acts.

Act One: A Known Rule and a Known Risk

The NBA’s circumvention rules broadly prohibit teams from providing players with compensation, business opportunities, or anything else of value outside their authorized player contracts. The rules also prohibit attempts, solicitations, inducements, and informal understandings intended to produce such benefits. The rule has a simple underlying principle: to prevent salary cap circumvention.

The NBA had given teams practical examples. A team representative could not recommend a player to a sponsor for an endorsement arrangement or initiate and facilitate that relationship. If a sponsor independently asked about a player, the team’s permissible response was generally limited to supplying the player’s or agent’s contact information.

The Clippers were not operating in unfamiliar territory. In 2015, the NBA fined the team $250,000 for conduct involving a potential endorsement opportunity for DeAndre Jordan. In 2019, the NBA investigated demands reportedly made by Uncle Dennis during Leonard’s free agency. The League subsequently required teams to report improper solicitations for benefits, even when the team rejected the request.

In December 2019, the NBA provided circumvention training to the Clippers’ senior leadership, including Ballmer, Zucker, and Frank. Investigators reported that all three understood the rule. This is the first compliance lesson: knowledge is not a control. Training can establish awareness, but only governance, monitoring, escalation, and accountability can translate awareness into compliant conduct.

Act Two: Pressure From a Powerful Stakeholder

According to the report, Uncle Dennis pressed the Clippers to help Leonard obtain approximately $10 million per year in off-court income. He communicated his demands to Frank, Ballmer, and Zucker. The report found no evidence that these demands were reported to the NBA, even though the reporting rule had been created in response to earlier concerns involving Robertson. Nor did investigators find evidence that senior leaders clearly instructed him to stop making the requests.

Instead, contemporaneous notes reflected assurances that Clippers’ personnel would help Leonard achieve his financial goals. Uncle Dennis requested a plan, a pipeline of potential companies, and more frequent communication. This was a decisive moment. The organization had received a red flag from the highest-risk source, involving one of its most commercially valuable stakeholders. The control that mattered was not another training presentation. It was the ability to say no, document the response, escalate the demand, and make the required report.

Act Three: The Commercial Ecosystem Becomes the Delivery Mechanism

During six days in June 2020, Zucker sent introduction emails connecting Uncle Dennis with Boingo, Daktronics, and Lockton. Each email was written as if the company had requested the introduction. Investigators did not credit that explanation. They concluded that the introductions were initiated by the Clippers in response to Uncle Dennis’ demands.

Leonard subsequently entered into endorsement agreements with all three companies. The agreements provided for $18 million in total compensation, all of which was paid by August 2021. Investigators identified several unusual characteristics: the agreements were negotiated rapidly during the COVID-19 shutdown, imposed minimal performance obligations, were not publicly announced, and produced little evidence of meaningful activation.

At the same time, each company was pursuing lucrative business with the Clippers or the team’s arena. The report described consulting agreements, substantial advance payments, and perceived links between vendor business and payments to Leonard. The investigators found the Daktronics arrangement particularly direct. They concluded that Clippers personnel proposed using an endorsement agreement with Leonard as part of a “spend back” arrangement connected to Daktronics’ pursuit of the Intuit Dome scoreboard contract.

Here, third-party risk and procurement risk converged. The vendors were not merely outside parties. They allegedly became the mechanism through which the prohibited benefit was delivered.

Act Four: Aspiration and the Appearance of Legitimacy

Aspiration’s relationship with the Clippers was substantial. It included a long-term sponsorship agreement, sustainability services for the Intuit Dome, and a $50 million personal investment by Ballmer. The report concluded that Zucker raised the possibility of an Aspiration endorsement agreement with Leonard, recruited a business agent to help structure it, communicated proposed financial terms, provided input on the term sheet, and remained involved after the formal introduction.

The final agreement called for $48 million in cash and equity over four years. Investigators described the compensation as extraordinarily high in relation to Leonard’s obligations and endorsement profile. The most significant issue involved a separate agreement under which the Clippers would purchase sustainability services for the Forum. Early documents contemplated $7 million in annual business for Aspiration, matching the annual cash component of Leonard’s endorsement agreement. When Aspiration’s co-founder threatened to abandon the Leonard agreement unless the Forum transaction was completed, internal Clippers’ communications reportedly reflected awareness of that linkage. Ballmer nevertheless approved the Forum agreement.

