Categories
Blog

Business Ethics Lessons from Star Trek’s Requiem for Methuselah

In corporate life, ethical decision-making is not only a question of right and wrong. It is also a test of leadership, trust, and long-term vision. Missteps in ethics erode corporate culture, destroy reputations, and invite regulatory and shareholder scrutiny.

Few Star Trek episodes present an ethical crucible as layered as Requiem for Methuselah. In this episode, the Enterprise crew, seeking an urgently needed medical cure for a deadly illness sweeping the ship, beams down to a remote, seemingly uninhabited planet. There, they meet the enigmatic Flint, a man who turns out to be immortal, having lived for over 6,000 years under various identities, from Methuselah to Da Vinci. Flint lives with Rayna, a beautiful, brilliant young woman who, as the crew later learns, is not human but an android he has created.

The story unfolds into a complex web of secrecy, autonomy, manipulation, and unintended consequences, a rich territory for ethical reflection. From this episode, we can draw five business ethics lessons directly applicable to today’s corporate compliance environment.

Lesson 1: Transparency Is Essential to Trust

Illustrated by: Flint initially hides critical facts from Kirk, Spock, and McCoy: his true identity, the fact that Rayna is an android, and the location of the life-saving mineral Ryetalyn they came to obtain. His secrecy stems from a desire to control the situation, but it breeds mistrust and escalating tension.

Ethics Lesson. In business, withholding material information, even with ostensibly good intentions, undermines trust—stakeholders, whether employees, customers, or regulators, expect honesty. Concealing facts creates suspicion, damages credibility, and can lead to decisions made on false assumptions. A compliance culture grounded in transparency prevents misunderstandings and reinforces stakeholder confidence.

What should you do?

  • Communicate openly about relevant facts, especially those impacting health, safety, or financial stability.
  • Establish disclosure protocols for potential conflicts of interest.
  • Recognize that partial truths can be as damaging as outright falsehoods.

Lesson 2: Autonomy Must Be Respected, Even with Good Intentions

Illustrated by Flint, Rayna was designed to be his companion, controlling her environment and limiting her exposure to the outside world. He claims to be protecting her, but in doing so, denies her agency. When she begins to form independent thoughts and feelings, particularly toward Kirk, Flint’s inability to let go leads to tragedy.

Ethics Lesson. Corporations sometimes restrict employee autonomy under the guise of protection, micromanaging, withholding career opportunities, or blocking external engagement. Even if the motive is to “protect” the employee or company, the result can stifle growth and foster resentment. Ethical leadership means equipping people to act responsibly, not controlling every move they make.

What should you do?

  • Empower individuals to make informed choices within ethical boundaries.
  • Provide access to opportunities and resources without paternalistic gatekeeping.
  • Respect the right of employees to voice concerns and explore options.

Lesson 3: Ends Do Not Justify the Means

Illustrated by: Flint’s primary objective, immortality, has allowed him to amass vast knowledge and wealth. Yet to achieve his goals in this episode, he manipulates the Enterprise crew, withholds the cure they need until his conditions are met, and engineers circumstances to force emotional outcomes for Rayna.

Ethics Lesson. In business, leaders may justify cutting corners or bending rules to achieve short-term results, winning a contract, securing market share, or hitting quarterly targets. But compromising ethics for results can cause long-term damage far outweighing the immediate gain. A sustainable corporate culture is built on the principle that ethical processes matter as much as business goals.

What should you do?

  • Evaluate not just what you achieve, but how you achieve it.
  • Build decision-making frameworks that weigh both outcomes and methods.
  • Reinforce that compliance and ethics are integral to success, not obstacles to it.

Lesson 4: Emotional Intelligence Is Critical in Ethical Decision-Making

Illustrated by: Kirk’s growing attachment to Rayna closes his eyes to the urgency of his mission. McCoy warns him about becoming too emotionally involved, but Kirk underestimates the impact on his judgment. Flint, likewise, fails to foresee that forcing Rayna to choose between him and Kirk will overwhelm her, leading to her breakdown.

Ethics Lesson. In corporate environments, emotions, whether loyalty, rivalry, or fear, can cloud ethical judgment. Leaders may overlook red flags, delay action, or make decisions based on personal feelings rather than principles. Ethical clarity often requires stepping back and separating personal attachment from professional responsibility.

What should you do?

  • Train leaders to recognize when emotions may be influencing decisions.
  • Encourage second opinions and peer review in high-stakes decisions.
  • Create safe spaces for voicing concerns about potential bias.

Lesson 5: Ethical Leadership Includes Considering Long-Term Impact

Illustrated by: Flint’s immortality has given him a unique long view of history, but in this episode, he fails to account for the long-term consequences of his actions toward Rayna and the Enterprise crew. His choices have immediate, tragic outcomes and lasting emotional scars.

Ethics Lesson. Businesses that focus solely on short-term gains, without assessing long-term impacts, risk harming their reputation, eroding stakeholder trust, and creating systemic problems. Ethical leaders anticipate not just the next quarter, but the next decade. Considering long-term consequences ensures ethical decisions hold up under the scrutiny of time.

What should you do?

  • Incorporate long-term risk and ethical impact into strategic planning.
  • Assess how today’s decisions will be perceived by future employees, customers, and regulators.
  • Prioritize sustainability, both in environmental and cultural terms.

