Categories
Blog

The Muppet C-Suite: A Compliance Professional’s Guide to Culture, Controls, and Chaos Part 2: Miss Piggy as CMO: Marketing, Reputation, and the Compliance Risks of Visibility

This week, we are honoring the return of The Muppets for a 2026 Special Edition. I thought it would be fun to look at business leadership teams through the lens of The Muppets. Every compliance professional has worked with a Kermit, managed a Piggy, worried about a Gonzo, or tried to contain an Animal. This series uses the Muppet executive team as a framework to explore leadership, governance, innovation, operational risk, and corporate compliance through the lens of the DOJ’s Evaluation of Corporate Compliance Programs and modern governance expectations.

In Part 2, we consider Miss Piggy, for if Kermit the Frog represents tone at the top, Miss Piggy represents what happens when tone meets brand, ambition, ego, visibility, and commercial pressure. And rest assured, every organization has a Miss Piggy. She is talented, visible, confident, persuasive, and deeply invested in how the enterprise is perceived. She understands audience, image, influence, and reputation. She knows that attention has value. She also knows that if she is not in the spotlight, something has gone terribly wrong.

As Chief Marketing Officer, Miss Piggy would be a powerful business asset. She would elevate the brand, command the room, and make sure the organization was never ignored. But from a compliance perspective, she would also pose a familiar governance challenge: how does a company manage a high-performing, high-visibility executive whose role creates real legal, ethical, and reputational risks? The answer is not to silence her. The answer is to govern the risk.

Marketing Is a Front-Line Compliance Function

Too many organizations still treat marketing as a creative function sitting outside the core compliance risk universe. That is a mistake. Marketing is where corporate promises become public commitments. It is where product claims, customer expectations, sustainability statements, influencer relationships, social media messaging, and reputational positioning move from internal strategy to external representation. That makes marketing a front-line compliance function.

Miss Piggy, as CMO, would own risks tied to:

  • misleading advertising,
  • unsubstantiated claims,
  • endorsement and influencer disclosures,
  • ESG and sustainability messaging,
  • customer communications,
  • crisis response, and
  • and brand conduct.

A best-practices compliance program should recognize marketing as a risk-owning function, not simply a department that occasionally needs legal review. The DOJ’s Evaluation of Corporate Compliance Programs asks whether compliance is operationally integrated into the business. Marketing is one of the places where that question becomes real. If compliance is not in the marketing workflow, it is not fully embedded in the business.

The Danger of Brand Overconfidence

Miss Piggy’s greatest strength is also her greatest risk: confidence. Confidence sells. Confidence builds loyalty. Confidence moves customers, investors, employees, and markets. But when confidence becomes overclaiming, the organization moves from brand leadership to regulatory exposure.

This is especially true in today’s environment, where companies face scrutiny over public statements about the following:

  • product performance,
  • privacy and data use,
  • artificial intelligence,
  • sustainability,
  • diversity and inclusion,
  • supply chain integrity, and
  • and social responsibility.

A CMO may view these statements as brand positioning. Regulators, plaintiffs’ lawyers, customers, and investors may view them as representations. That gap is where risk lives.

Miss Piggy would be very good at bold public messaging. A mature compliance program would make sure ‘bold’ does not become misleading. Every material claim should be substantiated, reviewed, documented, and tied back to actual operational capability. From a compliance perspective, the issue is not whether the brand voice is strong. The issue is whether the company can prove what the brand voice says.

Pre-Clearance Is a Control, Not a Creative Insult

Miss Piggy would not naturally enjoy pre-clearance. No high-performing marketing executive wants to be told that a slogan needs review, a campaign needs substantiation, or a public commitment needs documentation. But a mature compliance program should not approach marketing review as censorship. It should approach it as a risk-based control.

Not every tweet, tagline, or internal graphic requires legal and compliance approval. But high-risk communications do. That includes:

  • comparative advertising,
  • pricing claims,
  • product capability statements,
  • sustainability or ESG commitments,
  • AI-related statements,
  • customer testimonials,
  • influencer content,
  • and statements made during crisis response.