The compliance lesson is substance over form. A formal contract, documented introduction, consultant analysis, or stated business purpose does not end the inquiry. Compliance must ask who initiated the transaction, who benefits, whether the economics make sense, and whether supposedly independent agreements are actually connected.

Act Five: Expenses, Reporting, and the Control Environment

Investigators also identified hundreds of instances in which the Clippers paid personal travel, accommodations, gifts, and ticket expenses for Leonard, his family, or Uncle Dennis without making the deductions required by NBA rules. Frank was responsible for authorizing the payments.

The report further concluded that Ballmer, Zucker, and Frank failed to report Uncle Dennis’ improper solicitations. These findings move the case beyond isolated dealmaking. They suggest failures in expense management, accounts payable, executive approvals, legal review, reporting, and compliance escalation. Under the COSO Internal Control–Integrated Framework, internal controls support operational, reporting, and compliance objectives. They must operate across the enterprise, particularly where multiple transactions point toward the same underlying risk.

The Compliance Program Test

The DOJ’s Evaluation of Corporate Compliance Programs organizes its analysis around three fundamental questions:

  1. Is the compliance program well designed?
  2. Is it adequately resourced and empowered to function effectively?
  3. Does it work in practice?

The Clippers matter raises all three. The DOJ Organizational Sentencing Guidelines similarly require risk assessment, appropriate authority for compliance personnel, monitoring and auditing, confidential reporting mechanisms, consistent enforcement, and remediation. Prior misconduct must inform future risk assessment and control design.

The Caremark Doctrine provides the board-level perspective. The Delaware Supreme Court’s decision in Marchand v. Barnhill emphasizes that directors must make a good-faith effort to establish and monitor reporting systems addressing mission-critical compliance risks. The relevant point here is not that Caremark liability has been established. It is that known, central risks require reliable information to reach governing authorities, followed by documented oversight and action.

The Consequences

Following the report, the NBA imposed significant penalties. The Clippers were fined $30 million and required to forfeit five first-round draft picks. Ballmer received a one-year suspension, Zucker a one-year unpaid suspension, and Frank a six-month unpaid suspension. The organization was placed under a five-year compliance and monitoring program. Leonard was required to pay $700,000, and Robertson was prohibited from conducting business with NBA teams for five years.

These penalties demonstrate that governance failures can create consequences far beyond the value of the underlying transactions.

Compliance Takeaways

Compliance professionals should take five immediate lessons from this matter:

  • Treat prior violations as mandates for verified remediation, not completed training exercises.
  • Map interconnected relationships among vendors, executives, customers, agents, and other powerful stakeholders.
  • Require independent review when multiple agreements may produce benefits for the same individual.
  • Test the economic substance of transactions, including pricing, deliverables, advance payments, and ultimate beneficiaries.
  • Give compliance the authority to escalate and stop transactions involving senior executives or strategically important individuals.

The question is not whether an organization has rules. The question is whether its compliance system can withstand pressure from the people the business most wants to satisfy. In Part 2 (after Labor Day), we will examine the conflicts of interest embedded in the Clippers’ commercial ecosystem and consider how organizations should govern transactions where sponsors, vendors, executives, personal relationships, and individual benefits intersect.

Categories
Blog

Odyssey Week: Leadership: Penelope’s Loom: Integrity Under Pressure

Ed. Note: I was finally able to see the movie The Odyssey. To say it blew me away was an understatement. Even though it didn’t follow Homer’s work precisely or use ancient Greek, I still thought it was great cinema. Anytime you get people talking about the Greek classics, that is a win in my book. So check out the movie and enjoy it. Anne Hathaway was great as Penelope.

Penelope does not get enough credit. Odysseus gets the monsters, the storms, the speeches, the disguises, and the dramatic return. He gets the action scenes. Penelope gets the waiting. If the movie version made one thing clear, such an interpretation sells her short—very short.

Penelope is not simply waiting. She is governing under pressure. Opportunists surround her. The suitors have occupied her home, consumed her resources, pressured her to choose one of them, and treated uncertainty as an invitation to abuse. Odysseus is gone. Authority is contested. Telemachus is young. The house is under stress.