Why “Requiem for Methuselah” Matters for Business Ethics

The drama in Requiem for Methuselah is driven not by alien threats or galactic battles, but by human (and android) ethical dilemmas: secrecy, autonomy, manipulation, emotional entanglement, and shortsightedness. These are the same challenges corporate leaders face when navigating business ethics in the modern era.

An ethical corporate culture:

  • Practices transparency to build trust.
  • Respects the autonomy of individuals.
  • Rejects “ends justify the means” thinking.
  • Recognizes and manages the role of emotions in decision-making.
  • Considers the long-term legacy of choices made today.

The compliance department is not just a rules enforcer. According to the DOJ, it is the ethics steward of the organization, ensuring that decisions at every level meet both legal and moral standards.

Final ComplianceLog Reflections

Requiem for Methuselah is ultimately a cautionary tale about the cost of ethical missteps, even for someone with the wisdom of centuries. Flint’s intellect and resources could not compensate for a failure to act with transparency, respect, and foresight.

For today’s corporate leaders, the lesson is simple: ethical decision-making is not a luxury—it is the foundation of sustainable success. The compliance function’s role is to embed these values so deeply into the corporate DNA that they guide every choice, from the boardroom to the front line.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

THE BERKO TRIAL – PART 4: When Red Flags Become Evidence: Transaction Controls from the Berko Trial

Today in Part 4, I want to focus on some of the compliance lessons from the Asante Berko FCPA trial. The compliance lesson from the Berko trial is not simply that employees should not pay bribes. Every code of conduct already says that. The harder question is whether the compliance program can interrupt the operating pattern: a politically connected intermediary, milestone-linked invoices, personal email, cash discussions, incomplete diligence answers, and a commercial team under pressure to close. These were some of the questions that Goldman Sachs faced and successfully answered.

That is where policy becomes performance. Trial reporting described a legitimate infrastructure project surrounded by evidence that prosecutors said showed corrupt intent and concealment. The same emails, diligence questions, payment records, and escalation decisions that once lived inside a transaction later became evidence before a jury. For compliance professionals, the case is a control map. It shows where a high-risk deal can be tested, paused, corrected, or stopped before red flags mature into criminal exposure.

Begin With the Business Model

Your business justification should begin with how the deal is expected to work, not with a standard questionnaire. In the Berko transaction, commercial urgency, a major public need, concentrated government discretion, substantial projected fees, and local intermediaries all increased the risk profile. None of those facts establishes bribery. Together, however, they demand a more disciplined control environment.

The deal team should be required to explain the legitimate path to success. Which officials control each approval? Which regulatory, legislative, and contractual milestones must occur? What service does every intermediary perform? How is that service connected to value rather than access? Where could commercial pressure tempt someone to bypass the process?

This is consistent with the DOJ Evaluation of Corporate Compliance Programs (ECCP), which asks whether a company understands its business from a commercial perspective and devotes appropriate attention and resources to high-risk transactions. A generic country score is not enough. The risk assessment must reflect the transaction’s economics, approval structure, counterparties, compensation model, technology, and pressure points.

Make Third-Party Diligence Operational

Third-party diligence often fails because it is treated as an onboarding event. The questionnaire is completed, screening is run, a risk rating is assigned, and the business moves on. High-risk public-sector work requires continuous control.

Before engagement, the company should document the business rationale, beneficial ownership, politically exposed person and family links, qualifications, reputation, service scope, deliverables, compensation, payment terms, and proposed bank account. Compensation should be benchmarked against the actual work. Enhanced review should apply when fees are success-based, tied to government milestones, disproportionate to services, routed through unrelated entities or individuals, or connected to officials who control approvals.

After onboarding, controls must follow the intermediary into contracting, invoicing, payment, and monitoring. The DOJ guidance asks whether the company understands the business rationale, confirms that services were actually performed, assesses whether compensation is appropriate, tracks red flags, uses audit rights, and manages third parties throughout the relationship. The relevant question is not whether the intermediary passed diligence once. It is whether the relationship still makes sense when the invoice arrives.

Control the Channels Where Business Occurs

Personal email is not proof of bribery. The Berko facts were more specific. According to the trial reporting, sensitive payment discussions occurred through personal accounts. At the same time, routine deal work proceeded through corporate systems, and one exchange referred to the monitoring of a Goldman account. The control issue was the combination of channel separation, sensitive content, and knowledge of monitoring.

Companies need clear rules for personal email, messaging applications, approved mobile platforms, and bring-your-own-device arrangements. Those rules require technical support: approved-channel design, retention settings, monitoring consistent with law, exception approval, employee attestations, and escalation when business moves outside the system. The program should also test whether records can actually be collected and preserved across the jurisdictions where the company operates.

The ECCP asks how companies manage and preserve business communications on personal devices and messaging platforms. The DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy (VSD) likewise identifies appropriate controls over personal and ephemeral communications as part of timely remediation. A policy that cannot preserve the evidence it covers is not an effective control.

Give Compliance Real Stop Authority

Escalation is not effective if compliance can ask questions but cannot pause the transaction. High-risk deals need defined hard stops. Examples include incomplete beneficial ownership, inconsistent diligence answers, refusal to identify service providers, unexplained compensation, undisclosed PEP relationships, requests for cash, payments to personal or nominee accounts, and destination changes without a credible business reason.

A hard stop does not require the company to abandon every transaction containing a red flag. It requires the risk to be resolved before money or value moves. The control framework should identify who may impose a pause, who may clear it, whether any override is permitted, what evidence supports an override, and which risk decisions require senior escalation.