The control should be risk-tiered. Routine materials move quickly. High-risk materials receive enhanced review. Urgent communications have an expedited escalation path. This is the difference between a compliance program that enables the business and one that becomes a bottleneck. Miss Piggy does not need a hall monitor. She needs clear guardrails, fast answers, and a process she can trust.

Incentives Drive Marketing Behavior

The ECCP places significant emphasis on incentives and discipline. That principle applies directly to marketing. If Miss Piggy is rewarded only for reach, growth, visibility, impressions, engagement, and market buzz, then the compliance program should not be surprised when risk increases. People respond to what the organization measures and rewards. A mature organization would include compliance-sensitive measures in the CMO’s performance evaluation, such as:

  • accuracy of public claims,
  • adherence to review protocols,
  • cooperation with Legal and Compliance,
  • quality of campaign documentation,
  • responsible use of influencers and third parties,
  • and responsiveness to identified risks.

This does not mean making marketing timid. It means making marketing accountable. A high-performing CMO should be rewarded not simply for attention, but for trustworthy attention. In a mature company, brand value and compliance discipline should reinforce each other.

Reputation Risk Is Enterprise Risk

Miss Piggy understands reputation instinctively. She knows that perception matters. Compliance professionals should understand the same thing. Reputation risk is not soft risk. It can affect:

  • customer trust,
  • employee morale,
  • investor confidence,
  • regulatory scrutiny,
  • litigation exposure,
  • and board credibility.

Marketing sits at the center of that risk. A company may have excellent internal policies, strong controls, and thoughtful governance. But if its public messaging outruns its operational reality, the entire enterprise becomes exposed.

That is why marketing claims must be connected to internal controls. If the company says it has a rigorous third-party due diligence program, Compliance should be able to prove it. If the company says its AI is responsible, explainable, or human-supervised, Legal, Compliance, IT, and Risk should be able to document the governance structure behind that claim. The brand cannot promise what the control environment cannot support.

Miss Piggy as a Culture Carrier

Miss Piggy is not merely a marketing executive. She is a culture carrier. People watch her. They follow her cues. They imitate her confidence, her urgency, and sometimes her impatience. In many organizations, highly visible commercial leaders shape culture more powerfully than formal ethics statements. This creates opportunity.

If Miss Piggy publicly supports ethical marketing, substantiation of claims, customer transparency, and responsible branding, she becomes a compliance multiplier. She can make compliance feel commercially relevant rather than bureaucratic. But if she treats review processes as obstacles, dismisses concerns as negativity, or celebrates outcomes without regard to the methods used, the message to the organization is equally clear. Tone at the top matters. So does tone from the spotlight.

The CMO and the Board

Boards should care deeply about marketing risk. That does not mean the board should review every campaign. It means the board should understand whether the company has governance over high-risk communications and reputation-sensitive claims.

Board-level questions might include:

  • What public claims are we making that could create legal or regulatory exposure?
  • Are ESG, AI, privacy, and product claims substantiated?
  • Who approves high-risk public statements?
  • How do Legal, Compliance, and Marketing coordinate?
  • Do incentives reward responsible growth or merely visibility?
  • What reputational risks are emerging from social media, influencers, or public commitments?

These are not academic questions. They go directly to governance, controls, and oversight.

5 Key Takeaways for the Compliance Professional

1. Marketing is a risk-owning function.

Brand messaging, public claims, influencer relationships, and reputation management must be part of the compliance risk assessment.

2. Public claims require proof.

Companies should be able to substantiate material statements about products, ESG, AI, privacy, supply chains, and corporate responsibility.

3. Pre-clearance should be risk-based.

Compliance should not review everything, but it must review high-risk communications through a clear and efficient process.

4. Incentives shape marketing risk.

CMOs should be evaluated not only on visibility and growth but also on accuracy, cooperation, documentation, and responsible brand conduct.

5. Reputation risk is governance risk.

Boards and senior leaders should treat marketing claims as enterprise risk when those claims affect trust, regulatory exposure, or corporate credibility.

From Piggy to Gonzo

Miss Piggy teaches compliance professionals that visibility must be governed. Brand power creates opportunity, but it also creates exposure when public messaging runs ahead of facts, controls, or operational capability. In Part 3, we turn from reputation risk to innovation risk. Gonzo, as Chief Innovation Officer, will take us into the world of experimentation, emerging technologies, AI governance, and the compliance challenge of ensuring that innovation does not outrun accountability.