So Penelope does something quietly brilliant. She promises to choose a suitor after she finishes weaving a burial shroud for Laertes. By day, she weaves. By night, she unweaves. She buys time without surrendering the core issue. It is not flashy. It is not a thunderbolt. It is not a sword fight in the hall. It is disciplined patience under pressure.

That is why Penelope belongs in the leadership section of a compliance odyssey. She reminds us that integrity is not always dramatic. Sometimes it looks like refusing to sign the certification, approve the vendor, bless the transaction, release the report, close the investigation, or accept the explanation simply because everyone is tired of waiting.

The Corporate Translation

Penelope is the leader who understands that time pressure is not the same as good governance. Every organization has Penelope moments. The quarter is closing, and someone wants revenue recognized now. A third party has not cleared diligence, but the business sponsor says the relationship is too important to delay. A certification is due, but the control owner is not comfortable with the evidence. A board report needs to go out, but the investigation findings are still incomplete. A product launch is scheduled, but privacy, security, or regulatory concerns remain unresolved. A customer is demanding speed. A senior executive wants closure. The team is exhausted.

And then someone says the magic words: “Can we just move forward?” That is the sound of the loom beginning to tighten. Penelope’s lesson is not that delay is always virtuous. It is not. Delay can be passive, political, cowardly, or evasive. But some delay is not avoidance. It is governance. The question is whether the organization can tell the difference.

Defensible Delay Is Not Obstruction

In compliance, delay has a bad reputation. That is why compliance is known as The Land of No, populated by Dr. No. Sometimes it is the Department of Business (Non)Development. Whatever the moniker is, this is why business leaders often hear “we need more time” as “compliance is blocking the business.” Sometimes that criticism is fair. Compliance functions can be too slow, too opaque, too academic, or too disconnected from commercial reality. A policy review that disappears into a black hole is not governance. It is bureaucracy with a ticket number.

But there is another kind of delay: defensible delay. Defensible delay has a reason. It has an owner. It has a process. It has a timeline. It identifies the unresolved risk and the information needed to make a decision. It is communicated clearly. It is proportionate to the issue. It protects the company from making a false, rushed, or poorly documented commitment.

Penelope’s loom was not random. It had a purpose. It created time when the available choices were bad. That matters in corporate life. A leader who refuses to approve a questionable vendor is not “being difficult” if the due diligence is incomplete and red flags remain unresolved. A CFO who refuses to sign a certification without adequate support is not “overly cautious.” A compliance officer who asks for more facts before closing an investigation is not “dragging things out.” A privacy officer who pauses a product launch because sensitive data controls are not ready is not “anti-innovation.” Sometimes the most ethical sentence in business is “Not yet.”

Culture Is Built in the Waiting

Corporate culture is often revealed by what happens during delay. When a leader says, “We need more information,” does the organization respect the concern? Or does it start applying pressure?

Does the business provide the missing evidence, or does it complain that Legal is slowing things down? Does management support the control owner, or quietly ask for a more “practical” answer? Does the board ask why the delay is necessary or simply demand that the issue be resolved before the next meeting? Does compliance explain the path forward or hide behind process? These moments shape culture.

The DOJ’s Evaluation of Corporate Compliance Programs (ECCP) asks whether a compliance program works in practice, whether senior and middle management have encouraged or discouraged compliance through their words and actions, and whether compliance personnel have sufficient authority, resources, and access to function effectively. It also asks whether employees have practical guidance and know when to seek advice.

That is Penelope’s world. Culture is not only what the company says about integrity. It is whether the company protects people who slow down a decision for the right reasons. If every delay is treated as disloyalty, employees learn to approve first and worry later. That is not agility. That is ethical surrender in business casual.

Ethical Resilience Under Pressure

Penelope is not powerful in the obvious way. She does not command an army. She does not remove the suitors by force. Her resilience is quieter. She endures pressure without surrendering judgment. That kind of resilience is essential in compliance.

Ethical resilience is the capacity to hold the line when the organization is tired, when the facts are inconvenient, when the deadline is real, and when compromise would be easier. It is the controller who insists on evidence. The manager who escalates a concern before approving the payment. The compliance officer who says the investigation is not complete. The board member who asks whether management’s optimism is supported by testing. The executive who tells the team, “We will not do this the wrong way just because the right way takes longer.”