Trial testimony reportedly described months of compliance questions about the Ghanaian intermediary and inconsistent or incomplete answers, followed by Goldman’s withdrawal from the contemplated financing. That sequence should not be converted into a claim that every control operated early enough or that the company was legally exonerated. The more useful lesson is that the decision trail mattered. It documented the questions, the resistance, the escalation, and the exit.

Connect Diligence, Invoices, and Money

Many programs distribute the relevant facts across separate systems. Procurement sees the contract. Compliance sees the screening. Accounts payable sees the invoice. Treasury sees the destination account. Investigations see the allegation. No one sees the complete pattern.

Payment controls should require proof of service, account-name matching, country and entity consistency, independent approval for destination changes, and tight restrictions on cash. Analytics should flag round-dollar invoices, duplicate invoice numbers, payment splitting, milestone-timed consulting fees, payments to employees or related parties, high-risk correspondent routes, and transfers followed by cash withdrawals.

The decisive step is integration. Due diligence, PEP screening, contracting, procurement, accounts payable, treasury, and case-management data should be capable of producing a transaction-level view. That view allows compliance to ask whether a payment is not only properly approved but also commercially credible.

Build an Evidence-Grade Record

The defense’s most forceful theme was the missing last mile: no downstream bank record showing money reaching a Ghanaian official, no alleged recipient on the witness stand, and no eyewitness to a bribe. The jury nevertheless convicted Berko on all three charged counts. For an internal investigation, the lesson cuts both ways. Suspicion is not proof, but weak tracing can leave the company unable to determine what happened.

Preserve native emails, attachments, metadata, messaging exports, payment records, approval histories, translations, and custodial provenance—record who made each factual determination and what evidence supported it. For multilingual material, preserve the original, use qualified translators, document dialect and ambiguity, and maintain a process for reviewing disputed language. Financial tracing should move from payer to intermediary to ultimate recipient, including related-party accounts and cash conversion.

The current FCPA enforcement guidelines emphasize individual misconduct and caution against attributing nonspecific malfeasance to corporate structures. That makes an evidence-grade corporate record especially important. It can help separate an individual’s conduct from the organization’s response while also showing whether the program was designed and implemented effectively.

Test the Controls Before the Crisis

An effective program does not promise that no misconduct will ever occur. DOJ recognizes that even a strong program may fail to prevent an offense. The question is whether the program is risk-based, detects concerns, responds promptly, and improves from experience.

Replay a recent public-sector transaction against the Berko pattern. Could the company identify every approval-controlling official and intermediary? Would milestone-linked payments trigger review? Could compliance pause the deal? Would personal email activity be detected and preserved? Could investigators trace funds beyond the first intermediary? Measure time from red flag to pause, overdue enhanced diligence, unresolved PEP issues, payment exceptions, control overrides, and closure of remediation.

The practical takeaways are clear. Commercial urgency calls for greater discipline, not reduced scrutiny. Third-party diligence must remain connected to invoices, payments, monitoring, and escalation. Off-channel communications become an intent and preservation issue when combined with sensitive content and known monitoring. A deal exit matters, but an earlier hard stop may reduce exposure and preserve more business value.

Join us tomorrow as we conclude our 5-part series by moving the transaction to the enterprise. In it, we will explore such questions as who owns these controls, who funds and tests them, how accountability is imposed, and what your Board of Directors should demand as evidence that the program works in practice.

Resources:

United States v. Berko, No. 1:20-cr-00328-DG, Indictment, ECF No. 3 (E.D.N.Y. filed Aug. 26, 2020)

Stewart Bishop, “Goldman Jury Sees Cash Talk in Energy Deal Email Deluge,” Law360, Aug. 1, 2026; Stewart Bishop, “Goldman Exec Was Linchpin to Ghana Bribery Ploy, Jury Told,” Law360, Aug. 5, 2026.

Stewart Bishop, “Ex-Goldman Exec Convicted of Ghana Bribery Plot,” Law360, Aug. 6, 2026. Supplied trial reporting.

U.S. Attorney’s Office for the Eastern District of New York, “Former Goldman Sachs Investment Banker Convicted of Foreign Bribery and Money Laundering,” Aug. 6, 2026, DOJ Press Release.

Stewart Bishop, “Goldman Jury Sees Undercover Video as Bribe Trial Nears End,” Law360, Aug. 4, 2026—supplied trial reporting.

Stewart Bishop, “Shady Power Deal Used in Goldman Compliance Prep, Jury Told,” Law360, July 29, 2026

Stewart Bishop, “Like Milli Vanilli, Goldman FCPA Case Is a Ruse, Jury Told,” Law360, July 28, 2026.

SEC Final Judgment against Asante Berko

SEC Complaint against Asante Berko

DOJ Evaluation of Corporate Compliance Programs

DOJ Corporate Enforcement and Voluntary Self-Disclosure Policy

Categories
Compliance Into the Weeds

Compliance into the Weeds: Ted Lasso, Culture and Compliance

The award-winning Compliance into the Weeds is the only weekly podcast that takes a deep dive into a compliance-related topic, literally going into the weeds to explore a subject more fully. Looking for some hard-hitting insights on compliance? Look no further than Compliance into the Weeds! In this episode of Compliance into the Weeds, Tom Fox and Matt Kelly celebrate the return of Ted Lasso for Season 4.