Because every company eventually faces its Gonzo moment: the moment when someone says, “What could go wrong? ”

Categories
Innovation in Compliance

Innovation in Compliance: Capability without Governance Leads to Instability: Integrated GRC with Noor Aziz

Innovation spans many areas, and compliance professionals need not only to be ready for it but also to embrace it. Join Tom Fox, the Voice of Compliance, as he visits with top innovative minds, thinkers, and creators in the award-winning Innovation in Compliance podcast. In this episode,  host Tom visits with Noor Aziz, a Saudi Arabia–based governance, risk, and compliance professional with extensive ISO lead auditor credentials, internal audit and controls experience, and a growing focus on AI governance.

Noor argues that effective compliance must be practical and business-friendly—clear ownership, escalation, accountability, and evidence—so it still functions under operational pressure rather than becoming bypassed. She emphasizes leadership commitment, culture shaped by observed behavior, and integrated GRC to reduce silos that create duplication, inconsistent reporting, and “governance fatigue.” On AI, she frames governance as a board-level issue because adoption is outpacing accountability, creating future scrutiny around oversight, traceability, and defensibility; she notes, “capability without governance eventually creates instability.” She recommends change management, micro-learning, and ongoing communications, and concludes that governance is organizational infrastructure, not administrative overhead.

Key highlights:

  • Integrating Controls Audit and Risk
  • Breaking Down GRC Silos
  • Why AI Governance Is Board Level
  • Culture When Nobody’s Watching
  • Training That Actually Works: Microlearning and Ongoing Comms
  • Why Frameworks Fail in Execution
  • Maturing Governance for Business Value

Resources:

Connect with Noor Aziz on LinkedIn

Innovation in Compliance was recently ranked Number 4 in Risk Management by 1,000,000 Podcasts.

Categories
Red Flags Rising

Red Flags Rising: S01 E40: Jeff Stitt on the Craft of Compliance

Mike and Brent welcome to the podcast Jeff Stitt, the President of Acacia Trail Consulting. Jeff walks through how he went from becoming an engineer to being an on-the-spot chief compliance offer appointee in 1992 (01:36), to doing compliance at a bank (05:51), to having the opportunity to build and run a compliance program across Sub-Saharan Africa (08:00), and then to integrating a major acquisition into his company’s compliance program (12:10). Jeff explains how compliance programs are really “underwriting” the business’s activities (14:00) and then talks about the opportunity to build-out a global compliance program at a publicly traded company (16:30). Jeff concludes with a discussion about Acacia Trail (19:28) and what he’s seeing in the trade compliance space today (21:14). Mike and Brent then conclude with another edition of Brent Carlson’s Managing-Up (22:11).

Contact Jeff: jeff@acaciatrail.com

More about Jeff: https://www.linkedin.com/in/jeffreylstitt/

Contact Brent: brent@redflagsrising.com

More about Brent: www.redflagsrising.com

Contact Mike: michael.huneke@morganlewis.com

More about Mike: https://www.morganlewis.com/bios/michaelhuneke

Categories
Great Women in Compliance

Great Women in Compliance: Compliance Week 2026 Highlights with Nick Gallo

Team #GWIC and the #GWICfam were out in full force at the 2026 Compliance Week conference in Washington, DC.  Nick Gallo, a Great Gentleman in Compliance, was gracious enough (or agreed when he was “voluntold”) to be our roving reporter, asking people about their conference highlights, practical takeaways, and about AI in compliance, as that was one key event focus.

The episode also highlights the importance of collaboration, mentorship, and authentic connections in our community, and Compliance Week is such a great reminder of that. From discussions about everything from culture to analytics to celebrating Joe Murphy’s Lifetime Achievement Award, the conference reinforced both the rapid evolution of compliance and the generosity of the people working in it. You will hear the themes of friendships, learning, and shared purpose that continue to define the compliance community from our friends and colleagues.