The DOJ Justice Manual states that prosecutors should evaluate a company’s commitment to fostering a strong culture of compliance at all levels, including how the company incentivizes employee, executive, and director behavior through discipline, complaint handling, and compensation plans. That means ethical resilience cannot depend on heroic individuals. The system must support it.

People must know they will not be punished for raising legitimate concerns. Performance goals must not make ethical delay impossible. Leaders must model patience when facts matter. Governance bodies must ask for evidence, not just reassurance. Compliance must help the business move responsibly, not merely tell it to wait. Penelope’s loom works because she has discipline. A company’s compliance program works because discipline is built into the system.

What a Better Compliance Program Does

A better compliance program helps the organization make disciplined decisions under pressure. It defines which approvals require evidence. It gives control owners authority to withhold certifications when support is inadequate. It builds escalation paths for unresolved risk. It documents exceptions and unresolved issues. It trains leaders on how to respond when employees raise concerns. It tracks aging remediation items. It distinguishes between acceptable risk, unresolved risk, and ignored risk. It also makes delay visible.

If a vendor approval is paused, document the reason. If leadership cannot sign a certification, they should know what evidence is missing. If an investigation remains open, there should be a plan. If a product launch is delayed, stakeholders should understand which control or risk issue must be resolved. That is not bureaucracy. That is governance with receipts.

The Compliance Takeaway

Penelope’s loom is a lesson in ethical leadership. She shows that integrity is not always a grand public stand. Sometimes it is a disciplined refusal to be rushed into a bad decision. Sometimes it is the courage to say, “The facts are not ready.” Sometimes it is the wisdom to buy time without losing the trust of those who are waiting.

For compliance officers and business leaders, the challenge is to build organizations where prudent delay is respected and avoidance is exposed. Do not approve the questionable vendor because everyone is tired. Do not sign the certification because the calendar is unforgiving. Do not close the investigation because the subject is influential. Do not bless the transaction because the business has already promised the outcome.

Weave if you must. Unweave if you must. But know why you are doing it, tell the truth about the risk, and make sure the delay serves integrity rather than fear. That is Penelope’s gift to corporate compliance. She reminds us that sometimes the strongest leader in the room is the one patient enough not to make the wrong decision.

Final Thoughts

Taken together, the leadership lessons from The Odyssey show that corporate compliance is not sustained by slogans, heroes, or good intentions alone. The Trojan Horse reminds us that cleverness without discipline can become a control failure; Athena shows that wise counsel must have real authority, resources, and access to challenge power; and Odysseus demonstrates that even brilliant, high-performing leaders can become compliance risks when success becomes a shield from scrutiny.

Telemachus then carries the lesson into succession, showing that governance must survive the absence of the indispensable leader, with authority, control, ownership, and escalation clearly embedded into the business. Penelope completes the leadership arc by reminding us that integrity under pressure is often quiet, patient, and disciplined: the willingness to say “not yet” when facts are incomplete, risks are unresolved, and everyone else wants to move forward. Together, these stories teach that ethical leadership is not simply about winning the battle or reaching Ithaca; it is about building a compliance culture strong enough to resist shortcuts, challenge heroes, survive transitions, and hold the line when pressure is highest.

Categories
Compliance Into the Weeds

Compliance into the Weeds: Broken Execution in Day-to-Day Compliance Operations – The BAE Enforcement Action

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into compliance-related topics, literally going into the weeds to explore a subject in greater depth. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss the recent BAE export control enforcement action.

Matt views the BAE export control enforcement action as a strong example of how ITAR compliance failures often stem from routine breakdowns in day-to-day operations rather than dramatic smuggling schemes. He notes that BAE’s U.S. subsidiary sent technical information and services overseas without proper licenses, including to China and even some allied countries, showing that export controls apply to both data and services, not just physical weapons. Kelly argues that the case reveals common compliance weaknesses such as poor training, unclear procedures, weak system warnings, and employee turnover that can leave staff unsure of the rules. His broader point is that companies in export-controlled industries must maintain current licenses and build strong, monitored compliance programs because governments will continue using export controls as an important geopolitical tool.

Key highlights:

  • ITAR data shipments trigger BAE’s $36 million penalty
  • Broken execution in day-to-day compliance operations
  • Export-control warnings before sensitive file transmission
  • Missing Red-Flag Prompts in Export Control System
  • Self-Disclosed, Cooperated, Remediated, Monitored by Another Name

Resources:

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred the Davey, Communicator, and W3 Awards, all for podcast excellence.