Tom and Matt begin with why Ted Lasso resonates with compliance officers as a study of workplace dynamics, leadership, and building a culture of trust. They highlight how Ted focuses on coaching people and shaping club-wide culture through “thousands of imperceptible moments,” culminating in “total football,” where shared expectations and mutual support enable improvisation and performance. They connect this to compliance goals of embedding ethics so employees can handle new situations on the fly and to Jim Collins’ “level five” leadership and humility, illustrated by Ted renaming Trent Crimm’s book from “The Ted Lasso Way” to “The Richmond Way.” They also link the show to the military OODA loop (observe, orient, decide, act) as a model for empowered decision-making within clear objectives and boundaries and preview Season 4’s shift to Ted coaching a women’s team.

Key highlights:

  • Ted Lasso Returns Season Four
  • Culture and Trust at Richmond
  • Total Football and Compliance
  • The Richmond Way Leadership Lesson
  • Level Five Humility
  • OODA Loop Meets Compliance

Resources:

Matt in Radical Compliance

Tom

Instagram

Facebook

YouTube

Twitter

LinkedIn

A multi-award-winning podcast, Compliance into the Weeds was most recently honored as one of the Top 25 Regulatory Compliance Podcasts, a ⁠Top 10 Business Law Podcast⁠, and ⁠a Top 12 Risk Management Podcast⁠. Compliance into the Weeds has been conferred a Davey, Communicator, and W3 Award, all for podcast excellence. 

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 73 – From Zetar to the C-Suite: Why Expertise Matters in Internal Investigations

In the corporate compliance world, an internal investigation is often the moment of truth. Whether triggered by a whistleblower complaint, a regulatory inquiry, or a suspicious transaction, the investigation’s quality can determine whether the organization resolves the matter cleanly or faces prolonged legal, financial, and reputational damage.

Star Trek: The Original Series’ “The Lights of Zetar” offers a surprisingly apt allegory for why skilled professionals must handle these investigations. The crew must conduct what is, in effect, a complex and high-stakes investigation. Their approach yields five lessons that every compliance professional should apply when running an internal investigation.

Lesson 1: Preserve and Protect Critical Evidence Immediately

Illustrated by. When the lights first strike, the Enterprise experiences sudden and unexplained system failures. The crew immediately records sensor data, secures operational logs, and isolates the damage.

Compliance Lesson. Without swift action, crucial evidence can be lost, whether through routine data overwrites, deliberate destruction, or simple mishandling.

Lesson 2: Bring in the Right Expertise Early

Illustrated by: Once Mira Romaine exhibits strange symptoms, Dr. McCoy, Spock, and Scotty each contribute their specialized knowledge, medical science, Vulcan telepathy, and engineering diagnostics to piece together what is happening.

Compliance Lesson. A proper internal investigation is rarely a one-person job. Complex matters often require diverse expertise: forensic accounting, cybersecurity, HR policy, legal analysis, and industry-specific regulatory knowledge.

Lesson 3: Keep an Open Mind—The First Explanation May Be Wrong

Illustrated by: Only after gathering more evidence do they realize the lights are disembodied intelligences, survivors of the destroyed planet Zetar, seeking a human host.

Compliance Lesson. In corporate investigations, jumping to conclusions based on initial appearances can lead to flawed outcomes.

Lesson 4: Protect the People Involved Throughout the Process

Illustrated by: Mira Romaine is not treated merely as a subject of inquiry; she is a valued crew member whose well-being is a priority. The investigation’s goal is not just to “solve the problem” but to save her life.

Compliance Lesson. In internal investigations, individuals, whether complainants, witnesses, or subjects, must be treated with dignity and fairness. Mishandling these relationships can result in legal claims, loss of employee trust, and reputational harm.

Lesson 5: Deliver Actionable Solutions, Not Just Findings

Illustrated by: Once the crew determines that the Zetarians are inhabiting Lt. Romaine’s body, they devise a targeted plan to remove them using controlled atmospheric pressure in a medical isolation chamber.

Compliance Lesson. An investigation that ends with a report but no corrective action is a missed opportunity. The ultimate measure of success is not uncovering what happened but ensuring it does not happen again.

Final ComplianceLog Reflections

The Lights of Zetar reminds us that investigations are not abstract exercises; they are missions with real people, high stakes, and long-term consequences. The Enterprise crew approached their challenge with urgency, thoroughness, and empathy. For compliance officers, the lesson is clear: every internal investigation is an opportunity to demonstrate integrity, competence, and leadership. The quality of your investigative process will be remembered long after the incident itself fades from memory.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

The Importance of Expert Internal Investigations: Lessons from Star Trek’s The Lights of Zetar

In the corporate compliance world, an internal investigation is often the moment of truth. Whether triggered by a whistleblower complaint, a regulatory inquiry, or a suspicious transaction, the investigation’s quality can determine whether the organization resolves the matter cleanly or faces prolonged legal, financial, and reputational damage.

Star Trek: The Original Series’ “The Lights of Zetar” offers a surprisingly apt allegory for why skilled professionals must handle these investigations. In this episode, the Enterprise is on its way to Memory Alpha, the Federation’s central library, when it encounters a mysterious, pulsating light phenomenon. The lights incapacitate crew members, damage ship systems, and, most dangerously, invade the mind of Lieutenant Mira Romaine, who is accompanying the mission.

The crew must determine what the lights are, what they want, and how to neutralize them before they destroy both Romaine and Memory Alpha’s priceless archives. In doing so, they conduct what is, in effect, a complex and high-stakes investigation. Their approach yields five lessons that every compliance professional should apply when running an internal investigation.