Categories
Creativity and Compliance

Creativity and Compliance: Compliance 6-Pack: Part 4 – Using “Yes, And”

Tom and Ronnie continue their six-part series highlighting the role of improv in compliance.  This series links improv lessons to corporate compliance and some of the key tools and strategies Ronnie has brought from his former world of improv to the corporate compliance communications realm. In today’s Improv & Compliance Lesson 3, they focus on using “Yes, And” to Shift Compliance from the Office of No to a Collaborative Advisor.

Tom and Ronnie discuss the improv principle “Yes, and,” which means agreeing with the reality presented, dropping one’s agenda, and adding a new piece of information to build collaboratively. They explain how this mindset helps compliance move beyond the “office of no” by affirming and acknowledging business requests, then bridging to relevant risks, laws, and policies (e.g., gifts and entertainment, conflicts of interest) to problem-solve together without immediately shutting ideas down. Ronnie emphasizes “Yes, and” as both a personal communication technique and an organizational philosophy: learn the business, speak its language, and design simple, action-oriented, accessible policies and training that provide timely, embedded guidance. The episode ends with a preview of the next lesson on truth in comedy.

Resources:

Ronnie

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

Creativity and Compliance is a multiple-award-winning podcast and was recently honored as one of the Top 35 Podcasts on Creativity by Feedspot.

Categories
AI Today in 5

AI Today in 5: May 15, 2026, The Blind Spot Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

  1. Proactive ESH compliance. (Yahoo!Finance)
  2. The blind spot between cybersecurity and compliance. (UC Today)
  3. AI in healthcare: a checklist for compliance. (Morgan Lewis)
  4. Fiserv creates AI agents with banks. (American Banker)
  5. How AI is driving the digital supply chain. (Journal)

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on ⁠Amazon.com⁠.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on ⁠Amazon.com⁠.

Categories
Compliance Into the Weeds

Compliance into the Weeds: The DOJ Trainwreck and the Rising Risk Calculus for Compliance and Self-Disclosure

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore it more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly discuss how internal dysfunction at the U.S. Department of Justice is creating uncertainty for corporate compliance teams and corporations more generally.

Focusing on a reported turf battle between the long-standing Fraud Section in the Criminal Division, established in 1955 and central to FCPA enforcement and compliance guidance, and a newly created national Fraud Division, which was initially framed as targeting government benefits fraud. They argue the reorganization could drain expertise, reduce future DOJ guidance, and distort enforcement into politically selective actions, citing IBM’s $17 million settlement and an EEOC case involving The New York Times and Smartmatic’s experience. They also highlight DOJ staffing losses with a net 20% fewer lawyers, loss of experienced attorneys, reliance on inexperienced hires and bonuses, and warn that the volatility may chill voluntary self-disclosure despite DOJ messaging encouraging it.

Key highlights:

  • DOJ Train Wreck Overview
  • Fraud Section vs Fraud Division
  • Political Enforcement Reality
  • Self-Disclosure Gets Riskier
  • What Companies Should Do Now

Resources:

Matt on Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a Top 10 Business Law Podcast, and a Top 12 Risk Management Podcast. Compliance into the Weeds has been conferred a Davey, a Communicator Award, and a W3 Award, all for podcast excellence.

Categories
Blog

The Culture Builder’s Trilogy: Part 2 – The Art of Implementation: Where Compliance Culture Lives or Dies

Ed. Note: We are in the midst of a three-part blog post series on three recent books by Hemma Lomax and Ashley Dubriwny. There are The Art of Ideation, The Art of Celebration, and The Art of Implementation.

If The Art of Ideation is about imagining better compliance, The Art of Implementation is about making it real. Hemma Lomax and Ashley Dubriwny write that implementation is where culture lives or dies. That single sentence could serve as a mission statement for every Chief Compliance Officer.

Compliance professionals know this problem well. A program can include a strong code of conduct, a comprehensive policy inventory, a well-designed training calendar, a hotline, third-party procedures, and investigation protocols. Yet the DOJ does not ask whether a company has merely created compliance artifacts. It asks whether the program works in practice. It goes directly to the DOJ’s Evaluation of Corporate Compliance Programs (ECCP). The ECCP continues to ask whether a program is well-designed, adequately resourced, empowered to function effectively, and working in practice. That is why The Art of Implementation matters. It moves from aspiration to action. It asks how values become systems, how ideas become habits, and how culture becomes durable.