Categories
AI Today in 5

AI Today in 5: September 1, 2026, The Increased Burden Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. The new burden for compliance in the age of AI. (Forbes)
  2. How agentic AI is reshaping financial crime compliance. (AML Intelligence)
  3. ChatGPT says it didn’t steal Apple employees; rather, Apple has ‘poor offboarding.’ (WSJ)
  4. ChatGPT faces tougher safety issues in the EU. (FT)
  5. Banks are rethinking legacy SW costs to fund AI. (Asian Banking & Finance)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
AI Today in 5

AI Today in 5: August 31, 2026, The AI for Mental Health Treatment Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. AI implementation with compliance. (PharmExec)
  2. AI redefining regulation and compliance. (FinTechGlobal)
  3. AI on reading the body’s signals. (MedCityNews)
  4. Should you use AI for mental health treatment? (WSJ)
  5. Reimagining health care delivery through AI. (Cleveland)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

Dolly Parton and the Compliance Value of a Life Well Governed

Dolly Parton died this week. Her death closed one of the most remarkable careers in American entertainment, but it did not close the institutions, ideas, and expectations she built. For corporate compliance professionals, that durability is what makes her story more than a tribute. It becomes a lesson in how values can be converted into governance. Today I want to honor Parton, what she did, and what she stood for, and perhaps hope that her life will inspire all of us to be just a little better.

Parton was one of twelve children. Parton began singing on local radio and television as a child and appeared at the Grand Ole Opry at thirteen. She wrote her first song at age 6. She moved to Nashville after high school, established herself as a songwriter, and became a national star through The Porter Wagoner Show. She then built a solo career that crossed country, pop, film, television, theater, publishing, tourism, and philanthropy. She recorded more than fifty albums, wrote roughly 3,000 songs, won ten Grammy Awards, and created works such as “Jolene,” “I Will Always Love You,” and “9 to 5” that became part of the American vocabulary. One of the most amazing facts I learned while researching this piece was that “Jolene” and “I Will Always Love You” were written on the same day. How is that for creative inspiration?

Parton did not run a corporate compliance program, and her career should not be forced into that frame. Yet she demonstrated something every CCO and Board of Directors needs to understand: culture becomes credible when stated values, hard decisions, operating systems, and visible conduct reinforce one another over time. Her public identity rested on kindness, independence, dignity, humor, and respect. She repeatedly made those commitments tangible in contracts, businesses, philanthropy, and crisis response.

Her entrepreneurship deserves equal attention. Parton moved from performer to owner, producer, publisher, and partner, most visibly through Dollywood and the enterprises built around it. The portfolio was diverse, but it was not random. Music, storytelling, family entertainment, Appalachian identity, hospitality, and community investment all reinforced a coherent promise. Compliance professionals should recognize the governance advantage of that clarity. Diversification creates new legal, operational, third-party, and reputational risks, but a stable purpose helps leaders decide which opportunities fit, which controls must travel with the business, and which deals to decline.

Independence Before Applause

Parton understood the difference between access to power and surrender to it. She left Porter Wagoner in 1974 to build an independent career, expressing gratitude for the partnership without allowing it to define her future. She later declined an opportunity for Elvis Presley to record “I Will Always Love You” when his manager demanded a share of the publishing rights—saying no cost her an extraordinary short-term opportunity. Retaining ownership preserved the long-term value of her work, especially when Whitney Houston’s recording became a worldwide success. Business Insider called it “her smartest business move.”

That decision should resonate with compliance leaders. Independence is not a paragraph in a charter. It is the authority to resist pressure when revenue, status, or a powerful executive makes acquiescence attractive. A CCO needs direct access to the board, control over investigative escalation, sufficient resources, and protection against retaliation. Chuck Watson once said, “Sometimes the best deal is the one you don’t make.” A board should test whether that independence works when it is expensive, inconvenient, and unpopular. If compliance can say no only when nothing important is at stake, it is not independent.

Purpose Made Operational

Parton’s philanthropy offers an equally powerful lesson in program effectiveness. She created the Dollywood Foundation in 1988 to improve educational outcomes in her home county. Its Buddy Program paired students and offered a financial incentive for graduation; the dropout rate for the participating classes fell from 35 percent to 6 percent. In 1995, inspired by her father’s inability to read and write, she launched the Imagination Library. What began in Sevier County became a network operating across five countries that has delivered more than 300 million free books to young children.