Lesson 1: Preserve and Protect Critical Evidence Immediately

Illustrated by. When the lights first strike, the Enterprise experiences sudden and unexplained system failures. The crew immediately records sensor data, secures operational logs, and isolates the damage.

Compliance Lesson. In corporate investigations, the “scene of the incident” may be a server containing emails, a ledger of transactions, or a manager’s office with physical records. Without swift action, crucial evidence can be lost, whether through routine data overwrites, deliberate destruction, or simple mishandling.

How to apply this to investigations?

  • Secure relevant electronic and physical records as soon as the investigation begins.
  • Suspend auto-delete protocols and ensure data preservation orders are issued.
  • Document the chain of custody for all materials.

In The Lights of Zetar, the crew’s rapid evidence capture gave them the information needed to trace the lights’ origins and capabilities. Without it, they would have been operating blind.

Lesson 2: Bring in the Right Expertise Early

Illustrated by: Once Mira Romaine exhibits strange symptoms, Dr. McCoy, Spock, and Scotty each contribute their specialized knowledge, medical science, Vulcan telepathy, and engineering diagnostics to piece together what is happening.

Compliance Lesson. A proper internal investigation is rarely a one-person job. Complex matters often require diverse expertise: forensic accounting, cybersecurity, HR policy, legal analysis, and industry-specific regulatory knowledge. Relying solely on generalists can miss critical nuances.

How to apply this to investigations?

  • Assemble a multidisciplinary team at the outset, including internal experts and outside specialists if needed.
  • Ensure each team member understands their role and investigative boundaries.
  • Involve counsel early to maintain privilege over sensitive findings.

Just as the Enterprise crew leveraged multiple skill sets to solve a problem no one discipline could crack alone, compliance officers should make strategic use of the right expertise from day one.

Lesson 3: Keep an Open Mind—The First Explanation May Be Wrong

Illustrated by: Initially, the crew assumes the lights are a natural space phenomenon. Only after gathering more evidence do they realize the lights are disembodied intelligences, survivors of the destroyed planet Zetar, seeking a human host.

Compliance Lesson. In corporate investigations, jumping to conclusions based on initial appearances can lead to flawed outcomes. What looks like simple employee misconduct may be part of a larger systemic control failure; what appears to be a minor accounting error may conceal intentional fraud.

How to apply this to investigations?

  • Form working hypotheses, but treat them as provisional until confirmed by evidence.
  • Explore alternative explanations, even if they seem less likely.
  • Allow the facts, not convenience or organizational pressure, to drive conclusions.

Expert investigators, like the Enterprise crew, pivot their theories as new facts emerge.

Lesson 4: Protect the People Involved Throughout the Process

Illustrated by: Mira Romaine is not treated merely as a subject of inquiry; she is a valued crew member whose well-being is a priority. The investigation’s goal is not just to “solve the problem” but to save her life. Kirk ensures she receives medical care and emotional support even as they work to understand her condition.

Compliance Lesson. In internal investigations, individuals, whether complainants, witnesses, or subjects, must be treated with dignity and fairness. Mishandling these relationships can result in legal claims, loss of employee trust, and reputational harm.

How to apply this to investigations?

  • Maintain confidentiality to the fullest extent possible.
  • Protect against retaliation for cooperation.
  • Provide updates when feasible to those affected, balancing transparency with investigative integrity.

A humane approach builds trust in the compliance function and encourages future reporting.

Lesson 5: Deliver Actionable Solutions, Not Just Findings

Illustrated by: Once the crew determines that the Zetarians are inhabiting Lt. Romaine’s body, they devise a targeted plan to remove them using controlled atmospheric pressure in a medical isolation chamber. They do not stop at identifying the cause; they implement the cure.

Compliance Lesson. An investigation that ends with a report but no corrective action is a missed opportunity. The ultimate measure of success is not uncovering what happened but ensuring it does not happen again.

How to apply this to investigations?

  • Pair findings with concrete, practical recommendations for remediation.
  • Address both the immediate problem and any systemic weaknesses uncovered.
  • Follow up to confirm that corrective actions are implemented and effective.

The Enterprise crew’s solution not only saved Mira but also prevented the Zetarians from posing a future threat, exemplifying the kind of preventive mindset compliance investigations should aim for.

Why “The Lights of Zetar” Resonates for Compliance

In The Lights of Zetar, the stakes were both personal and institutional: the survival of a crew member and the preservation of Memory Alpha’s vast knowledge. The investigation had to be thorough, rapid, multidisciplinary, and compassionate, precisely the hallmarks of a high-quality corporate internal investigation.

An expert investigation:

  • Safeguards evidence before it’s lost.
  • Leverages the right mix of skills.
  • Keeps the fact-finding process objective.
  • Protects people while uncovering the truth.
  • Produces actionable, lasting solutions.

When these principles are followed, the compliance function not only resolves incidents but also strengthens the organization’s overall resilience.

Final ComplianceLog Reflections

The Lights of Zetar reminds us that investigations are not abstract exercises—they are missions with real people, high stakes, and long-term consequences. The Enterprise crew approached their challenge with urgency, thoroughness, and empathy.

For compliance officers, the lesson is clear: every internal investigation is an opportunity to demonstrate integrity, competence, and leadership. The quality of your investigative process will be remembered long after the incident itself fades from memory.