Lesson One: Mindset Before Method

The book begins with a critical insight: implementation begins with how you think. Lomax and Dubriwny identify four commitments of the culture builder’s mindset: empathy before enforcement, curiosity over control, influence rather than insistence, and legacy as a lens. For compliance professionals, this is not a rejection of enforcement. It is a recognition that enforcement without trust creates fear, not culture. A CCO must enforce standards, discipline misconduct, and protect the company. But a CCO must also understand why employees resist, where controls create friction, and how people make decisions under pressure.

This is the difference between a compliance function that says “no” and one that helps the business get to “yes, with controls.” The former may be respected in moments of crisis. The latter is trusted before the crisis arrives.

Lesson Two: Think, Build, Ship, Adopt, Tweak

One of the strongest frameworks in the book is the five forces of implementation: think, build, ship, see it adopted, and tweak. The model is practical and deeply consistent with the ECCP. “Think” means design the change with empathy. “Build” means operationalize the intention. A ship means starting before every detail is perfect. Adoption means embedding the practice into the culture. “Tweak” means to learn, adjust, and improve.

This is what compliance program effectiveness should look like. A CCO should not wait three years to discover that annual training did not change behavior. A third-party control should not remain unchanged after repeated red flags. An AI acceptable use policy should not sit static while employees quietly adopt new tools. A speak-up program should not wait for a scandal before testing whether employees trust it. The compliance application is straightforward. Build compliance like a product. Test. Measure. Listen. Improve.

Lesson Three: Alignment Accelerates Implementation

The book’s discussion of alignment is essential for compliance. Lomax and Dubriwny use Ocean’s Eleven as a cultural reference point. The plan works not because one person is brilliant, but because purpose, people, and process are aligned. Implementation fails when a good idea lacks the right coalition, operational fit, or timing.

This is a core challenge for the CCO. Compliance cannot implement an effective third-party program without the support of procurement, finance, legal, sales, audit, and business leadership. Compliance cannot govern AI without IT, data science, privacy, cybersecurity, HR, legal, and business users. Compliance cannot build a speak-up culture without managers. Stakeholder mapping is therefore not an administrative exercise. It is a governance control. It identifies who can accelerate the initiative, who can block it, who must own it, and who must maintain it after launch.

Lesson Four: Find Failure First

The pre-mortem section of The Art of Implementation is one of the most useful tools for compliance professionals. The authors ask teams to imagine that an initiative has failed and then work backward to identify why. This is precisely how CCOs should approach major program changes. Before launching a new hotline platform, ask why employees might still avoid reporting. Before deploying AI-assisted monitoring, ask about potential privacy, bias, transparency, and explainability concerns. Before rolling out a third-party due diligence platform, ask why business teams might work around it. Before redesigning incentives, ask what unintended behaviors the new metrics could create.

Pre-mortems are internal controls in action. They force the organization to identify failure modes before the market, the regulator, the whistleblower, or the plaintiff does. They can be and are a powerful tool at your disposal as a CCO or compliance professional.

Lesson Five: Movements Beat Mandates

A particularly powerful theme in the book is the distinction between mandates and movements. Mandates may produce obedience. Movements produce ownership. For compliance professionals, this is a critical distinction.

The Wells Fargo fake sale scandal remains a cautionary tale about mandates, metrics, and fear-based performance pressure. Employees may comply with the apparent demand for results while violating the organization’s deeper values. That is why incentives matter. The DOJ has emphasized that companies should use both incentives and consequences to promote compliance. Its compensation and clawback pilot report states that affirmative metrics and benchmarks can reward compliance-promoting behavior and that financial penalties can deter risky behavior.

This is where compliance culture becomes real. Employees need to see that ethical leadership, controlled discipline, speaking up, and responsible business performance are recognized, promoted, and rewarded. They also need to see that misconduct, retaliation, and willful blindness have consequences.

Compliance Application

The CCO’s implementation challenge is to convert program design into operational evidence. That evidence includes adoption data, control testing, investigation metrics, remediation tracking, third-party monitoring, AI use inventories, exception reporting, and incentive alignment. Implementation also requires courage. A CCO must be willing to ship pilots, gather feedback, and make changes. The compliance function must stop equating launch with success. Launch is the beginning. Adoption, evidence, and improvement are the proof.