This was not the purpose of branding. It was purpose translated into a defined population, a repeatable delivery model, local partnerships, funding, data, and measurable results. That is the same transition the Department of Justice asks companies to make when it evaluates whether a compliance program is well designed, adequately resourced, and working in practice. A value in the code of conduct must become an owner, a control, an escalation path, testing, and remediation. Intent is the beginning of a compliance program, not proof of one.

Listen to the People Who Experience Power

Parton’s film and song “9 to 5” gave popular form to workplace realities many employees already knew: power can be abused, unfairness can become routine, and people with the least authority often carry the greatest burden. The song endured because it recognized the lived experience behind organizational charts. It made a workplace issue visible without turning the people affected into abstractions.

Compliance programs fail when they listen only upward. Hotline statistics, exit interviews, culture surveys, investigation themes, retaliation allegations, and manager-level trends must reach leaders in a form that supports action. Boards should ask whether employees believe they can speak without losing status, opportunity, or employment. They should also ask whether the organization learns from weak signals before they become red flags. A speak-up system is not effective because a telephone number exists. It is effective when people trust the process and see consistent, fair outcomes.

Trust Earned Through Response

Parton’s businesses remained closely connected to the community that formed her. Dollywood became Sevier County’s largest employer, while its stated operating culture emphasizes hospitality, authenticity, collaboration, and respect. The company supports employee development, including tuition assistance. When wildfires devastated East Tennessee, Parton helped organize direct support for affected families. During the COVID-19 pandemic, her $1 million gift established a Vanderbilt research fund that supported work connected to the Moderna vaccine.

The compliance lesson is that reputation is a lagging indicator of accumulated conduct. Trust is built before a crisis through thousands of ordinary decisions about employees, customers, communities, and counterparties. A crisis tests it through the speed, fairness, transparency, and competence of the response. A company cannot purchase credibility with a campaign after years of contrary conduct. The best crisis communication remains a well-governed response supported by facts, accountable owners, and visible follow-through.

A Board Agenda Worthy of the Lesson

Parton’s legacy was unusually broad, but its organizing logic was simple. Know what matters. Protect it when pressure arrives. Build systems that carry values beyond the founder. Listen to people whose voices are easiest to overlook. Measure whether the work changes outcomes. Repeat the conduct long enough that stakeholders can rely on it.

  • For directors, that logic produces five practical questions. What principles will the company not trade away for a transaction or quarterly target?
  • Does the CCO possess real independence, resources, information, and access?
  • Which data prove that stated values operate at the employee and third-party level?
  • Are speak-up and investigation systems producing trust, learning, and remediation?
  • When the company faces a crisis, can the board see decisions, owners, deadlines, testing, and closure rather than a record showing only that management made a presentation?

Dolly Parton understood that a carefully created image can open a door, but only character and performance can keep it open for seven decades. Compliance leaders often describe their goal as building a culture of integrity. Her career reminds us what that requires: independent judgment, operational discipline, attention to the less powerful, measurable impact, and consistency when no applause is guaranteed. That is not only a fitting business lesson from her life; it is a demanding standard for every organization that wants to be trusted.

Categories
AI Today in 5

AI Today in 5: August 26, 2026, The 4 Places Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Four places AI cuts paperwork in food compliance. (FoodIndustryExec)
  2. AI changing communications compliance. (UC Today)
  3. AI-powered compliance monitoring. (Plan Adviser)
  4. Americas want transparency around the use of AI in healthcare. (Pew Research Center)
  5. Nvidia becoming AI’s bank. (WSJ)

For more information on using AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Blog

From Gatekeeper to Navigator: Dr. Hemma Lomax on the Decision Intelligence Gap

Compliance failures are usually narrated backward. Once the outcome is known, every warning appears obvious, every missed escalation looks negligent, and every decision seems to point toward the result. The board asks who knew what and when. The investigation searches for the broken control. Management wants the person or moment that explains the failure.

Dr. Hemma Lomax has done it again, leading the discussion in the compliance community. Her most recent book, The Decision Intelligence Gap, asks compliance professionals to look earlier. What happened before the decision became visible? Which assumptions hardened into facts? When did reversal become more expensive? Who noticed something that never gained enough purchase to change the direction? The book’s central insight is that the distance between intention and execution is not space. It is an operating environment shaped by incentives, defaults, authority, silence, pressure, and the accumulated residue of earlier decisions.