In other words, be the Enterprise—methodical, humane, and relentless in pursuit of the truth.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Great Women in Compliance

Great Women in Compliance: Beyond the Balance Sheet: Ethics Lessons from Australia’s Accounting Scandals

For this #GWIC roundtable episode, Lisa Fine and Ellen Hunt spoke with two renowned experts, Francine McKenna and Ursula Schmidt, about what Ethics & Compliance professionals should learn from recent accounting firm scandals in Australia.

Listen in as our guests help us unravel:

  • why similar scandals keep happening,
  • how the incentives and pressure at play in these scandals are universal,
  • the important role that culture plays,
  • how auditors and others should live up to their professional standards, and
  • why we still ignore those that bring issues forward.

There are lessons in these scandals for every #Ethics and #Compliance professional on how to improve your culture and program. A huge thank you to Francine and Ursula for sharing their insights, expertise, and wisdom with us.

Categories
Trekking Through Compliance

Trekking Through Compliance: Episode 72 – Surviving the Unknown: Risk Management Lessons from “That Which Survives”

In compliance, risk management is more than a checklist. It is the ongoing discipline of identifying threats, assessing their potential impact, and implementing measures to mitigate or neutralize them before they cause harm.

Few Star Trek episodes illustrate the escalating consequences of underestimated risks as effectively as That Which Survives. In it, the Enterprise crew encounters a seemingly lifeless planet guarded by Losira, an alien projection who can kill with a single touch. Her purpose is to protect the planet’s secrets, but her method is indiscriminate, deadly, and poorly aligned to the situation at hand.

For compliance professionals, this episode offers five important lessons on anticipating, assessing, and responding to risks, both known and unknown, within an organization.

Lesson 1: Identify Risks Before Engaging in New Ventures

Illustrated by: The Enterprise arrives at an uncharted planet. Within moments, a mysterious woman materializes and kills a crew member simply by touching him.

Compliance Lesson. Too often, companies rush into new markets, partnerships, or projects without conducting a thorough risk assessment. This can expose the organization to sanctions violations, corruption risks, cybersecurity vulnerabilities, or operational failures.

Lesson 2: Understand That Some Risks Are Intelligent and Adaptive

Illustrated by: Losira targets specific individuals and adapts her approach to their vulnerabilities.

Compliance Lesson. Not all risks are static. Fraudsters change tactics, cyber threats evolve, and corrupt third parties find new ways to conceal misconduct. A compliance program must anticipate that some risks will actively seek to bypass controls.

Lesson 3: Don’t Dismiss Low-Probability, High-Impact Threats

Illustrated by: At first, the crew assumes Losira’s appearances are isolated incidents, but they quickly realize she poses an existential threat.

Compliance Lesson. Rare events, such as a single high-value bribery transaction, a lone rogue employee, or a targeted cyberattack, can have catastrophic consequences. Organizations sometimes underprepare for these scenarios because they seem unlikely.

Lesson 4: Risk Mitigation Requires Cross-Functional Coordination

Illustrated by: The landing party on the planet and the Enterprise crew in orbit are each facing threats from Losira, but their survival depends on sharing information and coordinating responses. Without clear communication, both groups would be doomed.

Compliance Lesson. Compliance cannot manage risk in isolation. It must work with legal, internal audit, operations, IT, and HR to identify threats and implement controls.

Lesson 5: Address the Root Cause, Not Just the Symptoms

Illustrated by: The crew eventually discovers that Losira is an automated defense mechanism left behind by an extinct race. Once the crew understands her origin and purpose, they can neutralize the threat.

Compliance Lesson. In risk management, addressing surface-level problems without finding the underlying cause only delays future incidents. Compliance should integrate root cause analysis into all investigations.

Final ComplianceLog Reflections

That Which Survives is more than a suspense episode; it is a cautionary tale about the dangers of underestimating risk. Losira was not inherently evil; she was a misunderstood, unexamined part of an environment the crew did not fully assess before engagement.

The compliance officer’s mandate is to ensure the company doesn’t make the same mistake: to scan for threats before beaming in, to adapt to evolving risks, to prepare for unlikely but devastating events, to coordinate across the enterprise, and to address the root cause when problems arise. Risk management is not just about surviving; it is about ensuring that your organization thrives in any environment, whether it’s an unexplored planet or a rapidly changing market.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Fiona is an AI-generated voice

Categories
Daily Compliance News

Daily Compliance News: August 11, 2026, The Section 230 Liability Defense Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All, from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Russia’s hottest start-up is a sanctions evasion network. (WSJ)
  • 9th Circuit allows lawsuits against big tech to move forward. (Reuters)
  • Compliance alone can’t stop health care fraud. (MedCityNews)
  • Leadership training on change management. (FT)

To learn about the intersection of Sherlock Holmes and the modern compliance professional, check out Tom’s latest book, The Game is Afoot-What Sherlock Holmes Teaches About Risk, Ethics and Investigations on Amazon.com.

Categories
Blog

Risk Management in Compliance: Five Lessons from Star Trek’s That Which Survives

In compliance, risk management is more than a checklist. It is the ongoing discipline of identifying threats, assessing their potential impact, and implementing measures to mitigate or neutralize them before they cause harm.

Few Star Trek episodes illustrate the escalating consequences of underestimated risks as effectively as That Which Survives. In it, the Enterprise crew encounters a seemingly lifeless planet guarded by Losira, an alien projection who can kill with a single touch. Her purpose is to protect the planet’s secrets, but her method is indiscriminate, deadly, and poorly aligned to the situation at hand.