CCO Questions

  • Which compliance initiatives have been launched but not adopted?
  • Do we have stakeholder maps for our most important compliance priorities?
  • Are we running pre-mortems before major program changes, including AI governance, third-party risk, speak-up enhancements, and incentive redesign?
  • Do our incentives reward ethical behavior, promote control over ownership, and ensure transparency?
  • What compliance practices would continue if the current CCO left tomorrow?

Practical Takeaways

  1. Identify one compliance initiative that stalled and run a pre-mortem on why it failed.
  2. Build a stakeholder map for AI governance or third-party risk.
  3. Convert one compliance aspiration into a measurable operating practice.
  4. Review incentives and promotion criteria for compliance signals.
  5. Treat implementation as the evidence layer of the compliance program. Regulators do not reward intentions. They evaluate what works.

Implementation is where compliance culture is tested. It is where the organization discovers whether its ideas can survive business pressure, competing priorities, operational friction, and human resistance. Yet even the best-implemented program must still be sustained. Controls must be reinforced. Speak-ups must be protected. Ethical behavior must be recognized. Employees should see that integrity, not just performance, is valued by the organization. That is the work of the third book in the trilogy, The Art of Celebration.

Join us tomorrow for Part 3, where we will turn to celebration as a compliance discipline and explore how recognition, incentives, rituals, morale metrics, and cultural memory shape what employees believe the company truly values.

Categories
AI Today in 5

AI Today in 5: May 12, 2026, The RegTech as Infrastructure Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today In 5. All, from the Compliance Podcast Network. Each day, we consider five stories from the business world, compliance, ethics, risk management, leadership, or general interest about AI.

Top AI stories include:

For more information on the use of AI in compliance programs, Tom Fox’s new book, Upping Your Game, is available. You can purchase a copy of the book on Amazon.com.

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Red Flags Rising

Red Flags Rising: S01 E39: Pull, Push, Tap, Aim, Fire – What Recent Settlements and Indictments Teach about Clearing Compliance Jams

Mike and Brent return to discuss lessons from Brent’s Aikido instructor and Marine Corps combat veteran Frank Doran and how those lessons can help trade compliance professionals work through compliance jams. Mike and Brent discuss the enforcement wave that unfolded in March 2026 (01:28); their March 10, 2026, National Security Law & Enforcement event in New York City (01:51); how that event was designed to get to practical solutions (02:30); the need today to have a broader “compliance aperture” (03:59); the importance of effective communication up to management and boards, especially around “central compliance risks” (the standard under Delaware law) (04:37); Carole Basri’s prediction that soon many companies will have Chief National Security Officers (05:31); two significant enforcement actions from Q1 2026 (07:42); the DOJ National Security Division’s March 30, 2026, announcement regarding voluntary disclosures (11:37); two significant indictments from Q1 2026 (12:06); boards of directors’ duty of oversight when it comes to national security (13:39); and the relevance of increased agitation from the U.S. Congress for more enforcement (18:39); the status of the proposed Remote Access Security Act (19:35); and what is the compliance path forward, including Brent’s Fraud Four Circle Framework (21:57). Mike and Brent then conclude with a special edition of Brent Carlson’s “Managing Up” about Frank Doran and the meaning and importance—to not only infantrymen but also compliance professionals—of “Pull, Push, Tap, Aim, Fire” (24:40).

Resources:

BIS enforcement actions

DOJ NSD Voluntary Disclosure Policy (Mar. 30, 2026)

More about Frank Doran: https://aikido-west.org/frank-doran

Frank Doran, “Pull, Push, Tap, Aim, Fire” (1995)

Boards of Directors and the Duty of Oversight: “Boards of Directors Lovin’ It after McDonald’s? A Fresh Look at Directors’ Duty of Oversight in the New Era of Sanctions & Export Control Corporate Enforcement,” NYU PCCE Blog (Jan. 12, 2024)

Brent’s Fraud Four Circle Framework article: “A Light Shines Through the Darkness in Disputes, Investigations, and Trade Compliance: A Fresh Look at the Classic Fraud Triangle with the Fraud Four-Circle Framework℠,” NYU PCCE Blog (Jan. 8, 2026)