That makes this an important book for CCOs, boards, in-house counsel, audit, risk, and business leaders. It is not a conventional compliance manual. It does not provide a new risk taxonomy or a checklist for program design. It offers something more foundational: a way to examine how organizational choices form while there is still time to influence them.

A Book About the Decisions Before the Decision

Lomax defines the Decision Intelligence Gap in two related ways. It is the distance between the responsibility people carry for decisions and the visibility they have into how those decisions form. It is also the space between intention and execution, where choice remains alive. The book develops that idea across five parts: how choice narrows, how decision architecture changes what remains possible, how leaders can redesign the environment, how organizations should respond when things go wrong, and how learning can scale.

The governing image is the trolley problem viewed upstream. Compliance professionals know the familiar last-minute choice between two unacceptable outcomes. Lomax is more interested in what happened before anyone reached the lever. Who laid the track? When did the brakes become unavailable? Which earlier choices reduced the available paths? This move from moral drama to decision architecture is the book’s most valuable contribution.

Several concepts give that architecture practical shape. The silent hijack occurs when a concern is heard but never alters the decision. The threshold paradox describes the point at which an option remains technically open but becomes materially more costly to exercise. Designed desperation arises when the system makes the wrong choice easier, safer, or more serviceable than the right one. Defaults then carry yesterday’s decisions forward until repetition begins to look like legitimacy. None of these concepts removes individual agency. They show why accountability must examine both the actor and the conditions the organization created.

Why Compliance Leaders Should Read It

The book challenges the compliance function’s instinct to become the gatekeeper for every uncertain choice. Lomax does not argue against approvals, bright lines, or specialist authority. Some risks require them. Her sharper point is that a program can become excellent at routing questions to experts while failing to build decision capacity in the business. The CCO answers the immediate question, but the next employee facing similar terrain remains dependent on the same escalation.

Lomax proposes a navigation layer instead. Expertise should travel without automatically taking ownership of the decision. Employees need to understand the objective, the boundary being protected, the conditions that change the answer, the discretion that remains local, and the threshold for seeking another perspective. This is a powerful description of compliance as a business discipline. It moves the function from permission provider to designer of better choices while preserving hard stops where the risk requires them.

Her discussion of speak-up culture is equally strong. The important question is not only whether employees are permitted to report. It is what speaking has come to require and what happens when the room responds. A concern may be incomplete, inconvenient, or wrong. If the first response demands a finished case, the organization may force one employee to do the collective work of noticing, investigating, proving, and solving before the signal deserves attention. Lomax’s idea of being safe to learn goes beyond psychological safety. It asks whether people can contribute uncertainty, revise a position, or discover they were wrong without losing the standing to participate next time.

This insight should reshape investigations. A bad outcome does not prove poor reasoning, and a good outcome does not validate the process that produced it. Lomax’s account of outcome bias provides a disciplined basis for distinguishing accepted risk, ordinary mistake, flawed reasoning, reckless conduct, concealment, and misconduct. The compliance lesson is straightforward: reconstruct the information state at the time of the decision before hindsight rewrites what was knowable. Accountability then becomes more precise, more credible, and more useful to the next decision.

Lomax’s architecture also sharpens the familiar effectiveness question. A policy may be well designed on paper yet fail because the decision environment rewards delay, makes escalation costly, or teaches employees that exceptions are easier to approve than to revisit. Monitoring should therefore test not only control completion but also control use: who bypasses, who escalates, which questions recur, where decisions stall, and whether learning from one matter changes the next. This is where the book connects most directly to modern compliance evaluation.

The Most Useful Tool: HQDM

The book’s most immediately deployable framework is High-Quality Decision Making, or HQDM. It records five elements in proportion to the significance of the choice: the objective and what the organization is actually optimizing for; the thresholds that materially change the answer; the options genuinely available at the time; the rationale connecting facts, assumptions, uncertainty, and choice; and the learning plan, including what to monitor and what would trigger reconsideration.