For compliance professionals, this episode offers five important lessons on anticipating, assessing, and responding to risks, both known and unknown, within an organization.

Lesson 1: Identify Risks Before Engaging in New Ventures

Illustrated by: The Enterprise arrives at an uncharted planet, scans it briefly, and beams down a landing party. Within moments, a mysterious woman materializes and kills a crew member simply by touching him.

Compliance Lesson. Too often, companies rush into new markets, partnerships, or projects without conducting a thorough risk assessment. This can expose the organization to sanctions violations, corruption risks, cybersecurity vulnerabilities, or operational failures. Compliance should lead or be deeply involved in pre-engagement risk assessments. Before “beaming down” into a new business environment, map potential threats—regulatory, operational, reputational—and identify safeguards. Skipping this step can lead to preventable harm and costly remediation.

Lesson 2: Understand That Some Risks Are Intelligent and Adaptive

Illustrated by: Losira’s ability to appear anywhere, both on the planet and aboard the Enterprise, shows she is not a passive hazard. She targets specific individuals and adapts her approach to their vulnerabilities.

Compliance Lesson. Not all risks are static. Fraudsters change tactics, cyber threats evolve, and corrupt third parties find new ways to conceal misconduct. A compliance program must anticipate that some risks will actively seek to bypass controls. Build adaptive monitoring into your compliance systems. Use continuous transaction monitoring, real-time alerts, and data analytics to detect changes in patterns. A one-time risk assessment is not enough—ongoing vigilance is essential.

Lesson 3: Don’t Dismiss Low-Probability, High-Impact Threats

Illustrated by: At first, the crew assumes Losira’s appearances are isolated incidents, but they quickly realize she poses an existential threat. Even though she is only one individual, her capabilities could destroy the Enterprise if not addressed.

Compliance Lesson. Rare events, such as a single high-value bribery transaction, a lone rogue employee, or a targeted cyberattack, can have catastrophic consequences. Organizations sometimes underprepare for these scenarios because they seem unlikely. Compliance departments should incorporate low-probability, high-impact risks into the risk register. Conduct tabletop exercises to simulate rare but potentially devastating events, ensuring the organization has both prevention and response plans in place.

Lesson 4: Risk Mitigation Requires Cross-Functional Coordination

Illustrated by: The landing party on the planet and the Enterprise crew in orbit are each facing threats from Losira, but their survival depends on sharing information and coordinating responses. Without clear communication, both groups would be doomed.

Compliance Lesson. Compliance cannot manage risk in isolation. It must work with legal, internal audit, operations, IT, and HR to identify threats and implement controls. Silos breed blind spots, and blind spots breed crises. Establish cross-functional risk committees or working groups. Ensure that incident reporting and escalation procedures are well understood across departments. Make compliance the hub of a collaborative risk network, not a separate spoke.

Lesson 5: Address the Root Cause, Not Just the Symptoms

Illustrated by: The crew eventually discovers that Losira is an automated defense mechanism left behind by an extinct race. She’s not malicious—she’s simply executing a program without context or adaptability. Once the crew understands her origin and purpose, they can neutralize the threat.

Compliance Lesson. In risk management, addressing surface-level problems without finding the underlying cause only delays future incidents. For example, punishing an employee for violating a policy without examining why the policy was ignored leaves the organization vulnerable to repeat violations. Compliance should integrate root cause analysis into all investigations. Whether it’s a process flaw, cultural issue, or oversight gap, solving the real problem is the only way to reduce recurrence.

The Enterprise as a Risk Management Model

Captain Kirk and his crew succeed not because they are lucky, but because they adapt quickly, share intelligence, and dig deeper to understand the nature of the threat. These are precisely the attributes a corporate compliance department needs to lead risk management:

  • Proactive assessment before engagement.
  • Adaptive controls that respond to evolving risks.
  • Preparation for rare but high-impact events.
  • Collaboration across organizational functions.
  • Root cause remediation for lasting solutions.

Practical Compliance Takeaways

From That Which Survives, compliance professionals can draw these operational insights:

  1. Integrate Compliance Early—Risk management starts before contracts are signed or operations begin, not after.
  2. Invest in Technology—Data analytics, AI monitoring, and continuous auditing tools make adaptive risk management possible.
  3. Conduct Scenario Planning—Practice responding to “Losira-like” threats: targeted, intelligent, and hard to predict.
  4. Build Risk Alliances—Partner with all departments to create a unified threat picture.
  5. Close the Loop—Use each incident to strengthen your program against future threats.

Final ComplianceLog Reflections

That Which Survives is more than a suspense episode; it is a cautionary tale about the dangers of underestimating risk. Losira was not inherently evil; she was a misunderstood, unexamined part of an environment the crew did not fully assess before engagement.

The compliance officer’s mandate is to ensure the company doesn’t make the same mistake: to scan for threats before beaming in, to adapt to risks that evolve, to prepare for unlikely but devastating events, to coordinate across the enterprise, and to address the root cause when problems arise.

In other words, risk management is not just about surviving; it is about ensuring that your organization thrives in any environment, whether it’s an unexplored planet or a rapidly changing market.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha

Categories
Blog

Third-Party Due Diligence: 5 Lessons from Star Trek’s The Mark of Gideon

In the modern compliance landscape, third-party due diligence is not optional but essential. Regulators from the DOJ to the SFO have made it clear: if your business partner is involved in misconduct, you are on the hook if you did not take reasonable steps to know who you were dealing with.