For compliance professionals, HQDM offers a practical bridge between governance and evidence. It can improve a third-party exception, an AI use-case approval, an investigation disclosure decision, a market-entry choice, or a board risk-acceptance decision. It also creates a contemporaneous reasoning trace that can later help separate a defensible decision from one that merely benefited from luck. Lomax wisely cautions against turning inspectability into surveillance. The record should preserve decision-useful reasoning, not every tentative thought.

The framework also fits the board’s oversight role. A board cannot manage every operating decision. Still, it can ask whether management has identified the objective, made critical assumptions visible, established escalation thresholds, considered viable alternatives, and defined the conditions for returning to the decision. That is a better oversight record than a slide showing that the policy was approved and the training was completed.

Where the Book Requires Compliance Translation

The Decision Intelligence Gap is intentionally a thinking book, not an implementation guide. Its metaphors are memorable, its research base is broad, and its questions are often excellent. Yet compliance teams will still need to convert those ideas into governance mechanisms, owners, data, testing, and metrics. The book explains why a navigation layer matters, but it does not provide a detailed operating model for building one across a global enterprise.

The same issue appears with decision traces. The concept is sound, but the compliance application requires careful design. Records can create discovery, privilege, privacy, retention, and employee-relations consequences. A proportionate trace needs risk tiers, approved fields, access controls, retention rules, legal-hold integration, and guidance on what not to record. Otherwise, a tool intended to make reasoning visible may produce defensive writing or concealment.

AI adds another layer. Lomax correctly warns that putting a human in the loop is meaningless if the human merely approves the system’s preferred answer. A true navigation layer should expose sources, assumptions, uncertainty, alternatives, and override routes. Compliance leaders will need to add the control architecture: data governance, access management, validation, bias testing, monitoring, audit logs, incident response, and clear human accountability. NIST AI RMF and ISO/IEC 42001 can help operationalize that part of the vision.

The Verdict

This is a thoughtful, humane, and unusually relevant book for the compliance profession. Its strength lies in refusing the easy choice between individual blame and system excuse. People retain agency, but they exercise it inside conditions that can make signals harder to share, boundaries harder to hold, and reversals harder to justify. Effective compliance must examine both.

CCOs should read The Decision Intelligence Gap not as a substitute for the DOJ’s Evaluation of Corporate Compliance Programs, COSO, investigations protocols, or AI governance frameworks, but as a connective operating philosophy. It explains why policies can be clear while decisions remain poor and why speak-up programs can be available. At the same time, silence persists, and why lessons learned can be documented while organizational capability barely grows. It is especially valuable for compliance leaders ready to move from owning answers to building an organization that decides, learns, and adapts with integrity.

Questions for CCOs and Boards

Decision visibility. Which high-risk choices are becoming expensive to reverse before they reach formal approval?

Speak-up response. What does the organization do with an unfinished concern, and what does that response teach the next employee?

Accountability. Can investigations distinguish a bad outcome from poor reasoning and a mistake from misconduct without losing either fairness or rigor?

Learning loop. Where do investigation findings, exceptions, overrides, and near misses change the conditions of the next decision?

Navigation. Is compliance increasing the business’s capacity to recognize thresholds and exercise sound judgment, or merely increasing the number of questions routed to Compliance?

Categories
Everything Compliance - Shout Outs and Rants

Shout Outs and Rants: AI, Investigations, Kickbacks and Kids

Welcome to a new season of Everything Compliance – Shout Outs and Rants. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, who joins returning regulars Jonathan Armstrong and Karen Moore for the next iteration of Everything Compliance Shout Outs and Rants.

  • Adam shouts out to the Boeing documentary Free Fall and Peter Robison’s book Flying Blind for lessons on culture, whistleblowers, and safety, and praises United Airlines for returning a plane to address a mechanical issue.
  • Rebecca raises a compliance training dilemma: employees using company AI tools to answer test or “test-out” questions, which may look like cheating and undermine training records in an investigation, yet could mirror desired real-world behavior if employees are expected to consult policies, compliance, or an AI chatbot when issues arise.
  • Jonathan recounts a scandal involving Scotland’s First Minister John Swinney, including FOI-revealed travel costs (about £45,000 in flights and significant car hire) allegedly contrary to policy and justified as meetings in Kentucky.
  • Karen shouts out to the 25 incoming Fordham MSL Introduction to Corporate Compliance students and reflects on the shift from accidental to intentional compliance careers.

Everything Compliance Shout Outs and Rants is a production of the Compliance Podcast Network.