Few pop culture moments capture the risks of blind engagement as vividly as Star Trek: The Original Series’ “The Mark of Gideon.” In this episode, Captain Kirk beams down to what he believes is the planet Gideon for diplomatic talks—only to find himself aboard what appears to be an empty Enterprise. What follows is a masterclass in the dangers of walking into a deal without verifying the facts. For compliance professionals, Gideon’s deception is the perfect allegory for the hazards of onboarding a third party without a thorough vetting process. Let’s break down five key lessons.

Lesson 1: Verify the True Identity of Your Counterparty

Illustrated by: When Kirk believes he is beamed down to Gideon, he is actually inside a replica of the Enterprise. The Gideonites have created this fake environment to isolate him for their purposes.

Compliance Lesson. If you do not confirm the true identity of a third party, you may find yourself dealing with a façade. Shell companies, undisclosed beneficial owners, and entities with misleading corporate registrations are the corporate world’s “empty Enterprise.”Always confirm a third party’s corporate existence and ownership through independent sources. This means checking official registries, using reliable due diligence databases, and, when needed, engaging investigative firms to trace beneficial ownership. Without these checks, you risk contracting with a front for illicit activity.

Lesson 2: Understand the Real Motives Behind the Partnership

Illustrated by: The Gideonites’ true purpose is not peaceful diplomacy; instead, they want to infect their overpopulated planet with a deadly virus carried by Kirk. They present their plan as a noble solution to their problem, but it’s built on deception and exploitation.

Compliance Lesson. Third parties sometimes have agendas that differ sharply from what they present. They may seek access to your brand to legitimize questionable practices, gain entry to restricted markets, or launder illicit funds. Beyond standard questionnaires, compliance teams should assess the commercial rationale for the relationship. Why do they want to work with you? Who else do they do business with? Are their financials consistent with the scale of the deal? If their motives don’t align with your values and compliance commitments, that is a red flag.

Lesson 3: Never Rely Solely on What the Other Party Tells You

Illustrated by: Kirk repeatedly asks the Gideonites to explain what is happening, but their answers are vague, evasive, and occasionally contradictory. They hope his lack of information will keep him compliant long enough to serve their plan.

Compliance Lesson. Self-reported information from a potential third party should be viewed as one data point, not the whole picture. Misrepresentations are common, whether deliberate or due to internal ignorance. Cross-verify all claims with independent checks, customer references, industry reputation research, litigation and sanctions screening, and on-site visits when possible. If the only source for a claim is the counterparty itself, your risk exposure rises dramatically.

Lesson 4: Assess the Operating Environment Before Engagement

Illustrated by: The Gideonites hide the actual conditions on their planet. Kirk learns later that Gideon is overcrowded to the point of people standing shoulder-to-shoulder, unable to move freely. Had this been disclosed, he would have understood the real risks before arriving.

Compliance Lesson. A third party’s operating environment, political stability, corruption levels, and regulatory enforcement directly affect your compliance risk. Entering into a business relationship without assessing this environment is akin to beaming down blind. Incorporate country risk analysis into your process. Use resources like Transparency International’s Corruption Perceptions Index, U.S. State Department human rights reports, and local legal counsel. An otherwise legitimate partner in a high-risk jurisdiction requires enhanced due diligence and monitoring.

Lesson 5: Build Exit Strategies Into the Relationship

Illustrated by: Once Kirk understands the Gideonites’ true intentions, he must escape the replica Enterprise to stop their plan. Without a clear route back to his crew, he risks being trapped indefinitely.

Compliance Lesson. Some third-party relationships turn sour despite your best due diligence efforts. Whether due to leadership changes, shifts in political conditions, or the surfacing of previously hidden misconduct, you need a plan to disengage without disrupting your operations. Include termination clauses tied to compliance breaches in your contracts. Maintain operational flexibility so you can pivot to alternate suppliers or partners if needed. Regularly re-screen third parties to ensure ongoing compliance, not just a one-time check at onboarding.

Final ComplianceLog Reflections

In The Mark of Gideon, the Enterprise crew’s lack of verified intelligence before Kirk’s “beam down” mirrors what happens when companies rush into a third-party relationship to seize a perceived opportunity. The Gideonites knew how to manipulate the Federation’s diplomatic eagerness. Likewise, unscrupulous partners today exploit companies’ urgency to enter new markets or secure rare supply chains.

The lesson? Due diligence is not a delay; it is a safeguard. The few extra weeks spent vetting a partner can prevent years of litigation, regulatory penalties, and reputational damage.

“The Mark of Gideon” is not just a quirky Star Trek morality tale. It is a warning for every compliance professional. Without thorough third-party due diligence, you risk waking up in a corporate “replica Enterprise,” surrounded by partners whose true motives only become clear when it’s too late.

Your job as a compliance officer is to ensure the company doesn’t act blindly. By verifying identities, probing motives, cross-checking information, assessing environments, and building exit strategies, you safeguard your organization’s reputation and operational integrity. In short: trust, but verify, especially when the other side is as smooth-talking as the people of Gideon.

Resources:

⁠⁠Excruciatingly Detailed Plot Summary by Eric W. Weisstein⁠⁠

⁠⁠MissionLogPodcast.com⁠⁠

⁠⁠Memory Alpha